• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Handling Requests to Access PHI under HIPAA

November 8, 2018/in Blog, HIPAA

medical chart

HIPAA provides patients with fundamental rights to access, inspect and obtain a copy of their health information for as long as the information is maintained by the healthcare provider (covered entity) regardless of the date created, format of the PHI or where the PHI originated. Individuals also have the option of requesting a summary or explanation of the PHI requested. In responding to these requests, providers should be aware of the requirements under the HIPAA Privacy Rule.

HIPAA does not require these requests to be in a specific format. Healthcare providers may accept oral requests, require patients to submit written requests, or complete a form prepared by the provider. But the provider must make patients aware of such requirements and they cannot impose unreasonable measures that act as barriers to (or could unreasonably delay) one’s access. HHS lists the following examples as unreasonable measures:

  • If a patient asks to have a copy of their medical records mailed to their home address, the doctor may not require the patient to travel to the doctor’s office to request access and provide proof of identity.
  • A doctor may not require a patient to use a web portal for requesting access because not all patients may have access to the Internet.
  • A doctor may not require a patient to mail in a request for access because such a requirement could unreasonably delay the provider’s receipt of the request and thus, the patient’s access.

To avoid creation of any such barriers or delays, providers are encouraged to offer more than one method for patients to request access to their health information.

A patient’s right to access pertains to PHI within a designated record set which is a group of records maintained by or for a provider, including such items as:

  1. the patient’s medical and billing records,
  2. enrollment payment, claims adjudication, and case or medical management record systems kept by or for a health plan, and
  3. any other records that are used by or for the provider to make decisions about individuals. Access to PHI outside the scope of the designated record set is not permitted because such information is not used to make decisions about individuals. Examples of items that are not part of the designated record set include quality assessment records, patient safety activity records, or business planning, development, and management records that are used to make business decisions.

Once a patient request is received, the provider has 30 days to respond. According to HHS, 30 days is an outer limit and providers are expected to respond in a timely manner, well before 30 days. In the event this is not possible, and the patient is agreeable, the provider is encouraged to give access to the PHI as it becomes available. HIPAA does allow a one-time 30-day extension if the provider gives written notice within the initial 30-day period to the patient, along with the reasons for the delay and a date that access will be provided.

The provider should give access to PHI in the form and format requested by the patient, if readily producible. In this regard, providers are expected to have the capability to transmit PHI by mail and email if requested by the individual and therefore cannot require an individual to travel to the provider’s physical location in order to obtain the requested PHI.

On the other hand, if the patient’s request to access all or a portion of PHI is denied the patient has the right to have the denial reviewed by a licensed healthcare professional designated by the provider in certain circumstances.

Finally, the provider can only charge a cost-based and “reasonable” fee for providing the PHI. Fees for copies may only include cost of labor, paper or electronic supplies, postage if mailed, and if requested the time to prepare a summary or explanation of the PHI. Costs associated with verification and documentation, searching for/retrieving PHI, maintaining systems and storage cannot be passed onto the patient. For more information visit the following HHS links: Fees for Copies and Clarification of Permissive Fees.

Visit our compliance store for more information on HIPAA and other healthcare compliance products and stay tuned for our new book, HIPAA Privacy and Security.

Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2018/11/Featured-Image.jpg 500 800 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2018-11-08 12:00:222025-04-15 12:53:39Handling Requests to Access PHI under HIPAA

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only