Right to Request Restrictions
Under the HIPAA Privacy Rule, individuals can ask a healthcare provider or health plan to limit how their health information is used or shared, including limiting disclosures to family members or for treatment, payment, and healthcare operations. In most cases, the covered entity is not required to agree to the requested restriction, but if it does agree, it generally must honor that agreement. There is one situation where a provider must comply: when an individual pays out of pocket in full for a service and asks that it not be disclosed to a health plan.
The right to request restrictions, established under the HIPAA Privacy Rule at 45 CFR 164.522(a), permits an individual to request that a covered entity restrict the uses or disclosures of protected health information (PHI) to carry out treatment, payment, or health care operations, as well as certain disclosures to persons involved in the individual's care such as family members. Generally, a covered entity is not obligated to agree to a requested restriction; however, if it agrees, it is bound by that restriction except in specified circumstances (such as emergency treatment). Practitioners should note the exception typically requiring compliance when an individual pays in full out of pocket for an item or service and requests that the associated PHI not be disclosed to a health plan for payment or health care operations purposes. This right is a function of the Privacy Rule and applies to PHI in all forms, not solely electronic PHI, and it is distinct from the individual's right of access under 45 CFR 164.524. Additional restrictions may apply under other frameworks (for example, 42 CFR Part 2 for certain substance use disorder records) and under state law. Readers should verify the precise regulatory text, exceptions, and any applicable overlays against the current version of the regulation.
Why it matters
The right to request restrictions gives individuals a formal mechanism to shape how their protected health information (PHI) is used and shared, which is a core expression of the patient autonomy the HIPAA Privacy Rule is designed to protect. While covered entities are generally not obligated to agree to most requested restrictions, the one mandatory scenario, where an individual pays in full out of pocket and asks that the associated information not be disclosed to a health plan, carries real operational weight. Failing to honor a restriction the entity has agreed to, or failing to comply with the mandatory out-of-pocket restriction, can expose a covered entity to enforcement action by HHS OCR.
For compliance and privacy officers, this right is significant because it must be operationalized across intake workflows, billing systems, and electronic health record configurations. An agreed-upon restriction is binding (subject to specified exceptions such as emergency treatment), so the organization needs reliable ways to flag, track, and enforce restrictions once accepted. The mandatory out-of-pocket restriction is particularly challenging in practice because it requires systems to segregate self-paid services from claims and other transmissions to health plans, which many billing and EHR systems were not originally built to do at a granular level.
The right also intersects with other legal frameworks that may impose stricter or additional requirements. For example, records subject to 42 CFR Part 2 for certain substance use disorder information carry their own restrictions, and state law may add further protections. Treating the HIPAA right to request restrictions as the ceiling rather than one layer among several can create compliance gaps, so organizations should confirm which overlays apply to a given record before responding to a request.
Who it's relevant to
Inside Right to Request Restrictions
Common questions
Answers to the questions practitioners most commonly ask about Right to Request Restrictions.