Est.

HIPAA-Compliant Medical Record Request Procedures

Federal law requires specific custodians, complete authorizations, and strict timelines to succeed.

Reporter · · 8 min read
Cover illustration for “HIPAA-Compliant Medical Record Request Procedures”
Medical Records · September 23, 2026 · 8 min read · 1,858 words

A HIPAA medical record request only works if it follows the sequence the regulation actually lays out: find the right custodian, submit an authorization that meets every element the law requires, then track the clock the provider is legally bound to. If a step is skipped, the request either stalls in someone's inbox for weeks or gets denied outright on a technicality unrelated to the patient's entitlement to the records. The regulation governing all of this sits within a specific section of federal rules. Part 160 and Subparts A and E of Part 164, with the patient access right specifically at 45 CFR § 164.524. Everyone bound by it, providers, health plans, and their business associates, answers to the same rules regardless of size or specialty.

Identifying who holds the records before submitting any request

The first mistake most people make is assuming there's one custodian per patient. There isn't. Records live with whoever created or currently maintains them, and that's usually the provider's Health Information Management department, a centralized Release of Information team, or a vendor the practice contracts out to. Large hospital systems often split custodianship by facility, so a patient who saw a cardiologist at one campus and had imaging done at another may need to file two separate requests, not one.

Labs, imaging centers, and specialty practices each keep their own designated record set too. A designated record set, under 45 CFR 164.501, covers medical and billing records, enrollment and payment data, claims adjudication files, and any case or medical management records a health plan keeps, along with anything used to make decisions about the individual. Because PHI can live in more than one of these sets at once, a patient who gets back a thin stack of paper and assumes it's everything may simply have requested from the wrong record set, or only one of several.

Closed or retired practices complicate this further. Records don't vanish when a solo practitioner retires or a small clinic shuts its doors, they get transferred to a successor custodian or moved offsite into storage. Before submitting anything, confirm who holds the records now and where the request actually needs to go. Gather the basics in advance too: full legal name and any prior names, date of birth, contact information, the exact date ranges and record types needed, a preferred format (portal, PDF, paper, CD or USB), and a government-issued photo ID. Anyone acting as a personal representative also needs documented proof of that authority.

What makes a HIPAA authorization form legally valid

45 CFR § 164.508 sets the bar, and it's an unforgiving one. If a single required element is missing, the whole authorization is defective. Any PHI disclosed under it was released without proper permission. Not partially valid. Not valid with an asterisk. Defective.

Six elements have to be present under 45 CFR § 164.508(c)(1): a description of the information being disclosed, who's authorized to disclose it, who's authorized to receive it, the purpose of the disclosure, an expiration date or triggering event, and the patient's signature with a date. On top of that, 45 CFR § 164.508(c)(2) mandates three notice statements: that the patient can revoke the authorization in writing at any time, a statement disclosing whether the covered entity is conditioning treatment on the patient signing, and a statement that information disclosed under the authorization may be redisclosed by whoever receives it and may no longer be protected.

That last statement matters more than most patients realize. Once records leave an entity bound by federal health-privacy rules and land with, say, an attorney or an insurer that isn't itself covered, those protections don't automatically follow the data.

Submitting the request: the step-by-step sequence from form to confirmation

Diagram: The 30-Day Access Clock: How the Deadline Works. Visualizes: Show the legal timeline a covered entity must follow after receiving a HIPAA records request.

Start by confirming the request is properly made. A covered entity can require written requests, and can require its own form, but only if patients are told about that requirement in advance and the form itself doesn't create unreasonable delay.

Identity verification comes next, and the method is left to the covered entity's judgment as long as the steps taken are reasonable. In person, that usually means a photo ID reviewed on the spot. Through a portal, the authentication controls already required under the HIPAA Security Rule handle verification. By mail or fax, the form itself needs to collect enough identifying information to confirm who's asking.

From there, check the authorization against all six elements and three notice statements. If someone's requesting on the patient's behalf, proof of authority needs to be attached, and the signature needs a date next to it, not just a signature. Finally, scope the request precisely by specifying the exact treatment dates, the specific facility or provider location, and the exact record type (progress notes, imaging, labs, billing). Vague requests invite vague, incomplete responses, and multi-facility systems will need a separate request for each location involved.

Timelines the law sets for providers, and the consequences of missing them

Thirty days. That's the standard deadline for a covered entity to provide access after receiving a request, and HHS has been clear that 30 days is a ceiling, not a target. Where a provider has electronic health records and portal access already in place, there's little excuse for taking the full window.

One extension is allowed, and only one. If records are archived offsite or otherwise not readily accessible, the covered entity can extend by up to 30 more days, but it has to notify the patient in writing before the initial 30 days run out, explain the reason, and give a date by which the records will actually arrive. Silence past the deadline isn't a gray area, it's noncompliance.

