Skip to main content
Category: Individual Rights

Confidential Communications

Also known as: Confidential Communications Request, Right to Request Confidential Communications
Simply put

Under the HIPAA Privacy Rule, confidential communications refers to an individual's right to ask that a covered entity contact them about their health information in a specific way or at a specific location. For example, a patient might request that a health plan send correspondence to a work address instead of a home address, or by email rather than by mail. This is a mechanism for how and where protected health information is communicated, not a restriction on what may be disclosed.

Formal definition

Confidential communications, as addressed in the HIPAA Privacy Rule provisions on the right to request privacy protection, generally require covered entities to permit individuals to request that they receive communications of protected health information (PHI) by alternative means or at alternative locations. A covered health care provider must generally accommodate reasonable requests, while a health plan's obligation to accommodate typically applies where the individual states that disclosure could endanger them; practitioners should verify the specific conditions, accommodation standards, and any permissible conditions (such as information on how payment will be handled) against the current Privacy Rule text. This right concerns the method and destination of communication rather than the underlying permissibility of a use or disclosure. It is distinct from the separate right to request restrictions on uses and disclosures. Note that state law or other frameworks may impose additional requirements, and this term should not be confused with evidentiary or common-law concepts of confidential communication (e.g., privileged communications between trusting parties), which fall outside HIPAA's scope.

Why it matters

The right to request confidential communications gives individuals meaningful control over how and where their protected health information reaches them, which can be critical for personal safety and privacy. A patient may have compelling reasons to avoid having sensitive correspondence arrive at a shared home address or to prevent a phone call about test results from being overheard. For covered entities, honoring these requests is not merely a courtesy but a component of Privacy Rule compliance, and mishandling them can undermine patient trust and expose the entity to complaints filed with HHS OCR.

The accommodation standard differs depending on the type of covered entity. A covered health care provider generally must accommodate reasonable requests for alternative means or locations, while a health plan's obligation to accommodate typically applies where the individual states that disclosure could endanger them. Because these conditions and standards are specific to the current Privacy Rule text, practitioners should verify the exact requirements rather than relying on a general summary.

It is important to keep this HIPAA concept separate from evidentiary or common-law notions of confidential communication, such as privileged statements exchanged between parties who trust one another. Those concepts fall outside HIPAA's scope. The HIPAA right concerns the method and destination of communication, not the underlying permissibility of a use or disclosure, and state law or other frameworks may impose additional requirements beyond what the Privacy Rule provides.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers are responsible for establishing policies and procedures that allow individuals to request confidential communications and for ensuring staff respond appropriately. They should verify the accommodation standards that apply to their organization type, provider versus health plan, against the current Privacy Rule and document how requests are received, evaluated, and fulfilled.
Health Care Providers
Covered health care providers generally must accommodate reasonable requests for communications by alternative means or at alternative locations. Front-office and clinical staff who handle patient correspondence, appointment reminders, and results should understand how to route these communications correctly once a request is on file.
Health Plans
Health plans have an obligation to accommodate requests that typically applies where the individual states that disclosure could endanger them. Plan administrators and member services teams should be familiar with this narrower standard and confirm the specific conditions in the current regulation.
Compliance and Legal Teams
Compliance and legal professionals should ensure the organization distinguishes confidential communications from the separate right to request restrictions on uses and disclosures, and should account for any state law or other frameworks that may impose additional requirements beyond HIPAA.

Inside Confidential Communications

Right to Request Confidential Communications
A HIPAA Privacy Rule provision that generally allows individuals to request that a covered entity communicate protected health information (PHI) to them by alternative means or at alternative locations, such as by a specific phone number, email, or mailing address.
Alternative Means
The method by which PHI is communicated, for example receiving communications by mail rather than by phone, or through a designated channel the individual specifies.
Alternative Location
The place where PHI is directed, such as a work address instead of a home address, or a post office box rather than a residence.
Reasonableness of the Request
Covered entities generally must accommodate reasonable requests. Health plans must accommodate requests when the individual indicates that disclosure could endanger them; health care providers must accommodate reasonable requests without requiring an explanation of the reason.
Provider vs. Health Plan Distinction
The conditions a covered entity may impose differ by type. Providers generally may not require a reason for the request, while health plans may condition accommodation on statements of endangerment and on how payment will be handled, subject to the applicable regulatory text.
Permissible Conditions
A covered entity may require that requests be made in writing, specify an alternative address or method of contact, and, where payment is involved, provide information as to how payment will be managed. These conditions should be verified against the current Privacy Rule text.

