Skip to main content
Category: Individual Rights

Statement of Disagreement

Also known as: Statement of Disagreement with Amendment Request
Simply put

A Statement of Disagreement is a written explanation an individual may submit after a covered entity denies all or part of their request to amend their protected health information (PHI). It lets the individual formally record why they disagree with the denial, and this statement generally becomes part of their record. The covered entity may prepare a written rebuttal explaining why it stands by the denial.

Formal definition

Under the HIPAA Privacy Rule's individual right to request amendment of PHI, a Statement of Disagreement is the written submission an individual may provide when a covered entity denies, in whole or in part, a requested amendment. The Privacy Rule generally requires that the individual's Statement of Disagreement (and the underlying amendment request and denial, or an accurate summary) be identified and, in most cases, appended to or linked with the disputed record so it is available with future disclosures. The covered entity may prepare a written rebuttal to the Statement of Disagreement, a copy of which is generally provided to the individual. This term applies to PHI in all forms under the Privacy Rule and is distinct from the Security Rule, which governs only ePHI. This entry does not address specific procedural timeframes or content requirements; practitioners should verify the exact requirements against the current regulatory text, and note that state law or organizational policy may impose additional requirements.

Why it matters

The right to request amendment of one's protected health information is a core individual right under the HIPAA Privacy Rule, but that right does not obligate a covered entity to make every requested change. When a covered entity denies an amendment in whole or in part, the Statement of Disagreement is the mechanism that preserves the individual's voice in the record. Without it, a denial would be the final word, and the individual's objection would leave no trace in the documentation that may later inform their care or be disclosed to others. The statement helps ensure that anyone who later reviews the record can see that the accuracy or completeness of the information was contested.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for administering the amendment request and denial process and for ensuring that a properly submitted Statement of Disagreement is identified, appended to or linked with the disputed record, and made available with future disclosures. They also oversee whether and how the organization prepares any written rebuttal and provides a copy to the individual.
Health Information Management (HIM) Staff
HIM and medical records staff typically handle the operational task of incorporating the Statement of Disagreement, the underlying request, and the denial into the record so these documents travel with future disclosures of the disputed PHI. Accurate linking and retrieval are essential to meeting the Privacy Rule's expectations.
Compliance and Legal Teams
Compliance officers and legal counsel advise on the exact procedural requirements, help draft any rebuttal, and confirm the organization's process aligns with the current regulatory text. They should also assess whether applicable state law or organizational policy imposes additional obligations beyond the HIPAA Privacy Rule baseline.
Patients and Their Representatives
Individuals and their authorized representatives are the parties who exercise this right. A Statement of Disagreement gives them a formal way to record their objection when an amendment is denied, ensuring their disagreement becomes part of the record and is generally available alongside the disputed information in future disclosures.

Inside Statement of Disagreement

Purpose
A statement of disagreement is a written response an individual may submit when a covered entity denies their request to amend PHI in a designated record set under the HIPAA Privacy Rule. It allows the individual to document their disagreement with the denial.
Trigger Event
It arises only after a covered entity denies an amendment request. The right to submit it is part of the amendment process; if the covered entity grants the amendment, no statement of disagreement is needed.
Reasonable Length Limitation
A covered entity may generally require, by policy, that the statement of disagreement be limited to a reasonable length. Practitioners should verify specifics against the current regulatory text.
Covered Entity's Rebuttal Option
The covered entity may prepare a written rebuttal to the statement of disagreement. If it does so, it must generally provide the individual with a copy of that rebuttal.
Recordkeeping and Future Disclosures
The individual's amendment request, the denial, any statement of disagreement, and any rebuttal are generally appended to or linked with the disputed record. This documentation is typically included with, or its inclusion made clear in, future disclosures of the disputed PHI.
Scope
This concept is a mechanism of the HIPAA Privacy Rule, which covers PHI in all forms including oral, paper, and electronic. It is distinct from Security Rule safeguards, which govern only ePHI.

Common questions

Answers to the questions practitioners most commonly ask about Statement of Disagreement.

