HIPAA Patient Rights: 7 Protections Every Patient Should Know
Understand what HIPAA protects, what patients can request, and how privacy rules shape medical information.
HIPAA is the federal framework that limits how health information is used, shared, and protected in the United States. For patients, the law matters because it gives practical rights over medical records, privacy notices, disclosures, and the ability to challenge mistakes or misuse of protected health information.
This guide explains the main HIPAA protections in plain English. It covers what counts as protected health information, what patients can ask for, when providers may disclose information without permission, and what steps are available if privacy rules are ignored.
What HIPAA is designed to do
HIPAA, short for the Health Insurance Portability and Accountability Act, was enacted to improve the portability of health coverage and to protect health information. Today, its privacy and security rules are best known for setting national standards for medical confidentiality and for establishing patient rights over health data.
At its core, HIPAA tries to balance two goals:
- Allowing doctors, hospitals, insurers, and other covered entities to share information when that sharing is needed for care, billing, and operations.
- Preventing unnecessary or unauthorized disclosure of sensitive health information.
The law does not make health information completely untouchable. Instead, it creates rules about when information may be used, what notices patients must receive, and which choices patients can make about their own records.
What information HIPAA protects
HIPAA focuses on protected health information, often called PHI. This generally means identifiable health information that relates to a person’s condition, treatment, or payment for health care, whether it is written, spoken, or electronic.
Examples often include:
- Medical diagnoses and treatment plans
- Billing records and insurance claims
- Lab results and imaging reports
- Appointment records and visit summaries
- Other information that identifies the patient and connects to health care services
HIPAA’s protections are strongest when the information is held by covered entities such as health care providers, health plans, and certain business associates working for them.
The main rights patients get under HIPAA
Patients have several important rights under the Privacy Rule. These rights are not abstract policy statements; they are actionable tools that help patients see, manage, and correct their health information.
| Right | What it generally means |
|---|---|
| Access | Patients can inspect or obtain copies of their health records. |
| Amendment | Patients can request corrections to information in certain records. |
| Privacy notice | Patients must receive a notice explaining privacy practices. |
| Restrictions | Patients can ask for limits on some uses and disclosures. |
| Confidential communications | Patients can request contact in a different way or location. |
| Accounting of disclosures | Patients may request a record of certain disclosures. |
| Complaint rights | Patients can complain if privacy rights are violated. |
Not every request must be granted in every situation, but HIPAA gives patients a formal process to ask and, in many cases, to receive an explanation if a request is denied.
Getting access to medical records
One of the most important HIPAA rights is the right of access. Patients generally have a legal right to inspect and receive copies of information in a designated record set maintained by a covered entity. That often includes many medical and billing records.
This right matters because patients need their records to:
- Understand diagnoses and treatment options
- Check whether a chart contains errors
- Share information with a new doctor or specialist
- Support insurance claims or disability applications
- Monitor ongoing care over time
Patients can usually request records in the format they want if the provider can readily produce them that way. They may also direct the provider to send records to another person or entity, such as a new clinician or a family member assisting with care.
There are limits. Some information may be treated differently, and the law has special rules for certain records or specific circumstances. But as a general rule, access is broad and designed to help patients stay informed.
How amendment requests work
If a patient believes a medical record is inaccurate or incomplete, HIPAA allows a request to amend the record. This is not the same as demanding that a provider erase history. Instead, it is a formal request to correct or supplement a record that may be misleading.
Common reasons for amendment requests include:
- A mistaken medication list
- Incorrect allergy information
- Wrong demographic or contact information
- Incomplete notes that affect treatment decisions
The covered entity must review the request and respond within the required timeframe. If the request is approved, the record is updated. If it is denied, the patient should receive an explanation and may have the opportunity to submit a statement of disagreement that becomes part of the record.
When health information may be shared without permission
HIPAA does not require written permission for every disclosure. Providers and health plans may use or share PHI for certain purposes that the Privacy Rule permits, especially treatment, payment, and health care operations.
Examples of permitted disclosures can include:
- Sending lab results to a treating physician
- Submitting information to an insurer for payment
- Using records internally for quality improvement or compliance functions
- Sharing limited information when legally required
There are also situations where disclosure may occur for public health, safety, law enforcement, or other legally recognized purposes. These exceptions are limited and are meant to serve a broader public interest rather than ordinary convenience.
Outside these permitted categories, a covered entity generally needs the patient’s written authorization before using or disclosing PHI.
Special limits on certain kinds of information
HIPAA gives extra protection to some categories of health information. These rules reflect the sensitivity of certain data and the risk that misuse could affect insurance, employment, or personal privacy.
- Psychotherapy notes: These are treated more strictly than ordinary medical records.
- Sales of PHI: The law generally restricts selling protected health information without authorization.
- Genetic information: Health plans generally may not use or disclose genetic information for underwriting purposes.
