Skip to main content
Category: Individual Rights

Restriction Request

Also known as: Request for Restriction, Right to Request a Restriction, Request to Restrict Uses and Disclosures of PHI
Simply put

A restriction request is when a patient asks a healthcare provider or health plan to limit how their protected health information (PHI) is used or shared. Individuals have the right to make this request, but in most cases the covered entity is not required to agree to it. If a covered entity does agree, it generally must honor the restriction it accepted.

Formal definition

Under the HIPAA Privacy Rule, an individual may request that a covered entity restrict the use or disclosure of PHI, including restrictions on uses or disclosures for treatment, payment, or health care operations, and disclosures to persons involved in the individual's care. This is a right to request a restriction, not an absolute right to compel one; generally a covered entity is not required to agree to a requested restriction, though where it agrees it is bound to comply with the accepted restriction subject to applicable exceptions. Covered entities typically process such requests through a defined intake and review process, often using a written request form. Note that certain narrower restriction rights may be treated differently under the Privacy Rule and related HITECH provisions, and that other laws may impose additional or conflicting obligations; readers should verify specific scope, exceptions, and any mandatory-agreement circumstances against the current regulatory text.

Why it matters

The right to request a restriction is one of the individual rights granted under the HIPAA Privacy Rule, and it gives patients a formal channel to ask that their protected health information (PHI) be used or shared more narrowly than the rules would otherwise permit. Understanding this right matters because it is frequently misunderstood: individuals can make a restriction request at any time, but making a request is not the same as compelling the outcome. In most cases a covered entity is not required to agree to a requested restriction. Where a covered entity does agree, however, it is generally bound to comply with the restriction it accepted, subject to applicable exceptions, which creates a concrete downstream obligation for the organization.

For covered entities, mishandling restriction requests carries real compliance exposure. A defined intake and review process helps ensure requests are logged, evaluated consistently, and either accepted or declined in a documented way. Once a restriction is accepted, systems and workflows must actually be able to enforce it, because failing to honor a restriction the organization agreed to could itself be a Privacy Rule failing. Because certain narrower restriction rights may be treated differently under the Privacy Rule and related HITECH provisions, and because other laws may impose additional or even conflicting obligations, organizations should not treat all restriction requests as a single uniform category.

Readers should verify the specific scope of restriction rights, the exceptions that apply, and any circumstances in which agreement to a restriction may be mandatory against the current regulatory text. This entry describes the general right to request a restriction and does not attempt to catalog every specialized restriction scenario or state-law overlay that may apply.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are responsible for establishing and maintaining the intake and review process for restriction requests, including the written request form, the approval workflow, and the documentation of whether a request is accepted or declined. They must also ensure that any restriction the organization agrees to is actually honored going forward, since accepted restrictions generally become binding obligations subject to applicable exceptions.
Health Plans and Payers
As covered entities, health plans may receive restriction requests concerning uses or disclosures for payment and health care operations. They typically route these requests through a defined review process for approval, and where they agree to a restriction, they are generally bound to comply with it.
Healthcare Providers and Front-Desk / HIM Staff
Providers, including intake and health information management staff, often serve as the first point of contact for restriction requests and are frequently the ones who supply and collect the written request form. They need to know how to route requests for review and understand that a request does not automatically obligate the organization to agree.
Patients and Individuals
Individuals exercising the right to request a restriction should understand that they may ask a provider or health plan to limit how their PHI is used or shared, but that in most cases the covered entity is not required to agree. Where the entity does agree, it generally must honor the accepted restriction.
Legal and Regulatory Advisors
Attorneys and compliance advisors help organizations interpret the scope of restriction rights, identify circumstances where certain narrower restrictions may be treated differently under the Privacy Rule or related HITECH provisions, and reconcile HIPAA obligations with other laws that may impose additional or conflicting requirements. They should confirm specific exceptions and any mandatory-agreement scenarios against current regulatory text.

Inside Restriction Request

Right to Request Restriction
Under the HIPAA Privacy Rule, an individual generally has the right to request that a covered entity restrict the uses and disclosures of their protected health information (PHI) for treatment, payment, or health care operations, and disclosures to persons involved in the individual's care.
General Discretion to Agree
In most cases, a covered entity is not required to agree to a requested restriction. However, once the entity does agree, it is generally bound to comply with that restriction, except in specified circumstances such as emergency treatment.
Mandatory Restriction for Out-of-Pocket Payments
There is a specific exception where a covered entity generally must agree to restrict disclosure of PHI to a health plan for payment or health care operations purposes when the individual has paid for the item or service in full out of pocket, subject to the conditions in the applicable regulatory text.
Scope Limitation
A restriction request typically applies to particular uses or disclosures identified by the individual. It does not eliminate all uses of PHI, and certain disclosures required by law or for emergency treatment may still occur despite an agreed restriction.
Termination of a Restriction
An agreed-upon restriction may generally be terminated by the individual, or by the covered entity under conditions described in the regulation, typically with appropriate notice to the individual for information created or received after termination.

