Restriction Request
A restriction request is when a patient asks a healthcare provider or health plan to limit how their protected health information (PHI) is used or shared. Individuals have the right to make this request, but in most cases the covered entity is not required to agree to it. If a covered entity does agree, it generally must honor the restriction it accepted.
Under the HIPAA Privacy Rule, an individual may request that a covered entity restrict the use or disclosure of PHI, including restrictions on uses or disclosures for treatment, payment, or health care operations, and disclosures to persons involved in the individual's care. This is a right to request a restriction, not an absolute right to compel one; generally a covered entity is not required to agree to a requested restriction, though where it agrees it is bound to comply with the accepted restriction subject to applicable exceptions. Covered entities typically process such requests through a defined intake and review process, often using a written request form. Note that certain narrower restriction rights may be treated differently under the Privacy Rule and related HITECH provisions, and that other laws may impose additional or conflicting obligations; readers should verify specific scope, exceptions, and any mandatory-agreement circumstances against the current regulatory text.
Why it matters
The right to request a restriction is one of the individual rights granted under the HIPAA Privacy Rule, and it gives patients a formal channel to ask that their protected health information (PHI) be used or shared more narrowly than the rules would otherwise permit. Understanding this right matters because it is frequently misunderstood: individuals can make a restriction request at any time, but making a request is not the same as compelling the outcome. In most cases a covered entity is not required to agree to a requested restriction. Where a covered entity does agree, however, it is generally bound to comply with the restriction it accepted, subject to applicable exceptions, which creates a concrete downstream obligation for the organization.
For covered entities, mishandling restriction requests carries real compliance exposure. A defined intake and review process helps ensure requests are logged, evaluated consistently, and either accepted or declined in a documented way. Once a restriction is accepted, systems and workflows must actually be able to enforce it, because failing to honor a restriction the organization agreed to could itself be a Privacy Rule failing. Because certain narrower restriction rights may be treated differently under the Privacy Rule and related HITECH provisions, and because other laws may impose additional or even conflicting obligations, organizations should not treat all restriction requests as a single uniform category.
Readers should verify the specific scope of restriction rights, the exceptions that apply, and any circumstances in which agreement to a restriction may be mandatory against the current regulatory text. This entry describes the general right to request a restriction and does not attempt to catalog every specialized restriction scenario or state-law overlay that may apply.
Who it's relevant to
Inside Restriction Request
Common questions
Answers to the questions practitioners most commonly ask about Restriction Request.