The clock starts the moment the covered entity receives the request, not when someone gets around to forwarding it to the records vendor or business associate handling fulfillment. If a covered entity has directed patients to submit requests directly to a business associate, the clock starts there too, and the covered entity remains on the hook regardless of where the delay actually occurred.

What providers may and may not charge

Fees have to be reasonable and cost-based under 45 CFR § 164.524(c)(4), and the list of what's billable is narrower than most people expect. Providers can charge for the labor involved in copying and transmitting the record, with the list of permissible charges limited to specific allowable cost categories. Supplies used to fulfill the request, paper, a CD, a USB drive, are chargeable. So is postage, if mail delivery was requested. A summary or explanation of the record can be billed too, but only if the patient specifically agreed in advance to receive it and pay for it.

What can't be charged matters just as much. Per-page fees are off the table for records maintained electronically, full stop, that pricing model only applies when records exist on paper and the patient specifically wants paper copies or wants paper scanned. Fees beyond the defined allowable categories are not among the costs HIPAA permits providers to pass on to patients requesting their own records.

For electronic records, providers have three options: actual costs, an average-cost schedule, or a flat fee capped at $6.50. That $6.50 figure gets misunderstood constantly. It's not a universal cap on what any provider can charge, it's a voluntary option available only to providers who'd rather not calculate actual or average costs. A provider charging more than $6.50 isn't automatically violating anything, as long as the higher amount reflects actual or average allowable costs.

Record categories that require more than a standard HIPAA authorization

Psychotherapy notes sit in their own separate category. Defined at 45 CFR § 164.501, they're the notes a mental health professional keeps documenting or analyzing the content of a counseling session, whether individual, group, joint, or family, and they only qualify for this special status if they're physically or electronically separated from the rest of the medical record. When they are kept separate, HIPAA excludes them from the standard patient access right, and a covered entity generally can't release them without a separate, standalone written authorization under 45 CFR 164.508(a)(2). A patient who checks the box for "all mental health records" on a general authorization hasn't authorized release of these notes specifically, no matter how broad the language sounds.

Substance use disorder treatment records answer to a different rulebook altogether: 42 CFR Part 2. A standard HIPAA authorization does nothing to satisfy Part 2's consent requirements for federally assisted SUD programs. A 2024 final rule added a new wrinkle, creating "SUD counseling notes" as a category modeled directly on HIPAA's psychotherapy notes concept. Under.32(a)(1), a general medical-release authorization is explicitly insufficient to satisfy Part 2's consent-to-redisclose requirement, and these notes require their own dedicated consent distinct from broader treatment or payment authorizations. Part 2 imposes strict limits on how recipients may handle information disclosed under its framework. Practices treating SUD patients need a Part 2-specific consent now, and starting in 2026, a further separate consent specifically for SUD counseling notes.

Genetic information is more straightforward on the authorization side, a standard HIPAA authorization is sufficient. But the Genetic Information Nondiscrimination Act layers on a restriction no authorization can override: group health plans can't use genetic information for underwriting, period, regardless of what the patient consents to. HIV and AIDS records fall under state law that frequently goes further than the HIPAA floor, so the applicable state statute needs checking every time, since there's no single federal standard that covers this the way Part 2 covers SUD records.

The patient's right to amend records and providers' obligations regarding that request

Patients who believe their record contains something inaccurate or incomplete have a right under HIPAA to request an amendment, and the process is simpler than most people expect but still has teeth. The process involves submitting the request in an identifiable form and receiving a formal response from the provider within a defined timeframe, often within 60 days.

Agreement isn't required. A provider can deny the request on grounds the regulation permits, and denials do occur. But the patient retains options even after a denial, with HIPAA providing mechanisms to ensure the disagreement is associated with the record going forward.

Reviewing records carefully the moment they arrive matters because it catches errors early. Checking that date ranges match what was requested, that the right providers and facilities are represented, and that no pages are missing, is the practical trigger for catching errors early enough to do something about them.

OCR enforcement data on where the process most often breaks down

A significant and recurring source of complaints to the federal agency that enforces these rules has been failure to respond within the allowed time with the information actually requested. Not a dispute over fees, not a disagreement over authorization language, just providers missing the deadline or handing back an incomplete record. OCR's Right of Access Initiative has produced more than 50 enforcement actions, which says something about where real friction in the system lives: not in the complexity of the law itself, but in the operational failure to follow a 30-day clock that's been on the books for years.

Sources

  1. Medical Records Request Process: Step-by-Step Guide to Getting Your Health Records
  2. accountablehq.com
  3. Your HIPAA Right of Access: How to Request Your Medical Records, 30-Day Rule and Reasonable Fees
  4. 45 CFR 164.524 Explained: Your HIPAA Right of Access to Medical Records
  5. ecfr.gov
  6. accountablehq.com
  7. tavrn.ai
  8. hhs.gov
Filed underMedical Records

More in Medical Records