Medical Records Requests and HIPAA Regulations

A request for release of medical records is one of the more common requests a health care provider receives in the ordinary course…

Read More

Jim Hook, MPH

By Jim Hook, MPH | April 21, 2025

Health professional checking a medical records request form.

A request for release of medical records is one of the more common requests a health care provider receives in the ordinary course of managing a medical provider organization or practice. Patients and/or family members request health records for a number of reasons. Patients may request their own medical records for purposes of obtaining a consultation from another health care provider. They may may make a medical records request because they are seeking legal counsel on the possibility of improper or inadequate treatment from their healthcare provider. Patients may request records of their medical treatment to support a claim for payment by a disability insurance company. 

Who owns Medical Records?

Almost half of the states in the US have laws specifying health records belong to the healthcare provider who created the record. The rest of the states do not have specific laws on ownership of these documents. The exception is New Hampshire which specifies the medical records of any provider are the property of the patient. Regardless of the ownership of the physical or digital records, the HIPAA Privacy Rule requires HIPAA covered entities to provide individuals, upon request, with access to the protected health information (PHI) about them in one or more “designated record sets” maintained by or for the covered entity. So it is well established that individuals have a right to receive a copy of the PHI/ePHI in their medical or health records.

How Does the HIPAA Privacy Rule define PHI?

Individuals have a right to access PHI in a “designated record set.” A “designated record set” is defined at 45 CFR 164.501 as a group of records maintained by or for a covered entity that comprises the:

  • Medical records and billing records about individuals maintained by or for a covered health care provider;
  • Enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or
  • Other records that are used, in whole or in part, by or for the covered entity to make decisions about individuals. This last category includes records that are used to make decisions about any individuals, whether or not the records have been used to make a decision about the particular individual requesting access.

The term “record” means any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a covered entity.

What is not included PHI under the HIPAA Privacy Rule?

Despite the definition of record above, covered providers may have other records that include PHI, but are not subject to a medical records request. For example, hospitals may have record related to peer review or quality improvement activities that include the PHI of many patients. The inclusion of PHI does make these types of records subject to release to individual patients. Medical practices may compile records with PHI, e.g., insurance payments or diagnostic categories of the patient population, used for business planning purposes.

And there are two categories of medical records that are not subject to release to patients or a personal representative:

  • Psychotherapy notes kept by mental health practitioners, documenting or analyzing the contents of a counseling session that are maintained separately from a medical record. Note the distinction about where the records are maintained. Mental health practitioners are required to document various elements of office visits or encounter notes such as diagnoses and treatment recommendations. Those types of mental health records are subject to disclosure after a medical records request. Some states have stiffer requirements for obtaining informed consent for release of mental health records. 
  • Records compiled by a health care provider in anticipation of a legal matter such as a lawsuit or administrative action by a regulatory agency.

There are several other provisions in the Privacy Rule describing how covered providers must provide access to medical information. 

  • An individual’s personal representative (generally, a person with authority under State law to make health care decisions for the individual) also has the right to access PHI about the individual in a designated record set (as well as to direct the covered entity to transmit a copy of the PHI to a designated person or entity of the individual’s choice), upon request.
  • Covered providers may require a written request for medical records using the provider’s form. But the written request form must not be so complicated so as to be a barrier to patients making the request.
  • Covered providers are expected to verify the identity of the person requesting the release of medical records. 
  • Covered providers may not impose unreasonable measures on individuals or an individual’s personal representative who makes a medical records request. A provider’s office cannot demand the records be picked up in person, or conversely, can only be mailed to the requestor, or only be requested via an online patient portal.
  • Covered entities are required to provide a paper copy of the medical records when they keep medical records on paper. An individual may request an electronic copy of paper medical records, and the covered entity is required to provide an electronic copy if it is readily reproducible. If the covered entity maintains medical records in electronic form, it is required to produce an electronic copy if it is readily reproducible. A paper copy could be released only if the individual refuses to accept any of the electronic formats readily reproducible by the covered entity.

Timeliness and Cost of Providing Access to Medical Records

A covered entity is required to provide access after receiving a medical records request within 30 days of the request. If the covered entity cannot provide access within that time frame, it must notify the requestor of the reason for the delay, and provide access within no more than 30 additional days. Only one such deferral is allowed.

A covered entity may charge a reasonable cost-based fee for providing a copy of medical records. The reasonable fee may include only the actual costs of: (1) labor for copying the PHI requested by the individual, whether in paper or electronic form; (2) supplies for creating the paper copy or electronic media (e.g., CD or USB drive) if the individual requests that the electronic copy be provided on portable media; (3) postage, when the individual requests that the copy, or the summary or explanation, be mailed; and (4) preparation of an explanation or summary of the PHI, if agreed to by the individual.

