A request for release of medical records is one of the more common requests a health care provider receives in the ordinary course of managing a medical provider organization or practice. Patients and/or family members request health records for a number of reasons. Patients may request their own medical records for purposes of obtaining a consultation from another health care provider. They may may make a medical records request because they are seeking legal counsel on the possibility of improper or inadequate treatment from their healthcare provider. Patients may request records of their medical treatment to support a claim for payment by a disability insurance company.
Table of contents
- Who owns Medical Records?
- How Does the HIPAA Privacy Rule define PHI?
- What is not included PHI under the HIPAA Privacy Rule?
- Other HIPAA Privacy Rule Requirements related to Releasing PHI in a Designated Record Set
- Timeliness and Cost of Providing Access to Medical Records
- The Enlightening Case of Oregon Health & Science University
- Lessons learned in the OHSU Case
Who owns Medical Records?
Almost half of the states in the US have laws specifying health records belong to the healthcare provider who created the record. The rest of the states do not have specific laws on ownership of these documents. The exception is New Hampshire which specifies the medical records of any provider are the property of the patient. Regardless of the ownership of the physical or digital records, the HIPAA Privacy Rule requires HIPAA covered entities to provide individuals, upon request, with access to the protected health information (PHI) about them in one or more “designated record sets” maintained by or for the covered entity. So it is well established that individuals have a right to receive a copy of the PHI/ePHI in their medical or health records.
How Does the HIPAA Privacy Rule define PHI?
Individuals have a right to access PHI in a “designated record set.” A “designated record set” is defined at 45 CFR 164.501 as a group of records maintained by or for a covered entity that comprises the:
The term “record” means any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a covered entity.
What is not included PHI under the HIPAA Privacy Rule?
Despite the definition of record above, covered providers may have other records that include PHI, but are not subject to a medical records request. For example, hospitals may have record related to peer review or quality improvement activities that include the PHI of many patients. The inclusion of PHI does make these types of records subject to release to individual patients. Medical practices may compile records with PHI, e.g., insurance payments or diagnostic categories of the patient population, used for business planning purposes.
And there are two categories of medical records that are not subject to release to patients or a personal representative:
Other HIPAA Privacy Rule Requirements related to Releasing PHI in a Designated Record Set
There are several other provisions in the Privacy Rule describing how covered providers must provide access to medical information.
Timeliness and Cost of Providing Access to Medical Records
A covered entity is required to provide access after receiving a medical records request within 30 days of the request. If the covered entity cannot provide access within that time frame, it must notify the requestor of the reason for the delay, and provide access within no more than 30 additional days. Only one such deferral is allowed.
A covered entity may charge a reasonable cost-based fee for providing a copy of medical records. The reasonable fee may include only the actual costs of: (1) labor for copying the PHI requested by the individual, whether in paper or electronic form; (2) supplies for creating the paper copy or electronic media (e.g., CD or USB drive) if the individual requests that the electronic copy be provided on portable media; (3) postage, when the individual requests that the copy, or the summary or explanation, be mailed; and (4) preparation of an explanation or summary of the PHI, if agreed to by the individual.
The Enlightening Case of Oregon Health & Science University
There are no statistics on the number of times a provider’s office or a hospital promptly responds to a request to release medical records. But there are statistics on investigations by the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS). Because of many, many complaints from patients or their personal representatives, OCR launched what it calls their “Right of Access” initiative in 2019, making it one of their enforcement priorities.
In March 2025, OCR imposed civil monetary penalties of $200,000 in it’s 53rd Right of Access enforcement action against Oregon Health & Science University (OHSU). This case is worthwhile reviewing because it highlights both how a covered entity can foul up a medical records request, and how the OCR proceeds when investigating a complaint by a patient.
OHSU received a written request for medical records from an Affected Party (i.e., the patient) who had a personal representative, on April 24, 2019. OHSU referred the request to its business associate, DBS, which provided some but not all of the medical records. The Affected Party sent a subsequent request for medical records in November, 2019, which was denied because the request lacked a date. The OCR determined this was an erroneous denial. A second request was also denied in November, 2019, on grounds of failure to pay the invoice for the records. This denial was also judged by the OCR to be an error on the part of OHSU.
In May 2020, the Affected Party again requested the complete medical record. OHSU provided some additional records, but again did not provide the entire medical record. At that point, the Affected Party filed a complaint with the OCR. In July 2024, after another request from the Affected Party, OHSU again erroneously denied this request.
In September 2024, the OCR supplied “technical assistance” to OHSU. This common practice by the OCR usually consists of a letter to the noncompliant party outlining its obligations under the HIPAA Privacy Rule, and the specifics of the complaint by the Affected Party, now referred to as a Complainant. Upon sending such a letter, the OCR closes the complaint, assuming the noncompliant party knows what they must do per the regulations.
In January 2021, the Complainant filed a second complaint with the OCR, stating the Complainant had still not received a complete copy of the medical records. OCR sent a notice of the second complaint to OHSU in August, 2021. In September, 2021, the Complainant acknowledged receipt of the complete medical records. On September 9, 2024, OCR sent a Notice of Proposed Determination in this investigation outlining the sequence of events and the method used by OCR to impose a civil monetary penalty on OHSU.
Lessons learned in the OHSU Case
This case highlights several things about the way OCR approaches complaints about a request to access an individual’s medical records.
Sadly, there is no end of reasons why covered entities fail to comply with HIPAA when it comes to access to an individual’s medical records. Providers withhold records because patients haven’t paid their bills. Medical records of unemancipated minors were not released to parents. Physician offices have told patients that HIPAA prevents them from releasing their medical records to the patient!
Nowadays, there is really no excuse not to understand the HIPAA Privacy and Security Rules. Even small physician practices can have adequate HIPAA policies and procedures. And online training resources for office staff and even hospitals are readily available. And never, never ignore correspondence from the OCR!
