Category: HIPAA Privacy

  • OCR Settles Multiple Complaints Regarding Patient Right of Access

    by Jay Hodes โ€“ President, Colington Consulting

    In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would โ€œnot impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.โ€ The April notice specified OCR โ€œwill not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.โ€

    It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.

    Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.

    As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individualsโ€™ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.

    The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.

    The OCR listserv email regarding these cases states โ€œOCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.โ€ Message sending indeed as OCRโ€™s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”

    Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Important Notice Regarding Individualsโ€™ Right of Access to Health

    On January 28, the HHS Office for Civil Rights issued an important notice regarding an individualsโ€™ right of access to health records and more specifically, when a request is made to transmit medical records to a third party.

    Here is the full transcript of the notice:

    On January 25, 2013, HHS published a final rule entitled โ€œModifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules.โ€ (2013 Omnibus Rule). A portion of that rule was challenged in federal court, specifically provisions within 45 C.F.R. ยง164.524, that cover an individualโ€™s access to protected health information. On January 23, 2020, a federal court vacated the โ€œthird-party directiveโ€ within the individual right of access โ€œinsofar as it expands the HITECH Actโ€™s third-party directive beyond requests for a copy of an electronic health record with respect to [protected health information] of an individual . . . in an electronic format.โ€ Additionally, the fee limitation set forth at 45 C.F.R. ยง 164.524(c)(4) will apply only to an individualโ€™s request for access to their own records, and does not apply to an individualโ€™s request to transmit records to a third party.

    The right of individuals to access their own records and the fee limitations that apply when exercising this right are undisturbed and remain in effect. OCR will continue to enforce the right of access provisions in 45 C.F.R. ยง 164.524 that are not restricted by the court order. A copy of the court order in Ciox Health, LLC v. Azar, et al., No. 18-cv-0040 (D.D.C. January 23, 2020), may be found at https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51.

    What Healthcare Providers Should Know

    The HIPAA Privacy Rule permits a covered entity to impose a reasonable, cost-based fee to provide the individual (or the individualโ€™s personal representative) with a copy of the individualโ€™s PHI, or to direct the copy to a designated third party. The fee may include only the cost of certain labor, supplies, and postage:

    1. Labor for copying the PHI requested by the individual, whether in paper or electronic form.ย  Labor for copyingย includes onlyย labor for creating and delivering the electronic or paper copy in the form and format requested or agreed upon by the individual, once the PHI that is responsive to the request has been identified, retrieved or collected, compiled and/or collated, and is ready to be copied.ย  Labor for copyingย does not includeย costs associated with reviewing the request for access; or searching for and retrieving the PHI, which includes locating and reviewing the PHI in the medical or other record, and segregating or otherwise preparing the PHI that is responsive to the request for copying.
    2. Supplies for creating the paper copy (e.g.,ย  paper, toner) or electronic media (e.g., CD or USB drive)ย ifย theย  individual requests that the electronic copy be provided on portable media.ย  However, a covered entity mayย notย require anย  individual to purchase portable media; individuals have the right to have theirย  PHI e-mailed or mailed to them upon request.
    3. Labor to prepare an explanation or summary of the PHI, if the individualย in advanceย both chooses to receive an explanation or summaryย andย agrees to the fee that may be charged.
    4. Postage, when the individual requests that the copy, or the summary or explanation, be mailed.

    Thus, costs associated with updates to or maintenance of systems and data, capital for data storage and maintenance, labor associated with ensuring compliance with HIPAA (and other applicable law) in fulfilling the access request (e.g., verification, ensuring only information about the correct individual is included, etc.) and other costs not included above,ย even if authorized by State law, areย not permitted for purposes of calculating the fees that can be charged to individuals.ย  See 45 CFR 164.524(c)(4).

    Further, while the Privacy Rule permits the limited fee described above, covered entities should provide individuals who request access to their information with copies of their PHI free of charge.ย  While covered entities should forgo fees for all individuals, not charging fees for access is particularly vital in cases where the financial situation of an individual requesting access would make it difficult or impossible for the individual to afford the fee.ย  Providing individuals with access to their health information is a necessary component of delivering and paying for health care. We will continue to monitor whether the fees that are being charged to individuals are creating barriers to this access, will take enforcement action where necessary, and will reassess as necessary the provisions in the Privacy Rule that permit these fees to be charged.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • HIPAA Privacy Rule โ€“ What is Confusing About the Requirements

    by Jay Hodes – President, Colington Consulting

    A great deal of attention is given to protecting electronic health records. The HIPAA Security Rule defines all the administrative, technical and physical safeguards that must be in place in order to be compliant. But, what about paper documents containing protected health information (PHI), required verbal conversations that need to take place in a healthcare practice and marketing?

