Bindinglaw

US · guidance

CMS Pub. 100-01, ch. 6, § 190

The Health Insurance Portability and Accountability Act (HIPAA)

activein force · 2026-08-25 – presentas-observed

Privacy Rule

(Rev. 7, 06-25-04)

A. General Information

To improve the efficiency and effectiveness of the health care system, HIPAA included

provisions that required national standards for electronic health care transactions. At the

same time, Congress recognized that advances in electronic technology could erode the

privacy of health information. Consequently, Congress incorporated into HIPAA

provisions that mandated the adoption of Federal privacy protections for individually

identifiable health information.

The Department of Health and Human Services issued the regulation “Standards for

Privacy of Individually Identifiable Health Information”, 45 CFR Parts 160 and 164, (the

HIPAA Privacy Rule) to implement section 264 of HIPAA. The HIPAA Privacy Rule

establishes a set of basic national privacy standards and fair information practices. It sets

a floor of ground rules for health care providers, health plans, and health care

clearinghouses to follow to protect the privacy of an individual’s personal health

information.

The HIPAA Privacy Rule is based on the same fair information principles that are found

in the Privacy Act of 1974 and are now generally extended to the public and private

sectors of the health care delivery system. The HIPAA Privacy Rule applies to protected

health information (PHI) held by covered entities, as defined by the Rule, while the

Privacy Act protects records with individually identifiable information held by Federal

agencies. The Privacy Act continues to apply to Medicare and Medicare fee-for-service

(FFS) contractors in their day-to-day operations.

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is

responsible for providing outreach and technical assistance to covered entities (health

plans, health care clearinghouses, and health care providers who conduct certain financial

and administrative transactions electronically) and for enforcing the HIPAA Privacy

Rule. OCR maintains information on the HIPAA Privacy Rule at

http://www.hhs.gov/ocr/hipaa/

B. How CMS Applies Laws Affecting the use and Disclosure of Personal

Information

1. General rules

Since Medicare operates under both the Privacy Act and the HIPAA Privacy Rule,

CMS has determined how the provisions interact with each other as it uses personally

identifiable information in its day-to-day operations. For example, a use or disclosure

that is permitted under the HIPAA Privacy Rule (e.g., to facilitate cadaveric organ

donation and transplants), but not published in a Federal Register notice as a routine

use in a CMS system of records would not be permitted for Medicare. Similarly, if

the disclosure is a “routine use” under the Privacy Act, but the HIPAA Privacy Rule

prohibits the disclosure, CMS will not make the disclosure.

Exemption 6 of the Freedom of Information Act (FOIA) permits Federal agencies to

withhold personnel and medical files the disclosure of which would constitute a

clearly unwarranted invasion of personal privacy. When a FOIA request asks for

documents that include personal information, CMS must apply Exemption 6 to

preclude the release of, or must otherwise redact, identifying details before disclosing

the remaining information.

2. Information About Deceased Individuals

The application of Exemption 6 of the FOIA to information about deceased

individuals requires a different analysis than that applicable to living individuals

because under the Privacy Act of 1974, privacy rights are extinguished at death.

However, under FOIA, it is entirely appropriate to consider the privacy interest of a

decedent’s survivors under Exemption 6. Under the HIPAA Privacy Rule, the

personal health information of deceased as well as living persons is protected.

3. Requests for Access to Records

The FOIA and Privacy Act requests will continue to be handled according to current

procedures and timeliness standards. A FOIA request for access to public records

requires CMS, as a Federal agency, to provide the fullest possible disclosure of its

records to the public, subject to certain exceptions (e.g., proprietary information,

national defense risks). The Privacy Act requires CMS to provide individuals access

to their personal information maintained in a System of Records. Note that an

individual’s request under the Privacy Act to access his or her records must specify a

Privacy Act System of Records and must be addressed to the system manager

identified in the Federal Register notice.

A HIPAA Privacy Rule request for access is separate from both FOIA and the

Privacy Act and has its own timeliness standards associated with it. Requests for

access under the HIPAA Privacy Rule will be handled by CMS’ Central Office (see

section G below).

4. State Law Preemption Under HIPAA

Medicare is a national program that is administered under Federal statute and

regulation. CMS administers Medicare through Medicare FFS contractors that are

required to operate in accordance with statutory and regulatory requirements and

CMS administrative direction.

When considering the provisions of HIPAA, Congress expressly intended to defer to

more stringent state laws if those laws conflict with provisions in the HIPAA Privacy

Rule. The HIPAA Privacy Rule therefore explicitly preempts conflicting state law

provisions, unless they are more stringent or more protective of the individual’s

rights. Since the Federal law expressly preserves more stringent state laws, and

because of the complexity of this issue, contractors should ask CMS for guidance as

issues arise.

