Call Us Today! 877-659-2467

A Patient’s Right of Access is still an issue for many Covered Entities

Patient’s Right of Access

By Suze Shaffer

February 15, 2020

Many covered entities struggle to understand what is “right of access” for individuals. Under HIPAA and the Omnibus Rule, a patient has the “right” to request a copy of their medical record in the format of their choice (if available). What this means is, a medical provider is not required to purchase special equipment or software to meet these requests. With that said, if a patient requests a CD or DVD of their medical records and you do not have a DVD drive, you would not necessarily be required to purchase one. Keep in mind, DVD drives are only about $25 and it would not be unreasonable for a practice to purchase one. Of course, the ideal situation would be to direct the patient to your EHR portal and download it themselves. However, you can’t require them to do so.

When a patient requests the right to access their PHI (protected health information), be sure to have the patient sign a written request and make note of the date. A provider has 30 days to supply the patient with this information. To extend the time, the covered entity must, within the initial 30 days, inform the individual in writing of the reasons for the delay and the date by which the covered entity will provide access. Keep in mind, only one extension is permitted per access request.

The next area of confusion is the fee limitation. Copying fees for medical records are set by individual states and typically refer to the cost of labor, printing, and delivery of paper or electronic data. The labor fee does not permit the provider to charge for the preparation of the data but labor costs could include skilled technical staff time spent to create and copy the electronic file, such as compiling, extracting, scanning and burning [PHI] to media.

The Flat Fee rate option is not cap, merely an option rather than calculating the actual cost of labor and printing. Many providers are utilizing this method since it is easier than calculating the actual costs.

On January 23, 2020, a federal court vacated the “third-party directive” within the individual right of access “insofar as it expands the HITECH Act’s third-party directive beyond requests for a copy of an electronic health record with respect to PHI (protected health information) in an electronic format.” Additionally, the fee limitation set forth at 45 C.F.R. § 164.524(c)(4) will apply only to a patient’s request for access to their own records, and does not apply to a patient’s request to transmit records to a third party.

https://www.hhs.gov/hipaa/court-order-right-of-access/index.html

If you would like to read the Memorandum Opinion from the United States  District Court in the case  Ciox Health LLC vs Alex Azar:

https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51

We hope this will help clear up any misconceptions when it comes to a patient’s right to access their medical information.

If you would like more information, contact us at 877.659.2467 or complete the contact us form.

“Simplifying HIPAA through Partnership, Education, and Support”

About Suze Shaffer

Suze Shaffer is the Owner and President of Aris Medical Solutions, a healthcare compliance company dedicated to simplifying HIPAA compliance. Through its online compliance solution, the HIPAA Keeper™, Aris Medical Solutions provides healthcare providers and business associates with the tools, documentation, training, and expert guidance needed to achieve and maintain HIPAA compliance.

Through the HIPAA Keeper™, Aris has assisted organizations nationwide with conducting risk analyses, developing risk management plans, implementing HIPAA Privacy and Security policies and procedures, and strengthening safeguards for protected health information. Aris Medical Solutions also considers applicable federal and state privacy and security requirements to help clients build a more comprehensive compliance program.

Suze is also a speaker and has presented at numerous conferences and professional events on HIPAA compliance, cybersecurity, risk management, and data breach prevention. Helping organizations understand their responsibilities and identify vulnerabilities before they result in a breach, audit, or investigation. She believes effective compliance begins with education. By helping organizations understand not only what they are required to do, but why those safeguards are important, organizations are better prepared to protect patient information and reduce their compliance risks.

At Aris Medical Solutions, the mission is simple: “Simplifying HIPAA” through education, expert guidance, and the HIPAA Keeper™, Aris Medical Solutions helps organizations turn complicated compliance requirements into a manageable, ongoing process.

The information provided reflects regulatory requirements and guidance available at the time of writing and is intended for educational purposes only. It should not be considered legal advice.

Share This HIPAA Blog

HIPAA in 2020 – How the protection of our privacy maybe changing

January 15, 2020

Cell phone use in the workplace causing distrust

March 15, 2020
©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC