Skip to main content
Category: Individual Rights

Individual's Right to Direct Transmission

Also known as: Right to Direct a Copy to a Third Party, Directed Transmission Under the Right of Access
Simply put

Under the HIPAA right of access, individuals can ask a covered entity to send a copy of their protected health information (PHI) directly to another person or organization they choose, rather than receiving it themselves. For example, a patient can direct their doctor to send records to a specialist, a family member, or an app. This is part of the broader right individuals have to access and control access to their own health information.

Formal definition

The individual's right to direct transmission is a component of the HIPAA right of access under the Privacy Rule. When requested in writing by an individual, a covered entity must transmit a copy of the individual's PHI directly to another person or entity clearly designated by the individual, subject to the general scope, format, and other conditions applicable to the right of access. The right applies to PHI maintained in a designated record set. Note that specific procedural requirements (such as the required elements of a valid direction, permissible fees, timeliness, and format) are governed by the applicable regulatory text and subsequent guidance and enforcement developments; practitioners should verify current requirements against the prevailing HHS OCR guidance and regulation, as certain aspects of the directed-transmission requirement have been affected by later legal and regulatory developments not detailed in this evidence. This entry addresses only the HIPAA federal requirement; applicable state law may impose additional obligations.

Why it matters

The right to direct transmission gives patients meaningful control over the flow of their own health information. Rather than forcing individuals to act as intermediaries who receive records and then forward them, this component of the HIPAA right of access allows a patient to instruct a covered entity to send a copy of their protected health information (PHI) straight to a designated recipient, such as a specialist, a family member, or a health application. This supports care coordination, second opinions, and personal use of health data while keeping the individual in the driver's seat regarding who receives their information.

For compliance and privacy professionals, directed transmission is a frequent source of operational and legal risk because it sits at the intersection of the individual's access right and the more restrictive rules governing disclosures to third parties. Missteps, such as treating a valid patient-directed request as an ordinary authorization, imposing improper conditions, or charging fees beyond what the access right permits, have historically drawn HHS OCR scrutiny under its enforcement work on the right of access. It is important to note that certain aspects of the directed-transmission requirement have been affected by later legal and regulatory developments; practitioners should not assume the scope described in the original 2016 guidance applies unchanged today.

Because the specifics of what constitutes a valid direction, permissible fees, format, and timeliness are governed by the applicable regulatory text and subsequent guidance, organizations that codify outdated assumptions into their intake workflows risk both under-serving patients and creating compliance exposure. Verifying current requirements against prevailing HHS OCR guidance is essential rather than optional.

Who it's relevant to

Privacy Officers and HIM Professionals
Those responsible for processing record requests must be able to distinguish a patient-directed transmission under the right of access from a third-party authorization, and must apply the correct procedural rules for each. Given that certain directed-transmission requirements have been affected by later developments, these professionals should periodically re-verify their intake and fee practices against current HHS OCR guidance rather than relying on longstanding internal assumptions.
Covered Entities' Compliance Teams
Compliance staff at providers, health plans, and other covered entities should ensure policies, staff training, and workflows correctly implement the directed-transmission obligation while avoiding improper conditions or fees. This is an area where HHS OCR has historically focused enforcement attention on the right of access generally, making accurate implementation a priority.
Legal Counsel
Counsel advising healthcare organizations should track how legal and regulatory developments have affected the scope of the directed-transmission requirement over time, and should account for state law that may impose additional obligations beyond the HIPAA federal baseline. Counsel is well positioned to help teams confirm which version of the requirement currently applies.
Health App Developers and Third-Party Recipients
Organizations that may receive PHI as a designated recipient should understand that receiving records through an individual's directed transmission does not, by itself, subject them to HIPAA as a covered entity or business associate; HIPAA obligations attach through defined relationships. Recipients should still be aware that other laws may govern how they subsequently handle the information they receive.

Inside Individual's Right to Direct Transmission

Right to Direct Transmission
Under the HIPAA Privacy Rule's access provisions, an individual generally has the right to request that a covered entity transmit a copy of their protected health information (PHI) directly to a designated third party. This extends the individual's right of access beyond receiving the information themselves.
Written, Signed Direction Requirement
The direction to transmit to a third party typically must be in writing, signed by the individual, and must clearly identify the designated recipient and where to send the copy. Practitioners should verify the specific form and content requirements against current regulatory text and guidance.
Scope Limited to the Designated Record Set
The right generally applies to PHI maintained in a designated record set. It covers PHI in the forms the covered entity holds, and where readily producible, in the form and format requested by the individual (including electronic copies of ePHI).
Relationship to the Individual Right of Access
Directed transmission is an aspect of the individual's right of access, which is distinct from a HIPAA authorization for other disclosures. The distinction affects applicable timeframes, permissible fees, and the identity of the requester versus the recipient.
Fee Limitations
Fees charged in connection with the access right are generally subject to reasonableness and cost-based limitations under the Privacy Rule. Because the permissible fee framework has been the subject of regulatory and judicial developments, current amounts and calculation methods should be confirmed against the latest HHS guidance.
Response Timeframe
Covered entities are generally required to act on access requests, including directed transmissions, within a defined period established by the Privacy Rule. The specific number of days and any permitted extension should be verified against the current regulation.