C. CMS Programs that are Covered Entities Under HIPAA

The Federal health programs that CMS administers are health plans as defined in HIPAA

and are covered entities subject to the HIPAA Privacy Rule. These health plans are:

• Part A or Part B of the Medicare program under Title XVIII;

• The Medicaid program under Title XIX;

• The State Children’s Health Insurance Program (SCHIP); and

• The Medicare Advantage (formerly Medicare+Choice (M+C)) program and other

Medicare health plans.

The CMS is directly responsible for ensuring that the Medicare Fee-For-Service (FFS)

program, also known as the Original Medicare Plan, complies with the HIPAA Privacy

Rule. For the Medicaid and SCHIP programs, the appropriate State Agency is

responsible for ensuring compliance with privacy requirements. Medicare Advantage

(formerly M+C) plans are covered entities subject to the HIPAA Privacy Rule in their

own right and responsible for their own compliance.

D. Business Associates

Most health care providers and health plans do not carry out all of their health care

activities and functions by themselves; they require assistance from a variety of

contractors and other businesses. By definition, a business associate is a person or entity

that performs or assists in the performance of a function or activity involving the use or

disclosure of individually identifiable health information on behalf of a covered entity.

Medicare FFS contractors that perform health care activities involving the use of PHI on

behalf of the Medicare FFS health plan (i.e., claims processing functions) are business

associates of the Medicare FFS health plan (the covered entity). The HIPAA Privacy

Rule allows providers and plans to give PHI to their business associates as long as they

have satisfactory assurances and document those assurances, typically by contract, that

business associates will safeguard the information.

Medicare contracts have been modified to include the business associate provisions.

These provisions also address the contractor’s responsibility to ensure that subcontractors

or agents to whom they disclose Medicare data agree, by contract, to safeguard any PHI

as well. Contracts continue to include language that applies to contractors who maintain

or operate a Privacy Act protected systems of records on Medicare’s behalf.

Medicare contractors that perform health care activities involving the use of PHI on

behalf of the Medicare FFS health plan are not business associates of providers,

physicians, suppliers, clearinghouses, or other health plans. Likewise, providers,

physicians, suppliers, clearinghouses, or other health plans are not business associates of

the Medicare contractor unless the provider, physician, supplier, clearinghouse, or other

health plan is doing work on behalf of the Medicare contractor. For these reasons,

Medicare FFS contractors should not sign business associate agreements with any

provider, physician, supplier, clearinghouse, or other plan unless the provider, physician,

supplier, clearinghouse, or other health plan is doing work on the contractor’s behalf.

E. Trading Partner Agreements

Currently, Medicare contractors execute trading partner agreements (TPAs) with a

number of payers, including Medigap insurers, Medicare supplemental/employee retiree

health plans, multiple employer welfare trusts, TRICARE for Life, as well as State

Medicaid Agencies, for the purpose of exchanging adjudicated Medicare claims for

secondary liability determination by those partners. This exchange of data is commonly

referred to as the “claims crossover process.” For coordination of benefits (COB)

purposes, Medicare contractors and trading partners are not business associates of each

other since neither entity is doing work on the other’s behalf; therefore, MACs should not

sign business associate agreements with COB trading partners that receive claims

crossover data from them.

F. Notice of Privacy Practices

The HIPAA Privacy Rule requires each covered entity to develop and provide a plain

language notice that describes its legal duties, the uses and disclosures of protected health

information that it may make, and individual privacy rights and how to exercise them.

The individual rights include the right to inspect and copy protected health information,

to amend protected health information, to request restrictions, confidential

communications, an accounting of disclosures, a paper copy of the privacy notice, and

how to file complaints.

Medicare’s privacy notice was provided to beneficiaries for the first time in the 2003

Medicare & You handbook and is provided in the handbook every year. New enrollees

receive the privacy notice in the handbook that is mailed to them within 30 days of

Medicare entitlement. Medicare’s privacy notice is also posted on Medicare’s Web site

at www.medicare.gov.

Medicare’s Notice of Privacy Practices informs beneficiaries who are interested in

exercising individual rights to go to www.medicare.gov or call 1-800-MEDICARE.

Customer Service Representatives (CSR) at 1-800-MEDICARE use scripts to answer

questions regarding exercising individual rights and filing complaints.

