Skip to content
StudyDex
Health & Medicine

Must a Covered Entity Have an Established Complaint Process?

Quick answer

True. Under the HIPAA Privacy Rule (45 CFR 164.530(d)), a covered entity must provide a process for individuals to file complaints about its privacy policies or practices, identify a contact person or office, document all complaints and their disposition for six years, and never retaliate against a complainant.

The answer

True. The HIPAA Privacy Rule expressly requires every covered entity to have an established complaint process. The governing text is 45 CFR 164.530(d), which states that a covered entity must "provide a process for individuals to make complaints concerning the covered entity's policies and procedures required by this subpart... or its compliance with such policies and procedures."

This is not optional or best-practice guidance; it is a mandatory administrative requirement that sits alongside the duties to designate a privacy official, train the workforce, apply safeguards, and impose sanctions for violations.

What the complaint process must include

Several concrete obligations flow from the rule and related sections:

  • A contact person or office. The entity must name someone (often the Privacy Officer) who receives complaints, and this contact must be listed in the Notice of Privacy Practices (45 CFR 164.520).
  • An internal channel. Individuals must be able to complain directly to the covered entity, separate from their right to also complain to the HHS Office for Civil Rights (OCR).
  • Documentation. The entity must document all complaints received and their disposition, if any.
  • Six-year retention. Under 45 CFR 164.530(j), that documentation, like most Privacy Rule records, must be kept for six years from the date of creation or the date it was last in effect.
  • No retaliation and no waiver. Section 164.530(g) prohibits intimidation or retaliation against anyone who files a complaint, and 164.530(h) bars requiring individuals to waive their complaint rights as a condition of treatment or payment.

Why "false" is wrong

If you answered False, the likely reasoning is that filing complaints is the individual's right rather than the entity's duty, or that only OCR handles complaints. Both are misreadings. The right to complain and the entity's duty to build a process are two sides of the same rule: individuals get a right because the entity is required to provide the channel. And while OCR does accept complaints, that federal avenue does not relieve the covered entity of its own internal-process obligation.

The bigger picture

Think of the complaint process as one pillar of HIPAA's administrative requirements. The others, designating a privacy and security official, training workforce members, applying appropriate safeguards, and sanctioning employees who violate policy, form a compliance program. Skipping the complaint process is itself a compliance failure that OCR can cite. For exam purposes: the statement is true, the citation is 164.530(d), the retention period is six years, and retaliation is prohibited.

  1. 1

    Publish the process

    Name a contact person/office and describe how to complain in the Notice of Privacy Practices (164.520).

  2. 2

    Receive the complaint

    Accept complaints about the entity's privacy policies, practices, or compliance directly from individuals.

  3. 3

    Investigate and resolve

    Review the complaint, take corrective action if needed, and record the disposition.

  4. 4

    Document everything

    Log the complaint and its outcome in writing as required by 164.530(d).

  5. 5

    Retain six years

    Keep the documentation for six years from creation or last-effective date (164.530(j)).

  6. 6

    Protect the complainant

    No retaliation, intimidation, or forced waiver of rights (164.530(g) and (h)).

Frequently asked

Who should HIPAA complaints be directed to?

Complaints go to the covered entity's designated contact person or office (usually the Privacy Officer) named in the Notice of Privacy Practices. Individuals may also file separately with the HHS Office for Civil Rights.

How long must a covered entity retain complaint records?

Six years. Under 45 CFR 164.530(j), documentation of complaints and their disposition must be kept for six years from the date of creation or the date it was last in effect, whichever is later.

What is required in a HIPAA complaint process?

A named contact person or office, a channel for individuals to complain about privacy practices or compliance, written documentation of complaints and dispositions, six-year retention, and a strict ban on retaliation or forced waivers.

Can a covered entity retaliate against someone who files a complaint?

No. Section 164.530(g) prohibits any intimidating, threatening, coercive, or retaliatory action against an individual for filing a complaint, and 164.530(h) bars conditioning treatment or payment on waiving the right to complain.

Start freeLog in