Bindinglaw

US · guidance

CMS SOM App. A, Tag A-0143

§482.13(c)(1) - The patient has the right to personal privacy

activein force · 2026-07-22 – presentas-observed

Interpretive Guidelines §482.13(c)(1)

The underlying principle of this requirement is the patient’s basic right to respect, dignity, and comfort

while in the hospital.

Physical Privacy

“The right to personal privacy” includes at a minimum, that patients have physical privacy to the extent

consistent with their care needs during personal hygiene activities (e.g., toileting, bathing, dressing),

during medical/nursing treatments, and when requested as appropriate.

People not involved in the care of the patient should not be present without his/her consent while he/she

is being examined or treated. If an individual requires assistance during toileting, bathing, and other

personal hygiene activities, staff should assist, giving utmost attention to the individual’s need for

privacy. Privacy should be afforded when the MD/DO or other staff visits the patient to discuss clinical

care issues or conduct any examination or treatment.

However, audio/video monitoring (does not include recording) of patients in medical-surgical or

intensive-care type units would not be considered violating the patient’s privacy, as long as there exists a

clinical need, the patient/patient’s representative is aware of the monitoring and the monitors or speakers

are located so that the monitor screens are not readily visible or where speakers are not readily audible to

visitors or the public. Video recording of patients undergoing medical treatment requires the consent of

the patient or his/her representative.

A patient’s right to privacy may also be limited in situations where a person must be continuously

observed to ensure his or her safety, such as when a patient is simultaneously restrained and in seclusion

to manage violent or self-destructive behavior or when the patient is under suicide precautions.

Protecting Patient Personal Information

The right to personal privacy also includes limiting the release or disclosure of patient information.

Patient information includes, but is not limited to, the patient’s presence or location in the hospital;

demographic information the hospital has collected on the patient, such as name, age, address, income;

or information on the patient’s medical condition. Such patient information may not be disclosed

without informing the patient or the patient’s representative in advance of the disclosure and providing

the patient or the patient’s representative an opportunity to agree, prohibit, or restrict the disclosure.

Below is a summary of privacy issues that surveyors might encounter in hospital settings, and the related

privacy requirements.

Permitted Disclosures:

A hospital is permitted to use and disclose patient information, without the patient’s authorization, in

order to provide patient care and perform related administrative functions, such as payment and other

hospital operations.

• Payment operations include hospital activities to obtain payment or be reimbursed for the provision

of health care to an individual.

• Hospital operations are administrative, financial, legal, and quality improvement activities of a

hospital that are necessary to conduct business and to support the core functions of treatment and

payment. These activities include, but are not limited to: quality assessment and improvement

activities, case management and care coordination; competency assurance activities, conducting or

arranging for medical reviews, audits, or legal services, including fraud and abuse detection and

compliance programs; business planning, development, management, and administration and certain

hospital-specific fundraising activities.

Hospitals must develop and implement policies and procedures that restrict access to and use of patient

information based on the specific roles of the members of their workforce. These policies and

procedures must identify the persons, or classes of persons, in the workforce who need access to

protected health information to carry out their duties and the categories of protected health information

to which access is needed.

One example of a permitted disclosure is a Facility Directory. It is common practice in many hospitals

to maintain a directory of patient contact information. The hospital must inform the patient, or the

patient’s representative, of the individual information that may be included in a directory and the

persons to whom such information may be disclosed. The patient, or the patient’s representative, must

be given the opportunity to restrict or prohibit any or all uses and disclosures. The hospital may rely on

a patient’s/representative’s individual’s informal permission to list in its facility directory the patient’s

name, general condition, religious affiliation, and location in the provider’s facility.

The provider may

then disclose the patient’s condition and location in the facility to anyone asking for the patient by name,

and also may disclose religious affiliation to clergy. If the opportunity to prohibit or restrict uses and

disclosures cannot be provided due to the patient’s incapacity or emergency treatment circumstance, and

there is no patient representative available, the hospital may disclose patient information for the

facility’s directory if such disclosure is in the patient’s best interest. The hospital must provide the

patient or the patient’s representative an opportunity to prohibit or restrict disclosure as soon as it

becomes practicable to do so. The hospital may use patient information to notify, or assist in the

notification of, a family member, a personal representative of the patient, or another person responsible

for the care of the patient of their location, general condition, or death. The hospital must have

procedures in place, in accordance with State law, to provide appropriate information to patient families

or others in those situations where the patient is unable to make their wishes known.

Incidental Uses and Disclosures May be Acceptable:

An incidental use or disclosure is a secondary use or disclosure of patient information that cannot

reasonably be prevented, is limited in nature, and that occurs as a result of another use or disclosure that

is permitted. Many customary health care communications and practices play an important role in

ensuring the prompt delivery of effective care. Due to the nature of these communications and practices,

as well as of the hospital environment, the potential exists for a patient’s information to be disclosed

incidentally. For example, a hospital visitor may overhear a health care professional’s confidential

conversation with another health care professional or the patient, or may glimpse a patient’s information

on a sign-in sheet or nursing station whiteboard. The regulation protecting patient privacy does not

impede these customary and essential communications and practices and, thus, a hospital is not required

to eliminate all risk of incidental use or disclosure secondary to a permitted use or disclosure, so long as

the hospital takes reasonable safeguards and discloses only the minimum amount of personally

identifiable information necessary. For example, hospitals may:

• Use patient care signs (e.g. “falls risk” or “diabetic diet” ) displayed at the bedside or outside a

patient room;

• Display patient names on the outside of patient charts; or

• Use “whiteboards” that list the patients present on a unit, in an operating room suite, etc.

Hospitals are expected to review their practices and determine what steps are reasonable to safeguard

patient information while not impeding the delivery of safe patient care or incurring undue

administrative or financial burden as a result of implementing privacy safeguards.

Examples of reasonable safeguards could include, but are not limited to:

• Requesting that waiting customers stand a few feet back from a counter used for patient

registration;

• Use of dividers or curtains in areas where patient and physician or other hospital staff

communications routinely occur;

• Health care staff speaking quietly when discussing a patient’s condition or treatment in a semi-private room;

• Utilizing passwords and other security measures on computers maintaining personally

identifiable health information; or

• Limiting access to areas where white boards or x-ray light boards are in use, or posting the board

on a wall not readily visible to the public, or limiting the information placed on the board.

Survey Procedures §482.13(c)(1)

• Conduct observations/interview patients or their representatives to determine if patients are

provided reasonable privacy during examinations or treatments, personal hygiene activities and

discussions about their health status/care and other appropriate situations.

• Review hospital policy and interview staff concerning their understanding of the use of patient

information in the facility directory. Does the policy address the opportunity for the patient or

patient’s representative to restrict or prohibit use of patient information in emergent and non-emergent situations?

• Review hospital policy and conduct observations/interview staff to determine if reasonable

safeguards are used to reduce incidental disclosures of patient information.

• If audio and/or visual monitoring is utilized in the med/surg or ICU setting, conduct observations

to determine that monitor screens and/or speakers are not readily visible or audible to visitors or

the public.

History

Rev. 95, Issued: 12-12-13, Effective: 06-07-13, Implementation: 06-07-13

Provenance

Source
cms.gov
Retrieved
2026-07-22
Edition
som-2026-07-22
Content hash
3e23f0bfdd179f1aa3571d2ea305b5eb8a22460e05aea2b1246431fa4e7bea6d
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS SOM App. A, Tag A-0143 — §482.13(c)(1) - The pati… · binding.law