Request for Amendment Response
A Request for Amendment Response is a covered entity's formal reply to an individual who has asked to correct or add to protected health information (PHI) in their records. The covered entity generally must decide whether to accept or deny the request within a set timeframe and notify the individual of its decision. If the request is accepted, the entity corrects or supplements the record; if denied, the individual is generally entitled to certain follow-up rights, such as submitting a statement of disagreement.
Under the HIPAA Privacy Rule, a Request for Amendment Response is the action a covered entity takes in response to an individual's request to amend PHI maintained in a designated record set, as governed by 45 C.F.R. § 164.526. Generally, the covered entity must act on the request no later than 60 days after receipt, either by accepting the amendment (in whole or in part) or denying it; a single extension of no more than 30 days is permitted if the covered entity provides the individual with a written statement of the reasons for the delay and the date by which it will act (readers should verify current timeframes against the applicable regulatory text, as certain state deadlines may be shorter or otherwise differ). Where the entity accepts the amendment, it must make the appropriate change and, as required, inform relevant persons identified by the individual and business associates known to have the information. Where it denies the request, it must provide a written denial explaining the basis, the individual's right to submit a statement of disagreement, and the process for complaints. This term addresses the response obligation specifically; the underlying right to request amendment, permissible grounds for denial, and interactions with state law or the HITECH Act are related but distinct considerations.
Why it matters
The right to request amendment of PHI is one of the individual access rights that HHS OCR has emphasized in its enforcement of the HIPAA Privacy Rule. A covered entity's response to such a request is not a discretionary courtesy; it is a regulated obligation with defined timeframes and follow-up duties. Mishandling these requests, by missing the response deadline, failing to provide a proper written denial, or ignoring an individual's right to submit a statement of disagreement, can expose a covered entity to complaints and regulatory scrutiny.
Beyond compliance risk, the amendment response process directly affects data integrity and patient trust. When PHI in a designated record set is inaccurate or incomplete, downstream clinical and administrative decisions may be affected, and individuals reasonably expect a clear and timely reply when they flag a problem. A well-documented, consistent response process helps demonstrate good-faith engagement with individual rights.
Note that the amendment process addresses the response obligation specifically; it does not by itself compel an entity to change every record an individual disputes. Denials are permitted on defined grounds, and the requirement is that the covered entity respond appropriately and preserve the individual's follow-up rights. Readers should also be aware that state law or the HITECH Act may impose additional or shorter requirements that go beyond the baseline federal rule.
Who it's relevant to
Inside Request for Amendment Response
Common questions
Answers to the questions practitioners most commonly ask about Request for Amendment Response.