Since Medicare’s privacy notice describes the uses and disclosures of PHI in the day-to-day operations of Medicare (including Medicare FFS contractors), FFS contractors are

not required to develop a separate privacy notice for Medicare beneficiaries.

G. Individual Rights and Complaints

NOTE: For Individual Rights Under the Privacy Act of 1974, see §10 above.

The HIPAA Privacy Rule gives individuals rights with respect to their PHI. These rights

are listed in covered entities’ privacy notices. The Notice of Privacy Practices for the

Original Medicare Plan includes the right to:

1. See and get a copy of personal health information held by Medicare.

CMS Central Office is responsible for responding to beneficiary requests for

access to records under the HIPAA Privacy Rule. Medicare FFS contractors

should only respond to those requests for information related to payment of a

claim, for which they are already responsible under the contract under existing

customer service procedures. Simple telephone inquiries, such as asking about

the status of a claim or requesting a duplicate Medicare Summary Notice, are not

considered a HIPAA request for access and should be handled under existing

customer service procedures.

2. Have personal health information amended if it is wrong or missing, and

Medicare agrees. If Medicare disagrees, a statement of disagreement may be

added to the personal health information.

Central office is responsible for handling beneficiary requests to amend the record

under the HIPAA Privacy Rule. Contractors will not be responding to requests to

amend records.

Requests for changes to claims or payment records, such as an appeal or change

of address request, are not considered HIPAA Privacy Rule requests for

amendments, and should be handled according to current procedures.

Note, however, that if the request for amendment involves medical records,

contractors should explain that, except in rare circumstances, only the source of

the medical record (i.e., the provider) may make changes to the record.

3. Get a listing of those receiving personal medical information from Medicare.

CMS Central Office is responsible for responding to beneficiary requests for an

accounting of disclosures under the HIPAA Privacy Rule. Contractors will not be

responding to requests for an accounting of disclosures.

The listing does not cover personal health information that was given to the

individual or his or her personal representative, that was given out to pay for

health care or Medicare operations, or that was given out for law enforcement

purposes.

4. Ask Medicare to communicate in a different manner or at a different place, for

example, by sending materials to a P.O. box instead of the address on file.

Current regulations and existing agreements with the Social Security

Administration are extremely prescriptive, often governing precisely how CMS

can respond to requests for confidential communications.

Operationally, CMS can only maintain one address at a time. Because of this,

routine change of address requests should be handled according to current change

of address procedures.

5. Ask Medicare to limit how personal health information is used and given out to

pay claims and run the Medicare program.

CMS Central Office is responsible for responding to beneficiary requests to

restrict disclosure of PHI. Contractors will not be responding to requests to

restrict disclosure of PHI.

6. Get a separate paper copy of the privacy notice.

Contractors who receive requests for a paper copy of the Notice of Privacy

Practices for the Original Medicare Plan should refer requestors to their Medicare

& You handbook.

7. File a complaint.

Medicare’s Notice of Privacy Practices informs individuals of the right to file

complaints about Medicare’s privacy practices with either Medicare or the

Secretary of Health and Human Services. The privacy notice refers individuals to

www.medicare.gov or 1-800-MEDICARE for further information on filing a

complaint.

CMS is required to document in written or electronic form the complaints

received and their disposition. There is no requirement to respond in a particular

manner or time frame.

For the privacy rights listed above where CMS Central Office is responsible for

responding to the request, contractors should advise beneficiaries to address their

requests to:

HIPAA Privacy

P.O. Box 8050

U.S. Department of Health and Human Services

Centers for Medicare & Medicaid Services

7500 Security Boulevard

Baltimore, MD 21244-1850

H. Privacy Authorizations

An authorization is a document that an individual uses to give a covered entity

permission to disclose his or her PHI for a particular purpose (e.g., for marketing) or to a

third party specified by the individual. A covered entity is generally not required to

obtain an authorization for the use or disclosure of PHI for treatment, payment, or health

care operations, as well as for certain public priority activities under specified conditions

(e.g., health care oversight, law enforcement). Contractors should inform providers that

contractors are unable to make payment for Medicare claims if the provider fails to

provide the information needed to process them.

The HIPAA Privacy Rule specifies certain core elements and required statements for a

valid authorization. Contractors may add more elements to their authorizations as long as

the core elements and required statements remain and no provisions are added that

conflict with these core elements and statements.

Contractors must also accept an authorization from another entity, provided it includes all

of the core elements and required statements, and no provisions are added that conflict

with these core elements and statements.

