US · guidance
CMS Pub. 100-01, ch. 6, § 190
The Health Insurance Portability and Accountability Act (HIPAA)
Privacy Rule
(Rev. 7, 06-25-04)
A. General Information
To improve the efficiency and effectiveness of the health care system, HIPAA included
provisions that required national standards for electronic health care transactions. At the
same time, Congress recognized that advances in electronic technology could erode the
privacy of health information. Consequently, Congress incorporated into HIPAA
provisions that mandated the adoption of Federal privacy protections for individually
identifiable health information.
The Department of Health and Human Services issued the regulation “Standards for
Privacy of Individually Identifiable Health Information”, 45 CFR Parts 160 and 164, (the
HIPAA Privacy Rule) to implement section 264 of HIPAA. The HIPAA Privacy Rule
establishes a set of basic national privacy standards and fair information practices. It sets
a floor of ground rules for health care providers, health plans, and health care
clearinghouses to follow to protect the privacy of an individual’s personal health
information.
The HIPAA Privacy Rule is based on the same fair information principles that are found
in the Privacy Act of 1974 and are now generally extended to the public and private
sectors of the health care delivery system. The HIPAA Privacy Rule applies to protected
health information (PHI) held by covered entities, as defined by the Rule, while the
Privacy Act protects records with individually identifiable information held by Federal
agencies. The Privacy Act continues to apply to Medicare and Medicare fee-for-service
(FFS) contractors in their day-to-day operations.
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is
responsible for providing outreach and technical assistance to covered entities (health
plans, health care clearinghouses, and health care providers who conduct certain financial
and administrative transactions electronically) and for enforcing the HIPAA Privacy
Rule. OCR maintains information on the HIPAA Privacy Rule at
http://www.hhs.gov/ocr/hipaa/
B. How CMS Applies Laws Affecting the use and Disclosure of Personal
Information
1. General rules
Since Medicare operates under both the Privacy Act and the HIPAA Privacy Rule,
CMS has determined how the provisions interact with each other as it uses personally
identifiable information in its day-to-day operations. For example, a use or disclosure
that is permitted under the HIPAA Privacy Rule (e.g., to facilitate cadaveric organ
donation and transplants), but not published in a Federal Register notice as a routine
use in a CMS system of records would not be permitted for Medicare. Similarly, if
the disclosure is a “routine use” under the Privacy Act, but the HIPAA Privacy Rule
prohibits the disclosure, CMS will not make the disclosure.
Exemption 6 of the Freedom of Information Act (FOIA) permits Federal agencies to
withhold personnel and medical files the disclosure of which would constitute a
clearly unwarranted invasion of personal privacy. When a FOIA request asks for
documents that include personal information, CMS must apply Exemption 6 to
preclude the release of, or must otherwise redact, identifying details before disclosing
the remaining information.
2. Information About Deceased Individuals
The application of Exemption 6 of the FOIA to information about deceased
individuals requires a different analysis than that applicable to living individuals
because under the Privacy Act of 1974, privacy rights are extinguished at death.
However, under FOIA, it is entirely appropriate to consider the privacy interest of a
decedent’s survivors under Exemption 6. Under the HIPAA Privacy Rule, the
personal health information of deceased as well as living persons is protected.
3. Requests for Access to Records
The FOIA and Privacy Act requests will continue to be handled according to current
procedures and timeliness standards. A FOIA request for access to public records
requires CMS, as a Federal agency, to provide the fullest possible disclosure of its
records to the public, subject to certain exceptions (e.g., proprietary information,
national defense risks). The Privacy Act requires CMS to provide individuals access
to their personal information maintained in a System of Records. Note that an
individual’s request under the Privacy Act to access his or her records must specify a
Privacy Act System of Records and must be addressed to the system manager
identified in the Federal Register notice.
A HIPAA Privacy Rule request for access is separate from both FOIA and the
Privacy Act and has its own timeliness standards associated with it. Requests for
access under the HIPAA Privacy Rule will be handled by CMS’ Central Office (see
section G below).
4. State Law Preemption Under HIPAA
Medicare is a national program that is administered under Federal statute and
regulation. CMS administers Medicare through Medicare FFS contractors that are
required to operate in accordance with statutory and regulatory requirements and
CMS administrative direction.
When considering the provisions of HIPAA, Congress expressly intended to defer to
more stringent state laws if those laws conflict with provisions in the HIPAA Privacy
Rule. The HIPAA Privacy Rule therefore explicitly preempts conflicting state law
provisions, unless they are more stringent or more protective of the individual’s
rights. Since the Federal law expressly preserves more stringent state laws, and
because of the complexity of this issue, contractors should ask CMS for guidance as
issues arise.