Common questions

Answers to the questions practitioners most commonly ask about Confidential Communications.

Does an individual have to explain why they are requesting a confidential communication?
Generally, no. Under the HIPAA Privacy Rule, a covered health care provider must accommodate reasonable requests by individuals to receive communications of protected health information by alternative means or at alternative locations, and it may not require the individual to explain the basis for the request. Health plans may accommodate such requests when the individual states that disclosure of all or part of the information could endanger the individual, and specific conditions may apply. Readers should verify the exact conditions against the current regulatory text.
Is granting a confidential communication request optional for a covered entity?
No. For covered health care providers, accommodating reasonable requests is an obligation under the Privacy Rule, not a discretionary courtesy. The covered entity may, however, evaluate whether a request is reasonable and may condition accommodation on certain factors, such as information as to how payment will be handled or specification of an alternative address or method of contact. This is distinct from the request itself being optional; the general duty to accommodate reasonable requests applies.
How should a covered entity operationalize confidential communication requests?
In most cases, entities establish a documented intake process so requests can be received, evaluated for reasonableness, and implemented across systems. This typically includes recording the individual's specified alternative means or location, updating contact information in the relevant records or systems, and communicating the accommodation to staff who handle mailings, calls, or electronic notices. Specific procedures should align with the current Privacy Rule and the entity's own policies.
What conditions may a covered entity place on accommodating a request?
A covered entity may require that the request be in writing, may condition accommodation on receiving information about how payment will be handled, and may require specification of an alternative address or other method of contact. It may not require an explanation of the basis for the request from an individual seeking to receive communications by alternative means or at alternative locations. Entities should confirm the applicable conditions against the current regulatory text.
How does a confidential communication request interact with billing and payment notices?
Confidential communication requests can affect where and how billing statements, explanations of benefits, and payment-related notices are sent. Because a covered entity may condition accommodation on information about how payment will be handled, entities generally coordinate with billing functions to ensure that payment communications follow the requested alternative means or location rather than default contact channels. Implementation should be verified against current requirements and the entity's policies.
How does confidential communication differ from a request to restrict disclosures?
These are distinct rights under the Privacy Rule. A confidential communication request concerns the means or location by which an individual receives PHI, while a request for restriction concerns whether certain uses or disclosures of PHI occur at all. The standards and the entity's obligations differ between the two, so entities generally track and process them separately. Readers should consult the current regulatory text for the specific standards applicable to each.

Common misconceptions

Confidential communications is a Security Rule requirement about encrypting electronic messages.
The right to request confidential communications is a HIPAA Privacy Rule provision concerning how and where PHI is communicated to an individual, and it applies to PHI in multiple forms, not only ePHI. It is distinct from the Security Rule's technical safeguards for electronic transmission, which are governed separately.
A covered entity must honor any confidential communications request exactly as demanded.
Covered entities generally must accommodate reasonable requests, but they may impose permissible conditions, such as requiring the request in writing or specifying an alternative address, and the standards differ between health care providers and health plans.
A provider can require the individual to explain why they want confidential communications.
Health care providers generally may not require an individual to provide a reason for a confidential communications request. Health plans, by contrast, may condition accommodation on a statement that disclosure could endanger the individual, subject to the applicable regulatory text.

Best practices

Establish a documented process for receiving, evaluating, and responding to confidential communications requests, and consider requiring requests in writing where permitted.
Train staff to distinguish provider obligations from health plan obligations, since providers generally cannot ask for a reason while health plans may apply endangerment and payment-related conditions.
Capture the individual's specified alternative means or location clearly in the record system so downstream communications are routed correctly.
Avoid conditioning accommodation on unreasonable requirements; document the basis whenever a request is denied as unreasonable and verify the standard against the current Privacy Rule text.
Coordinate confidential communications preferences across billing, appointment reminders, and other touchpoints to reduce the risk of inadvertent disclosure to an unintended address or contact.
Check whether applicable state law or other frameworks impose additional confidentiality requirements beyond HIPAA, as these may expand an individual's rights or the covered entity's obligations.