{"id":838,"date":"2026-08-17T05:03:37","date_gmt":"2026-08-17T05:03:37","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=838"},"modified":"2026-08-17T05:04:22","modified_gmt":"2026-08-17T05:04:22","slug":"hipaa-privacy-rule","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/hipaa-privacy-rule\/","title":{"rendered":"HIPAA Privacy Rule: Access, Consent and Rights"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: HIPAA PRIVACY RULE\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">The HIPAA Privacy Rule governs who may see protected health information, what patients can demand about their own records, and when consent is required.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>The HIPAA Privacy Rule sets national standards for the use and disclosure of protected health information in any form, paper, electronic or spoken. It defines what a covered entity may do with PHI without asking, what needs written authorisation, and the rights individuals hold over their own records. Where the Security Rule is about protecting data, the Privacy Rule is about permission.<\/p>\n<\/div>\n\n<p>A useful split: the Privacy Rule asks whether you should have the data. The <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa-security-rule\/\">Security Rule<\/a> asks whether you are protecting what you have.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#permitted\">Permitted uses and disclosures<\/a><\/li>\n    <li><a href=\"#auth\">When authorisation is required<\/a><\/li>\n    <li><a href=\"#rights\">Individual rights<\/a><\/li>\n    <li><a href=\"#implement\">What compliance looks like<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports it<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"permitted\">Permitted uses and disclosures<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 220\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Three tiers of disclosure: permitted without authorisation, permitted with opportunity to object, and requiring written authorisation.\">\n  <rect x=\"12\" y=\"34\" width=\"238\" height=\"132\" rx=\"16\" fill=\"#e3f0e9\"\/>\n  <text x=\"131\" y=\"62\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">No authorisation<\/text>\n  <text x=\"131\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Treatment<\/text>\n  <text x=\"131\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Payment<\/text>\n  <text x=\"131\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Healthcare operations<\/text>\n  <text x=\"131\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-style=\"italic\" fill=\"#3a6f5d\">The TPO exception<\/text>\n\n  <rect x=\"261\" y=\"34\" width=\"238\" height=\"132\" rx=\"16\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"62\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#a2603a\">Chance to object<\/text>\n  <text x=\"380\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Facility directories<\/text>\n  <text x=\"380\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Telling family or friends<\/text>\n  <text x=\"380\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Disaster relief<\/text>\n  <text x=\"380\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-style=\"italic\" fill=\"#a2603a\">Informal agreement is enough<\/text>\n\n  <rect x=\"510\" y=\"34\" width=\"238\" height=\"132\" rx=\"16\" fill=\"#1c267a\"\/>\n  <text x=\"629\" y=\"62\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Written authorisation<\/text>\n  <text x=\"629\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Marketing<\/text>\n  <text x=\"629\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Sale of PHI<\/text>\n  <text x=\"629\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Most psychotherapy notes<\/text>\n  <text x=\"629\" y=\"150\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-style=\"italic\" fill=\"#b9c1e6\">Signed, specific, revocable<\/text>\n\n  <text x=\"380\" y=\"200\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Public interest disclosures, such as public health reporting and court orders, sit alongside these as separate permissions.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Treatment, payment and operations is the exception most day-to-day disclosures rely on.<\/figcaption>\n<\/figure>\n\n<h2 id=\"auth\" class=\"c-sage\">When authorisation is required<\/h2>\n\n<p>Anything outside the permitted categories needs a signed authorisation. To be valid it has to be specific about what is disclosed and to whom, state an expiry, explain the right to revoke, and be written plainly. A blanket consent buried in terms of service does not qualify.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Activity<\/th><th>Authorisation needed?<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Sending records to a specialist for treatment<\/td><td>No<\/td><\/tr>\n    <tr><td>Submitting a claim to an insurer<\/td><td>No<\/td><\/tr>\n    <tr><td>Quality improvement and internal audit<\/td><td>No, healthcare operations<\/td><\/tr>\n    <tr><td>Marketing a third-party product to patients<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Selling PHI to a data broker<\/td><td>Yes, and the authorisation must state payment is involved<\/td><\/tr>\n    <tr><td>Research using identifiable records<\/td><td>Yes, unless waived by an IRB or privacy board<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"rights\" class=\"c-apri\">Individual rights<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Right<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Access<\/strong><\/td><td>A