Skip to main content
Category: Individual Rights

Request for Amendment Response

Also known as: Amendment Request Response, Response to Request for Amendment of PHI, PHI Amendment Response
Simply put

A Request for Amendment Response is a covered entity's formal reply to an individual who has asked to correct or add to protected health information (PHI) in their records. The covered entity generally must decide whether to accept or deny the request within a set timeframe and notify the individual of its decision. If the request is accepted, the entity corrects or supplements the record; if denied, the individual is generally entitled to certain follow-up rights, such as submitting a statement of disagreement.

Formal definition

Under the HIPAA Privacy Rule, a Request for Amendment Response is the action a covered entity takes in response to an individual's request to amend PHI maintained in a designated record set, as governed by 45 C.F.R. § 164.526. Generally, the covered entity must act on the request no later than 60 days after receipt, either by accepting the amendment (in whole or in part) or denying it; a single extension of no more than 30 days is permitted if the covered entity provides the individual with a written statement of the reasons for the delay and the date by which it will act (readers should verify current timeframes against the applicable regulatory text, as certain state deadlines may be shorter or otherwise differ). Where the entity accepts the amendment, it must make the appropriate change and, as required, inform relevant persons identified by the individual and business associates known to have the information. Where it denies the request, it must provide a written denial explaining the basis, the individual's right to submit a statement of disagreement, and the process for complaints. This term addresses the response obligation specifically; the underlying right to request amendment, permissible grounds for denial, and interactions with state law or the HITECH Act are related but distinct considerations.

Why it matters

The right to request amendment of PHI is one of the individual access rights that HHS OCR has emphasized in its enforcement of the HIPAA Privacy Rule. A covered entity's response to such a request is not a discretionary courtesy; it is a regulated obligation with defined timeframes and follow-up duties. Mishandling these requests, by missing the response deadline, failing to provide a proper written denial, or ignoring an individual's right to submit a statement of disagreement, can expose a covered entity to complaints and regulatory scrutiny.

Beyond compliance risk, the amendment response process directly affects data integrity and patient trust. When PHI in a designated record set is inaccurate or incomplete, downstream clinical and administrative decisions may be affected, and individuals reasonably expect a clear and timely reply when they flag a problem. A well-documented, consistent response process helps demonstrate good-faith engagement with individual rights.

Note that the amendment process addresses the response obligation specifically; it does not by itself compel an entity to change every record an individual disputes. Denials are permitted on defined grounds, and the requirement is that the covered entity respond appropriately and preserve the individual's follow-up rights. Readers should also be aware that state law or the HITECH Act may impose additional or shorter requirements that go beyond the baseline federal rule.

Who it's relevant to

Privacy Officers
Privacy officers are typically responsible for ensuring the covered entity meets its response obligations under 45 C.F.R. § 164.526, including the general 60-day timeframe, the permitted 30-day extension with written notice, and the proper handling of denials and statements of disagreement. They should verify that policies reflect the current regulatory text and any applicable state-law variations.
Health Information Management Staff
HIM and medical records teams often receive and process amendment requests, make accepted changes within the designated record set, and coordinate notification to relevant persons and business associates. A clearly documented responsible office or role helps ensure requests are logged and answered within the required period.
Compliance and Legal Teams
Compliance and legal professionals advise on permissible grounds for denial, the wording of written denials, and the individual's follow-up rights. They also assess where state law or the HITECH Act may add requirements beyond the federal baseline and confirm penalty and enforcement considerations against current HHS OCR guidance.
Business Associates
Business associates that maintain PHI on behalf of a covered entity may need to support amendment responses, for example, by making corrections or forwarding accepted amendments, consistent with their business associate agreement. Their obligations flow through that agreement rather than attaching automatically.

Inside Request for Amendment Response

Timeframe for Response
Under the HIPAA Privacy Rule, a covered entity must generally act on an individual's request for amendment no later than 60 days after receiving the request. A single 30-day extension is permitted if, within the original period, the entity provides the individual a written statement of the reasons for the delay and the date by which it will act. Practitioners should verify the exact timing requirements against the current regulatory text (generally located at 45 C.F.R. § 164.526).
Acceptance of the Amendment
If the covered entity accepts the requested amendment in whole or in part, it generally must make the amendment, inform the individual that the request is accepted, and make reasonable efforts to notify and provide the amendment to relevant persons identified by the individual and to persons known to have the affected PHI who may rely on it to the individual's detriment.
Denial of the Amendment
A covered entity may deny a request under specific permitted grounds, for example, when the PHI was not created by the entity (unless the originator is no longer available), is not part of the designated record set, would not be available for access, or is already accurate and complete. A denial must generally be a timely, written statement in plain language.
Contents of a Written Denial
A denial typically must include the basis for the denial, the individual's right to submit a written statement of disagreement and how to do so, a statement that the individual may request that the amendment request and denial be included in future disclosures, and a description of how the individual may complain to the covered entity or to HHS OCR.
Statement of Disagreement and Rebuttal
Following a denial, the individual may submit a statement of disagreement. The covered entity may prepare a written rebuttal and must provide the individual a copy. These documents, along with the request and denial, generally must be included with or referenced in subsequent disclosures of the disputed record.
Documentation Obligations
The covered entity must generally document its designated record sets and the titles of persons or offices responsible for receiving and processing amendment requests, and retain this documentation for the period required by the Privacy Rule's documentation standard.

