HIPAA Privacy Rule Requirements for Covered Entities

A plain-language breakdown of what the Privacy Rule requires, who must comply, and what documentation covered entities need to have in place.

The HIPAA Privacy Rule is the regulatory foundation for how healthcare organizations handle protected health information. It governs who can access PHI, under what circumstances it can be used or disclosed, what rights patients have over their own information, and what documentation covered entities must maintain to demonstrate compliance. For organizations building or refreshing a HIPAA compliance program, understanding the Privacy Rule’s requirements in their full scope is the starting point.

This article provides a comprehensive overview of Privacy Rule requirements for covered entities, organized around the core compliance obligations that OCR evaluates during audits and investigations.

Who the Privacy Rule Applies To

The Privacy Rule applies to covered entities, which fall into three categories under 45 CFR Part 160.

Healthcare providers that transmit health information electronically in connection with covered transactions. This includes physician practices, hospitals, behavioral health providers, dental offices, home health agencies, nursing facilities, pharmacies, and any other provider that submits electronic claims or engages in other covered electronic transactions.

Health plans, including employer-sponsored health plans, health insurance issuers, HMOs, Medicare and Medicaid programs, and other payers that provide or pay the cost of medical care.

Healthcare clearinghouses that process nonstandard health information into standard formats or vice versa.

Business associates — entities that perform functions on behalf of covered entities involving the creation, receipt, maintenance, or transmission of PHI — are subject to many Privacy Rule requirements through their Business Associate Agreements and are directly liable for certain obligations under the HITECH Act. A separate article on Business Associate Agreements covers those requirements in detail.

What Counts as Protected Health Information

Protected health information is individually identifiable health information that is created, received, maintained, or transmitted by a covered entity. It includes information in any form — written, oral, or electronic — that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for health care.

The eighteen identifiers that make health information individually identifiable include names, geographic data smaller than a state, dates other than year, telephone numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate and license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full-face photographs, and any other unique identifying number or code.

Health information from which all eighteen identifiers have been removed using one of two approved de-identification methods is no longer PHI and is not subject to Privacy Rule protections. De-identification is a specific technical and administrative process — simply removing a patient’s name from a record does not de-identify it if other identifying elements remain.

Permitted Uses and Disclosures

The Privacy Rule establishes a general rule that covered entities may not use or disclose PHI except as permitted or required by the rule. Understanding what is permitted — and what requires patient authorization — is the operational core of Privacy Rule compliance.

Treatment, payment, and healthcare operations. The Privacy Rule permits covered entities to use and disclose PHI without patient authorization for treatment, payment, and healthcare operations. Treatment includes the provision, coordination, and management of health care. Payment includes activities related to obtaining reimbursement for health care. Healthcare operations includes quality assessment, competency assurance, legal services, auditing, and other administrative functions necessary to run the organization. These are the broadest categories of permitted activity and cover the vast majority of PHI use in normal healthcare operations.

Required disclosures. Covered entities are required — not merely permitted — to disclose PHI in two circumstances: to the individual who is the subject of the information when they request access or an accounting of disclosures, and to HHS when it is undertaking a compliance investigation, review, or enforcement action.

Other permitted disclosures without authorization. The Privacy Rule permits disclosures without patient authorization in a number of additional circumstances, including disclosures to the individual, uses and disclosures incident to otherwise permitted uses and disclosures, public interest and benefit activities such as public health reporting and law enforcement, and limited data set disclosures for research and public health purposes.

Uses and disclosures requiring authorization. Uses and disclosures that fall outside the permitted categories require a valid written authorization from the patient. Psychotherapy notes, uses of PHI for marketing purposes, and the sale of PHI each require authorization. A valid authorization must include specific elements defined in the Privacy Rule and must be written in plain language.

The Minimum Necessary Standard

When using or disclosing PHI or requesting PHI from another covered entity, covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose. This standard applies to most uses and disclosures — exceptions include disclosures to or requests by a health care provider for treatment purposes, disclosures to the individual, disclosures authorized by the individual, and disclosures required by law.

Covered entities must implement policies and procedures that identify the persons or classes of persons in the workforce who need access to PHI to carry out their duties and the categories and conditions of PHI to which they need access. For routine and recurring requests and disclosures, covered entities should implement standard protocols that limit PHI to what is necessary. For non-routine requests, covered entities must develop criteria for determining the minimum necessary PHI and review requests on an individual basis.

Individual Patient Rights

The Privacy Rule establishes a comprehensive set of rights for individuals with respect to their PHI. Covered entities must have documented policies and procedures for responding to each of these rights and must respond to requests within the timeframes specified in the rule.


📋 Need the actual Privacy Rule documentation? Our Privacy Policies and Procedures Manual Template is a complete, pre-drafted policy manual covering every Privacy Rule requirement — ready to customize for your organization in Microsoft Word.

Right of access. Individuals have the right to inspect and obtain a copy of their PHI in a designated record set. The 2021 updates to the Privacy Rule significantly strengthened this right, reducing the response deadline to 15 calendar days with a possible 15-day extension and requiring covered entities to provide PHI in the format requested by the individual when readily producible. Covered entities may charge only a reasonable, cost-based fee for copies. OCR has made right of access a significant enforcement priority and has brought numerous actions against covered entities for failing to provide timely access.

