Skip to main content
Category: Individual Rights

Alternative Means of Communication

Simply put

Under the HIPAA Privacy Rule, this generally refers to an individual's right to ask a healthcare provider or health plan to contact them in a particular way or at a particular location. For example, a patient might request that appointment reminders be sent to a work address rather than a home address, or by phone rather than by mail, to protect their privacy. This term concerns how protected health information reaches a patient, not the assistive tools sometimes called 'alternative communication' in clinical or educational settings.

Formal definition

In the HIPAA context, an alternative means of communication (more precisely, the right to request confidential communications) is an individual right under the Privacy Rule that allows a person to request that a covered entity communicate protected health information (PHI) by alternative means or at alternative locations. Health care providers are generally required to accommodate reasonable requests without requiring the individual to state a reason, while health plans generally must accommodate reasonable requests where the individual clearly states that disclosure could endanger them. This is distinct from the Security Rule's technical safeguards for electronic PHI and is separate from the unrelated clinical or educational concept of 'augmentative and alternative communication (AAC).' Practitioners should note that specific conditions, limits, and permitted circumstances for imposing requirements attach to this right and should be verified against the current text of the Privacy Rule; state law or other frameworks may impose additional requirements.

Why it matters

The right to request confidential communications is one of the ways the HIPAA Privacy Rule gives individuals a measure of control over how their protected health information (PHI) reaches them. For many patients, the concern is not whether information is disclosed at all, but where and how it arrives. A patient may not want a diagnosis, appointment reminder, or billing statement sent to a shared home address, a family phone, or an employer's mailbox. Accommodating a reasonable request to communicate by an alternative means or at an alternative location can therefore be a meaningful protection against unwanted disclosure to household members, employers, or others.

For covered entities, this right carries operational obligations that differ depending on the type of entity. Health care providers are generally required to accommodate reasonable requests without requiring the individual to explain why, whereas health plans generally must accommodate reasonable requests where the individual clearly states that the disclosure could endanger them. Because the specific conditions, limits, and circumstances under which a covered entity may impose requirements attach to this right, organizations should verify the current text of the Privacy Rule rather than rely on general summaries.

It is important not to confuse this HIPAA right with the unrelated clinical and educational concept of augmentative and alternative communication (AAC), which describes tools and strategies that help individuals with severe communication impairments. Despite the similar wording, AAC concerns assistive communication for people with speech difficulties and has no bearing on the Privacy Rule right to request confidential communications. Practitioners should also note that state law or other frameworks may impose additional or stricter requirements beyond HIPAA.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers are typically responsible for establishing and maintaining policies and procedures that allow the organization to receive, evaluate, and accommodate requests for confidential communications. They should ensure workflows distinguish provider obligations from health plan obligations and verify the applicable requirements against the current Privacy Rule text.
Health Care Providers and Front-Office Staff
Providers and staff who handle appointment reminders, billing communications, and patient outreach need to recognize and honor reasonable requests to be contacted by an alternative means or at an alternative location. Generally, providers must accommodate such requests without requiring the patient to state a reason.
Health Plans
Health plans have a related but distinct obligation. They generally must accommodate reasonable requests for confidential communications where the individual clearly states that disclosure of PHI could endanger them, and they should confirm the specific conditions permitted under the Privacy Rule.
Compliance and Legal Professionals
Compliance and legal staff advising healthcare organizations should map how this right interacts with organizational communication systems and should flag where state law or other frameworks may impose additional obligations beyond HIPAA. They should also ensure this Privacy Rule right is not conflated with the unrelated clinical concept of augmentative and alternative communication.

Inside Alternative Means of Communication

Right to Request Confidential Communications
Under the HIPAA Privacy Rule, individuals generally have the right to request that a covered entity communicate PHI with them by alternative means or at alternative locations. This is a component of the Privacy Rule, which covers PHI in all forms, not solely ePHI.
Alternative Means
Refers to the method or channel of communication requested by the individual, such as receiving communications by email rather than by phone, or by mail rather than in person. The individual specifies how they wish to be contacted.
Alternative Location
Refers to where communications are directed, such as a work address instead of a home address, or an alternate mailing address, so that PHI is not disclosed at a location the individual considers sensitive.
Covered Entity Accommodation Obligation
Health care providers generally must accommodate reasonable requests for confidential communications and typically may not require an explanation of the reason for the request. Health plans generally must accommodate reasonable requests when the individual clearly states that disclosure could endanger them, subject to conditions in the applicable regulatory text.
Reasonableness and Conditions
Covered entities may generally impose reasonable conditions on accommodating requests, such as how the individual will handle payment and specifying an alternative address or method of contact. Specific conditions should be verified against the current regulation.
Scope Boundary
This right addresses how and where a covered entity communicates PHI to the individual. It is distinct from the right to request restrictions on uses and disclosures, and it does not by itself limit the content of what may be disclosed for permitted purposes.

