Skip to main content
CoreFolioHIPAA
How-to

How long do you have to respond to a HIPAA complaint?

HIPAA sets no deadline for answering a patient privacy complaint. What 45 CFR 164.530(d) requires, and how to set timeframes your practice can meet.

By CoreFolio

10-minute read

HIPAA sets no deadline. 45 CFR § 164.530(d) requires your practice to have a process for patients to complain about its privacy practices, and to document every complaint and how it was resolved — but it names no acknowledgment window and no resolution window.1 Your practice picks its own timeframes, writes them into its procedure, and is then measured against the standard it set for itself.

That answer catches people off guard, because several neighboring patient-rights obligations in the Privacy Rule do come with a number attached. Records access has 30 days. Filing with the federal regulator has 180. Neither of those is the complaint clock, and borrowing one of them into your own procedure is how a practice ends up promising a turnaround it never agreed to and cannot keep.

Key takeaways

  • The Privacy Rule requires a complaint process plus documentation of what you decided. It puts no clock on either step (45 CFR § 164.530(d)).1
  • The deadlines people associate with complaints belong to other obligations: 180 days is the patient's window to go to the federal regulator, and 30 days is the clock on a records-access request.23
  • Some states do fix acknowledgment and resolution clocks, but those rules generally reach health plans, hospitals, and licensed clinics or facilities rather than practitioner-owned offices.4
  • Because you choose the number, the risk shifts onto you: a written promise you routinely miss is weaker evidence than a longer one you consistently keep.
  • Complaint records carry the same six-year retention as the rest of your Privacy Rule documentation (§ 164.530(j)(2)).5

What does 45 CFR 164.530(d) actually require?

The standard is two sentences long, and both of them are about existence rather than speed. A covered entity must “provide a process for individuals to make complaints” concerning its privacy policies and procedures or its compliance with them. And, as an implementation specification, it must “document all complaints received, and their disposition, if any.”1

Read those two obligations closely and you can see what a regulator would look for:

  • A route in. Patients have to be able to complain, and they have to know how. The notice of privacy practices must carry “a brief description of how the individual may file a complaint with the covered entity,” along with a statement that they will not be retaliated against for filing one.6
  • A named person. The complaint contact is the person or office designated under § 164.530(a)(1)(ii) — the same designation the notice has to publish.6
  • A written record of the outcome. “Disposition” means what you decided and what you did, not just that a call came in.1
  • No retaliation. A covered entity “may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual” for filing a complaint.7

What is conspicuously absent is any number. There is no five-day acknowledgment, no thirty-day resolution, no maximum investigation period.

Why is “no deadline” not the same as “no obligation”?

The absence of a federal number does not leave the timing unexamined — it moves the yardstick from the regulation to your own document.

45 CFR § 164.530(i) requires a covered entity to implement policies and procedures “designed to comply with the standards” of the Privacy Rule, reasonably designed for the size and type of the entity's activities.8 Once your written procedure says you acknowledge a complaint in five business days, five business days is the standard you have adopted for yourself. A file full of complaints acknowledged three weeks later, against a procedure promising five days, is a self-documented gap — and it is documented in the very records § 164.530(d)(2) obliges you to keep.

This is the practical reason to be conservative rather than ambitious when you fill in those fields. A solo practice whose privacy officer also runs the front desk should not promise a 24-hour response. The regulation does not ask for speed; it asks for a process that works and a record that shows it worked.

Where do the deadlines people quote actually come from?

Three numbers circulate in conversations about HIPAA complaints, and none of them is a response deadline for your practice.

The numberWhat it actually governsSource
180 daysThe window for a patient to file a complaint with the Office for Civil Rights (OCR), the U.S. Department of Health and Human Services (HHS) agency that enforces HIPAA. OCR may extend it for good cause.HHS complaint process; 45 CFR § 160.306.2
30 daysActing on a patient's request for access to their own records — a different right, with its own procedure.45 CFR § 164.524(b)(2)(i).3
5 and 30 daysGrievances handled by a licensed health care service plan in California — a rule for plans, not for treating practices.Cal. Health & Safety Code § 1368.4
No numberYour acknowledgment and resolution of a privacy complaint brought to you directly.45 CFR § 164.530(d).1

The 180-day figure is the one most often misread as a practice obligation. It runs the other direction: a person who believes their privacy rights were violated must generally file with OCR “within 180 days of when you knew that the act or omission complained of occurred,” and OCR may extend that period on a showing of good cause.2 It is a limitation period on the patient, not a service level on you.

Do state laws set a complaint deadline for your practice?

Usually not, if your practice is a practitioner-owned outpatient office — but the reason matters more than the answer, because it tells you when to look again.

Prescriptive grievance clocks are real. California's Knox-Keene Act, for example, requires “a written acknowledgment within five calendar days of the receipt of a grievance,” and treats any grievance still unresolved after 30 days as one the entity must report to its regulator.4 But read the first line of that section: the duty runs to “every plan.” It is an obligation of licensed health care service plans. The same pattern repeats elsewhere — the states that fix grievance timelines generally attach them to health plans, hospitals, and licensed clinics or facilities, which are regulated as institutions, and route complaints about individual practitioners to a licensing board instead.

