HIPAA Compliance
HIPAA

42 CFR Part 2 HIPAA Alignment Update

This article is written by the American Institute of Healthcare Compliance Audit Education Department 

By February 16, 2026, all HIPAA-covered entities—including healthcare providers, health plans, and healthcare clearinghouses—that create, receive, or maintain Substance Use Disorder (SUD) records subject to 42 CFR Part 2 must update their Notice of Privacy Practices (NPP). The update requires clearly detailing enhanced protections for SUD records. The information in this AIHC update is not legal or consulting advice, but for educational purposes to prompt compliance.

Does this new rule apply to my organization?

Yes, it can, but this requirement is specifically targeted at those handling Part 2 records. Entities must ensure their websites and privacy policies reflect these changes by February 16, 2026. Covered entities, including health plan sponsors and providers, must align their notices with the new, stricter privacy rules for sensitive SUD information by this date.

Tips to Update Your NPP

The NPP must contain the elements, information and statements specified in 45 CFR 164.520 and must include a specific header, a description of permitted uses/disclosures (treatment, payment, operations), individual rights, covered entity duties, and contact information for complaints.

It must be provided by the first service date and, as of February 16, 2026, align with updated substance use records regulations.

Key elements mandated by 45 CFR 164.520 include: 

  • Required Header: A specific statement regarding how medical information is used and the patient's rights.
    • i.e., “THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.”1
  • Permitted Uses and Disclosures: A detailed description of how the covered entity may use or disclose Protected Health Information (PHI) without the patient’s written authorization,2 including for treatment, payment, and healthcare operations.
  • Individual Rights: Information on the right to access, amend, request restrictions, receive confidential communications, and receive an accounting of disclosures.
    • A statement that other uses or disclosures will only be made with the individual’s authorization, and that the individual has the right to revoke her/his authorization subject to certain limitations.3
    • A summary of certain specified rights the individual has concerning his/her information.4
  • Covered Entity Duties: Statements confirming the entity's responsibility to protect privacy, provide notice of privacy practices, and abide by the terms of the notice.
  • Complaints Procedure: Instructions on how individuals can file complaints with the covered entity or the Secretary of Health and Human Services (HHS).
  • Contact Information: A designated person or office to contact for further information.
  • Effective Date: The NPP’s effective date.5
  • Special Considerations: Specific language regarding the restriction of uses/disclosures for underwriting purposes, the sale of PHI, and marketing, as well as updated, clearer descriptions regarding substance use disorder records.
  • Posting the Notice: The NPP must be prominently posted on the entity's website and physically at the service location by February 16, 2026 and, for plans without a website, distributed to participants by April 17, 2026 (within 60 days of the change).

Key Considerations:

Update Policies & Retrain Workforce - Organizations should act promptly to review their existing notices and implement the required changes before the deadline. Review and update internal privacy policies, procedures, and training materials to comply with the final rule.

Review your BAAs - Business Associate Agreements should be reviewed to ensure they account for the enhanced protections of SUD information.

For more information, check the updated Fact Sheet 42 CFR Part 2 Final Rule:

https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html.

References:

https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520

1 45 CFR 164.520(b)(1)(i)

2 45 CFR 164.520(b)(1)(ii)

3 45 CFR 164.520(b)(1)(ii)

4 45 CFR 164.520(b)(1)(iv)-(vii)

5 45 CFR 164.520(b)(1)(viii)

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Right of Access Compliance

A Contemporary Risk Management and Regulatory Imperative 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The HIPAA Right of Access (ROA) provision continues to stand as a vital patient-rights protection and a persistent enforcement focus for OCR. Since 2022, the OCR has escalated enforcement activity—issuing multiple monetary settlements ranging from small practices to large organizations, including significant penalties such as $200,000 against Oregon Health & Science University (OHSU) in 2025. This article updates the scholarly discussion with recent data, reviews enforcement activity, and underscores strategic imperatives for compliance through inclusive workforce education, robust policy frameworks, centralized oversight, and ongoing auditing.

Introduction

Since its introduction, HIPAA’s Right of Access—which empowers patients to access their protected health information (PHI)—has been elevated by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as a leading enforcement priority. OCR’s Right of Access Initiative, instituted in 2019, has remained dynamically active, with continued resolution of complaints and repeated emphasis across enforcement years 2022 through 2025.

Regulatory Framework of the Right of Access

Under HIPAA, individuals are entitled to access their PHI in “designated record sets” (45 C.F.R. § 164.524). Covered entities must provide this access within 30 days of receiving a request, with a single 30-day extension permitted if documented and communicated to the patient.

Key requirements include:

  • Timeliness: Records must be provided within the prescribed timeframes.
  • Reasonable fees: Covered entities may charge only cost-based fees for labor, supplies, and postage.
  • Format: Information must be provided in the form and format requested, if readily producible.
  • Exceptions: Access may be denied under limited circumstances, such as if disclosure is reasonably likely to endanger life or safety.

Failure to meet these requirements can result in HIPAA violations, OCR investigations, and reputational harm.

Recent Enforcement Activity (2022–2025)

OCR’s enforcement record demonstrates an ongoing pattern of provider noncompliance with the Right of Access. Key examples include:

2022:
- Multiple ROA settlements involving dental practices, including one finalized in December 2022.
- Memorial Hermann Health System settled for $240,000 over delayed access requests.

2023:
- OCR resolved 13 enforcement actions totaling $4.18 million, nearly doubling 2022’s penalties.
- Life Hope Labs was fined $16,500 for delayed records release.

2024:
- OCR imposed $170,000 in penalties against a dental practice and a Los Angeles County mental health program.

2025:
- Oregon Health & Science University (OHSU) was fined $200,000 for failing to provide timely access to a patient’s representative.
- OCR also continued settlements tied to ransomware incidents, such as the Comstar breach affecting over 585,000 individuals.

Enforcement Trend Analysis

Recent enforcement illustrates key trends:

  • Widespread focus: ROA cases involve providers of all sizes and types.
  • Significant financial liability: Penalties range from modest fines to $200,000+.
  • Business associate accountability: Covered entities are liable for their partners’ noncompliance.
  • Cybersecurity overlap: Breaches and ransomware are increasingly tied to ROA violations.

Compliance Challenges in Healthcare Organizations

Despite regulatory clarity, many organizations continue to struggle with operationalizing the Right of Access. Common barriers include:

  • Lack of workforce training: Staff may be unaware of timelines, fee structures, or documentation requirements.
  • Decentralized recordkeeping: PHI may be stored across multiple EHR platforms, making access requests cumbersome.
  • Inconsistent policies: Outdated or incomplete policies may lead to variable practices across departments.
  • Cultural barriers: Some providers remain reluctant to share full records, particularly behavioral health information, despite HIPAA requirements.

These challenges highlight the need for strong compliance frameworks that integrate policy, training, and oversight.

Risk Mitigation Through Compliance Programs

Right of Access compliance should be viewed not only as a legal requirement but as a risk management strategy. By embedding compliance into organizational culture, healthcare leaders can reduce the likelihood of OCR investigations and enhance patient satisfaction.

Effective strategies include:

1.  Policy development  

     Create and regularly update written policies aligned with HIPAA and state privacy rules.

2.  Workforce training  

     Ensure all staff—front desk, nursing, HIM, billing, IT—understand their responsibilities.

3.  Monitoring and auditing  

     Conduct regular internal audits of access requests, timeliness, and fees.

4.  Centralized oversight  

     Designate a privacy officer or compliance team to oversee all Right of Access processes.

5.  Patient engagement  

     Communicate clearly with patients regarding their rights, timelines, and any applicable fees.

6.  Cybersecurity integration  

     Align ROA procedures with breach and ransomware response protocols.

Conclusion

The HIPAA Right of Access reflects a core principle of modern healthcare: empowering patients with information to participate in their care. Recent enforcement actions from 2022–2025 highlight the continued priority OCR places on this right, with penalties applied to providers of all sizes.

