Satisfactory Assurances
Satisfactory assurances are documented commitments a covered entity must obtain before it uses or discloses protected health information (PHI) in certain situations, confirming that the recipient will handle the information appropriately. For example, when responding to a subpoena or discovery request, a covered entity generally must receive satisfactory assurances that reasonable steps were taken to notify the patient or to obtain a protective order. Similarly, before a business associate handles PHI on the covered entity's behalf, the covered entity must obtain satisfactory assurances that the associate will safeguard the information.
Under the HIPAA Privacy Rule, 'satisfactory assurances' is a term of art referring to documented commitments a covered entity must obtain before certain permitted uses or disclosures of PHI. In the business associate context, the satisfactory assurances that a business associate will appropriately safeguard PHI must generally be documented through a written contract or other written agreement (commonly a business associate agreement). In the litigation context, a covered entity that is not a party to the litigation may disclose PHI in response to a subpoena or discovery request only upon receiving satisfactory assurances that reasonable efforts were made either to notify the individual of the request or to secure a qualified protective order. This term applies to PHI in all forms under the Privacy Rule and is distinct from the Security Rule's ePHI-specific safeguard requirements. Note that the specific procedural conditions constituting satisfactory assurances differ by context; practitioners should confirm the applicable requirements against the current regulatory text, and note that state law may impose additional or stricter notification requirements.
Why it matters
Satisfactory assurances function as a gatekeeping requirement under the HIPAA Privacy Rule, ensuring that PHI is not released or handed off without documented protections in place. In the business associate context, these assurances are the mechanism by which a covered entity extends privacy and safeguarding obligations to the vendors and partners that handle PHI on its behalf. Without obtaining and documenting them, a covered entity may be disclosing PHI in a manner the Privacy Rule does not permit, exposing itself to enforcement action by HHS OCR.
The requirement is especially significant in litigation, where a covered entity that is not a party to a lawsuit may feel pressure to comply quickly with a subpoena or discovery request. The Privacy Rule generally prohibits such disclosures unless the covered entity first receives satisfactory assurances that reasonable efforts were made either to notify the individual whose information is sought or to secure a qualified protective order. This protects patients from having their health information swept into legal proceedings without notice or safeguards.
Because the specific conditions that constitute satisfactory assurances differ by context, and because state law may impose additional or stricter notification requirements, this term is a frequent source of confusion and compliance risk. Treating a subpoena as automatically sufficient authority to disclose, or engaging a vendor without a written agreement, are common missteps that the satisfactory assurances requirement is designed to prevent.
Who it's relevant to
Inside Satisfactory Assurances
Common questions
Answers to the questions practitioners most commonly ask about Satisfactory Assurances.