Common questions

Answers to the questions practitioners most commonly ask about Request for Amendment Response.

Does a covered entity have to make the amendment if the individual requests it?
No. A request for amendment is a request, not a directive. Under the Privacy Rule, a covered entity may deny a request on specific permitted grounds, such as when the information was not created by the covered entity (unless the originator is no longer available to act), is not part of the designated record set, would not be available for inspection under the access provisions, or is already accurate and complete. When the entity denies a request, it must generally provide a written denial and inform the individual of their right to submit a statement of disagreement. So a proper response can be either an acceptance or a denial, provided the applicable requirements are followed.
If a request is granted, does the covered entity delete or overwrite the original information in the record?
Generally no. Amending a record under the Privacy Rule typically means appending or otherwise linking the amendment to the existing information, not erasing the original entry. The goal is to correct or supplement the designated record set while preserving the integrity and history of the record. The exact mechanics depend on the record system and organizational policy, and readers should confirm their approach against the current regulatory text and any applicable state law, which may impose additional recordkeeping requirements.
How long does a covered entity have to respond to a request for amendment?
Under the Privacy Rule, a covered entity must generally act on a request for amendment no later than 60 days after receiving it. If the entity cannot act within that period, it may extend the time by no more than 30 additional days, provided it gives the individual a written statement of the reasons for the delay and the date by which it will complete action. Only one such extension is permitted. Because timeframes and their conditions can be nuanced, readers should verify the specifics against the current text of the applicable regulation.
What should a written denial of an amendment request include?
A denial should generally be in writing, use plain language, and state the basis for the denial. It typically also informs the individual of their right to submit a written statement of disagreement, describes how to file such a statement, and explains that the individual may request that the amendment request and the denial accompany future disclosures of the affected information. It should also describe how the individual may complain to the covered entity or to HHS OCR. Confirm the precise content requirements against the current regulatory text before finalizing template language.
What happens when an amendment is accepted, who else needs to be notified?
When a covered entity accepts an amendment, it generally must make reasonable efforts to inform and provide the amendment to persons identified by the individual as needing it, as well as persons, including business associates, that the entity knows have the affected information and may have relied or could foreseeably rely on it to the individual's detriment. Coordinating these notifications is often the more operationally demanding part of the process, so tracking downstream recipients is a common implementation focus.
If we did not create the record, can we simply refuse the amendment request?
Not automatically. The fact that the covered entity did not originate the information is a permitted basis for denial only when the originator is still available to act on the request. If the party that created the information is no longer available, that ground may not apply and the entity may need to consider the request on other grounds. Because this determination can be fact-specific, organizations often build a review step to identify the correct originator before issuing a denial.

Common misconceptions

A covered entity must respond to a request for amendment within 30 days.
The Privacy Rule generally allows up to 60 days to act on a request, with a single 30-day extension available if the individual is notified in writing of the reason for the delay and the expected completion date. Confirm the current timing against 45 C.F.R. § 164.526.
A covered entity must amend any record an individual claims is wrong.
The rule provides for a right to request amendment, not an absolute right to have records changed. The entity may deny requests on defined grounds, such as when the PHI is accurate and complete or was not created by the entity, provided it follows the required denial process.
Denying an amendment ends the covered entity's obligations.
A denial triggers additional obligations, including providing a compliant written denial, accepting and responding to any statement of disagreement, optionally issuing a rebuttal, and including the relevant documents in future disclosures of the disputed information.

Best practices

Track amendment requests against the 60-day response window and document any single 30-day extension in writing to the individual before the original period expires, verifying current timing against the applicable regulatory text.
Maintain clearly defined designated record sets and designate the titles of persons or offices responsible for receiving and processing amendment requests, as required by the Privacy Rule's documentation standard.
Use written denials in plain language that include all required elements, such as the basis for denial, the right to submit a statement of disagreement, and how to file a complaint with the entity or HHS OCR.
Establish a workflow for handling statements of disagreement and optional rebuttals, and ensure these documents are linked to the disputed record so they accompany future disclosures.
When accepting an amendment, make reasonable efforts to notify relevant persons identified by the individual and others known to hold the affected PHI who may rely on it.
Check whether state law or other frameworks impose additional or more stringent amendment-related requirements beyond HIPAA, and confirm procedures against the current version of the regulation.