Healthcare leaders must proactively address this risk by developing robust policies, ensuring comprehensive workforce training, monitoring compliance, and integrating cybersecurity protections. In doing so, organizations protect themselves from regulatory enforcement while upholding the trust and dignity of the patients they serve.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking?  Part 2 of 2

Written by: A. Michi McClure, J.D., an AIHC member and Volunteer on the CEU Education Committee   

This article follows Part 1 on the topic of understanding potential HIPAA violations when releasing information.  Is it Right of Access or Information Blocking?  Both have penalties. If you haven’t yet, read Part 1. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

Right of Access Initiative 

An individuals’ right to access their Health Information is located at 45 CFR § 164.524 as part of the HIPAA rule. It provides individuals to exercise the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103.  The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.  On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS).

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are a continuation from the information provided in Part 1, demonstrating a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

To whom can the information be released?

In addition to the individual, the following individuals or entities may be allowed access to PHI under certain circumstances:

  1. Personal representatives: Individuals may designate a personal representative, such as a legal guardian, healthcare proxy, or other authorized person, to act on their behalf in obtaining access to their PHI.
  2. Parents and guardians: Parents or legal guardians may access the PHI of their minor children or children for whom they are legal guardians.
  3. Healthcare providers: Other healthcare providers may be granted access to an individual's PHI for the purpose of providing treatment or coordinating care.
  4. Business associates: Business associates that provide services to covered entities, such as billing or transcription services, may be allowed access to PHI to perform their services.

EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. Authorized parties may include:

  1. Other healthcare providers: Healthcare providers may be authorized to access an individual's EHI for the purpose of providing treatment or coordinating care.
  2. Health plans: Health plans may be authorized to access an individual's EHI for the purpose of administering benefits and coordinating care.
  3. Caregivers and family members: Caregivers and family members may be authorized to access an individual's EHI with the individual's consent or as authorized by law.
  4. Researchers: Researchers may be authorized to access de-identified EHI for research purposes, subject to certain privacy and security requirements.
  5. Public health authorities: Public health authorities may be authorized to access EHI for the purpose of monitoring and responding to public health threats.

May the request be denied?

A covered entity may deny a request for access to protected health information (PHI) under certain limited circumstances. The covered entity must provide a written denial and explanation of the denial to the individual, along with information on how to request a review of the denial. The limited circumstances under which a request for access may be denied include:

  1. Psychotherapy notes: Covered entities are not required to provide access to psychotherapy notes, which are notes recorded by a mental health professional documenting or analyzing the contents of a counseling session.
  2. Information compiled for legal proceedings: Covered entities may deny access to information that is created for the purpose of legal proceedings, such as attorney-client privileged communications.
  3. Information prohibited by law: Covered entities may deny access to PHI if providing access would be prohibited by another law.
  4. Information that may cause harm: Covered entities may deny access to PHI if they reasonably believe that providing access would endanger the life or physical safety of the individual or another person.

Under the information blocking rule, healthcare providers and other covered entities may only deny a request for access to EHI under certain limited circumstances. The exceptions under which a request for access may be denied include:

  1. Preventing harm: A healthcare provider may limit the access to EHI if they believe that providing access could reasonably result in harm to the individual or another person.
  2. Privacy: A healthcare provider may limit access to EHI if they reasonably believe that providing access would violate the privacy of another person.
  3. Security: A healthcare provider may limit access to EHI if they reasonably believe that providing access would pose a security risk to the EHI or to other systems that are part of the electronic health record ecosystem.
  4. Infeasibility: A healthcare provider may limit access to EHI if the request is not technically feasible or if providing access would require unreasonable effort or resources.

If access is denied, the healthcare provider must also provide information on how to file a complaint.

Fees allowed to be charged to the patient?

Yes, covered entities under HIPAA Privacy Rule may charge a reasonable, cost-based fee for providing individuals with access to their protected health information (PHI).

  • The fee may only include the cost of labor for copying the PHI, supplies for creating the paper or electronic copy, and postage if the individual has requested that the PHI be mailed to them.
  • The fee may not include the cost of searching for and retrieving the PHI or any other associated administrative costs.

Covered entities are required to inform individuals of the fee in advance.

  • The fee may not be a barrier to individuals accessing their PHI. Covered entities must also provide access to the PHI in the format requested by the individual if it is readily producible in that format.

It's important to note that there are some situations where fees cannot be charged, such as when an individual requests access to their PHI for the purposes of filing a complaint with the HHS or if the covered entity fails to provide the individual with access to their PHI in a timely manner. Some state laws may limit or prohibit the fees that can be charged for providing access to PHI.

