Cybersecurity: 24/7/365

A patient asks the front desk for a copy of her medical record. She is told to put it in writing, that it will take a few weeks, and that there is a $75 charge for the file.
Three things just went wrong, and any one of them could become a complaint to the Office for Civil Rights. Records requests are the single most enforced corner of the HIPAA Privacy Rule, and the violations are almost never malicious. They are front-desk habits nobody ever corrected.
Yes, and it is broader than most staff assume. The right of access under the HIPAA Privacy Rule lets an individual inspect and obtain a copy of their protected health information held in a designated record set. It is one of the core individual rights under HIPAA — the Health Insurance Portability and Accountability Act — and OCR treats it as such.
That set covers medical and billing records, and anything else a healthcare provider or health plan uses to make decisions about the patient. It is not limited to the chart your EHR prints.
Two things follow that practices frequently get wrong. Patients do not need to explain why they want their records — asking the reason as a condition of release is improper. And no authorization form is required for patients requesting their own health records. Authorization is for disclosures to third parties; a patient exercising their own privacy rights does not need to authorize you to give them their own information.
It is also not a HIPAA violation for anyone to ask for medical records. The request is the patient exercising a right. The violation risk sits entirely on how you respond.
The duty falls on covered entities, and the category is wider than "the doctor's office."
Business associates matter here too. If you use an outside copy service, a release-of-information vendor, or a records platform, that company is a business associate handling PHI on your behalf. Your business associate agreement should say how access requests are handled and how fast — because when a vendor is slow or overcharges, the complaint is filed against your practice, not theirs. Our BAA guide covers what that agreement needs to contain.
The same applies to your EHR vendor. If exporting a full designated record set requires a support ticket and a week of turnaround, that is a problem you own under the 30-day clock.
Covered entities must act on a request within 30 calendar days. Not 30 business days, and not "when the records clerk gets to it."
"Act on" means deliver the health information, or issue a written denial on one of the narrow permitted grounds. Acknowledging the request is not acting on it.
One 30-day extension is available, but only if you notify the patient in writing within the original window, and the notice must state the reason and the date you will deliver. An extension you did not tell the patient about does not exist.
Some state law is stricter. Several states require release in 15 days or fewer, and where state law gives the patient more access or faster access, it wins. Check yours and set your internal target to the shorter one.
The practical failure is that nobody owns the clock. Requests arrive at the front desk, by fax, by portal message, and by post, and no single person is tracking the date each one landed. Assign an owner and keep a log with the request date, the due date, and the delivery date.
Fees are where covered entities most often stray, usually because they are passing along a copy service's invoice without checking it. HIPAA is specific about what may be recovered.
You may charge a reasonable, cost-based fee limited to three things: labour for copying, supplies such as paper or a USB drive, and postage if the patient asks for mail delivery.
You may not charge for:
For electronic copies of records held electronically, the cost basis is usually very small. A $75 charge for a PDF is not defensible, and "our copy vendor set the price" is not a defence — the obligation is yours.
You may also offer a flat $6.50 fee for electronic copies as an alternative to calculating actual costs. It is an option, not a cap, and many practices find it simpler than itemising.
The exclusions are narrow. Most health information a practice wants to hold back is not excludable, and covered entities carry the burden of justifying anything withheld.
Everything else in the designated record set goes, including records you consider unflattering, records with an unpaid balance attached, and health information that mentions another provider. You cannot withhold records over an unpaid bill. That one comes up constantly and it is squarely improper.
A limited right to deny exists on narrow grounds — for example where a licensed professional determines access is reasonably likely to endanger someone's life. Those denials must be in writing and carry review rights. They are rare and should involve counsel.
Patients may ask for a specific form and format, and you must provide it if the record is readily producible that way. If your system exports PDF and the patient wants PDF, that is the answer — printing it to paper because that is your habit is not.
Patients may also direct you to send a copy to a third party. That request must be in writing, signed, and identify the recipient. Note the fee difference: the low flat-fee option applies to copies going to the patient, and courts narrowed the fee limits that apply to patient-directed transmissions to third parties, so price those separately.
Patients may specify delivery by unencrypted email. If they have been warned of the risk and still prefer it, you may honour that — the same principle covered in our guide to texting patients under HIPAA.
These get conflated. They are separate rights under HIPAA with separate rules, and covered entities owe both.
The right of access gets the patient their information. An accounting of disclosures, a different provision, gets them a list of certain disclosures you made to others over the previous six years. Notably, it excludes disclosures for treatment, payment, and healthcare operations — which is most of them — so the list is usually shorter than patients expect.
Both requests have their own timelines. Do not answer one when the patient asked for the other.
OCR — the arm of Health and Human Services that runs health information privacy enforcement — launched a Right of Access Initiative and has since resolved dozens of cases, most of them small practices and most of them settled for five figures. In 2024, OCR issued 22 financial penalties and collected $9.9 million across all HIPAA enforcement, and access complaints remain a large share of what it acts on.
The pattern in those cases is depressingly consistent. A patient asks for records, waits, complains to the United States Department of Health and Human Services, and the practice still does not deliver until OCR makes contact. HIPAA penalties run from $145 to $2.19 million per violation, and the settlements attach to conduct that a same-week response would have avoided entirely.
The enforcement math is unusual here. Most HIPAA risk is contingent on a breach happening. This one is fully within your control: a patient asks, and you either deliver in time or you do not.
Write a one-page procedure and train the front desk on it, because the front desk is where requests are won or lost. HIPAA does not expect a records department; it expects covered entities of every size to deliver health information on time.
Then check what your practice actually did with the last ten requests. Auditors will, and this is exactly the ground our OCR audit preparation guide covers. If you cannot reconstruct those ten from a log, that gap is the first thing to fix.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.