C. CMS Programs that are Covered Entities Under HIPAA
The Federal health programs that CMS administers are health plans as defined in HIPAA
and are covered entities subject to the HIPAA Privacy Rule. These health plans are:
• Part A or Part B of the Medicare program under Title XVIII;
• The Medicaid program under Title XIX;
• The State Children’s Health Insurance Program (SCHIP); and
• The Medicare Advantage (formerly Medicare+Choice (M+C)) program and other
Medicare health plans.
The CMS is directly responsible for ensuring that the Medicare Fee-For-Service (FFS)
program, also known as the Original Medicare Plan, complies with the HIPAA Privacy
Rule. For the Medicaid and SCHIP programs, the appropriate State Agency is
responsible for ensuring compliance with privacy requirements. Medicare Advantage
(formerly M+C) plans are covered entities subject to the HIPAA Privacy Rule in their
own right and responsible for their own compliance.
D. Business Associates
Most health care providers and health plans do not carry out all of their health care
activities and functions by themselves; they require assistance from a variety of
contractors and other businesses. By definition, a business associate is a person or entity
that performs or assists in the performance of a function or activity involving the use or
disclosure of individually identifiable health information on behalf of a covered entity.
Medicare FFS contractors that perform health care activities involving the use of PHI on
behalf of the Medicare FFS health plan (i.e., claims processing functions) are business
associates of the Medicare FFS health plan (the covered entity). The HIPAA Privacy
Rule allows providers and plans to give PHI to their business associates as long as they
have satisfactory assurances and document those assurances, typically by contract, that
business associates will safeguard the information.
Medicare contracts have been modified to include the business associate provisions.
These provisions also address the contractor’s responsibility to ensure that subcontractors
or agents to whom they disclose Medicare data agree, by contract, to safeguard any PHI
as well. Contracts continue to include language that applies to contractors who maintain
or operate a Privacy Act protected systems of records on Medicare’s behalf.
Medicare contractors that perform health care activities involving the use of PHI on
behalf of the Medicare FFS health plan are not business associates of providers,
physicians, suppliers, clearinghouses, or other health plans. Likewise, providers,
physicians, suppliers, clearinghouses, or other health plans are not business associates of
the Medicare contractor unless the provider, physician, supplier, clearinghouse, or other
health plan is doing work on behalf of the Medicare contractor. For these reasons,
Medicare FFS contractors should not sign business associate agreements with any
provider, physician, supplier, clearinghouse, or other plan unless the provider, physician,
supplier, clearinghouse, or other health plan is doing work on the contractor’s behalf.
E. Trading Partner Agreements
Currently, Medicare contractors execute trading partner agreements (TPAs) with a
number of payers, including Medigap insurers, Medicare supplemental/employee retiree
health plans, multiple employer welfare trusts, TRICARE for Life, as well as State
Medicaid Agencies, for the purpose of exchanging adjudicated Medicare claims for
secondary liability determination by those partners. This exchange of data is commonly
referred to as the “claims crossover process.” For coordination of benefits (COB)
purposes, Medicare contractors and trading partners are not business associates of each
other since neither entity is doing work on the other’s behalf; therefore, MACs should not
sign business associate agreements with COB trading partners that receive claims
crossover data from them.
F. Notice of Privacy Practices
The HIPAA Privacy Rule requires each covered entity to develop and provide a plain
language notice that describes its legal duties, the uses and disclosures of protected health
information that it may make, and individual privacy rights and how to exercise them.
The individual rights include the right to inspect and copy protected health information,
to amend protected health information, to request restrictions, confidential
communications, an accounting of disclosures, a paper copy of the privacy notice, and
how to file complaints.
Medicare’s privacy notice was provided to beneficiaries for the first time in the 2003
Medicare & You handbook and is provided in the handbook every year. New enrollees
receive the privacy notice in the handbook that is mailed to them within 30 days of
Medicare entitlement. Medicare’s privacy notice is also posted on Medicare’s Web site
at www.medicare.gov.
Medicare’s Notice of Privacy Practices informs beneficiaries who are interested in
exercising individual rights to go to www.medicare.gov or call 1-800-MEDICARE.
Customer Service Representatives (CSR) at 1-800-MEDICARE use scripts to answer
questions regarding exercising individual rights and filing complaints.
Since Medicare’s privacy notice describes the uses and disclosures of PHI in the day-to-day operations of Medicare (including Medicare FFS contractors), FFS contractors are
not required to develop a separate privacy notice for Medicare beneficiaries.