These restrictions show that HIPAA is not just about secrecy. It is also about preventing high-risk uses of deeply personal information that could affect a person’s access to care, benefits, or privacy.
What a notice of privacy practices should tell patients
Covered entities must provide a notice of privacy practices. This document explains how health information may be used and disclosed, what patient rights exist, and how patients can complain if something goes wrong.
A useful privacy notice should help patients understand:
- Which uses of information are routine
- Which uses require authorization
- How to request access or amendments
- How to request restrictions or confidential communications
- Who to contact with a privacy concern
Patients should keep this notice with their medical paperwork. It is often the fastest way to find the correct contact person and understand the provider’s internal process.
Can patients ask for restrictions or private communications?
Yes. HIPAA allows patients to request restrictions on certain uses and disclosures and to ask for communications in a more private way. For example, a patient may ask a provider to contact them at work instead of at home, or to send mail to a different address.
Requests for restrictions are not always mandatory for the provider to accept. However, patients can still make the request, and the provider must handle it according to HIPAA’s rules and its own policies.
These rights are especially useful for patients who want to reduce the chance that sensitive information reaches household members, employers, or others who might see routine mail or messages.
Accounting of disclosures and complaint rights
Patients can ask for an accounting of certain disclosures, which is a report showing when and why health information was shared in specific circumstances. This is helpful when a patient wants to trace where information went or determine whether a disclosure was proper.
If a patient believes a provider, insurer, or other covered entity has violated HIPAA, the patient can file a complaint. Complaints may go to the organization itself and, in some cases, to the U.S. Department of Health and Human Services’ Office for Civil Rights.
A good complaint should describe:
- What happened
- When it happened
- Who was involved
- What part of the privacy process failed
- What resolution the patient wants
Filing a complaint is often the correct next step when a request is ignored, a record is mishandled, or health information is disclosed in a way that appears inconsistent with the Privacy Rule.
How HIPAA relates to security and electronic records
HIPAA also reaches beyond paper charts. Electronic health records, messaging systems, and digital billing platforms all create privacy and security risks. For that reason, the law works alongside security standards that require safeguards against unauthorized access, alteration, or loss of electronic protected health information.
Those safeguards can include access controls, audit logging, authentication methods, and policies limiting who may view data. In practice, the privacy rule and security rule work together: one regulates permitted uses and disclosures, while the other helps protect the systems that store the information.
Frequently asked questions about HIPAA patient rights
Can a patient see their full medical record?
In many cases, yes. Patients generally have the right to inspect or receive copies of information in a designated record set, subject to limited exceptions.
Does HIPAA let a patient correct every error?
No. Patients can request an amendment, but the covered entity may deny the request in some cases. If denied, the patient should receive an explanation and may be able to submit a statement of disagreement.
Can a doctor share information with family members?
HIPAA allows some sharing with family members or others involved in care or billing, depending on the circumstances and the patient’s preferences or objections.
What should a patient do if a privacy rule is broken?
The patient can file a complaint with the provider or insurer and, if needed, with the federal government. Keeping copies of letters, emails, and dates can make the complaint more effective.
Does HIPAA stop all sharing of health information?
No. It limits sharing, but it still allows disclosures for treatment, payment, operations, public health, and other specific legal purposes.
Practical steps patients can take
Patients do not need to be privacy experts to use HIPAA effectively. A few simple habits can make a big difference:
- Ask for and keep a copy of the privacy notice.
- Review records for errors as soon as possible.
- Use written requests when asking for access, amendments, or restrictions.
- Keep a record of phone calls, dates, and names.
- Raise concerns quickly if information appears to have been shared improperly.
These steps help patients protect their records and make it easier to prove what was requested if a dispute later arises.
Why HIPAA still matters in everyday care
HIPAA is often discussed as a legal topic, but its real impact is personal. It affects whether a patient can get a copy of a chart, whether an insurer can use data in certain ways, whether a mistake can be corrected, and whether sensitive information stays private.
For patients, the law creates a practical framework for control and accountability. For providers and health plans, it creates a clear set of obligations that shape how information must be handled from the first appointment to the final bill.
References
- Your Rights Under HIPAA — U.S. Department of Health and Human Services. 2024-03-26. https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html
- Summary of the HIPAA Privacy Rule — U.S. Department of Health and Human Services. 2024-12-20. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
- HIPAA Patient Rights Explained — Compliancy Group. 2026-01-01. https://compliancy-group.com/hipaa-patient-rights/
- How HIPAA Protects Patient Privacy — St. Jude Children’s Research Hospital. 2025-01-01. https://www.stjude.org/care-treatment/patient-families/new-patients/how-hipaa-protects-patient-privacy.html
- HIPAA Privacy Rule and Patient Rights Policy — Columbia University. 2024-01-01. https://universitypolicies.columbia.edu/content/hipaa-privacy-rule-and-patient-rights-policy
Read full bio of Sneha Tete





