Medical Records, Patient Information, and the Health Information Organization Corporation
NH Medical Records Privacy Law
Health · Marketing
Declares medical information in provider records to be the patient's property, sets deadlines and fee caps for copies, and forbids providers from revealing confidential information without consent except as law requires. It adds state-law limits beyond HIPAA on using health information for marketing and fundraising, requires notice to patients of disclosures that HIPAA allows but state law forbids, and gives patients an opt-out from the state health information exchange.
- Where
- New Hampshire
- Citation
- N.H. Rev. Stat. Ann. ch. 332-I
- Status
- In force
- Last amended
- 2025-09-13
- Enforced by
- Courts, through individual civil actions (RSA 332-I:4-5); provider licensing boards
- People can sue
- Limited
- Penalties
- For marketing/fundraising violations and unauthorized disclosures under RSA 332-I:4-5, aggrieved individuals may recover special or general damages of not less than $1,000 per violation, plus costs and reasonable legal fees.
- Applies to
- Health care providers licensed or lawfully providing care in New Hampshire, and third-party vendors storing or issuing medical records for them
- Business associates of health care providers
- The state health information organization and parties exchanging data through it
What a privacy notice must say
- Give a clear and conspicuous opportunity to opt out of fundraising communications before or with them; an opt-out acts as revocation of authorization.RSA 332-I:4, II
Rights it gives people
- Individuals must be given a clear opportunity to opt out of sharing their information through the health information organization, which must keep audit logs.RSA 332-I:3, III, VI
- Where records are electronic, patients may obtain an audit-trail-based report of access by a named provider within the prior 3 years.RSA 332-I:2, I(g)
- Patients and authorized requestors are entitled to copies of medical records within 30 days (14 days at no cost when requested by the patient's provider), in electronic form where available, subject to capped fees.RSA 332-I:1, I(b)-(f)
Practices it requires
- Do not reveal confidential patient communications or information without consent unless provided by law or needed to protect the individual or the public.RSA 332-I:2, I(e)
- Do not release or use patient-identifiable medical information for sales or marketing without written authorization.RSA 332-I:1, III; 332-I:4, I
Security duties
- Do not disclose PHI for marketing or fundraising by voicemail, unattended fax or other insecure methods.RSA 332-I:4, III
Breach duties
- Promptly notify individuals in writing when their PHI is used or disclosed in a way HIPAA allows but RSA 332-I:4 does not; business associates bear the cost when they caused it.RSA 332-I:5
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: effective_date: the chapter's earliest source note is 1989, 43:2; exact effective date not shown, left null
Research reference, not legal advice.