G. Individual Rights and Complaints
NOTE: For Individual Rights Under the Privacy Act of 1974, see §10 above.
The HIPAA Privacy Rule gives individuals rights with respect to their PHI. These rights
are listed in covered entities’ privacy notices. The Notice of Privacy Practices for the
Original Medicare Plan includes the right to:
1. See and get a copy of personal health information held by Medicare.
CMS Central Office is responsible for responding to beneficiary requests for
access to records under the HIPAA Privacy Rule. Medicare FFS contractors
should only respond to those requests for information related to payment of a
claim, for which they are already responsible under the contract under existing
customer service procedures. Simple telephone inquiries, such as asking about
the status of a claim or requesting a duplicate Medicare Summary Notice, are not
considered a HIPAA request for access and should be handled under existing
customer service procedures.
2. Have personal health information amended if it is wrong or missing, and
Medicare agrees. If Medicare disagrees, a statement of disagreement may be
added to the personal health information.
Central office is responsible for handling beneficiary requests to amend the record
under the HIPAA Privacy Rule. Contractors will not be responding to requests to
amend records.
Requests for changes to claims or payment records, such as an appeal or change
of address request, are not considered HIPAA Privacy Rule requests for
amendments, and should be handled according to current procedures.
Note, however, that if the request for amendment involves medical records,
contractors should explain that, except in rare circumstances, only the source of
the medical record (i.e., the provider) may make changes to the record.
3. Get a listing of those receiving personal medical information from Medicare.
CMS Central Office is responsible for responding to beneficiary requests for an
accounting of disclosures under the HIPAA Privacy Rule. Contractors will not be
responding to requests for an accounting of disclosures.
The listing does not cover personal health information that was given to the
individual or his or her personal representative, that was given out to pay for
health care or Medicare operations, or that was given out for law enforcement
purposes.
4. Ask Medicare to communicate in a different manner or at a different place, for
example, by sending materials to a P.O. box instead of the address on file.
Current regulations and existing agreements with the Social Security
Administration are extremely prescriptive, often governing precisely how CMS
can respond to requests for confidential communications.
Operationally, CMS can only maintain one address at a time. Because of this,
routine change of address requests should be handled according to current change
of address procedures.
5. Ask Medicare to limit how personal health information is used and given out to
pay claims and run the Medicare program.
CMS Central Office is responsible for responding to beneficiary requests to
restrict disclosure of PHI. Contractors will not be responding to requests to
restrict disclosure of PHI.
6. Get a separate paper copy of the privacy notice.
Contractors who receive requests for a paper copy of the Notice of Privacy
Practices for the Original Medicare Plan should refer requestors to their Medicare
& You handbook.
7. File a complaint.
Medicare’s Notice of Privacy Practices informs individuals of the right to file
complaints about Medicare’s privacy practices with either Medicare or the
Secretary of Health and Human Services. The privacy notice refers individuals to
www.medicare.gov or 1-800-MEDICARE for further information on filing a
complaint.
CMS is required to document in written or electronic form the complaints
received and their disposition. There is no requirement to respond in a particular
manner or time frame.
For the privacy rights listed above where CMS Central Office is responsible for
responding to the request, contractors should advise beneficiaries to address their
requests to:
HIPAA Privacy
P.O. Box 8050
U.S. Department of Health and Human Services
Centers for Medicare & Medicaid Services
7500 Security Boulevard
Baltimore, MD 21244-1850
H. Privacy Authorizations
An authorization is a document that an individual uses to give a covered entity
permission to disclose his or her PHI for a particular purpose (e.g., for marketing) or to a
third party specified by the individual. A covered entity is generally not required to
obtain an authorization for the use or disclosure of PHI for treatment, payment, or health
care operations, as well as for certain public priority activities under specified conditions
(e.g., health care oversight, law enforcement). Contractors should inform providers that
contractors are unable to make payment for Medicare claims if the provider fails to
provide the information needed to process them.
The HIPAA Privacy Rule specifies certain core elements and required statements for a
valid authorization. Contractors may add more elements to their authorizations as long as
the core elements and required statements remain and no provisions are added that
conflict with these core elements and statements.
Contractors must also accept an authorization from another entity, provided it includes all
of the core elements and required statements, and no provisions are added that conflict
with these core elements and statements.