No, under the information blocking rule, healthcare providers and other covered entities may not charge fees that are not reasonably necessary for accessing, exchanging, or using EHI.

  • This means that if an individual requests access to their EHI or for their EHI to be transmitted to another entity, covered entities are generally not allowed to charge fees that are higher than the cost of labor and resources required to fulfill the request.

Additionally, if a covered entity charges fees for any other services or products related to EHI, such as an EHR system, the fee must be reasonably related to the actual cost of providing the service or product. The covered entity must also provide a detailed explanation of the fees and how they were calculated and must make the fees publicly available.

It's important to note that there are some circumstances where a covered entity may be able to charge fees that are higher than the cost of labor and resources, such as when the request is complex or involves large amounts of EHI. However, these fees must be reasonable, and the covered entity must provide an itemized bill explaining the fees.

Please review Part 1 for more information. 

We also encourage consulting with your malpractice Risk Attorney.  Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs.  If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking? Part 1 of 2

Written by: A. Michi McClure, J.D. an AIHC member and Volunteer on the CEU Education Committee   

The right of access and information blocking are both related to the access and exchange of health information, but they are different in several key ways. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

 

Right of Access Initiative 

Individuals’ Right under HIPAA to Access their Health Information 45 CFR § 164.524

This initiative helps to empower individuals to take control of their own health information, allowing them to better manage their healthcare and make informed decisions about their health. By ensuring that individuals have access to their own health information, this initiative also helps to improve the quality and continuity of care, while also protecting the privacy and security of that information.

The right of access is a requirement under HIPAA that individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

ePHI is defined in HIPAA regulation as any protected health information (PHI) that is created, stored, transmitted, or received in any electronic format or media. The right of access also includes the right to request that their PHI be transmitted to another entity, such as another healthcare provider or a personal health record (PHR). Covered entities must provide individuals with timely access to their PHI and may only deny access under certain limited circumstances.

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103

Information blocking is a practice in which a healthcare provider, health plan, or other covered entity intentionally interferes with the access, exchange, or use of electronic health information. The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.

The ultimate goal of the Information Blocking Act is to promote greater collaboration and coordination among healthcare providers and other stakeholders, which can lead to improved quality of care, better patient outcomes, and more efficient use of healthcare resources. By breaking down barriers to the exchange of health information, this legislation aims to facilitate the development and implementation of innovative healthcare solutions that can improve the overall health of the population.

On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS). Prior to this date the definition of EHI was limited to the data elements represented in the United States Core Data for Interoperability (USCDI) v1.

Covered entities may not use information blocking practices to prevent or interfere with access, exchange, or use of EHI, except in certain limited circumstances.

Confused?

While both the right of access and information blocking are designed to promote the access and exchange of health information, the right of access focuses on individuals' access to their own PHI, while information blocking focuses on the sharing of EHI between covered entities.

Additionally, the right of access is a long-standing requirement under HIPAA, while information blocking is a more recent requirement under the 21st Century Cures Act.

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are provided as a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

Enforcement date:

The HIPAA Privacy Rule was first enforced in the United States on April 14, 2003. The Office for Civil Rights (OCR) began an enforcement initiative in 2019.

First enforced in the United States on September 1, 2023.

Goal:

To give individuals greater control over their own health information. This initiative:

  • Ensures individuals the right to access their own medical records and to receive copies of those records in a timely manner, without undue delay or cost.
  • Provides individuals the right to request access to their health information held by covered entities, such as healthcare providers, health plans, and healthcare clearinghouses.
    • These entities must provide individuals with their requested information in the format and manner requested by the individual if it is readily producible in that format. This information can include medical and billing records, as well as other health information such as test results and imaging reports.

The goal of the Information Blocking Act, also known as the 21st Century Cures Act, is:

  • To improve the interoperability of electronic health records (EHRs) and other health information technology (HIT) systems in the United States.
  • Aims to promote the secure and efficient sharing of health information among healthcare providers, patients, and other stakeholders in the healthcare system.
  • Prohibits healthcare providers, health IT developers, and health information exchanges from engaging in practices that prevent or discourage the access, exchange, or use of electronic health information. This includes actions such as charging excessive fees for access to health information, creating technical barriers to the sharing of health information, and imposing unreasonable delays on the release of health information.

