{"@context":"https://schema.org","@type":"Article","headline":"Confidential communications request","description":"Learn how a HIPAA confidential communications request changes the means or location used for PHI messages and how provider and health-plan rules differ.","url":"https://finnihealth.com/resources/glossary/confidential-communications-request","datePublished":"2026-08-16T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Confidential communications request","item":"https://finnihealth.com/resources/glossary/confidential-communications-request"}]}}
Glossary term

Confidential communications request

Learn how a HIPAA confidential communications request changes the means or location used for PHI messages and how provider and health-plan rules differ.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

alternative contact request confidential contact method

A confidential communications request asks a HIPAA covered provider or health plan to send PHI communications by alternative means or to an alternative location. Examples include portal-only messages, a different mailing address, a safe phone number, or limited voicemail wording. The rule sets different conditions for providers and health plans. The request changes communication delivery and remains distinct from a restriction on underlying uses or disclosures.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Provider and health-plan conditions differ

Under 45 CFR 164.522(b), a covered health-care provider must accommodate a reasonable request for alternative means or locations. It may require writing, payment-handling information when appropriate, and an alternative address or contact method. It may not require an explanation of the request's basis as a condition.

A health plan must accommodate a reasonable request when the individual clearly states that disclosure could endanger them. The plan may require that statement.

The request needs operational fields

Record the person, safe means or location, PHI communication types, prohibited delivery route, voicemail rule, safe time window, effective date, urgent backup, payment handling, owner, and verification evidence. Route the control to scheduling, clinical messaging, billing, statements, vendors, and portals that can send covered communications.

The Notice of Privacy Practices rule requires the notice to describe the right and how to exercise it.

It differs from a restriction request

A confidential-communication control changes how or where the entity contacts the individual. A restriction request under section 164.522(a) asks the entity to limit specified uses or disclosures. The implementation owner should classify the request before configuring systems.

The HIPAA Privacy Rule overview gives the federal scope. State privacy, consumer-health, insurance, and safety rules may add protections.

A test closes the workflow

A fictional family requests portal-only clinical messages, mailed billing to a safe address, and neutral voicemail. Portal and mail work, while the first reminder leaves detailed voicemail. The control result is 2 of 3 communication routes verified. The request remains open until the voicemail setting is corrected and retested.

Receive the request through a safe route

Train scheduling, clinical, billing, and portal teams to recognize plain-language requests such as “do not call my home” or “send statements to this address.” Route the request promptly to the privacy owner without requiring the person to explain a sensitive reason when the provider rule does not allow that condition.

Verify identity and the requested channel carefully. Confirmation through the unsafe phone number or address can defeat the request. Ask the person which current route is safe for verification, how much detail may be used, and what to do when the preferred route is unavailable. Record any authorized personal representative separately.

If the request is incomplete, preserve the safe elements already known while obtaining what is needed. An open decision should not silently revert communications to a channel the person identified as unsafe.

Propagate one decision across every sender

A practice may communicate through the EHR, patient portal, scheduling platform, billing vendor, clearinghouse, laboratory, survey tool, call center, mail house, and individual staff devices. Create a sender inventory and specify the exact setting or workflow change for each one. Some systems need an alert because a global address field cannot safely express the request.

Use minimum-necessary alerts. A scheduling banner might say “follow confidential communication plan” and link authorized staff to the instructions instead of displaying the person's reason. Keep the sensitive rationale out of general notes and appointment printouts.

Define an urgent-contact fallback with the person. Emergency or time-sensitive clinical communication may need a different safe route, named contact, neutral message, or escalation. Test both ordinary and urgent paths before closing implementation.

Manage changes and closure

Record approval, conditions, effective time, systems updated, vendors notified, staff trained, test results, failures, and correction evidence. Recheck after a phone, address, portal, payer, vendor, or personal-representative change. The individual should have an accessible way to revise or end the request.

Useful measures include routes configured divided by routes due, first test messages delivered safely divided by tests due, and communication failures corrected by target divided by failures found. Keep every failed route in the denominator until a successful retest.

Audit recent outbound events after activation, not only configuration screens. Compare actual envelopes, caller ID, voicemail content, portal notifications, email subjects, text previews, and vendor logs with the approved plan. A correct profile can still feed a downstream template that exposes sensitive detail.

Before closing, ask:

  • Which entity received the request, and is it a provider or plan?
  • What exact means, location, content limit, and time window are safe?
  • Which systems and vendors can originate a communication?
  • How will identity be verified without using the unsafe route?
  • What is the urgent fallback and who may use it?
  • Which event triggers retesting or revision?

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni