Skip to main content
Category: Individual Rights

Right to Request Restrictions

Also known as: Right to Request a Restriction, Right to Request Restriction of Uses and Disclosures, Restriction Request
Simply put

Under the HIPAA Privacy Rule, individuals can ask a healthcare provider or health plan to limit how their health information is used or shared, including limiting disclosures to family members or for treatment, payment, and healthcare operations. In most cases, the covered entity is not required to agree to the requested restriction, but if it does agree, it generally must honor that agreement. There is one situation where a provider must comply: when an individual pays out of pocket in full for a service and asks that it not be disclosed to a health plan.

Formal definition

The right to request restrictions, established under the HIPAA Privacy Rule at 45 CFR 164.522(a), permits an individual to request that a covered entity restrict the uses or disclosures of protected health information (PHI) to carry out treatment, payment, or health care operations, as well as certain disclosures to persons involved in the individual's care such as family members. Generally, a covered entity is not obligated to agree to a requested restriction; however, if it agrees, it is bound by that restriction except in specified circumstances (such as emergency treatment). Practitioners should note the exception typically requiring compliance when an individual pays in full out of pocket for an item or service and requests that the associated PHI not be disclosed to a health plan for payment or health care operations purposes. This right is a function of the Privacy Rule and applies to PHI in all forms, not solely electronic PHI, and it is distinct from the individual's right of access under 45 CFR 164.524. Additional restrictions may apply under other frameworks (for example, 42 CFR Part 2 for certain substance use disorder records) and under state law. Readers should verify the precise regulatory text, exceptions, and any applicable overlays against the current version of the regulation.

Why it matters

The right to request restrictions gives individuals a formal mechanism to shape how their protected health information (PHI) is used and shared, which is a core expression of the patient autonomy the HIPAA Privacy Rule is designed to protect. While covered entities are generally not obligated to agree to most requested restrictions, the one mandatory scenario, where an individual pays in full out of pocket and asks that the associated information not be disclosed to a health plan, carries real operational weight. Failing to honor a restriction the entity has agreed to, or failing to comply with the mandatory out-of-pocket restriction, can expose a covered entity to enforcement action by HHS OCR.

For compliance and privacy officers, this right is significant because it must be operationalized across intake workflows, billing systems, and electronic health record configurations. An agreed-upon restriction is binding (subject to specified exceptions such as emergency treatment), so the organization needs reliable ways to flag, track, and enforce restrictions once accepted. The mandatory out-of-pocket restriction is particularly challenging in practice because it requires systems to segregate self-paid services from claims and other transmissions to health plans, which many billing and EHR systems were not originally built to do at a granular level.

The right also intersects with other legal frameworks that may impose stricter or additional requirements. For example, records subject to 42 CFR Part 2 for certain substance use disorder information carry their own restrictions, and state law may add further protections. Treating the HIPAA right to request restrictions as the ceiling rather than one layer among several can create compliance gaps, so organizations should confirm which overlays apply to a given record before responding to a request.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for establishing policies and procedures for receiving, evaluating, agreeing to, and documenting restriction requests. They must ensure the organization can honor an agreed-upon restriction on an ongoing basis and can reliably comply with the mandatory out-of-pocket restriction when it applies.
Billing and Revenue Cycle Staff
Because the mandatory restriction hinges on out-of-pocket payment in full and non-disclosure to a health plan, billing and revenue cycle teams need workflows that can identify self-paid services and suppress the corresponding transmissions to health plans for payment or health care operations purposes.
Health Information Management and EHR Administrators
HIM professionals and EHR administrators must configure systems to flag, segregate, and enforce accepted restrictions, and to prevent inadvertent disclosure of restricted information. This can be technically demanding where systems were not designed for granular, record-level restriction handling.
Compliance and Legal Teams
Compliance and legal staff should assess where additional frameworks, such as 42 CFR Part 2 for certain substance use disorder records or state law, impose requirements beyond the HIPAA baseline, and should confirm current regulatory text and exceptions before finalizing organizational policy.
Front-Desk and Intake Personnel
Intake staff are often the first point of contact for restriction requests and for offers to pay out of pocket. They need clear scripts and escalation paths so requests are captured accurately and routed to the appropriate personnel for evaluation and documentation.

Inside Right to Request Restrictions

Right to Request Restrictions
A HIPAA Privacy Rule provision that permits an individual to ask a covered entity to limit the use or disclosure of their protected health information (PHI) for treatment, payment, or health care operations, and to limit disclosures to persons involved in the individual's care.
General Discretion to Agree
In most cases, a covered entity is not required to agree to a requested restriction. When it does agree, it is generally bound to honor that restriction except in specified circumstances such as emergency treatment.
Mandatory Restriction for Out-of-Pocket Payments
As introduced under the HITECH Act, a covered entity generally must comply with a request to restrict disclosure of PHI to a health plan for payment or health care operations purposes when the individual has paid for the item or service in full out of pocket, subject to applicable regulatory conditions. Readers should verify the specific conditions against the current regulatory text.
Scope Limited to Privacy Rule
This right arises under the HIPAA Privacy Rule, which covers PHI in all forms (oral, paper, and electronic). It is distinct from Security Rule safeguard obligations, which apply only to electronic PHI.
Emergency Treatment Exception
Even where a restriction has been agreed to, a covered entity generally may use or disclose the restricted PHI to provide emergency treatment, with follow-up obligations to request that the receiving provider not further use or disclose the information.
Termination of a Restriction
An agreed restriction may generally be terminated by the individual at any time, or by the covered entity under conditions permitted by the Privacy Rule, typically with notice to the individual for information created or received after termination.

Common questions

Answers to the questions practitioners most commonly ask about Right to Request Restrictions.

Does a covered entity have to agree to every restriction a patient requests?
No. Under the HIPAA Privacy Rule, a covered entity is generally not required to agree to most requested restrictions on the use or disclosure of PHI. The right is a right to request, not a right to compel agreement in most circumstances. There is a notable exception: a covered entity generally must comply with a request to restrict disclosure to a health plan for payment or health care operations purposes when the individual has paid for the item or service in full out of pocket, subject to the conditions set out in the regulation. Readers should verify the specific conditions and any exceptions against the current regulatory text.
Once a restriction is agreed to, does it override every other use or disclosure of the information?
Not in all cases. Even when a covered entity agrees to a restriction, the Privacy Rule generally permits certain uses and disclosures despite the restriction, such as disclosures needed to provide emergency treatment, and the restriction does not typically bar other permitted or required disclosures outside its stated scope. An agreed restriction also does not eliminate other legal obligations that may apply. The precise boundaries depend on the terms of the agreed restriction and the applicable regulatory provisions, which should be confirmed against current guidance.
How should a covered entity document and track an agreed-to restriction?
As a practical matter, covered entities typically maintain a documented record of each agreed restriction, including its scope, effective date, and the specific PHI and purposes it covers, so that workforce members and systems can honor it. Because restrictions must be operationally enforceable, many organizations flag the affected records so that downstream uses and disclosures are handled consistently. The specific documentation and retention practices should align with the organization's policies and the applicable regulatory requirements, which readers should verify against current text.
Can a covered entity terminate a restriction it previously agreed to?
In general, the Privacy Rule allows an agreed restriction to be terminated under defined conditions, such as when the individual agrees to or requests the termination, or when the covered entity informs the individual that it is terminating the restriction, with such termination typically applying only to PHI created or received after the individual is notified. The individual's agreement to terminate may be handled in accordance with the regulation's provisions. Organizations should confirm the exact termination conditions and any documentation expectations against the current regulatory text.
How do restrictions apply when PHI is shared with business associates?
When a covered entity has agreed to a restriction, it generally needs to ensure that the restriction is honored in relevant downstream handling of the affected PHI, including by business associates that use or disclose that information on its behalf. Obligations to business associates typically flow through the business associate agreement rather than attaching to the vendor directly under the Privacy Rule. In practice, covered entities should communicate applicable restrictions so that business associates can operationalize them, and confirm these arrangements against the terms of their agreements and current guidance.
How does the out-of-pocket payment restriction interact with the rest of a patient's records or with other payers?
The mandatory restriction generally applies to disclosure to a health plan for payment or health care operations concerning a specific item or service the individual has paid for in full out of pocket. It typically does not extend automatically to unrelated items or services, and complexities can arise when restricted and non-restricted information are commingled in a record or when other providers or payers are involved. Because operationalizing this restriction can be technically challenging, and because state law or other frameworks may impose additional requirements, covered entities should review the specific conditions and their own workflows against the current regulatory text.

Common misconceptions

A covered entity must agree to any restriction an individual requests.
In most cases the covered entity retains discretion to decline a requested restriction. The primary mandatory exception, introduced under the HITECH Act, generally involves disclosures to a health plan when the individual has paid out of pocket in full. Readers should confirm the specific conditions against the current regulatory text.
Once a restriction is agreed to, it applies absolutely and can never be overridden.
An agreed restriction is generally binding, but the Privacy Rule provides exceptions, such as using or disclosing the restricted information to provide emergency treatment. Restrictions may also be terminated under conditions the rule permits.
The right to request restrictions is a Security Rule matter about electronic data.
This right is established under the HIPAA Privacy Rule and applies to PHI in all forms, including oral and paper. It is separate from the Security Rule, which addresses safeguards for electronic PHI only.

Best practices

Maintain a documented process for receiving, evaluating, and responding to restriction requests, distinguishing discretionary requests from mandatory out-of-pocket restrictions.
Train workforce members and, where relevant, coordinate with business associates through business associate agreements so that agreed restrictions are honored across systems and workflows that handle the affected PHI.
Configure records systems to flag or segregate restricted PHI so that agreed restrictions are consistently applied and are not inadvertently disclosed for treatment, payment, or operations.
Document each agreed restriction, its scope, any termination, and the emergency-treatment or other exceptions relied upon, keeping records consistent with Privacy Rule requirements.
Verify the current conditions for mandatory out-of-pocket restrictions against the applicable regulatory text rather than relying on general summaries, since specific requirements are set by regulation.
Check whether applicable state law or other frameworks impose additional restriction or confidentiality requirements beyond HIPAA, and reconcile any differences in your policies.