Common questions

Answers to the questions practitioners most commonly ask about Restriction Request.

Must a covered entity always agree to a patient's request to restrict use or disclosure of their PHI?
No. Under the HIPAA Privacy Rule, a covered entity is generally not required to agree to most requested restrictions on the use or disclosure of PHI. The rule preserves the entity's discretion to decline. There is a notable exception: in most cases a covered entity must agree to a request to restrict disclosure to a health plan for payment or health care operations purposes when the individual has paid for the item or service in full out of pocket, unless disclosure is otherwise required by law. Beyond that specific circumstance, agreement is largely voluntary. Readers should verify the current regulatory text for the precise scope of any mandatory restriction.
Does a granted restriction mean the covered entity can never disclose that PHI under any circumstances?
No. Even when a restriction has been agreed to, it does not create an absolute bar on all disclosures. A covered entity may still use or disclose restricted PHI to provide emergency treatment where needed, and certain disclosures required by law or otherwise permitted outside the restriction's scope may continue. A restriction also does not typically override disclosures the covered entity is legally compelled to make. The restriction binds the entity only to the extent it agreed and only for the uses and disclosures the restriction covers. Consult the current Privacy Rule for the specific exceptions.
How should we document and track a restriction once we agree to one?
As a practical matter, covered entities generally document the agreed restriction in a form that identifies the individual, the specific PHI covered, the uses or disclosures being restricted, and the parties to whom the restriction applies. Because a restriction must actually be honored to be meaningful, many organizations flag the affected records in their systems so that workforce members and downstream processes recognize the limitation. Documentation practices are not dictated in exhaustive detail by the rule, so organizations typically build them into their own policies and procedures. Verify your approach against current guidance and any applicable state law.
Can a covered entity terminate a restriction it previously agreed to?
Generally, yes, subject to conditions. A covered entity may terminate an agreed restriction if the individual agrees to or requests the termination, and in some cases the individual may request termination orally, though documentation of oral agreement is prudent. A covered entity may also unilaterally terminate a restriction, but such termination is typically effective only with respect to PHI created or received after the individual has been informed of the termination; it does not retroactively lift the restriction on previously restricted information. Confirm the exact termination conditions against the current regulatory text.
How do restriction requests interact with business associates who handle the PHI?
When a covered entity agrees to a restriction, the practical challenge is ensuring that any business associates handling the affected PHI also honor it, since the covered entity remains responsible for the restricted PHI it discloses. Obligations to a business associate attach through the business associate agreement and the entity's own operational controls rather than automatically. Organizations typically need processes to communicate applicable restrictions to relevant business associates and to confirm they can operationally support the limitation. Address this in your agreements and workflows and verify against current guidance.
How does the out-of-pocket payment restriction affect coordination with health plans?
When an individual pays in full out of pocket for an item or service and requests that the related PHI not be disclosed to their health plan for payment or health care operations, the covered entity must generally honor that request in most cases. Operationally, this often requires the ability to segregate the self-paid service in records and billing systems so the restricted information is not routed to the plan. Because this can be complex when services are bundled, organizations typically address it in their procedures. This restriction pertains to payment and operations disclosures and does not necessarily bar disclosures required by law; verify the precise scope against the current Privacy Rule.

Common misconceptions

A covered entity must honor every restriction request an individual submits.
In most cases the covered entity is not required to agree to a requested restriction. A notable exception generally applies to disclosures to a health plan when the individual has paid in full out of pocket, subject to the conditions in the current regulatory text.
An agreed restriction blocks all uses and disclosures of the affected PHI.
Even with an agreed restriction, certain disclosures may still be permitted or required, such as those needed for emergency treatment or otherwise required by law. The restriction applies to the specific uses and disclosures identified, not to all handling of the information.
The right to request restrictions is a Security Rule requirement addressing ePHI.
The restriction request right is an individual right under the HIPAA Privacy Rule, which covers PHI in all forms including oral, paper, and electronic. It should not be confused with the Security Rule, which governs only electronic PHI.

Best practices

Establish a documented intake process for restriction requests so requests are recorded, tracked, and routed for a timely decision consistent with your policies and the Privacy Rule.
Train workforce members to recognize the mandatory restriction scenario involving out-of-pocket payments to a health plan and to route those requests appropriately, verifying conditions against the current regulatory text.
Configure systems and workflows to flag PHI subject to an agreed restriction so that agreed limits are actually enforced across records and downstream disclosures.
Document any agreement or denial of a restriction and communicate the outcome to the individual, including any circumstances under which restricted information may still be disclosed, such as emergency treatment or disclosures required by law.
Define and document procedures for terminating a restriction, including how the individual is notified and how the change applies to information created or received after termination.
Review restriction request policies against current HIPAA requirements and applicable state law, since state law or the HITECH Act may impose additional obligations beyond the federal baseline; verify specifics against current guidance.