District Court Limits HIPAA Right of Access
Time 2 Minute Read

The District Court for the District of Columbia recently invalidated certain Department of Health and Human Services (“HHS”) rules regarding an individual’s access to their protected health information (“PHI”). The Court held that: (1) individuals can only direct their electronic PHI to third parties (and not hard copy PHI); and (2) the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Omnibus Rule provisions regarding the caps on fees that HIPAA-covered entities may charge for such requests did not follow relevant administrative law procedures.

Under the HIPAA Privacy Rule, individuals may request that covered entities provide them access to their PHI, but they may also direct the covered entities to provide such PHI directly to a third party, such as an electronic medical record service. The Health Information Technology for Economic and Clinical Health Act of 2009 provided a statutory cap of $6.50 that covered entities could charge for such an access request, but that rate was interpreted to only apply to requests for access to PHI by individuals. Covered entities and their service providers typically charged higher rates, such as $20-$30, for access requests made by companies on behalf of the patient. In 2016, HHS guidance stated that the $6.50 rate applied to all requests for access to PHI, whether they came from the patient or third parties.

In its ruling, the court held that HHS’s actions were “arbitrary and capricious” and “did not follow the requisite notice and comment procedure.”

The case may mark a blow to HHS’ Right of Access initiative. As we’ve noted, the U.S. Department of Health and Human Services’ Office for Civil Rights has engaged in two separate actions that address patients’ rights to access their PHI.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 1 Minute Read

On February 6, 2026, the Federal Trade Commission announced its second report to Congress on its efforts to combat ransomware and other cyber attacks.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page