I. Core Elements and Required Statements for an Authorization
The core elements of a valid authorization are:
1. A description of the information to be used or disclosed that identifies the
information in a specific and meaningful fashion;
2. The name or other specific identification of the person(s), or class of persons,
authorized to make the requested use or disclosure;
3. The name or other specific identification of the person(s) or class of persons, to
whom the covered entity may make the requested use or disclosure;
4. A description of each purpose of the requested use or disclosure. The
statement, “at the request of the individual” is a sufficient description of the
purpose when the beneficiary initiates the authorization and does not, or elects not
to, provide a statement of the purpose;
5. An expiration date or an expiration event that relates to the individual or the
purpose of the use or disclosure; and
6. The signature of the individual and date. If a personal representative of the
individual signs the authorization, a description of such representative’s authority
to act for the individual must also be provided. Although the HIPAA Privacy
Rule requires only a description of the representative’s authority to act for the
individual, CMS is requiring that documentation showing the representative’s
authority be attached to the authorization (e.g., a Power of Attorney).
In addition to the core elements, the authorization must contain statements adequate to
place the individual on notice of all of the following:
1. The individual’s right to revoke the authorization in writing, how the individual
may revoke the authorization, and the exceptions to the right to revoke, e.g., “You
have the right to take back (“revoke”) your authorization at any time in writing,
except to the extent that Medicare has already acted based on your permission.
To revoke your authorization, send a written request to: [Each Medicare
contractor or CMS: Please insert Name, Address, and Telephone number of your
organization here]”;
2. The inability to condition treatment, payment, enrollment or eligibility for
benefits on the authorization, e.g., “I understand refusal to authorize disclosure of
my personal medical information will have no effect on my enrollment, eligibility
for benefits, or the amount Medicare pays for the health services I receive”;
3. The potential for information disclosed pursuant to the authorization to be
subject to redisclosure by the recipient and no longer protected, e.g.: “Your
personal medical information that you authorize Medicare to disclose may be
subject to redisclosure and no longer protected by law.”
In addition, the authorization must be written in plain language and a signed copy must
be provided to the individual (or the individual should be advised to retain a copy).
The CMS is developing a standard authorization for beneficiaries or their personal
representatives to request disclosure of PHI to third parties. The standard will contain the
elements for compliance with both the HIPAA Privacy Rule and Privacy Act
requirements. Contractors will be notified when the standard authorization is available.
J. Personal Representatives and Third Party Authorizations
The HIPAA Privacy Rule requires covered entities to treat an individual’s personal
representative as the individual with respect to uses and disclosures of the individual’s
PHI, as well as exercising the individual’s privacy rights listed in the covered entity’s
Notice of Privacy Practices. A personal representative may also authorize disclosures of
an individual’s PHI (see §190H above).
In addition to these formal designations of a personal representative, the HIPAA Privacy
Rule permits a covered entity to disclose to any person identified by the individual the
protected health information directly relevant to such person’s involvement with the
individual’s care or payment related to the individual’s care. Therefore, a verbal
authorization is allowed under the HIPAA Privacy Rule for those individuals involved in
the care of an individual.
Contractors should continue to handle routine inquiries, such as telephone requests for
the status of claims, under existing customer service procedures that include verification
of the individual’s identity. Therefore, with the beneficiary’s verbal or written
permission, contractors may continue to speak to third parties on behalf of the individual.
See Exhibit D - Disclosure Desk Reference Guide for Call Centers for detailed
instructions on disclosing PHI over the telephone.
Contractors may also continue to handle Congressional inquiries under existing customer
service procedures (see §10J above).
K. Administrative Requirements
As Medicare’s business associate, contractors are not subject to the administrative
requirements of the HIPAA Privacy Rule. However, under the Privacy Act, contractors
must comply with the privacy provisions specified in their contracts. Contractors are not
required to designate a privacy official. However, contractors are required to have in
place a senior official or other responsible party to address the privacy concerns of the
organization and to establish an internal control system to monitor compliance with
privacy requirements.
Similarly, as Medicare’s business associate, contractors are not subject to the HIPAA
Privacy Rule’s requirement to train staff specifically on the HIPAA Privacy Rule.
However, under the Privacy Act, contractors are required to ensure that employees
understand their responsibility to protect the privacy and confidentiality of CMS’s
records.
It is CMS policy that any data collected on behalf of CMS in the administration of a
Medicare contract belongs to CMS. Any disclosure of individually identifiable
information without prior consent from the individual to whom the information pertains,
or without statutory or contract authorization, requires prior approval by CMS.
History
(Rev. 7, 06-25-04)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
385a51f8514b465b4d7f75282e5869c5374317663173f9cfd8cc9c199c600c56
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.