A Woman in Texas Waited 13 Months for Her Own Medical Records

She asked politely. Then she asked again. Then she filed a complaint with the Office for Civil Rights. The result? Cignet Health paid $4.3 million in penalties — one of the largest HIPAA enforcement actions in history at the time — partly because they refused to give 41 patients access to their own protected health information.

That case still rattles compliance officers. And it should rattle you, because HIPAA patients rights aren't suggestions. They're federal mandates backed by real consequences. If your organization handles PHI, you need to know exactly what patients are entitled to — and what happens when you fall short.

This post breaks down every major right patients hold under HIPAA, the enforcement trends HHS is leaning into in 2026, and the operational changes your workforce needs to make today.

What Are HIPAA Patients Rights, Exactly?

The HIPAA Privacy Rule gives individuals a specific set of rights over their protected health information. These rights apply to every covered entity — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. Business associates also play a role when they handle PHI on a covered entity's behalf.

Here are the core rights patients hold under the Privacy Rule:

  • Right to access their PHI — Patients can request and receive copies of their medical records and billing records.
  • Right to request amendments — If a patient believes their record contains an error, they can ask for a correction.
  • Right to an accounting of disclosures — Patients can request a list of certain disclosures made of their PHI.
  • Right to request restrictions — Patients can ask that you limit how their PHI is used or disclosed.
  • Right to confidential communications — A patient can ask to be contacted at a different phone number or address.
  • Right to receive a Notice of Privacy Practices — Covered entities must explain how they use and disclose PHI.
  • Right to file a complaint — Patients can report violations to the covered entity or directly to OCR.

You can review the full text of these requirements on the HHS guidance page for individuals.

The Right That Gets Practices in the Most Trouble

Of all the HIPAA patients rights, the right of access generates the most OCR enforcement actions. It's not close.

In 2019, OCR launched its HIPAA Right of Access Initiative. Since then, more than 45 enforcement actions have resulted in settlements and corrective action plans. The targets range from massive hospital systems to solo practitioners.

Here are a few real examples:

  • Banner Health (2023): $1.25 million settlement for failing to provide timely access to records.
  • Optum Medical Care (2023): $160,000 settlement after a patient waited months for her records.
  • Dr. Brockley (a solo dentist, 2022): $30,000 settlement for failing to provide a patient with records within the required timeframe.

The pattern is clear. OCR doesn't care how big or small your practice is. If a patient asks for their records and you drag your feet, you're exposed.

How Fast Do You Actually Have to Respond?

The HIPAA Privacy Rule requires covered entities to act on an access request no later than 30 calendar days. You can take a one-time 30-day extension if you notify the patient in writing and explain the reason for the delay. That's it. Sixty days maximum.

I've seen practices treat record requests like low-priority paperwork. That habit is now a six-figure liability.

The Amendment Right Nobody Trains For

Patients have the right to request that you amend their PHI if they believe it's inaccurate or incomplete. Most front-desk staff I've worked with have never heard of this right, let alone been trained on how to process the request.

You can deny an amendment request — but only under specific conditions. The record must have been created by another entity, the PHI must not be part of the designated record set, or the information must already be accurate and complete. And if you deny the request, you must provide a written denial with the reason and inform the patient of their right to submit a statement of disagreement.

Handling this wrong creates complaint fodder. Handling it right takes about ten minutes of staff training. The HIPAA Introduction Training 2026 course walks through these patient-facing scenarios in plain language your team will actually absorb.

Breach Notification: The Right Patients Don't Know They Have Until It's Too Late

When a breach of unsecured PHI occurs, the HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery. If the breach affects 500 or more people, you also have to notify HHS and prominent media outlets.

Patients have a right to know when their health information has been compromised. This isn't optional. And OCR has made clear through enforcement actions that delayed or missing breach notification letters trigger investigations and penalties.

The HHS Breach Notification Rule page spells out the exact requirements, including what your notification letter must contain.

Confidential Communications: A Right That Saves Lives

This is the one that keeps me up at night. A patient fleeing domestic violence asks your office to call her cell phone — not her home number. A teenager asks you to send appointment reminders to a different address. Under HIPAA, covered entities must accommodate reasonable requests for confidential communications.

You can't ask why. You can't demand an explanation. You just have to do it.

I've watched practices fumble this because their EHR system defaults to a single contact method and nobody knows how to override it. That's a workflow problem masquerading as a technology problem. And it puts real people at risk.

What Counts as a "Reasonable" Request?

A request is reasonable if the patient explains that disclosure of PHI could endanger them, or simply provides an alternative contact method. You can require the patient to provide information on how payment will be handled, but you cannot condition the accommodation on an explanation of the reason for the request.

Notice of Privacy Practices: More Than a Clipboard Formality

Every covered entity must provide patients with a Notice of Privacy Practices (NPP) that explains how their PHI may be used and disclosed. You must make a good-faith effort to obtain a written acknowledgment from the patient.

Most practices nail the "hand them a clipboard" part. Where they fail is keeping the NPP current. If your notice still references pre-2013 language and doesn't reflect the Omnibus Rule changes, you're operating with a document that misrepresents patients' rights. That alone is a compliance gap OCR can act on.

Review your NPP annually. Make sure it reflects current uses of ePHI, any health information exchanges you participate in, and the full scope of HIPAA patients rights.

What OCR Is Watching in 2026

The Right of Access Initiative isn't slowing down. OCR has signaled that patient access remains a top enforcement priority. But I'm also seeing increased scrutiny around:

  • Reproductive health information — New rules finalized in 2024 added protections around reproductive healthcare PHI, and enforcement is ramping up.
  • Telehealth disclosures — Patients have the same rights to PHI created during telehealth visits as in-person encounters.
  • Third-party app access — When patients direct you to send ePHI to a personal health app, you must comply, even if you have concerns about the app's security. Your liability ends once the data leaves your system at the patient's direction.

Staying current with these shifts is exactly why workforce training matters. Browse the full HIPAACertify course catalog to find role-specific modules that address these evolving requirements.

The Operational Checklist You Need Right Now

Here's what I tell every practice manager I work with. Print this out. Tape it to the wall in your admin office.

  • Designate a specific person (or role) responsible for processing patient access requests.
  • Log every request with the date received and track the 30-day deadline.
  • Train every front-desk employee on how to accept record requests, amendment requests, and confidential communication requests.
  • Review your Notice of Privacy Practices at least once a year.
  • Document every denial of an access or amendment request with the specific legal basis.
  • Run a tabletop breach notification drill at least annually.

None of this is complicated. But all of it requires intention, documentation, and a workforce that understands what HIPAA patients rights actually mean in practice.

Patients Are Getting Smarter. Your Team Needs to Keep Up.

Ten years ago, most patients didn't know they could request their records electronically. Now they file OCR complaints from their phones. The HHS online complaint portal has made it trivially easy to report a covered entity that doesn't respond.

Every complaint triggers a review. Many trigger investigations. Some trigger six- and seven-figure penalties.

The organizations that avoid those outcomes are the ones that treat patient rights as operational priorities — not legal footnotes. They train their workforce. They build systems. They respond within 30 days, every time.

Your patients have rights. Your job is to honor them before OCR has to remind you.