Skip to main content
Category: Individual Rights

Right to Amendment

Simply put

The Right to Amendment generally refers to an individual's ability under the HIPAA Privacy Rule to request that a covered entity correct or add to their protected health information when they believe it is inaccurate or incomplete. A covered entity may accept or deny such a request under certain conditions, and denials typically must follow specified procedures. This entry describes the general concept; readers should verify specific requirements against the current regulatory text.

Formal definition

Under the HIPAA Privacy Rule, the Right to Amendment is an individual right permitting a person to request that a covered entity amend protected health information (PHI) or a record about the individual maintained in a designated record set for as long as the information is retained. Covered entities may deny requests under defined circumstances, and must follow required procedures for accepting or denying amendments, including timelines and notice obligations. This right applies to PHI in all forms and is distinct from Security Rule obligations, which govern only electronic PHI. The evidence packet provided does not contain HIPAA-specific source material for this term; the specific procedural requirements, timeframes, and permissible grounds for denial should be confirmed against the current HIPAA Privacy Rule text, and readers should note that state law or other frameworks may impose additional requirements.

Why it matters

The Right to Amendment is a foundational individual right under the HIPAA Privacy Rule because the accuracy of protected health information can directly affect the care an individual receives, the decisions clinicians make, and the way an individual is represented across the healthcare system. When a record contains inaccurate or incomplete information, the ability to request a correction gives individuals a meaningful mechanism to participate in the integrity of their own health data. For covered entities, honoring this right in a consistent and documented manner is part of demonstrating good-faith compliance with the Privacy Rule's individual rights provisions.

Mishandling amendment requests carries compliance risk. Because the Privacy Rule generally requires covered entities to follow specified procedures when accepting or denying a request, including applicable timelines and notice obligations, failures in these processes can become the subject of complaints to HHS OCR, which enforces the HIPAA rules. Note that penalty tiers and enforcement outcomes are determined by HHS OCR and are adjusted over time; readers should confirm current figures and enforcement guidance against the applicable regulatory sources rather than relying on any fixed amount.

It is important to recognize that the Right to Amendment does not give an individual an unconditional right to change any part of a record. A covered entity may deny a request under defined circumstances, and the amendment right generally applies to PHI within a designated record set. The evidence provided for this entry does not contain HIPAA-specific source material, so the precise grounds for denial, procedural steps, and timeframes should be verified against the current HIPAA Privacy Rule text.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are typically responsible for establishing and maintaining the policies and procedures that govern how amendment requests are received, evaluated, granted, or denied. They should ensure that timelines, notice obligations, and permissible grounds for denial are handled consistently and documented, and should verify these procedures against the current HIPAA Privacy Rule text and any applicable state law.
Health Information Management (HIM) Professionals
HIM staff often manage the designated record set and are involved in locating the relevant PHI, applying accepted amendments, and preserving the original information as required. Because the amendment right generally applies for as long as the information is retained, these professionals play a central role in operationalizing accepted requests accurately.
Covered Entities
Covered entities hold the obligation to respond to amendment requests under the Privacy Rule and to follow required procedures for acceptance or denial. Consistent handling reduces the risk of complaints to HHS OCR and supports demonstrable compliance with individual rights provisions.
Business Associates
Business associates that maintain PHI in a designated record set on behalf of a covered entity may be involved in fulfilling amendment requests, with obligations flowing through the business associate agreement. The specific responsibilities depend on the terms of that agreement and the applicable regulatory requirements, which should be confirmed against current guidance.
Individuals and Patient Advocates
Individuals and those assisting them benefit from understanding that they may request corrections or additions to their PHI when they believe it is inaccurate or incomplete, while also recognizing that a covered entity may deny a request under defined circumstances and must follow a specified process when doing so.

