The HIPAA Privacy Rule intends to protect the privacy of patients seeking health care while permitting important uses of health information.
The Privacy Rule limits the use and disclosure of PHI and establishes patient rights.
The Privacy Rule allows covered entities to analyze their own needs and implement programs based on their environment. However, it requires that all new privacy policies and procedures be compliant with the Privacy Rule and monitored at least annually.
The Privacy Rule also requires covered entities to develop processes to handle complaints. The covered entity must identify where individuals can submit complaints. They must advise that complaints can also be forwarded to the Secretary of Health and Human Services (HHS) without fear of retaliation for submitting the complaint.