Common questions

Answers to the questions practitioners most commonly ask about Alternative Means of Communication.

Does an individual have to explain why they want to receive communications by alternative means or at an alternative location?
Generally, no. Under the Privacy Rule's provisions on confidential communications, covered entities are typically required to accommodate reasonable requests without requiring the individual to state a reason. In many cases a health plan may condition accommodation on the individual stating that disclosure could endanger them, but for health care providers a reason generally is not required. Requirements can vary, and readers should verify the specific conditions against the current regulatory text, as state law may impose additional obligations.
Is accommodating an alternative means of communication an optional courtesy that a covered entity can decline at will?
No. Accommodating reasonable requests is a Privacy Rule requirement, not a discretionary courtesy. A covered entity generally cannot refuse a reasonable request outright, though it may impose reasonable conditions, such as specifying how the request must be made or addressing how payment is handled. What qualifies as reasonable, and the permissible conditions, should be confirmed against the current regulation.
How should a covered entity document and track a patient's request for alternative communications?
As a practical matter, organizations typically capture the request in the individual's record or in a system field that flags the preferred contact method and location, so that staff acting on the record honor it consistently. Because this is a Privacy Rule obligation covering PHI in all forms, tracking should extend beyond electronic systems to mailed statements, phone contact, and appointment reminders. Specific documentation retention practices should align with current regulatory recordkeeping expectations.
What conditions may a covered entity reasonably attach to accommodating these requests?
Covered entities may generally require that requests be made in writing, specify an alternative address or method of contact, and address how payment for services will be handled when a request affects billing communications. These conditions must be reasonable and cannot be used to effectively deny a legitimate request. The precise permissible conditions differ between providers and health plans, so readers should confirm against the applicable provisions of the current rule.
Which staff and systems need to be aware of an alternative communication request to keep it from failing in practice?
Because a single request can affect front-desk staff, billing and claims teams, clinical staff sending reminders, and any automated messaging systems, accommodation typically requires that the preference be visible across those functions. Since the Privacy Rule reaches oral, paper, and electronic PHI, a request honored only in the electronic record but not in mailed correspondence would generally represent an incomplete accommodation. Workforce training on these procedures is a common supporting control.
How does an alternative communication request interact with communications sent to a health plan subscriber versus an individual member?
This is a frequent implementation challenge, particularly where explanations of benefits or billing statements are directed to a policyholder rather than the individual who received care. Health plans generally must accommodate reasonable requests when disclosure of the information could endanger the individual, but the mechanics of separating member-level communications can be complex and may intersect with state confidentiality laws. Organizations should evaluate these scenarios against both the current Privacy Rule provisions and any applicable state requirements.

Common misconceptions

A covered entity must honor any request for alternative communication no matter what.
Covered entities generally must accommodate reasonable requests, and may impose reasonable conditions such as requiring an alternative address or information about payment. The obligation applies to reasonable requests, and health plans and providers are subject to differing conditions in the applicable regulatory text, which should be verified.
Requesting confidential communications is the same as restricting who can access PHI.
Alternative means of communication govern how and where PHI is transmitted to the individual. Restricting uses and disclosures is a separate right under the Privacy Rule. Accommodating a communication request does not by itself restrict permitted uses and disclosures.
Individuals must justify why they want alternative communications.
For health care providers, the covered entity generally may not require an explanation of the reason for the request. For health plans, an individual may need to state that disclosure could endanger them, subject to conditions in the applicable regulation.

Best practices

Establish a documented intake process for individuals to submit requests for alternative means or locations of communication, and record how each request was handled.
Train staff to accommodate reasonable requests without demanding an explanation from provider patients, while understanding the differing conditions that may apply to health plans.
Define in advance what reasonable conditions your organization will apply, such as requiring a specific alternative address or clarifying payment handling, and confirm these against the current Privacy Rule text.
Verify the individual's requested contact method or address and configure systems so that PHI is routed accordingly to reduce inadvertent disclosure at the original location.
Coordinate with IT and security teams so that alternative electronic channels used for ePHI are handled consistently with Security Rule safeguards, keeping in mind the Security Rule governs only ePHI.
Review applicable state law and other frameworks, which may impose additional confidential communication requirements beyond HIPAA, and confirm all specifics against current regulatory guidance.