Common questions

Answers to the questions practitioners most commonly ask about Individual's Right to Direct Transmission.

Does the individual's right to direct transmission mean a covered entity must send PHI anywhere the individual requests, in any format?
Not without limits. While the Privacy Rule generally requires covered entities to honor an individual's written, signed, and clearly identified request to transmit a copy of their PHI to a designated third party, the right applies to PHI maintained in a designated record set. Covered entities must generally provide the copy in the form and format requested if it is readily producible, and otherwise in a readable alternative form as agreed. Practical constraints, such as whether the requested format is readily producible, may apply. Readers should verify the current scope of this right against the applicable regulatory text, as its application has been affected by later legal developments.
Is directing transmission to a third party the same as authorizing a disclosure, so that the same rules and fee structures apply?
No, these are distinct concepts with a specific regulatory meaning that differs from common usage. A direction to transmit under the individual's access right is treated as an extension of the individual's own right of access, which is generally subject to specific limitations on what may be charged. A separate authorization for disclosure is a different mechanism governed by its own Privacy Rule requirements. Conflating the two can lead to incorrect fee handling and process errors. The permissible scope and fee treatment for third-party directions have been the subject of legal challenges, so readers should confirm the current standard against applicable regulatory guidance.
What documentation should we require before transmitting an individual's PHI to a third party at their direction?
Generally, the request should be in writing, signed by the individual, and clearly identify the designated recipient and where to send the copy. Establishing a standardized intake form and verifying the requester's identity through your organization's normal access-verification procedures helps reduce error and unauthorized disclosure. Because specific documentation and verification expectations can vary, and because state law may impose additional requirements, confirm your process against current regulatory guidance and legal counsel.
How should we handle identity verification when honoring a transmission request?
Covered entities are generally expected to verify the identity of the individual making the access request using reasonable procedures, and the Security Rule's administrative and technical safeguards are relevant where ePHI is involved. Verification should not be applied in a way that creates unreasonable barriers to the individual's access. The specific method is not dictated by a single mandated approach, so organizations typically document their verification procedures in policy and apply them consistently.
What are reasonable timeframes for acting on a direction to transmit PHI?
The Privacy Rule generally imposes a timeframe for responding to access requests, with a limited extension available under defined conditions. Because the exact number of days and the conditions for extension are set by the regulatory text and can be affected by updates, you should confirm the current applicable timeframe against the regulation rather than relying on memory. Building the deadline into your workflow tracking helps demonstrate timely response.
How does this right interact with data we hold as a business associate rather than as a covered entity?
The individual's right of access, including the right to direct transmission, runs to the covered entity that maintains the designated record set. A business associate's obligations regarding access requests generally flow through its business associate agreement and its support of the covered entity's compliance, rather than the business associate independently fulfilling the individual right. Clarify in the BAA how requests received by a business associate are routed and handled, and confirm responsibilities against the current agreement and applicable regulatory guidance.

Common misconceptions

Directing PHI to a third party is the same as signing a HIPAA authorization.
A directed transmission is an exercise of the individual's right of access, not an authorization for other uses and disclosures. The two mechanisms have different requirements, and in most cases the access right carries different fee limits and timeframes than a standard authorization. Treating them interchangeably can lead to noncompliant fees or delays.
The right applies to any and all information the covered entity holds about the individual.
The right generally applies to PHI in the designated record set. Certain categories of information may fall outside that set or be subject to specific exclusions, so covered entities should scope the request to the designated record set as defined by the Privacy Rule.
A covered entity can charge whatever it wants to transmit records to a third party.
Fees associated with the access right are generally constrained to reasonable, cost-based amounts under the Privacy Rule. The permissible fee framework has evolved through regulatory and judicial developments, so current limits should be confirmed against the latest HHS guidance rather than assumed.

Best practices

Establish a documented intake process that captures a written, signed direction clearly identifying the designated recipient and delivery destination before transmitting PHI.
Train staff to distinguish an access-based directed transmission from a HIPAA authorization, since the applicable fees and timeframes generally differ between the two.
Scope each request to the PHI within the designated record set and honor the requested form and format where readily producible, including electronic copies of ePHI.
Apply only reasonable, cost-based fees consistent with the access right, and verify current permissible fee limits against the latest HHS guidance before billing.
Track and meet the response timeframe required for access requests, and confirm the current deadline and any allowable extension against the applicable regulatory text.
Confirm the identity of the individual and the accuracy of the recipient's delivery details to reduce the risk of misdirected disclosures, and consult applicable state law for any additional requirements beyond HIPAA.