A health plan disclosure restriction is the HIPAA rule requiring a covered entity to accept an individual's request when the disclosure is for payment or health care operations, is not otherwise required by law, and the PHI pertains solely to an item or service paid in full by the individual or someone other than the plan. Every condition must be verified for the defined service.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
This is a specific mandatory restriction
Under 45 CFR 164.522, covered entities generally must permit restriction requests but usually need not agree. Paragraph (a)(1)(vi) creates the narrower health-plan situation they must accept when its conditions are met. Record the individual, plan, item or service, dates, payment status, disclosure purpose, and legal-review result.
Paid in full and solely related need proof
Verify that the individual or another person besides the health plan paid the covered entity in full and that the PHI at issue pertains solely to that item or service. Bundled care, later balance changes, coordination of benefits, refunds, or a disclosure required by law can complicate the analysis. HHS's Privacy Rule overview provides the federal context; the restriction section supplies the operative conditions. Route ambiguity to the privacy or legal owner before release.
Implement the restriction across systems
Flag relevant billing, clinical, claims, portal, release, analytics, and vendor workflows without hiding information needed for lawful care. Train staff on plan-specific routing and exception escalation. Document any broader voluntary restriction separately because different termination rules can apply.
Use a gate checklist
A fictional request has six gates: correct plan, defined service, full payment, solely related PHI, payment-or-operations purpose, and no legal requirement to disclose. Five are verified; the legal-requirement check is pending. Readiness is 5 of 6 gates, so the release decision remains on hold.
Define the item or service before payment
Identify the covered entity, individual, health plan, exact item or service, service date, provider, codes when known, expected charges, related documentation, and requested restriction. Discuss the request before a claim or eligibility transaction is sent when feasible. A restriction cannot undo every disclosure already made.
Explain the distinction between paying the provider in full and satisfying other charges. Facility, clinician, laboratory, pharmacy, transportation, or vendor services may be billed by different entities. Payment to one does not necessarily establish full payment for another entity's item or service.
Do not promise that the plan will know nothing about the episode. Other lawful disclosures, independently billed services, prior records, coordination requirements, or information the individual sends can exist. State the scope the practice can actually control.
Reconcile full payment and later changes
Create a payment gate that confirms expected amount, discounts, adjustments, refunds, returned payments, chargebacks, payment-plan status, and zero balance before the affected plan disclosure. Record who paid, because payment may come from the individual or another person besides the plan.
If the final amount changes after service, hold related plan transactions while billing and privacy owners determine whether full payment still exists. A later refund or uncovered charge should not silently remove an active restriction. Notify the individual through an approved route when a material change requires action.
For recurring services, treat each defined item, service, or agreed episode according to qualified review. One payment should not create an unbounded restriction for future care.
Map solely related PHI
List the records and transactions that pertain solely to the paid item or service: claim drafts, encounter records, line items, remittance work, utilization documents, portal messages, analytics feeds, and business-associate files. Identify mixed records that also concern other services or a disclosure required by law.
Do not delete or hide the clinical record from authorized care teams. The restriction concerns a specified health-plan disclosure for payment or operations, not clinical integrity. Use targeted flags and release rules rather than broad record suppression.
Mixed records require careful segmentation or another lawful operational solution. Route uncertainty to qualified privacy and legal review instead of labeling the whole chart restricted.
Block every plan-facing route
Test claim submission, eligibility, prior authorization, utilization management, payer portals, clearinghouses, automated exports, billing vendors, collection files, refunds, audits, and plan-directed record releases. Cancel queued work and reconcile acknowledgments when the request becomes effective.
Give staff a minimum-necessary instruction that identifies the affected item and plan without exposing the person's reason. Define an exception owner for legally required disclosures and preserve the source, decision, PHI, recipient, and date if an exception is used.
Monitor the active restriction
Review the zero balance, service scope, plan identity, system flags, queued transactions, and vendor controls until the relevant work closes. Trigger review after a coding change, additional service, corrected claim, refund, payer change, subpoena, audit, or legal requirement.
Useful measures include requests meeting every gate, restricted cases with no prohibited plan disclosure, affected routes tested, and exceptions supported by current authority. Count failed, ambiguous, refunded, and mixed-record cases separately.
Before release, ask:
- Which item or service is paid in full, by whom, and to which entity?
- Which PHI pertains solely to that item or service?
- Is the recipient a health plan and the purpose payment or operations?
- Is any disclosure required by law?
- Which systems or vendors can send information to the plan?
- What later event reopens payment or scope review?
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni