Skip to main content
Category: Individual Rights

Right to Confidential Communications

Also known as: Confidential Communications Request, Right to Request Confidential Communications, Alternative Communications Request
Simply put

This is a right under the HIPAA Privacy Rule that lets a person ask a healthcare provider or health plan to contact them in a specific way or at a specific location, rather than by the default method. For example, someone might request that they be called on a cell phone instead of a home phone, or that mail be sent to a work address instead of a home address. The goal is generally to protect the person's privacy in situations where a normal communication method could reveal sensitive health information to others.

Formal definition

The Right to Confidential Communications is an individual right established under the HIPAA Privacy Rule at 45 CFR § 164.522(b), permitting individuals to request that a covered entity communicate protected health information (PHI) by alternative means or at alternative locations. Under the applicable regulatory text, health care providers must generally accommodate reasonable requests without requiring the individual to state a reason, while health plans may condition accommodation on the individual's statement that disclosure could endanger them, and may impose conditions such as specifying an alternative address and, where relevant, addressing payment of claims. A covered entity may require that such requests be made in writing. The right, and the process for making a request, must be described in the entity's Notice of Privacy Practices. This right is distinct from the right to request restrictions on uses and disclosures (also addressed in § 164.522) and from the rights to access or amend PHI. It is an obligation of covered entities under the Privacy Rule; business associates are bound only as provided through their business associate agreements and applicable regulation. Readers should note that state law or the HITECH Act may impose additional requirements, and specific regulatory provisions should be verified against the current text of 45 CFR § 164.522.

Why it matters

The Right to Confidential Communications addresses a practical privacy gap: even when a covered entity handles PHI appropriately, the default method of contacting a patient can inadvertently expose sensitive health information to family members, roommates, employers, or others who share an address, phone, or mailbox. A voicemail left on a shared home phone, an appointment reminder mailed to a household, or an explanation of benefits sent to a policyholder can reveal treatment relationships or diagnoses the individual intended to keep private. This right gives individuals a mechanism to steer those communications toward channels they control.

For compliance and privacy officers, this right matters because it is an enforceable obligation under the HIPAA Privacy Rule, not merely a courtesy. Health care providers must generally accommodate reasonable requests without requiring the individual to explain why, while health plans operate under a somewhat different standard that may permit conditions such as a statement that disclosure could endanger the individual. Failing to build workflows that capture, honor, and maintain these preferences can create Privacy Rule compliance exposure, and the right must be described in the entity's Notice of Privacy Practices.

Because the accommodation standard and the process differ between providers and health plans, organizations should not assume a single blanket procedure satisfies the requirement in all contexts. Readers should also note that state law or the HITECH Act may impose additional or stricter requirements, and specific obligations should be verified against the current text of 45 CFR § 164.522.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are responsible for establishing the intake process for confidential communications requests, ensuring the Notice of Privacy Practices accurately describes the right and how to exercise it, and confirming that accommodated preferences are consistently honored across communication channels. They should also account for the differing standards that apply to providers versus health plans and for any additional requirements imposed by state law or the HITECH Act.
Health Care Providers
Providers must generally accommodate reasonable requests to receive communications by alternative means or at alternative locations, typically without requiring the individual to state a reason. Front-desk, scheduling, and clinical communication workflows should be able to capture and apply these preferences so that reminders, results, and other PHI communications reach the patient through the requested channel.
Health Plans
Health plans operate under a distinct standard and may condition accommodation on the individual's statement that disclosure could endanger them. Plans may also impose conditions such as requiring an alternative address and addressing how claims payments are handled. Plan operations should route communications like benefit explanations and correspondence in a manner consistent with an accommodated request.
Business Associates
Business associates are not directly subject to this individual right under the Privacy Rule; their obligations arise only as provided through the business associate agreement and applicable regulation. Where a business associate handles communications on a covered entity's behalf, the agreement and operational arrangements should reflect any confidential communication preferences the covered entity is obligated to honor.
Individuals and Patients
Individuals can use this right to protect their privacy in situations where a default communication method could reveal sensitive information to others who share their household, phone, or mailbox. The Notice of Privacy Practices describes how to make a request, and a covered entity may require that the request be submitted in writing.

Inside Right to Confidential Communications

Individual's Right to Request
Under the HIPAA Privacy Rule, an individual has the right to request that a covered entity communicate protected health information (PHI) to them by alternative means or at alternative locations. For example, requesting that communications be sent to a work address instead of home, or to a specific phone number.
Reasonableness Standard for Accommodation
Covered entities are generally required to accommodate reasonable requests for confidential communications. Health plans must accommodate such requests if the individual clearly states that disclosure by the standard means could endanger them; health care providers must accommodate reasonable requests without requiring a statement of endangerment. Readers should verify the specific conditions against the current regulatory text.
Permissible Conditions on Requests
A covered entity may condition accommodation on the individual specifying an alternative address or method of contact and, in some cases, on information as to how payment will be handled. It may not require an explanation of the reason for the request beyond what the rule permits.
Scope Limited to PHI Communications
This right addresses how and where PHI is communicated to the individual, not whether the underlying uses or disclosures are permitted. It is distinct from the right to request restrictions on uses and disclosures, which is a separate Privacy Rule provision.
Applies Across PHI Forms
Because this is a Privacy Rule right, it applies to PHI in all forms, oral, paper, and electronic, not solely to electronic PHI governed by the Security Rule.

