Privacy Notice Required Content - Individual Rights, v1.0

Specifies requirements for part of the contents of the privacy notice for individuals. The privacy notice must contain a statement of the individual's rights with respect to PHI and a brief description of how the individual may exercise these rights.

Assessment Step

1
Content of Notice (ContentofNotice)
Does the covered entity's privacy notice contain a statement of the individual's rights with respect to protected health information and a brief description of how the individual may exercise these rights? These rights include the right to request restrictions on certain uses and disclosures of PHI, to receive confidential communications of PHI, to inspect and copy PHI, to amend PHI, to receive an accounting of disclosures of PHI, and the right of an individual, including an individual who has agreed to receive the privacy notice electronically, to obtain a paper copy of the privacy notice.
Artifact
PrivacyNotice
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.), including the actual notice of privacy practices, that support the assessor's response to this assessment step.
The criteria apply to descriptions of uses and disclosures of protected health information in the privacy notice provided to individuals by the covered entity.


The following are exceptions to an individual's right to adequate notice of the uses and disclosures of PHI that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to PHI:

  1. Group health plans that do not create or receive PHI other than summary health information (see Section 164.520(a)(2) for additional details); and
  2. An inmate does not have a right to notice under this section, and the requirements of this section do not apply to a correctional institution that is a covered entity.

Conformance Criteria (1)

Include Required Content
The covered entity's privacy notice must contain a statement of the individual's rights with respect to protected health information and a brief description of how the individual may exercise these rights. These rights include the right to request restrictions on certain uses and disclosures of PHI, to receive confidential communications of PHI, to inspect and copy PHI, to amend PHI, to receive an accounting of disclosures of PHI, and the right of an individual, including an individual who has agreed to receive the privacy notice electronically, to obtain a paper copy of the privacy notice.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.520(b)(1)(iv)