The six patient rights under the HIPAA Privacy Rule are the right to receive a Notice of Privacy Practices, the right to access and obtain a copy of protected health information in a designated record set, the right to request an amendment of protected health information in a designated record set, the right to receive an accounting of certain disclosures of protected health information, the right to request restrictions on certain uses and disclosures of protected health information, and the right to request confidential communications.
The Notice of Privacy Practices right requires covered entities that are subject to the notice requirement to provide a written notice describing permitted uses and disclosures, the covered entity’s legal duties, the individual’s rights, and how to file a complaint. The notice must be provided using the delivery method and timing required for the covered entity’s setting, such as at the point of service in a healthcare provider setting when the rule requires it.
The access right allows an individual to inspect or obtain a copy of protected health information in a designated record set maintained by the covered entity, subject to the HIPAA Privacy Rule conditions and limited grounds for denial. Covered entities must maintain procedures for receiving access requests, verifying identity, meeting the required response timeframes, and producing records in the requested form and format when readily producible.
The amendment right allows an individual to request that the covered entity amend protected health information in a designated record set when the individual believes the information is inaccurate or incomplete. Covered entities must evaluate the request using the HIPAA Privacy Rule standards, act within required timeframes, and apply the required process for approvals, denials, and documentation, including handling a statement of disagreement when applicable.
The accounting of disclosures right allows an individual to obtain a record of certain disclosures of protected health information made by the covered entity during the applicable accounting period, subject to exclusions defined in the HIPAA Privacy Rule. Covered entities must be able to identify disclosures that are subject to accounting and produce an accounting that meets the required content and timing requirements.
The restriction right allows an individual to request limits on certain uses or disclosures for treatment, payment, or healthcare operations and to request limits on disclosures to persons involved in the individual’s care or notification purposes. Covered entities are not required to agree to most requested restrictions, but they must comply with restrictions they accept. The HIPAA Privacy Rule also requires compliance with a requested restriction on disclosures to a health plan for payment or healthcare operations when the individual pays in full out of pocket for the item or service and requests that the information not be disclosed to the health plan.
The confidential communications right allows an individual to request that communications about protected health information be made by an alternative means or at an alternative location. Covered entities must accommodate reasonable requests and implement the request across relevant workflows, including billing and appointment communications, to prevent disclosures that conflict with the approved method.

