When a patient asks for a copy of their records, HIPAA's Right of Access gives you a clear operational answer. You generally must act on the request within 30 calendar days of receiving it. You may take one 30-day extension if you notify the patient in writing, within the first 30 days, of the reason and the date you will finish. You must provide the records in the form and format the patient requested if you can readily produce it that way. And you may charge only a reasonable, cost-based fee — a narrow list of items, not your overhead. You may not require the patient to explain why they want their records, and you may not condition access on payment of an outstanding bill. Most front-office friction disappears once staff know those defaults cold.
What the Right of Access covers
Under 45 CFR § 164.524, an individual has the right to inspect and obtain a copy of protected health information about them held in a designated record set. That set is broader than most staff assume. It generally includes:
- Medical records and billing records
- Enrollment, payment, claims adjudication, and case or medical management records
- Any other records the practice uses, in whole or in part, to make decisions about the individual
- Records held by a business associate on your behalf
- Records you received from other providers, if they sit in your designated record set and you use them to make decisions about that patient
You may require requests in writing, provided you tell individuals of that requirement. What you may not do is erect barriers: no forcing an in-person pickup for records the patient asked to have mailed, no portal-only channel, no asking why.
The 30-day clock and the one extension
The clock is 30 calendar days, not 30 business days, and it starts when you receive the request — not when someone gets around to opening the release form. One 30-day extension is permitted. To take it, you must provide the individual, within the original 30 days, a written statement of the reason for the delay and the date by which you will complete the request. There is no second extension.
Identity verification is allowed and expected, but it has to be reasonable. Verification that functions as a stalling tactic — a notarized form, a mandatory in-person appearance — is itself a barrier to access.
What you can and cannot charge
The permitted fee is reasonable and cost-based, and HHS is explicit about what may go into it.
| You may include | You may not include |
|---|---|
| Labor for copying the PHI, whether paper or electronic | Costs of verifying the requester's identity |
| Supplies (paper, CD, USB drive) if the individual asked for that medium | Costs of documenting the request |
| Postage, if the individual asked for the records to be mailed | Costs of searching for and retrieving the PHI |
| Preparing an explanation or summary — but only if the individual agreed in advance to both the summary and the fee | Costs of maintaining systems, infrastructure, or data storage |
| General administrative overhead |
You must inform the individual in advance of the approximate fee. HHS guidance describes three permitted approaches to calculating it: actual allowable costs, an average-cost schedule for standard request types, or — for an electronic copy of PHI that you maintain electronically — a flat fee, which HHS guidance caps at $6.50. Fee methodology, particularly for third-party requests, has been litigated — confirm current HHS guidance and your state's fee schedule before publishing a price list.
Form, format, and electronic copies
If the individual requests a particular form and format, you must provide it that way if it is readily producible. If it is not, you must offer a readable hard copy or another format you and the individual agree on. The practical rules:
- If the PHI is maintained electronically and the patient asks for an electronic copy, you must provide it electronically. "We only release paper" is not a valid answer for records that live in your EHR.
- The patient chooses the delivery method within reason — portal, secure email, encrypted drive, mail.
- If the individual asks for their records by unencrypted email, you may send them that way, provided you have warned the individual of the risk and they still want it. The individual is entitled to accept that risk; you are not entitled to refuse access over it.
Sending records to a third party
An individual may direct you to transmit a copy of their PHI to a designated third party. Distinguish this carefully from a HIPAA authorization — the two arrive at the front desk looking similar and are governed differently.
| Right-of-access request | HIPAA authorization | |
|---|---|---|
| Who initiates | The individual | Typically a third party (attorney, insurer, employer) with the individual's signature |
| Form | Signed, written request clearly identifying the recipient and where to send it | A valid authorization meeting the Privacy Rule's content requirements |
| Timing | Subject to the Right-of-Access deadlines | Not governed by the 30-day access clock |
| Fee | Cost-based limits apply; third-party fee treatment has been litigated — check current guidance | Governed by state law and contract |
The narrow grounds for denial
Denial grounds are limited and specific. The unreviewable categories include psychotherapy notes and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding. There are also reviewable grounds — most notably where a licensed health care professional determines that access is reasonably likely to endanger the life or physical safety of the individual or another person. On a reviewable ground, the individual may have the denial reviewed by another licensed professional.
Any denial must be in writing, in plain language, state the basis, explain any review rights, and describe how to complain. Things that are not valid reasons to deny or delay:
- The patient has an unpaid balance
- The patient will not say why they want the records
- The patient asked by email instead of on your form
- The records are voluminous
A front-desk workflow that holds up
- One intake point. A single monitored email address and a single form — and a rule that requests arriving any other way still count and still start the clock.
- Date-stamp on receipt. The clock starts here. Put the due date on the record immediately.
- Verify identity reasonably. Photo ID, or date of birth plus address, or an authenticated portal session.
- Log it. Requester, date received, scope, format requested, delivery method, due date, and the staff member who owns it.
- Scope broad requests with the patient — but never let scoping become a stall.
- Quote the fee in advance, in writing.
- Deliver in the requested format and document what was sent, to whom, when, and how.
- If you need the extension, send the written notice inside the first 30 days. An extension you forgot to notice is just a violation.
- Review the open-requests log weekly. Nothing should age past its due date without someone knowing.
Don't forget information blocking
A second set of federal rules, under the 21st Century Cures Act, prohibits information blocking — practices likely to interfere with the access, exchange, or use of electronic health information — unless a defined exception applies. In practical terms, sitting on an electronic records request, or making patients clear unnecessary hurdles to get their EHI, can create exposure under two regimes at once. Read the information blocking exceptions alongside the Privacy Rule, not after it.
Common questions
How long do we have to respond to a patient's records request?
You generally must act on the request within 30 calendar days of receiving it. One 30-day extension is allowed if you give the individual written notice of the reason and the completion date within that first 30 days. State law may require faster.
Can we refuse to release records because the patient owes us money?
No. An outstanding balance is not a permitted ground for denying an individual's Right of Access under HIPAA.
What can we charge for a copy of records?
Only a reasonable, cost-based fee: labor for copying, supplies if the patient requested a specific medium, postage if mailed, and preparing a summary if the patient agreed to it in advance. You may not charge for searching, retrieving, verifying, documenting, system maintenance, or overhead.
Do we have to email records if the patient asks us to, even unencrypted?
Yes, if the individual requests it and you have warned them of the security risk. The individual has the right to accept that risk; declining to send records at all is not a permitted response.