Final Standards for
Privacy of Individually Identifiable Health Information
§ 164.522 Rights to request privacy protection
for protected health information.
(a)
- Standard: right of an individual to request
restriction of uses and disclosures.
- A covered entity must permit an individual
to request that the covered entity restrict:
- Uses or disclosures of protected health
information about the individual to carry
out treatment, payment, or health care operations;
and
- Disclosures permitted under §
164.510(b).
- A covered entity is not required to agree to
a restriction.
- A covered entity that agrees to a restriction
under paragraph (a)(1)(i) of this section may
not use or disclose protected health information
in violation of such restriction, except that,
if the individual who requested the restriction
is in need of emergency treatment and the restricted
protected health information is needed to provide
the emergency treatment, the covered entity may
use the restricted protected health information,
or may disclose such information to a health care
provider, to provide such treatment to the individual.
- If restricted protected health information is
disclosed to a health care provider for emergency
treatment under paragraph (a)(1)(iii) of this
section, the covered entity must request that
such health care provider not further use or disclose
the information.
- A restriction agreed to by a covered entity
under paragraph (a) of this section, is not effective
under this subpart to prevent uses or disclosures
permitted or required under §§ 164.502(a)(2)(i),
164.510(a) or 164.512.
- Implementation specifications: terminating a restriction.
A covered entity may terminate its agreement to a
restriction, if :
- The individual agrees to or requests the termination
in writing;
- The individual orally agrees to the termination
and the oral agreement is documented; or
- The covered entity informs the individual that
it is terminating its agreement to a restriction,
except that such termination is only effective
with respect to protected health information created
or received after it has so informed the individual.
- Implementation specification: documentation. A covered
entity that agrees to a restriction must document
the restriction in accordance with §
164.530(j).
(b)
- Standard: confidential communications requirements.
- A covered health care provider must permit individuals
to request and must accommodate reasonable requests
by individuals to receive communications of protected
health information from the covered health care
provider by alternative means or at alternative
locations.
- A health plan must permit individuals to request
and must accommodate reasonable requests by individuals
to receive communications of protected health
information from the health plan by alternative
means or at alternative locations, if the individual
clearly states that the disclosure of all or part
of that information could endanger the individual,
- Implementation specifications: conditions on providing
confidential communications.
- A covered entity may require the individual
to make a request for a confidential communication
described in paragraph (b)(1) of this section
in writing.
- A covered entity may condition the provision
of a reasonable accommodation on:
- When appropriate, information as to how
payment, if any, will be handled; and
- Specification of an alternative address
or other method of contact.
- A covered health care provider may not require
an explanation from the individual as to the basis
for the request as a condition of providing communications
on a confidential basis.
- A health plan may require that a request contain
a statement that disclosure of all or part of
the information to which the request pertains
could endanger the individual.
|
|
|