I. Core Elements and Required Statements for an Authorization

The core elements of a valid authorization are:

1. A description of the information to be used or disclosed that identifies the

information in a specific and meaningful fashion;

2. The name or other specific identification of the person(s), or class of persons,

authorized to make the requested use or disclosure;

3. The name or other specific identification of the person(s) or class of persons, to

whom the covered entity may make the requested use or disclosure;

4. A description of each purpose of the requested use or disclosure. The

statement, “at the request of the individual” is a sufficient description of the

purpose when the beneficiary initiates the authorization and does not, or elects not

to, provide a statement of the purpose;

5. An expiration date or an expiration event that relates to the individual or the

purpose of the use or disclosure; and

6. The signature of the individual and date. If a personal representative of the

individual signs the authorization, a description of such representative’s authority

to act for the individual must also be provided. Although the HIPAA Privacy

Rule requires only a description of the representative’s authority to act for the

individual, CMS is requiring that documentation showing the representative’s

authority be attached to the authorization (e.g., a Power of Attorney).

In addition to the core elements, the authorization must contain statements adequate to

place the individual on notice of all of the following:

1. The individual’s right to revoke the authorization in writing, how the individual

may revoke the authorization, and the exceptions to the right to revoke, e.g., “You

have the right to take back (“revoke”) your authorization at any time in writing,

except to the extent that Medicare has already acted based on your permission.

To revoke your authorization, send a written request to: [Each Medicare

contractor or CMS: Please insert Name, Address, and Telephone number of your

organization here]”;

2. The inability to condition treatment, payment, enrollment or eligibility for

benefits on the authorization, e.g., “I understand refusal to authorize disclosure of

my personal medical information will have no effect on my enrollment, eligibility

for benefits, or the amount Medicare pays for the health services I receive”;

3. The potential for information disclosed pursuant to the authorization to be

subject to redisclosure by the recipient and no longer protected, e.g.: “Your

personal medical information that you authorize Medicare to disclose may be

subject to redisclosure and no longer protected by law.”

In addition, the authorization must be written in plain language and a signed copy must

be provided to the individual (or the individual should be advised to retain a copy).

The CMS is developing a standard authorization for beneficiaries or their personal

representatives to request disclosure of PHI to third parties. The standard will contain the

elements for compliance with both the HIPAA Privacy Rule and Privacy Act

requirements. Contractors will be notified when the standard authorization is available.

J. Personal Representatives and Third Party Authorizations

The HIPAA Privacy Rule requires covered entities to treat an individual’s personal

representative as the individual with respect to uses and disclosures of the individual’s

PHI, as well as exercising the individual’s privacy rights listed in the covered entity’s

Notice of Privacy Practices. A personal representative may also authorize disclosures of

an individual’s PHI (see §190H above).

In addition to these formal designations of a personal representative, the HIPAA Privacy

Rule permits a covered entity to disclose to any person identified by the individual the

protected health information directly relevant to such person’s involvement with the

individual’s care or payment related to the individual’s care. Therefore, a verbal

authorization is allowed under the HIPAA Privacy Rule for those individuals involved in

the care of an individual.

Contractors should continue to handle routine inquiries, such as telephone requests for

the status of claims, under existing customer service procedures that include verification

of the individual’s identity. Therefore, with the beneficiary’s verbal or written

permission, contractors may continue to speak to third parties on behalf of the individual.

See Exhibit D - Disclosure Desk Reference Guide for Call Centers for detailed

instructions on disclosing PHI over the telephone.

Contractors may also continue to handle Congressional inquiries under existing customer

service procedures (see §10J above).

K. Administrative Requirements

As Medicare’s business associate, contractors are not subject to the administrative

requirements of the HIPAA Privacy Rule. However, under the Privacy Act, contractors

must comply with the privacy provisions specified in their contracts. Contractors are not

required to designate a privacy official. However, contractors are required to have in

place a senior official or other responsible party to address the privacy concerns of the

organization and to establish an internal control system to monitor compliance with

privacy requirements.

Similarly, as Medicare’s business associate, contractors are not subject to the HIPAA

Privacy Rule’s requirement to train staff specifically on the HIPAA Privacy Rule.

However, under the Privacy Act, contractors are required to ensure that employees

understand their responsibility to protect the privacy and confidentiality of CMS’s

records.

It is CMS policy that any data collected on behalf of CMS in the administration of a

Medicare contract belongs to CMS. Any disclosure of individually identifiable

information without prior consent from the individual to whom the information pertains,

or without statutory or contract authorization, requires prior approval by CMS.

History

(Rev. 7, 06-25-04)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
385a51f8514b465b4d7f75282e5869c5374317663173f9cfd8cc9c199c600c56
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.