Privacy Protection Request, v1.0

Specifies that a covered entity must have policies and procedures to permit an individual to request that the covered entity restrict uses or disclosures of protected health information about the individual, and disclosures to a family member or other designated person.
An indivdual's rights to request privacy protection for his/her PHI must be allowed by an organization's policies and procedures, subject to certain conditions and restrictions, such as emergency treatment, as described in the referenced citation.
Due to the complexity of the rule as originally written, the assessor must use the full text of the citation section to perform this assessment.

Assessment Step

1
Privacy Protection Request for PHI (PrivacyProtectionRequestforPHI)
Does the covered entity have policies and procedures to permit an individual to request that the covered entity restrict uses or disclosures of protected health information about the individual to carry out treatment, payment, or health care operations; and disclosures to a family member, other relative, or a close personal friend of the individual, or any other person identified by the individual, as provided by the referenced citation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

Request Privacy Protection
The covered entity must have policies and procedures to permit an individual to request that the covered entity restrict uses or disclosures of protected health information about the individual to carry out treatment, payment, or health care operations; and disclosures to a family member, other relative, or a close personal friend of the individual, or any other person identified by the individual, as provided by the referenced citation.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.522