Right to Confidential Communications
This is a right under the HIPAA Privacy Rule that lets a person ask a healthcare provider or health plan to contact them in a specific way or at a specific location, rather than by the default method. For example, someone might request that they be called on a cell phone instead of a home phone, or that mail be sent to a work address instead of a home address. The goal is generally to protect the person's privacy in situations where a normal communication method could reveal sensitive health information to others.
The Right to Confidential Communications is an individual right established under the HIPAA Privacy Rule at 45 CFR § 164.522(b), permitting individuals to request that a covered entity communicate protected health information (PHI) by alternative means or at alternative locations. Under the applicable regulatory text, health care providers must generally accommodate reasonable requests without requiring the individual to state a reason, while health plans may condition accommodation on the individual's statement that disclosure could endanger them, and may impose conditions such as specifying an alternative address and, where relevant, addressing payment of claims. A covered entity may require that such requests be made in writing. The right, and the process for making a request, must be described in the entity's Notice of Privacy Practices. This right is distinct from the right to request restrictions on uses and disclosures (also addressed in § 164.522) and from the rights to access or amend PHI. It is an obligation of covered entities under the Privacy Rule; business associates are bound only as provided through their business associate agreements and applicable regulation. Readers should note that state law or the HITECH Act may impose additional requirements, and specific regulatory provisions should be verified against the current text of 45 CFR § 164.522.
Why it matters
The Right to Confidential Communications addresses a practical privacy gap: even when a covered entity handles PHI appropriately, the default method of contacting a patient can inadvertently expose sensitive health information to family members, roommates, employers, or others who share an address, phone, or mailbox. A voicemail left on a shared home phone, an appointment reminder mailed to a household, or an explanation of benefits sent to a policyholder can reveal treatment relationships or diagnoses the individual intended to keep private. This right gives individuals a mechanism to steer those communications toward channels they control.
For compliance and privacy officers, this right matters because it is an enforceable obligation under the HIPAA Privacy Rule, not merely a courtesy. Health care providers must generally accommodate reasonable requests without requiring the individual to explain why, while health plans operate under a somewhat different standard that may permit conditions such as a statement that disclosure could endanger the individual. Failing to build workflows that capture, honor, and maintain these preferences can create Privacy Rule compliance exposure, and the right must be described in the entity's Notice of Privacy Practices.
Because the accommodation standard and the process differ between providers and health plans, organizations should not assume a single blanket procedure satisfies the requirement in all contexts. Readers should also note that state law or the HITECH Act may impose additional or stricter requirements, and specific obligations should be verified against the current text of 45 CFR § 164.522.
Who it's relevant to
Inside Right to Confidential Communications
Common questions
Answers to the questions practitioners most commonly ask about Right to Confidential Communications.