Common questions

Answers to the questions practitioners most commonly ask about Right to Confidential Communications.

Does the right to confidential communications let a patient request that we hide or withhold their information from the covered entity itself?
No. This is a common misconception. The right to confidential communications, under the HIPAA Privacy Rule, generally addresses how and where a covered entity communicates PHI with the individual, for example, by an alternative means (such as a specific phone number) or at an alternative location (such as a work address rather than a home address). It does not give the individual a right to keep their information from the covered entity's own records or workforce. Restricting what is disclosed to others is a distinct right (the right to request restrictions), which operates under different standards. Readers should verify the specific provisions against the current regulatory text.
Can a covered entity refuse a confidential communications request simply because it seems inconvenient or the patient will not explain why?
Not straightforwardly. In most cases, a covered entity (particularly a health care provider) must accommodate reasonable requests for confidential communications and generally may not require the individual to explain the reason for the request. Providers typically must accommodate reasonable requests, while health plans generally must accommodate reasonable requests when the individual states that disclosure could endanger them. This differs from the right to request restrictions, which a covered entity is generally not required to grant. Because the precise conditions and any exceptions vary, confirm the applicable requirements against the current Privacy Rule text, and note that state law may impose additional obligations.
How should we handle the actual mechanics of a confidential communications request at intake?
As a practical matter, many covered entities incorporate a field or form allowing individuals to specify an alternative means (such as email, a designated phone number, or no voicemail) or alternative location for communications. It is generally advisable to document the request, the accommodation provided, and the effective scope, and to route it so that relevant workforce members and systems honor it. The Privacy Rule permits certain reasonable conditions on requests, such as specifying how the request is made or how payment will be handled, but the details should be confirmed against the current regulatory text.
What conditions are we generally permitted to place on accommodating these requests?
Covered entities may generally impose certain reasonable conditions consistent with the Privacy Rule, which can include requiring that requests be made in writing, specifying an alternative address or method of contact, and, in some cases for providers, addressing how payment will be handled when accommodation affects billing communications. Any conditions imposed should be reasonable and not defeat the purpose of the accommodation. Because the permitted conditions are defined by regulation, verify the specifics against the current Privacy Rule provisions.
How do we make sure an accommodation actually persists across our systems and staff?
Operationally, honoring a confidential communications accommodation typically depends on administrative processes and system configuration so that the preferred contact method or location is applied consistently, for example, across appointment reminders, billing statements, and clinical follow-up. Since HIPAA obligations attach to the covered entity, and information may also flow through business associates under a business associate agreement, it is generally prudent to confirm that any vendors handling communications on your behalf can also apply the accommodation. Documentation and periodic review help demonstrate that the accommodation is being maintained.
How does this right interact with a business associate that sends communications on our behalf?
The confidential communications obligation attaches to the covered entity under the Privacy Rule, not directly to every vendor. Where a business associate performs functions such as sending statements or reminders, the covered entity generally remains responsible for ensuring accommodations are honored, and the relevant expectations typically flow through the business associate agreement. Covered entities should confirm that their agreements and their vendors' operational capabilities support honoring these requests, and should verify the precise allocation of responsibilities against the current regulatory text and their contractual terms.

Common misconceptions

A covered entity must honor any and every confidential communication request an individual makes.
The obligation generally extends to reasonable requests. Providers must accommodate reasonable requests, and health plans must accommodate when disclosure could endanger the individual, but entities may impose permissible conditions such as requiring an alternative address or contact method. The precise standards should be confirmed against the current Privacy Rule text.
The right to confidential communications is the same as the right to request restrictions on uses and disclosures.
These are two separate rights under the Privacy Rule. Confidential communications concern how and where PHI is delivered to the individual, while restriction requests concern whether and to whom PHI may be used or disclosed. Conflating them can lead to mishandled requests.
This right only applies to electronic communications or systems.
As a Privacy Rule provision, it applies to PHI in all forms, including oral and paper communications, not just electronic PHI. The Security Rule, by contrast, governs only ePHI and does not itself establish this right.

Best practices

Establish a documented intake process for confidential communication requests that captures the requested alternative means or location without requiring individuals to explain their reasons beyond what the Privacy Rule permits.
Train workforce members who handle patient or member contact to recognize confidential communication requests and to distinguish them from restriction requests, routing each to the correct workflow.
Configure record and communication systems so that approved alternative contact preferences are consistently applied across mailings, calls, billing, and other PHI communications.
Apply a consistent reasonableness standard and, where appropriate for health plans, address the endangerment condition; document the basis for accommodating or, in limited permissible cases, declining a request.
Review policies against the current HIPAA Privacy Rule text and applicable state law, which may impose additional or stricter confidentiality requirements beyond the federal baseline.
Periodically audit whether accommodated preferences remain in effect and are honored in practice, since a documented policy alone does not guarantee correct handling of every communication.