Does filing a statement of disagreement force the covered entity to change or delete the disputed information in the record?
No. A statement of disagreement does not require the covered entity to alter, correct, or remove the original information. It is the mechanism an individual uses after a covered entity denies a request for amendment under the HIPAA Privacy Rule. The disputed record generally remains as it was, and the individual's statement is appended to or associated with it. The right to have the record actually changed is a separate matter tied to the amendment request itself, which the covered entity may deny for permitted reasons.
Can an individual submit a statement of disagreement of any length and require it to be distributed everywhere the record has ever gone?
Not without limits. The Privacy Rule generally permits a covered entity to reasonably limit the length of a statement of disagreement. In addition, the covered entity's obligation to include the statement, its rebuttal, and related materials typically applies to future disclosures of the disputed portion of the record, rather than requiring retroactive redistribution to every prior recipient. Specific length and handling limits should be confirmed against the current regulatory text.
What documents must a covered entity keep together once a statement of disagreement is submitted?
In most cases the covered entity should retain and associate several items with the disputed record: the individual's request for amendment, the covered entity's denial, the individual's statement of disagreement, and any rebuttal the covered entity prepares. Keeping these linked helps ensure that the appropriate materials accompany future disclosures of the disputed portion of the record. Retention practices should be aligned with the covered entity's documentation policies and verified against current requirements.
How should staff handle future disclosures of a record that has an associated statement of disagreement?
Generally, when the covered entity later discloses the disputed portion of the record, it must include the statement of disagreement, or an accurate summary of it, along with any rebuttal, so that recipients see the individual's position. If the individual did not submit a statement of disagreement, the covered entity may instead be required to include the amendment request and denial when the individual requests it. Workflows should flag disputed records so this material is not omitted.
What can a covered entity do if it wants to respond to an individual's statement of disagreement?
The covered entity may prepare a written rebuttal to the statement of disagreement. If it does so, it generally must provide a copy of that rebuttal to the individual. The rebuttal is then handled alongside the statement of disagreement and the disputed record for future disclosures. This gives the covered entity a way to document its own position without changing the original record or reversing its denial of the amendment.
Are HITRUST controls or certification relevant to managing statements of disagreement?
The statement of disagreement is a specific requirement under the HIPAA Privacy Rule, enforced by HHS OCR, and it exists independently of any private framework. HITRUST CSF controls may help an organization operationalize documentation, retention, and access practices that support this obligation, but HITRUST certification is not a legal requirement and does not by itself establish compliance with the Privacy Rule's amendment and disagreement provisions. The underlying obligations should be verified against the current regulatory text.

Common misconceptions

A statement of disagreement forces the covered entity to change the record.
It does not compel amendment. When a covered entity denies an amendment request, the individual may document disagreement, but the underlying disputed information generally remains in the record; the statement is appended rather than a substitute for the entry.
The individual can write a statement of disagreement of any length they wish.
A covered entity may generally require, by policy, that the statement be limited to a reasonable length. The specific limitations should be verified against the current Privacy Rule text.
Once a statement of disagreement is filed, the dispute is closed and nothing further is exchanged.
The covered entity may prepare a written rebuttal and, in most cases, must provide the individual a copy. The request, denial, statement, and any rebuttal are typically maintained and made available with future disclosures of the disputed PHI.

Best practices

Maintain written policies and procedures that clearly describe how individuals may submit a statement of disagreement following an amendment denial, including any reasonable length limits established by the entity.
Ensure the amendment request, the denial, the statement of disagreement, and any rebuttal are appended to or linked with the relevant record in the designated record set so they travel with the disputed PHI.
Establish a consistent process to include this documentation, or a clear reference to it, in future disclosures of the disputed information.
If the covered entity elects to prepare a written rebuttal, document that a copy was provided to the individual and retain evidence of that provision.
Train workforce members involved in amendment handling to distinguish granting an amendment from denying it, since a statement of disagreement is relevant only after a denial.
Verify current requirements, including any timelines and length limitations, against the applicable Privacy Rule text, and check whether state law or other frameworks impose additional obligations.