How to submit a request for a list of everyone who has accessed your health information

Did you know that under the Privacy Rule of HIPAA, you are entitled to receive a list of the names and (if known) the addresses of everyone who has accessed your health information file?

Here's a sample letter that you can customize and send to your insurance company to find out who has viewed your heath information. Many insurance companies have a member email function on their web site so you can submit this request without even paying for postage.

<Your address>
<date>

Dear Sir or Madam:

This is a request under the Privacy Rule of the Health Insurance Portability and Accountability Act (HIPAA), CFR Title 45 Subtitle A Subchapter C Part 164 Subpart E § 164.528, Accounting of disclosures of protected health information.

The applicable code may be accessed online at: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.528.

Pursuant to my rights under the Privacy Rule of HIPAA, I am seeking an accounting that includes the names and business addresses of all UHC employees and contractors who have accessed my health information during the past 6 years. The accounting must include all information described below.

(i) The date of the disclosure;

(ii) The name of the entity or person who received the protected health information and, if known, the address of such entity or person;

(iii) A brief description of the protected health information disclosed; and

(iv) A brief statement of the purpose of the disclosure that reasonably informs the individual of the basis for the disclosure or, in lieu of such statement, a copy of a written request for a disclosure under § 164.502(a)(2)(ii) or § 164.512, if any.

See also  Court Ruling May Spur Competitive Health Plans to Bring Back Copays for Preventive Services

I am seeking strict compliance with this request through the US Health and Human Services (HHS) Office of Civil Rights, which is the federal agency that enforces this provision of HIPAA.

The requested records may be mailed to me at the address that your company has on file. My Member ID is xxxxxxxxxxxxxxx. My date of birth is xx/xx/xxxx.

As the records that I am seeking should be readily available in your files, I ask that they be provided without undue delay.

Thank you in advance for your fulfillment of this request.

Sincerely,

<Your name>

submitted by /u/gpslouis
[comments]