HHS OCR HIPAA FAQ 226
How does a covered entity identify an individual’s personal representative?
Length: 68 wordsOfficial source
State or other law determines who is authorized to act on an individual’s behalf, thus the Privacy Rule does not address how personal representatives should be identified.
Covered entities
should continue to identify personal representatives the same way they have in the past. However, the HIPAA Privacy Rule does require covered entities to verify a personal representative’s authority in accordance with
45 CFR 164.514
(h).
Date Created: 12/19/2002