ComplianceOnline

Retaliation and Waiver


A covered entity may not retaliate against a person for exercising rights provided by the HIPAA Privacy Rule, for assisting in an investigation by HHS or another appropriate authority, or for opposing an act or practice that the person believes in good faith violates the Privacy Rule. A covered entity may not require an individual to waive any right under the Privacy Rule as a condition for obtaining treatment, payment, and enrollment or benefits eligibility.