HIPAA Privacy Rule: Access, Consent and Rights

HIPAA Privacy Rule permitted disclosures and patient rights

The HIPAA Privacy Rule governs who may see protected health information, what patients can demand about their own records, and when consent is required.

  • Glossary
  • HIPAA

The short answer

The HIPAA Privacy Rule sets national standards for the use and disclosure of protected health information in any form, paper, electronic or spoken. It defines what a covered entity may do with PHI without asking, what needs written authorisation, and the rights individuals hold over their own records. Where the Security Rule is about protecting data, the Privacy Rule is about permission.

A useful split: the Privacy Rule asks whether you should have the data. The Security Rule asks whether you are protecting what you have.

Permitted uses and disclosures

No authorisation Treatment Payment Healthcare operations The TPO exception Chance to object Facility directories Telling family or friends Disaster relief Informal agreement is enough Written authorisation Marketing Sale of PHI Most psychotherapy notes Signed, specific, revocable Public interest disclosures, such as public health reporting and court orders, sit alongside these as separate permissions.
Swipe to see the full diagram. Treatment, payment and operations is the exception most day-to-day disclosures rely on.

When authorisation is required

Anything outside the permitted categories needs a signed authorisation. To be valid it has to be specific about what is disclosed and to whom, state an expiry, explain the right to revoke, and be written plainly. A blanket consent buried in terms of service does not qualify.

ActivityAuthorisation needed?
Sending records to a specialist for treatmentNo
Submitting a claim to an insurerNo
Quality improvement and internal auditNo, healthcare operations
Marketing a third-party product to patientsYes
Selling PHI to a data brokerYes, and the authorisation must state payment is involved
Research using identifiable recordsYes, unless waived by an IRB or privacy board

Individual rights

RightWhat it means in practice
AccessA copy of their records, generally within 30 days, in the electronic format requested where feasible
AmendmentAsk for corrections. You may refuse, but must record the disagreement
Accounting of disclosuresA list of certain disclosures made over the previous six years
RestrictionRequest limits on use. Mandatory when they paid out of pocket in full
Confidential communicationsAsk to be contacted by a specific channel or at a specific address
Notice of privacy practicesA plain-language notice of how PHI is used and what rights apply

The right of access drives most enforcement

Failing to provide records on time is among the most frequently penalised HIPAA violations, and the fines are routine rather than exceptional. If you build health software, an export path for a patient’s full record is a compliance feature, not a nice-to-have.

What compliance looks like

Role-based access

People see only what their job requires, which is the minimum necessary standard made operational.

A privacy officer

A named individual accountable for the policies and for handling complaints.

Records of disclosures

Logging that can answer an accounting request without a manual reconstruction.

How Osto supports it

Privacy is enforced through access. Osto provides identity and access management, role-based control and audit logging that records who reached which record and when, plus file access DLP to catch PHI leaving through channels it should not. The compliance platform maps those controls to HIPAA and generates the policy documentation the rule expects.

Free security assessment

Privacy enforced through access, not policy alone

Role-based access, audit logging and DLP turn a privacy policy into something you can actually demonstrate.

Get a free security assessment Book a platform walkthrough

Access recorded · Policies generated · One platform, everything

Frequently asked questions

What is the HIPAA Privacy Rule?

The national standard governing use and disclosure of protected health information in any form. It defines what covered entities may do with PHI without authorisation, what requires consent, and the rights individuals hold over their records.

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule covers PHI in every form and governs permission: who may access it and for what. The Security Rule covers electronic PHI only and governs protection: the safeguards that keep it secure.

What is the TPO exception?

Treatment, payment and healthcare operations. Disclosures for these three purposes are permitted without patient authorisation, which covers most routine sharing between providers and payers.

How long do you have to respond to a records request?

Generally 30 days, with one 30-day extension available if the individual is notified of the reason. Delays are among the most commonly enforced violations.

Does the Privacy Rule apply to business associates?

Partly. Business associates are bound by the use and disclosure limits in their BAA and by the minimum necessary standard, and must support covered entities in honouring individual rights.