The Enlightening Case of Oregon Health & Science University

OHSU Logo

There are no statistics on the number of times a provider’s office or a hospital promptly responds to a request to release medical records. But there are statistics on investigations by the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS). Because of many, many complaints from patients or their personal representatives, OCR launched what it calls their “Right of Access” initiative in 2019, making it one of their enforcement priorities.

In March 2025, OCR imposed civil monetary penalties of $200,000 in it’s 53rd Right of Access enforcement action against Oregon Health & Science University (OHSU). This case is worthwhile reviewing because it highlights both how a covered entity can foul up a medical records request, and how the OCR proceeds when investigating a complaint by a patient.

OHSU received a written request for medical records from an Affected Party (i.e., the patient) who had a personal representative, on April 24, 2019. OHSU referred the request to its business associate, DBS, which provided some but not all of the medical records. The Affected Party sent a subsequent request for medical records in November, 2019, which was denied because the request lacked a date. The OCR determined this was an erroneous denial. A second request was also denied in November, 2019, on grounds of failure to pay the invoice for the records. This denial was also judged by the OCR to be an error on the part of OHSU.

In May 2020, the Affected Party again requested the complete medical record. OHSU provided some additional records, but again did not provide the entire medical record. At that point, the Affected Party filed a complaint with the OCR. In July 2024, after another request from the Affected Party, OHSU again erroneously denied this request. 

In September 2024, the OCR supplied “technical assistance” to OHSU. This common practice by the OCR usually consists of a letter to the noncompliant party outlining its obligations under the HIPAA Privacy Rule, and the specifics of the complaint by the Affected Party, now referred to as a Complainant. Upon sending such a letter, the OCR closes the complaint, assuming the noncompliant party knows what they must do per the regulations. 

In January 2021, the Complainant filed a second complaint with the OCR, stating the Complainant had still not received a complete copy of the medical records. OCR sent a notice of the second complaint to OHSU in August, 2021. In September, 2021, the Complainant acknowledged receipt of the complete medical records. On September 9, 2024, OCR sent a Notice of Proposed Determination in this investigation outlining the sequence of events and the method used by OCR to impose a civil monetary penalty on OHSU.

Lessons learned in the OHSU Case

This case highlights several things about the way OCR approaches complaints about a request to access an individual’s medical records.

  • OCR investigations take a long time to grind out a proposed determination. It is not uncommon for investigations that result in civil monetary penalties to take at least a few years. Covered entities will be retaining and paying for legal counsel during this time.
  • OCR almost always starts with a polite letter to the covered entity explaining the complaint they have received, quoting the regulations that the covered entity may be violating, and asking for steps the covered entity will take to prevent similar problems in the future. It is important for covered entities to both solve the problem for the initial complainant as well as prevent similar situations in the future.
  • OCR’s antennae are tuned to look for repeat complaints either by the same complainant about the same issue, or for complaints from multiple complainants about the same issue. Very often, multiple complaints move the OCR to open an investigation that includes onsite visits by OCR investigators.
  • Although the OCR may limit an investigation of a violation of the Right to Access rules, when the OCR comes to investigate one issue, it often undertakes a complete audit of a covered entity’s HIPAA Privacy and Security Rule compliance. And most covered entities are found to have additional violations besides the one triggering the investigation.
  • In this case, OCR reaffirmed its position that the covered entity remains responsible for furnishing the medical records. It cannot point to a failure by a business associate as a way of avoiding its liability.
  • Civil Monetary Penalties (CMP) can be significant. At the top end of the range, the CMP is a minimum of $50,000 for each violation due to willful neglect and uncorrected within 30 days. The cap for an entire year of identical violations is $1,500,000! In this case, part of the calculation of penalty was based on the number of days between the first communication from the OCR to the date OHSU finally released all of the medical records.

Sadly, there is no end of reasons why covered entities fail to comply with HIPAA when it comes to access to an individual’s medical records. Providers withhold records because patients haven’t paid their bills. Medical records of unemancipated minors were not released to parents. Physician offices have told patients that HIPAA prevents them from releasing their medical records to the patient!

Nowadays, there is really no excuse not to understand the HIPAA Privacy and Security Rules. Even small physician practices can have adequate HIPAA policies and procedures. And online training resources for office staff and even hospitals are readily available. And never, never ignore correspondence from the OCR!