copy of their records, generally within 30 days, in the electronic format requested where feasible<\/td><\/tr>\n    <tr><td><strong>Amendment<\/strong><\/td><td>Ask for corrections. You may refuse, but must record the disagreement<\/td><\/tr>\n    <tr><td><strong>Accounting of disclosures<\/strong><\/td><td>A list of certain disclosures made over the previous six years<\/td><\/tr>\n    <tr><td><strong>Restriction<\/strong><\/td><td>Request limits on use. Mandatory when they paid out of pocket in full<\/td><\/tr>\n    <tr><td><strong>Confidential communications<\/strong><\/td><td>Ask to be contacted by a specific channel or at a specific address<\/td><\/tr>\n    <tr><td><strong>Notice of privacy practices<\/strong><\/td><td>A plain-language notice of how PHI is used and what rights apply<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The right of access drives most enforcement<\/p>\n  <p>Failing to provide records on time is among the most frequently penalised HIPAA violations, and the fines are routine rather than exceptional. If you build health software, an export path for a patient&#8217;s full record is a compliance feature, not a nice-to-have.<\/p>\n<\/div>\n\n<h2 id=\"implement\" class=\"c-plum\">What compliance looks like<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Role-based access<\/p>\n    <p>People see only what their job requires, which is the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/minimum-necessary-standard\/\">minimum necessary standard<\/a> made operational.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">A privacy officer<\/p>\n    <p>A named individual accountable for the policies and for handling complaints.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Records of disclosures<\/p>\n    <p>Logging that can answer an accounting request without a manual reconstruction.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto supports it<\/h2>\n\n<p>Privacy is enforced through access. Osto provides <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">identity and access management<\/a>, role-based control and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">audit logging<\/a> that records who reached which record and when, plus <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">file access DLP<\/a> to catch PHI leaving through channels it should not. The compliance platform maps those controls to HIPAA and generates the policy documentation the rule expects.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Privacy enforced through access, not policy alone<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Role-based access, audit logging and DLP turn a privacy policy into something you can actually demonstrate.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Access recorded &middot; Policies generated &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the HIPAA Privacy Rule?<\/summary>\n  <p>The national standard governing use and disclosure of protected health information in any form. It defines what covered entities may do with PHI without authorisation, what requires consent, and the rights individuals hold over their records.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between the Privacy Rule and the Security Rule?<\/summary>\n  <p>The Privacy Rule covers PHI in every form and governs permission: who may access it and for what. The Security Rule covers electronic PHI only and governs protection: the safeguards that keep it secure.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the TPO exception?<\/summary>\n  <p>Treatment, payment and healthcare operations. Disclosures for these three purposes are permitted without patient authorisation, which covers most routine sharing between providers and payers.<\/p>\n<\/details>\n\n<details>\n  <summary>How long do you have to respond to a records request?<\/summary>\n  <p>Generally 30 days, with one 30-day extension available if the individual is notified of the reason. Delays are among the most commonly enforced violations.<\/p>\n<\/details>\n\n<details>\n  <summary>Does the Privacy Rule apply to business associates?<\/summary>\n  <p>Partly. Business associates are bound by the use and disclosure limits in their BAA and by the minimum necessary standard, and must support covered entities in honouring individual rights.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> HIPAA Security Rule &middot; HIPAA Breach Notification Rule &middot; PHI &middot; Covered Entity &middot; Minimum Necessary Standard &middot; Business Associate Agreement<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The HIPAA Privacy Rule governs who may see protected health information, what patients can demand about their own records, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":839,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[332,333,334],"class_list":["post-838","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-hipaa-privacy-rule","tag-patient-rights-hipaa","tag-privacy-rule"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/838","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=838"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/838\/revisions"}],"predecessor-version":[{"id":840,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/838\/revisions\/840"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/839"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=838"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=838"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=838"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}