HIPAA Rights

Fact sheet

HIPAA: The Health Insurance Portability and Accountability Act of 1996

HIPAA gives you rights about who can look at and receive your medical records and health information.

Who must follow this law?1

  • Most doctors, nurses, pharmacies, hospitals, clinics, nursing homes, outpatient therapists (such as PTs, OTs, and SLPs), durable medical equipment providers, and many other health care providers
  • Health insurance companies, HMOs, and most employer group health plans
  • Certain government programs that pay for health care, such as Medicare and Medicaid

What information is protected?2

  • Information your doctors, nurses, and other health care providers put in your medical record
  • Conversations your doctor has about your care or treatment with nurses and others
  • Information about you in your health insurer’s computer system
  • Billing information about you at your clinic
  • Most other health information about you held by those who must follow this law

You have a right to:3

  •  Ask to see and get a copy of your health records
    •  In most cases, you should receive copies within 30 days; you may have to pay for the cost of copying and mailing
    • You may not have copies of your records when information in your file might endanger yourself or someone else of
  • Ask that incorrect or incomplete information be removed or changed in your health records
    • In most cases, your health records should be updated within 60 days
  • Receive a notice that tells you how your health information may be used and shared
  • Decide if you want to give your permission before your health information can be used or shared for certain purposes, such as for marketing
  • Get a report on when and why your health information was shared for certain purposes
    • You can get this report for free once a year. In most cases you should get the report within 60 days, but it can take an extra 30 days if you are given a reason
  • Ask to be contacted at different places or in a different way such as through your office or by mail
  • Ask that your information not be shared with certain people, groups or companies. However, your provider or health insurer does not have to agree to do what you ask
  • File complaints if you believe your information was used or shared in a way that is not allowed by law or you were not allowed to exercise your rights
    • Complaints can be filed with your provider or health insurer or the U.S. Government (Office of Civil Rights of the U.S. Department of Health and Human Services)

Your health information cannot be used or shared without your written permission unless this law allows it. For example, without your authorization, your provider generally cannot:

  • Give your information to your employer
  • Use or share your information for marketing or advertising purposes
  • Share private notes about your mental health counseling sessions

To make sure that your information is protected in a way that does not interfere with your health care, your information can be used and shared:*

  • For your treatment and care coordination
  • To pay doctors and hospitals for your health care and help run their businesses
  • With your family, relatives, friends or others you identify who are involved with your health care or your health care bills, unless you object
  • To make sure doctors give good care and nursing homes are clean and safe
  • To protect the public’s health, such as by reporting when the flu is in your area
  • To make required reports to the police, such as reporting gunshot wounds

For more information about HIPAA please contact the following agencies:

  1. 45 C.F.R. § 160.102. This is the section of the Code of Federal Regulations (“C.F.R.”), where you can find the rules that describe rules about privacy of medical records and health information.
  2. 45 C.F.R. § 160.103.
  3. 45 C.F.R. §§ 164.520, 164.524, 164.528
  4. 45 C.F.R. § 164.502.

Disability Rights South Carolina is the Protection and Advocacy System for South Carolina. This publication provides legal information but is not intended to be legal advice. As the law may change, please contact Disability Rights South Carolina for updates. Please let us know if you would like this information in an alternative format.

The Protection and Advocacy System for South Carolina. This publication was made possible by funding, in part, by SAMHSA. These contents are solely the responsibility of the grantee and do not necessarily represent the official views of SAMHSA.

Last updated: 2023

Download PDF