Skip to main content
Category: Individual Rights

Denial of Access

Also known as: Access Denial
Simply put

Denial of access generally refers to preventing an authorized person or system from reaching resources they are permitted to use, or delaying time-sensitive operations. In a security context, this may result from a deliberate attack or from a technical failure or misconfiguration. The term can also be used more broadly in legal and administrative settings to describe being refused access to records, tribunals, or other protected rights.

Formal definition

In information security terms, denial of access is closely related to the concept of denial of service (DoS), which NIST defines as the prevention of authorized access to resources or the delaying of time-critical operations, where time-critical may range from milliseconds to hours. A denial-of-service attack is a cyberattack in which an adversary seeks to make a machine or network resource unavailable to its intended users. The specific application of denial of access within a given compliance program (for example, how it maps to Security Rule availability considerations or to particular controls) is context-dependent and is not defined by the evidence provided here; readers should verify the intended meaning against the relevant regulatory text or control framework. Note also that outside the security context, denial of access carries distinct meanings in legal and public-records settings, such as being refused inspection of public records or access to a tribunal, which are governed by separate authorities rather than by HIPAA.

Why it matters

Denial of access matters because the availability of information and systems is a core security objective, not merely a convenience. When an authorized person or system cannot reach the resources they are permitted to use, whether because of a deliberate attack or a technical failure, the consequences can range from operational disruption to, in time-sensitive settings, harm that unfolds in milliseconds or over hours. NIST characterizes denial of service as the prevention of authorized access to resources or the delaying of time-critical operations, underscoring that timing itself can be a critical dimension of the harm.

In a security context, denial of access is closely tied to denial-of-service (DoS) attacks, in which an adversary deliberately seeks to make a machine or network resource unavailable to its intended users. For organizations that handle sensitive information, an inability to access records or systems when needed can undermine both operations and the trust that authorized users and stakeholders place in those systems.

It is important to recognize that the term carries distinct meanings outside the security domain. In legal and public-records settings, denial of access can describe being refused inspection of public records or access to a tribunal, matters governed by separate authorities rather than by security frameworks. How denial of access maps to any particular compliance program's controls or availability considerations is context-dependent and should be verified against the relevant regulatory text or control framework.

Who it's relevant to

Security and IT professionals
Those responsible for maintaining system availability need to understand denial of access both as a potential attack vector, such as denial-of-service attacks that make resources unavailable to intended users, and as a possible consequence of technical failure or misconfiguration. Where and how this concept maps to specific availability controls in a given framework should be verified against that framework's current text.
Compliance and privacy officers
Professionals overseeing compliance programs should be aware that denial of access is a context-dependent term whose application to particular controls or availability considerations is not universally defined. They should confirm the intended meaning against the relevant regulatory text or control framework rather than assuming a single fixed interpretation.
Legal and records professionals
Outside the security context, denial of access carries distinct meanings, such as being refused inspection of public records or access to a tribunal. These situations are governed by separate authorities and should not be conflated with the security-oriented, denial-of-service sense of the term.

Inside Denial of Access

Right of Access (Baseline)
Under the HIPAA Privacy Rule, individuals generally have a right to inspect and obtain copies of their protected health information (PHI) held in a designated record set by a covered entity or, through it, a business associate. Denial of access refers to a covered entity's refusal, in whole or in part, to grant this request.
Grounds Permitting Denial
The Privacy Rule identifies limited circumstances under which access may be denied. These are generally categorized as reviewable and unreviewable grounds, and denial outside these permitted grounds is typically not compliant. Practitioners should confirm the specific permitted grounds against the current regulatory text.
Unreviewable Grounds
Certain denials are generally not subject to a review process, such as requests for psychotherapy notes or information compiled in anticipation of litigation. The specific list should be verified against the applicable Privacy Rule provisions.
Reviewable Grounds
Other denials, such as those where a licensed professional determines access is reasonably likely to endanger the life or physical safety of the individual or another person, are generally subject to review by a designated reviewing official upon the individual's request.
Partial Access Obligation
Where only a portion of the requested PHI falls under a permitted denial ground, the covered entity is generally expected to provide access to the portions not subject to denial rather than denying the entire request.
Written Denial and Notice Requirements
When access is denied, the covered entity is generally required to provide a timely written denial that includes the basis for the denial, information about any applicable review rights, and how the individual may complain to the entity or to HHS OCR.
Scope Limitation
Denial of access is a Privacy Rule concept governing PHI in all forms (oral, paper, and electronic). It is distinct from Security Rule access controls, which are technical safeguards restricting workforce or system access to ePHI rather than governing an individual's right to their own records.