Two situations should send you to counsel before you fill in a number:

  • Your practice is itself a licensed clinic, facility, or plan. Then the institutional grievance rules in your state may well apply to you directly, and they will be more specific than anything HIPAA says.
  • You have taken on a health plan's grievance work by contract. Delegated grievance authority can carry the plan's own clocks with it. This is a fact about your contracts, not about your state, so no general guidance can tell you the answer — the agreement can.

Separately, several state licensing boards require practitioners to tell patients how to file a complaint with the board. That is a disclosure obligation about an external channel, not a deadline on your internal privacy complaint process, and the two are easy to conflate. Confirm what your own board requires.

How do you choose timeframes you can actually meet?

Because the numbers are yours, treat them as an operational commitment rather than a compliance formality:

  1. Separate acknowledgment from resolution. Acknowledging that a complaint arrived is fast and almost always achievable. Investigating it is not. Two different numbers describe reality better than one.
  2. Size the number to your slowest realistic week. Vacation, a departure, a busy season. The timeframe has to survive the worst week, not the average one.
  3. Build in a documented extension rather than an unwritten one. A procedure that says complex matters may take longer, with the reason recorded, is more defensible than one that silently blows a deadline.
  4. Say where the patient can go next. Your notice already has to describe how to complain to you and to the Secretary.6 Repeating the escalation route in the procedure keeps staff from improvising it.
  5. Write the no-retaliation rule down where staff will see it. The prohibition binds the practice, and workforce members are the ones who might breach it without meaning to.7

What has to be documented?

Every complaint received and its disposition — including complaints you conclude have no merit.1 The disposition is the part practices tend to skip, and it is the part that shows the process functioned rather than merely existed.

Retention runs six years “from the date of its creation or the date when it last was in effect, whichever is later.”5 For a complaint record, that generally means six years from the date the matter was closed. The procedure document itself is retained on the same clock, which means an older version you have since replaced still has to be kept.

What to do next

Start by finding out whether your practice can answer three questions in writing: who receives a privacy complaint, how a patient is told that route exists, and where the record of the last complaint and its outcome is kept. Many small practices have the first, assume the second, and cannot produce the third.

Then set your two timeframes deliberately. Pick an acknowledgment window your front office can hold during a bad week, pick a resolution window that leaves room to actually investigate, and write both into the procedure with the extension path spelled out. If your practice is a licensed facility, or has agreed to administer grievances for a health plan, take that question to your counsel first — those are the situations where a state or contractual clock overrides the one you would otherwise choose.

Sources

Footnotes

  1. 45 CFR § 164.530(d) (complaints to the covered entity): (d)(1) the covered entity must provide a process for individuals to make complaints concerning its privacy policies and procedures or its compliance with them; (d)(2) it must document all complaints received, and their disposition, if any. No acknowledgment or resolution deadline appears in the standard. law.cornell.edu/cfr/text/45/164.530 2 3 4 5 6

  2. U.S. Department of Health and Human Services, Office for Civil Rights, “How to File a Health Information Privacy or Security Complaint” — a complaint must be filed within 180 days of when the complainant knew that the act or omission occurred, and OCR may extend that period for good cause. The complaint procedures themselves are at 45 CFR § 160.306. hhs.gov/hipaa/filing-a-complaint/complaint-process 2 3

  3. 45 CFR § 164.524(b)(2)(i) (access to protected health information — timely action): the covered entity must act on a request for access no later than 30 days after receipt of the request. law.cornell.edu/cfr/text/45/164.524 2

  4. Cal. Health & Safety Code § 1368(a) (Knox-Keene Health Care Service Plan Act of 1975): every plan must provide for a written acknowledgment within five calendar days of the receipt of a grievance, and § 1368(c) requires quarterly reporting of grievances pending and unresolved for 30 or more days. The duty runs to licensed health care service plans. leginfo.legislature.ca.gov — HSC 1368 2 3

  5. 45 CFR § 164.530(j)(2) (retention period): documentation required by § 164.530(j)(1) must be retained for six years from the date of its creation or the date when it last was in effect, whichever is later. law.cornell.edu/cfr/text/45/164.530 2

  6. 45 CFR § 164.520(b)(1)(vi) (notice of privacy practices — complaints): the notice must state that individuals may complain to the covered entity and to the Secretary, give a brief description of how to file a complaint with the covered entity, and state that the individual will not be retaliated against for filing one. law.cornell.edu/cfr/text/45/164.520 2 3

  7. 45 CFR § 164.530(g)(1) (refraining from intimidating or retaliatory acts), covering retaliation for the filing of a complaint under § 164.530. law.cornell.edu/cfr/text/45/164.530 2

  8. 45 CFR § 164.530(i)(1) (policies and procedures): a covered entity must implement policies and procedures designed to comply with the standards, implementation specifications, and other requirements of the Privacy Rule, reasonably designed for its size and activities. law.cornell.edu/cfr/text/45/164.530