Right to request amendment. Individuals may request that a covered entity amend PHI in a designated record set. The covered entity may deny the request under certain circumstances but must document both the request and the response. If the amendment is denied, the individual has the right to submit a statement of disagreement.

Right to an accounting of disclosures. Individuals have the right to receive an accounting of certain disclosures of their PHI made by the covered entity in the six years prior to the request. Disclosures for treatment, payment, and healthcare operations are excluded from the accounting requirement, as are disclosures authorized by the individual.

Right to request restrictions. Individuals may request that a covered entity restrict the use or disclosure of their PHI for treatment, payment, or healthcare operations, or restrict disclosures to persons involved in their care. Covered entities are generally not required to agree to restrictions, with one significant exception: if an individual pays out of pocket in full for a service and requests that information about the service not be disclosed to a health plan, the covered entity must agree to that restriction.

Right to receive communications by confidential means. Individuals may request that a covered entity communicate with them about PHI by alternative means or at alternative locations. Healthcare providers must accommodate reasonable requests. Health plans must accommodate requests if the individual states that disclosure of the information could endanger them.

Notice of Privacy Practices Requirements

Covered entities must provide individuals with a written Notice of Privacy Practices describing how the covered entity may use and disclose PHI, the individual’s rights regarding their PHI, the covered entity’s legal duties with respect to PHI, and how to file a complaint with the covered entity and with HHS.

Healthcare providers with direct treatment relationships must provide the notice no later than the first date of service delivery and must make a good faith effort to obtain written acknowledgment of receipt. Health plans must provide the notice at enrollment, within 60 days of a material revision, and at least once every three years. The notice must be posted at the covered entity’s physical service delivery sites and on any website maintained by the covered entity.

Administrative Requirements

Beyond the rules governing PHI use and patient rights, the Privacy Rule imposes a set of administrative requirements that form the structural foundation of a compliant privacy program.

Privacy Officer designation. Covered entities must designate a Privacy Officer responsible for developing and implementing privacy policies and procedures and for receiving complaints. The Privacy Officer does not need to hold that title exclusively but must be a specific, identified individual with defined responsibilities.

Workforce training. Covered entities must train all workforce members on their privacy policies and procedures as necessary and appropriate for them to carry out their functions. Training must occur within a reasonable period of time after a person joins the workforce and whenever there are material changes to policies or procedures that affect the workforce member’s duties. Training must be documented.

Sanctions policy. Covered entities must apply appropriate sanctions against workforce members who fail to comply with privacy policies. The sanctions policy must be documented and communicated to the workforce.

Mitigation. Covered entities must mitigate, to the extent practicable, any harmful effects known to the covered entity resulting from a use or disclosure of PHI in violation of its policies or the Privacy Rule.

Complaint procedures. Covered entities must have documented procedures for individuals to file complaints about the covered entity’s privacy practices and must designate a contact person or office for receiving complaints. Covered entities may not retaliate against any individual for filing a complaint.

Documentation and retention. Covered entities must maintain written privacy policies and procedures and documentation of required activities, including training records, complaint logs, and authorization forms. Documentation must be retained for six years from the date of creation or the date when it was last in effect, whichever is later.

Where Organizations Most Commonly Fall Short

OCR enforcement activity and complaint investigations reveal consistent patterns of Privacy Rule non-compliance. Understanding the most common failure points helps organizations prioritize their compliance efforts.

Failure to provide timely right of access. OCR has made right of access a top enforcement priority and has brought dozens of actions against covered entities for failing to provide individuals with copies of their records within the required timeframe or for charging excessive fees. This is the most common individual complaint category OCR receives.

Impermissible disclosures to unauthorized parties. Disclosures of PHI to family members, employers, or other parties without proper authorization or a permissible basis under the Privacy Rule are among the most frequently reported violations. Workforce training on permissible disclosures is the primary control for this risk.

Missing or outdated Notice of Privacy Practices. Covered entities that have not updated their Notice of Privacy Practices to reflect regulatory changes, or that cannot demonstrate appropriate distribution practices, face compliance exposure that is straightforward to correct with a policy review.

Lack of minimum necessary policies. Organizations that have not implemented documented procedures for limiting PHI access and disclosure to the minimum necessary are at risk both for internal access control failures and for OCR scrutiny when those failures surface in a complaint or breach.

Build Your Privacy Rule Documentation Library

The HIPAA Essentials Library Privacy Bundle includes professionally written, editable templates for every Privacy Rule requirement covered in this article — the HIPAA Privacy Policy, Uses and Disclosures Policy, Minimum Necessary Standard Policy, Patient Rights Policy, Notice of Privacy Practices, Privacy Officer Role Description, Business Associate Agreement, workforce training materials, and more. Every document is written by certified compliance professionals and is ready to customize in Microsoft Word.

For organizations that need complete coverage across Privacy, Security, and Breach Notification requirements, the Compliance Essentials Bundle combines all three documentation libraries into a single, cohesive package. Available immediately after purchase.


Ready to build a compliant Privacy Rule program? Our Privacy Bundle includes all core Privacy Rule policies and procedures, patient rights forms, and supporting documentation — everything your covered entity needs to meet the requirements covered in this article. Templates are delivered in editable Microsoft Word format, available immediately after purchase.