Inside Right to Amendment

Individual Right to Request Amendment
Under the HIPAA Privacy Rule, an individual generally has the right to request that a covered entity amend PHI or a record about them maintained in a designated record set, for as long as that information is kept.
Designated Record Set Scope
The right applies to PHI within a designated record set, which typically includes medical and billing records and other records used to make decisions about individuals. Information outside a designated record set is generally not subject to this right.
Grounds for Denial
A covered entity may deny an amendment request in certain circumstances, such as when the information was not created by the covered entity (unless the originator is no longer available), is not part of the designated record set, would not be available for inspection under the access right, or is accurate and complete as determined by the entity.
Amendment Distinguished From Deletion
The right to amendment generally allows an individual to add corrective or clarifying information; it does not typically require the covered entity to delete or erase existing entries in the record.
Timeliness and Response Obligations
The Privacy Rule generally requires covered entities to act on an amendment request within a defined timeframe and to provide either the amendment or a written denial. Readers should verify the specific timeframes against the current regulatory text.
Denial Process and Individual Recourse
When a request is denied, the individual is generally entitled to a written denial and typically has the right to submit a statement of disagreement, which the covered entity may rebut and must include with subsequent disclosures of the disputed information.
Notification to Others
When an amendment is made, the covered entity is generally expected to make reasonable efforts to notify and provide the amendment to persons identified by the individual and to relevant business associates or others that received the information.

Common questions

Answers to the questions practitioners most commonly ask about Right to Amendment.

Does the right to amendment mean a covered entity must change any record a patient disputes?
No. The Privacy Rule generally grants individuals the right to request an amendment, but a covered entity may deny the request under specific permitted grounds, for example, when the entity did not create the record, when the information is not part of the designated record set, or when the entity determines the record is accurate and complete. The right is a right to request and to have that request considered, not an automatic right to alter the record.
If an amendment request is granted, does the original entry get deleted from the record?
Generally no. Amendment under the Privacy Rule typically involves adding the amending information to the designated record set rather than erasing the original entry. The purpose is to correct or supplement the record while preserving an accurate history, so the original information usually remains alongside the amendment.
What should a covered entity do when it denies an amendment request?
In most cases the entity must provide the individual with a timely written denial that explains the basis for the denial and describes how the individual may submit a statement of disagreement, as well as how they may complain. Covered entities should confirm the specific content and timing requirements against the current Privacy Rule text, and note that state law may impose additional obligations.
How does a statement of disagreement work if the patient contests a denial?
When an amendment is denied, the individual generally may submit a statement of disagreement, and the covered entity may prepare a rebuttal. The Privacy Rule typically requires that these materials, or an accurate summary, be included with the disputed information in future disclosures. Entities should verify the exact handling and length limitations against current regulatory guidance.
If a business associate holds the record, who handles the amendment request?
The amendment obligation generally rests with the covered entity, but where a business associate maintains records in the designated record set, the business associate agreement typically should address how amendment requests are handled and passed through. HIPAA obligations attach through these defined relationships rather than to every vendor by default, so responsibilities should be spelled out in the applicable agreement.
Does an amendment need to be communicated to others who received the original information?
When an amendment is made, the Privacy Rule generally directs the covered entity to make reasonable efforts to inform and provide the amendment to persons the individual identifies who need it, and to those known to have the information who may have relied or could rely on it to the individual's detriment. Confirm the specific notification expectations against the current regulatory text.

Common misconceptions

The right to amendment means an individual can force a provider to delete or rewrite existing entries in their record.
The right generally allows amendment by adding corrective or supplemental information rather than erasing prior entries. Covered entities are typically not required to delete original documentation, and they may deny requests on defined grounds such as the information being accurate and complete.
A covered entity must grant every amendment request.
The Privacy Rule permits denial in specific circumstances, including where the entity did not create the information, the information is not part of the designated record set, it would not be available for inspection, or it is accurate and complete. Denials generally must be provided in writing, and the individual typically may submit a statement of disagreement.
The right to amendment applies to any information a covered entity holds about a person.
This right generally applies to PHI within a designated record set. Information outside that set, such as certain records not used to make decisions about the individual, is typically not subject to the amendment right. Note this is a Privacy Rule concept and is distinct from Security Rule obligations, which govern only ePHI.

Best practices

Establish and document a written policy and standard procedure for receiving, tracking, and responding to amendment requests within the timeframes required by the Privacy Rule, verifying current deadlines against the applicable regulatory text.
Clearly define what constitutes your designated record set so staff can consistently determine whether requested information falls within the scope of the amendment right.
When denying a request, provide a written denial that states a permissible basis, informs the individual of their right to submit a statement of disagreement, and explains how to file a complaint.
Implement a reliable method to link amendments, statements of disagreement, and any rebuttals to the relevant record so they are included in future disclosures of the disputed information.
Make reasonable efforts to identify and notify business associates and other recipients who received the affected PHI when an amendment is made, and document these efforts.
Check whether applicable state laws impose additional or more stringent amendment or recordkeeping requirements beyond HIPAA, and confirm current obligations against the applicable regulatory text before finalizing procedures.