Common questions

Answers to the questions practitioners most commonly ask about Denial of Access.

Does a covered entity have to grant individuals access to all of their protected health information on request?
Not in every case. While the HIPAA Privacy Rule generally gives individuals a right of access to inspect and obtain copies of PHI held in a designated record set, that right is not absolute. Certain categories of information are excluded from the access right, and the rule recognizes both grounds on which access may be denied outright and grounds on which a denial may be reviewable. The scope of the right and the specific exceptions should be confirmed against the current Privacy Rule text, and covered entities should note that state law may grant broader access rights than HIPAA.
Is every refusal to provide records the same kind of denial with the same consequences?
No. Under the Privacy Rule, denials generally fall into different categories, and the distinction matters. Some denials are unreviewable, while others entitle the individual to have the decision reviewed by a licensed health care professional designated to serve as a reviewing official. Treating all refusals as equivalent can lead a covered entity to skip a review process the rule requires. Because the categories and procedures carry specific regulatory meaning, verify the applicable grounds and required steps against the current regulation.
What should a covered entity include when it issues a denial of access to an individual?
A denial should generally be provided to the individual in a manner consistent with the Privacy Rule's requirements, which typically call for a timely, written response that explains the basis for the denial and, where applicable, informs the individual of any right to have the denial reviewed and how to complain. The precise required contents and timing should be confirmed against the current Privacy Rule text and any applicable OCR guidance, and organizations should account for state law that may impose additional notice obligations.
How should staff handle a partial denial when only some of the requested records are withheld?
Where the grounds for denial apply only to a portion of the requested PHI, the covered entity should generally provide access to the portions that are not subject to denial rather than refusing the entire request. Workflows and staff training should support identifying and releasing the accessible portions while documenting the specific basis for withholding the rest. Confirm the applicable handling requirements against the current regulation.
What role does a reviewing official play when a denial is challenged?
For denials that fall into the reviewable category, the Privacy Rule generally provides that the individual may request review, and the covered entity designates a licensed health care professional who did not participate in the original decision to act as the reviewing official. The covered entity is generally expected to act in accordance with that official's determination. Organizations should establish in advance who can serve in this role and document the review, verifying the specific requirements against the current regulatory text.
How should denials of access be documented and retained?
As a practical matter, covered entities should maintain records of access requests, the disposition of each request, the specific grounds for any denial, and any review conducted, consistent with the Privacy Rule's documentation and retention requirements. Good documentation supports demonstrating compliance in the event of an OCR inquiry or complaint. The applicable retention period and documentation specifics should be confirmed against the current regulation, and state law may impose longer retention obligations.

Common misconceptions

A covered entity can deny access whenever it believes releasing records is inconvenient, risky to the organization, or when the individual has an unpaid bill.
Denial is generally permitted only on the limited grounds specified in the Privacy Rule. Non-payment of a bill is generally not a valid basis to deny an individual access to their PHI. Denials outside permitted grounds are typically not compliant, and practitioners should verify the permitted grounds against the current regulation.
If any part of a record qualifies for denial, the entire access request can be refused.
Covered entities are generally expected to provide access to any portion of the PHI that is not subject to a permitted denial ground, rather than withholding the full record.
Achieving HITRUST CSF certification or implementing Security Rule access controls demonstrates that an entity is handling denial of access correctly.
Denial of access is a HIPAA Privacy Rule obligation enforced by HHS OCR. HITRUST certification is issued by a private organization and does not by itself establish HIPAA compliance. Security Rule access controls govern system-level access to ePHI and are a separate matter from an individual's right of access.

Best practices

Maintain a documented policy that lists the specific reviewable and unreviewable grounds for denial permitted under the current Privacy Rule, and train workforce members to apply only those grounds rather than ad hoc reasons such as unpaid balances.
When a denial is warranted, provide a timely written denial that states the basis, explains any applicable review rights, and describes how the individual may file a complaint with the entity or HHS OCR.
Default to partial access: release all portions of the designated record set not subject to a permitted denial ground rather than refusing the entire request.
Establish and document a review process with a designated licensed reviewing official for denials made on reviewable grounds, and honor timely individual requests for such review.
Log all access requests, denials, the grounds cited, and the dates of each step to support accountability and to demonstrate compliance if questioned by HHS OCR.
Confirm permitted denial grounds, notice content, and response timeframes against the current regulatory text, and check whether applicable state law or other frameworks impose additional or stricter access obligations.