    These topics are all covered in the HIPAA Privacy Rule. The rule clearly defines the โ€œwhatโ€ of protected health information in terms of health care providersโ€™ responsibilities, when it comes to patient privacy.ย  Although the Privacy Rule includes what is covered in terms of electronic transfers of PHI, the rule is also very extensive about the handling of PHI. Let me address a couple important sections of the Privacy Rule where many providers struggle in understanding what is and is not required. When it comes to uses and disclosures of protected health information (PHI), in general, a health care provider does not need patient authorization to:

    • Use or disclose PHI for treatment, payment or health care operations.
    • Use or disclose PHI for the treatment activities of another health care provider.
    • Disclose PHI to another covered entity or health care provider for the payment of the entity that receives the information.
    • Disclose PHI to another covered entity for health care operations activities of the entity that receives the information, if both entities have a relationship with the individual and the disclosure is for the purpose of conducting quality assessment and improvement activities, reviewing the competence or qualifications of health care professionals or for fraud and abuse detection or compliance.

    However, the heath care provider must still provide the patient with its Notice of Privacy Practices (NPP) and make a good faith effort to obtain written acknowledgement that the patient received the NPP.

    A health care practice must always be aware of the minimum necessary standard. The standard, a key protection of the HIPAA Privacy Rule, is derived from confidentiality codes and practices in common use today. It is based on sound, current practice that protected health information should not be used or disclosed when it is not necessary to satisfy a particular purpose or carry out a function. The minimum necessary standard requires health care providers to evaluate their practices and enhance safeguards, as needed, to limit unnecessary or inappropriate access to and disclosure of protected health information. The Privacy Ruleโ€™s requirements for the minimum necessary standard are designed to be sufficiently flexible to accommodate the various circumstances of any covered entity.

    Another confusing area of the HIPAA Privacy Rule concerns marketing. The Privacy Rule defines โ€œmarketingโ€ as making โ€œa communication about a product or service that encourages recipients of the communication to purchase or use the product or service.โ€ Generally, if the communication is โ€œmarketing,โ€ then the communication can occur only if the health care provider first obtains an individualโ€™s authorization.

    The Privacy Rule exceptions to the definition of marketing fall into three categories:

    • A communication is not โ€œmarketingโ€ if it is made to describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication, including communications about:
    • The entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and
    • Health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits.

    This exception to the marketing definition permits communications by a health care providerโ€™s own products or services.

    1. A communication is not โ€œmarketingโ€ if it is made for treatment of the individual.
    2. A communication is not โ€œmarketingโ€ if it is made for case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers or settings of care to the individual.
    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • What is the HIPAA Privacy Rule?

    Part of the Heath Insurance Portability and Accountability Act (HIPAA) that became law in 1996, the HIPAA Privacy Rule defined the part of the law that protects patientsโ€™ protected health information (PHI). Among organizations this rule applies to are health plans and providers who use electronic medical records (EMR) either internally or to invoice insurance companies. The Privacy Rule defines safeguards to protect patient privacy, whether it is disclosed intentionally or not. What does that mean for you?

    The Standards for Privacy of Individually Identifiable Health Information (โ€œPrivacy Ruleโ€) established, for the first time, a set of national standards for the protection of certain health information. Before 1996, states had their own laws in place for patient information. Laws could vary in stringency and penalties for non-compliance were not equally severe. There were also some federal privacy laws in place, but it was a gray area, especially since the use of computers for holding the data of patient files or sending it to insurance companies for claims was not at all widespread until the late 90s.

    With new uses for electronic media, storage, and transmission, there was a need for new rules that every healthcare practitioner or institution would adhere to. Some doctors or health insurance companies were selling and distributing patientsโ€™ private health histories or medical records. HIPAA changed the rules to protect patient privacy; there must be a valid medical reason to transmit patient information and the patient must be informed of the intent and give permission in each case. It also mandates that a patient may access his or her own medical files at any time.

    What is protected health information?

    The Privacy Rule protects all individually identifiable health information (IIHI) held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information protected health information (PHI). This includes:

    ยทย ย ย ย ย ย  the individualโ€™s past, present or future physical or mental health orย condition

    ยทย ย ย ย ย ย  the provision of health care to the individual, or

    ยทย ย ย ย ย ย  the past, present, or future payment for the provision of health care to theย individual

    and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. IIHI includes many common identifiers such as name, address, birth date, Social Security Number, and not so common identifiers like IP or URL addresses.

    Who needs to comply?

    The Privacy Rule, as well as all the Administrative Simplification rules, apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form.ย  This includes Business Associates of those entities, which is any company or organization that may have access to PHI in the course of its business with the healthcare provider.ย  Business Associates must also comply with HIPAA rules. The laws regarding compliance are complex and the procedures and policies that are required should be reviewed every year. Even the smallest HIPAA violation may result in initiating a compliance investigation which can lead to civil and criminal penalties or the need for government imposes corrective action plans.ย  The government will not except any excuses for failing to comply with HIPAA.

    How to protect yourself

    Navigating and complying with HIPAA Privacy Rules takes serious resources. Rules can and do change as the landscape of electronic security evolves. Protecting patient data requires a forward-thinking and broad perspective. To mitigate risk of a data breach or accidental non-compliance, it makes sense to trust experienced experts who will guide you in all aspects of HIPAA compliance.

    Colington Consultants will help you implement and maintain a comprehensive HIPAA compliance program. We offer cost-effective consulting services for HIPAA Security and Privacy Rule compliance.ย Call us atย 844.740.7100ย today to schedule a free, initial consultation.

    This blog was previously posted May 11, 2018