Front Office

Responding to a Patient's Request for Their Records

When a patient asks for a copy of their records, HIPAA's Right of Access gives you a clear operational answer. You generally must act on the request within 30 calendar days of receiving it. You may take one 30-day extension if you notify the patient in writing, within the first 30 days, of the reason and the date you will finish. You must provide the records in the form and format the patient requested if you can readily produce it that way. And you may charge only a reasonable, cost-based fee — a narrow list of items, not your overhead. You may not require the patient to explain why they want their records, and you may not condition access on payment of an outstanding bill. Most front-office friction disappears once staff know those defaults cold.

What the Right of Access covers

Under 45 CFR § 164.524, an individual has the right to inspect and obtain a copy of protected health information about them held in a designated record set. That set is broader than most staff assume. It generally includes:

  • Medical records and billing records
  • Enrollment, payment, claims adjudication, and case or medical management records
  • Any other records the practice uses, in whole or in part, to make decisions about the individual
  • Records held by a business associate on your behalf
  • Records you received from other providers, if they sit in your designated record set and you use them to make decisions about that patient

You may require requests in writing, provided you tell individuals of that requirement. What you may not do is erect barriers: no forcing an in-person pickup for records the patient asked to have mailed, no portal-only channel, no asking why.

The 30-day clock and the one extension

The clock is 30 calendar days, not 30 business days, and it starts when you receive the request — not when someone gets around to opening the release form. One 30-day extension is permitted. To take it, you must provide the individual, within the original 30 days, a written statement of the reason for the delay and the date by which you will complete the request. There is no second extension.

Identity verification is allowed and expected, but it has to be reasonable. Verification that functions as a stalling tactic — a notarized form, a mandatory in-person appearance — is itself a barrier to access.

State law can be stricter. Several states impose shorter turnaround times or tighter fee caps than HIPAA. Where they conflict, follow the requirement that is more protective of the individual, and build your SOP to the tighter of the two so staff only have to remember one number.

What you can and cannot charge

The permitted fee is reasonable and cost-based, and HHS is explicit about what may go into it.

You may includeYou may not include
Labor for copying the PHI, whether paper or electronicCosts of verifying the requester's identity
Supplies (paper, CD, USB drive) if the individual asked for that mediumCosts of documenting the request
Postage, if the individual asked for the records to be mailedCosts of searching for and retrieving the PHI
Preparing an explanation or summary — but only if the individual agreed in advance to both the summary and the feeCosts of maintaining systems, infrastructure, or data storage
General administrative overhead

You must inform the individual in advance of the approximate fee. HHS guidance describes three permitted approaches to calculating it: actual allowable costs, an average-cost schedule for standard request types, or — for an electronic copy of PHI that you maintain electronically — a flat fee, which HHS guidance caps at $6.50. Fee methodology, particularly for third-party requests, has been litigated — confirm current HHS guidance and your state's fee schedule before publishing a price list.

Form, format, and electronic copies

If the individual requests a particular form and format, you must provide it that way if it is readily producible. If it is not, you must offer a readable hard copy or another format you and the individual agree on. The practical rules:

  • If the PHI is maintained electronically and the patient asks for an electronic copy, you must provide it electronically. "We only release paper" is not a valid answer for records that live in your EHR.
  • The patient chooses the delivery method within reason — portal, secure email, encrypted drive, mail.
  • If the individual asks for their records by unencrypted email, you may send them that way, provided you have warned the individual of the risk and they still want it. The individual is entitled to accept that risk; you are not entitled to refuse access over it.

Sending records to a third party

An individual may direct you to transmit a copy of their PHI to a designated third party. Distinguish this carefully from a HIPAA authorization — the two arrive at the front desk looking similar and are governed differently.

Right-of-access requestHIPAA authorization
Who initiatesThe individualTypically a third party (attorney, insurer, employer) with the individual's signature
FormSigned, written request clearly identifying the recipient and where to send itA valid authorization meeting the Privacy Rule's content requirements
TimingSubject to the Right-of-Access deadlinesNot governed by the 30-day access clock
FeeCost-based limits apply; third-party fee treatment has been litigated — check current guidanceGoverned by state law and contract

The narrow grounds for denial

Denial grounds are limited and specific. The unreviewable categories include psychotherapy notes and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding. There are also reviewable grounds — most notably where a licensed health care professional determines that access is reasonably likely to endanger the life or physical safety of the individual or another person. On a reviewable ground, the individual may have the denial reviewed by another licensed professional.

Any denial must be in writing, in plain language, state the basis, explain any review rights, and describe how to complain. Things that are not valid reasons to deny or delay:

  • The patient has an unpaid balance
  • The patient will not say why they want the records
  • The patient asked by email instead of on your form
  • The records are voluminous

A front-desk workflow that holds up

  1. One intake point. A single monitored email address and a single form — and a rule that requests arriving any other way still count and still start the clock.
  2. Date-stamp on receipt. The clock starts here. Put the due date on the record immediately.
  3. Verify identity reasonably. Photo ID, or date of birth plus address, or an authenticated portal session.
  4. Log it. Requester, date received, scope, format requested, delivery method, due date, and the staff member who owns it.
  5. Scope broad requests with the patient — but never let scoping become a stall.
  6. Quote the fee in advance, in writing.
  7. Deliver in the requested format and document what was sent, to whom, when, and how.
  8. If you need the extension, send the written notice inside the first 30 days. An extension you forgot to notice is just a violation.
  9. Review the open-requests log weekly. Nothing should age past its due date without someone knowing.
Keep the packet. For each request, retain the original request, the due-date calculation, the fee notice, and proof of delivery. That bundle is exactly what you would need to produce if a complaint is ever filed — and Right-of-Access complaints are among the most common HIPAA complaints regulators act on.

Don't forget information blocking

A second set of federal rules, under the 21st Century Cures Act, prohibits information blocking — practices likely to interfere with the access, exchange, or use of electronic health information — unless a defined exception applies. In practical terms, sitting on an electronic records request, or making patients clear unnecessary hurdles to get their EHI, can create exposure under two regimes at once. Read the information blocking exceptions alongside the Privacy Rule, not after it.

On the proposed Security Rule changes: updates to the HIPAA Security Rule have been published for public comment but are not final. Nothing in a proposal changes the Privacy Rule's Right of Access, and you should not rewrite policies as though a proposed rule were law. Track it; do not act on it as settled.

Common questions

How long do we have to respond to a patient's records request?

You generally must act on the request within 30 calendar days of receiving it. One 30-day extension is allowed if you give the individual written notice of the reason and the completion date within that first 30 days. State law may require faster.

Can we refuse to release records because the patient owes us money?

No. An outstanding balance is not a permitted ground for denying an individual's Right of Access under HIPAA.

What can we charge for a copy of records?

Only a reasonable, cost-based fee: labor for copying, supplies if the patient requested a specific medium, postage if mailed, and preparing a summary if the patient agreed to it in advance. You may not charge for searching, retrieving, verifying, documenting, system maintenance, or overhead.

Do we have to email records if the patient asks us to, even unencrypted?

Yes, if the individual requests it and you have warned them of the security risk. The individual has the right to accept that risk; declining to send records at all is not a permitted response.