Bindinglaw

US · guidance

CMS SOM App. B, Tag G438

§484.50(c) Standard: Rights of the patient

activein force · 2026-07-22 – presentas-observed

The patient has the right to—

(6) Have a confidential clinical record. Access to or release of patient information

and clinical records is permitted in accordance with 45 CFR parts 160 and 164.

Interpretive Guidelines §484.50(c)(6)

45 CFR Part 160 and 164 pertain to requirements of the Health Insurance Portability and

Accountability Act of 1996 (“HIPAA”). The HIPAA Privacy Rule (45 CFR Part 160 and

Subparts A and E of Part 164), Security Rule (45 CFR Part 160 and Subparts A and C of

Part 164), and Breach Notification Rule (45 CFR §§ 164.400–414) protect the privacy

and security of health information and provide individuals with certain rights regarding

their health information as follows:

• The Privacy Rule sets national standards for covered entities (health plans,

health care clearinghouses, and health care providers that conduct certain health

care transactions electronically) and their business associates, including

appropriate safeguards to protect the privacy of protected health information

(PHI) and the limits and conditions under which PHI is permitted or required to

be used or disclosed;

• The Security Rule specifies safeguards that covered entities and their business

associates must implement to protect the confidentiality, integrity, and availability

of electronic protected health information (ePHI)

• The Breach Notification Rule requires covered entities and their business

associates to notify affected individuals, U.S. Department of Health & Human

Services (HHS), and in some cases, the media of a breach of unsecured PHI.

The HIPAA Privacy Rule also gives certain patients’ rights over their health information,

including rights to examine and obtain a copy of their health records, and to request

corrections.

HHAs have unique concerns and risks regarding staff and contractors who transport

documents and/or electronic devices containing PHI, such as during their visits to

patient’s homes. Compliance with §484.50(c)(6) is evidenced by documentation of

HIPAA training for all staff and monitoring HIPAA compliance to manage the risk of

inappropriate PHI disclosure or unsecured ePHI. Each covered entity and business

associate is responsible for ensuring its compliance with the HIPAA Privacy, Security,

and Breach Notification Rules, as applicable, including consulting appropriate counsel as

necessary.

Survey procedures §484.50(c)(6)

Verify that the agency staff maintain the confidentiality of protected health information

that they transport and use.

History

Rev. 219; Issued: 04-12-24; Effective: 04-12-24; Implementation: 04-12-24

Provenance

Source
cms.gov
Retrieved
2026-07-22
Edition
som-2026-07-22
Content hash
452e308adefdc38e211fa3a7a629fe0c344bef9343dfef45e52a2c4d8ebaabd4
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.