When must records be provided:

Covered entities, such as healthcare providers and health plans, are generally required to provide patients with access to their protected health information (PHI) upon request, unless an exception applies.

Specifically, a covered entity must provide access to PHI within 30 days of receiving a request from the individual, unless the covered entity provides a written explanation of the delay and the reason for the delay and extends the time-period by an additional 30 days.

Under the information blocking rule, EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. These circumstances are listed below in the following chart.

It's important to note that a healthcare provider must provide a clear explanation for any limitations on access to EHI and must make a good faith effort to provide access to as much EHI as possible.

Healthcare providers are also required to make available any information blocking policies or procedures that they have in place, and to provide patients with information on how to file a complaint if they believe that their access to EHI has been improperly limited or blocked.

What information is subject to?

Under HIPAA, individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. PHI is broadly defined as any information, including demographic information, that:

  1. Relates to the individual's past, present, or future physical or mental health or condition;
  2. Relates to the provision of healthcare to the individual; or
  3. Identifies the individual or could reasonably be used to identify the individual.

Some examples of PHI that are subject to the right of access include:

  • Medical and clinical records, including diagnoses, test results, and treatment plans;
  • Billing and insurance information;
  • Prescription and medication records;
  • Immunization records;
  • Lab reports;
  • Radiology images;
  • Health insurance enrollment and coverage information; and
  • Personal demographic information, such as name, address, and social security number, if it is included in the individual's health record.

Under the information blocking rule, electronic health information (EHI) is subject to the right of access and exchange. EHI is defined as:

  • Electronic protected health information (ePHI) that is created, stored, transmitted, or received by a covered entity or business associate that is subject to HIPAA.

Some examples of EHI that are subject to the information blocking rule include:

  1. Clinical notes, including progress notes and operative notes;
  2. Diagnostic imaging, including X-rays, MRIs, and CT scans;
  3. Laboratory test results;
  4. Pathology reports;
  5. Medication lists and prescription histories;
  6. Immunization records;
  7. Vital signs and other clinical measurements;
  8. Patient demographic information, such as name, address, and social security number, if it is included in the EHI.

Penalties?

YES

The right of access initiative is enforced by the Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS). OCR can investigate complaints of noncompliance and may take enforcement actions against covered entities that violate the right of access requirements.

  • If OCR determines that a covered entity has violated the right of access requirements, the covered entity may be subject to civil monetary penalties, which can range from $100 to $50,000 per violation, depending on the severity of the violation.
  • The maximum annual penalty for all violations of an identical requirement or prohibition is $1.5 million.

In addition to civil monetary penalties, OCR may require the covered entity to develop a corrective action plan and to monitor the covered entity's compliance.

It's important to note that individuals also have the right to file a complaint with OCR if they believe that a covered entity has violated their right of access. OCR may investigate complaints and take enforcement actions as appropriate.

YES

There are penalties for violating the information blocking rule which is enforced by the Office of the National Coordinator for Health Information Technology (ONC) and the Department of Health and Human Services (HHS). Covered entities that engage in information blocking practices may be subject to enforcement actions, which can include:

  1. Civil monetary penalties: The HHS may impose civil monetary penalties of up to $1 million per violation for each instance of information blocking.
  2. The maximum annual penalty for all violations of an identical requirement or prohibition is $5 million.
  3. Disincentives for health information exchange: The HHS may also take steps to limit or restrict a covered entity's participation in certain health information exchange programs or to exclude the entity from certain government healthcare programs.
  4. Publication of violators: The ONC may publish the names of covered entities that have engaged in information blocking practices, which can harm the entity's reputation and public image.

In Summary 


It is important to respect patient access to information while protecting confidential information. This can be a daunting task for any size organization. After reviewing the information above and you still have questions, consider additional training in HIPAA and release of information.

Additional and important aspects of this topic not covered in this article is information excluded from both Right of Access and Information Blocking rules, when the request may be denied, to whom the information can be released and allowable (and unallowable) fees a patient can be charged. These topics will be covered in Part 2.

We also encourage consulting with your malpractice Risk Attorney. Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs. If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More