A patient is seen on a Tuesday afternoon following a warehouse fire at their job site. The clinical encounter takes forty minutes. Over the next ninety days, your office receives four separate requests for that chart: one from a plaintiff's attorney, one from a workers' compensation carrier, one from the employer's HR department, and one from the patient's own portal login. An acute stress disorder encounter routinely generates more records traffic in a quarter than a routine follow-up generates in five years, because these visits sit at the intersection of an injury event, a payer dispute, and a legal claim.

This article is about the paperwork, not the medicine. It covers what your staff must capture at intake, how the chart should be segmented, who you may release to without an authorization, and which vendors in your stack need a signed agreement before they ever touch the file.

Why an Acute Stress Disorder Encounter Generates Three Files, Not One

These encounters typically follow a discrete event with a date, a location, and often a third party who bears financial responsibility. That single fact reshapes your entire records workflow.

First, the encounter frequently involves referral to a behavioral health specialist, which means protected health information moves between organizations early and repeatedly. Second, the event is often covered by workers' compensation, auto medical payments, or liability insurance rather than the patient's group health plan, so the requester population widens. Third, patients in these circumstances are unusually likely to exercise confidential communication and restriction rights, because they do not want the encounter surfacing at home or at work.

Your operational answer is to treat the chart as three distinct components: the designated record set, any psychotherapy notes maintained separately, and the disclosure log. Staff who cannot tell you which component a document belongs in will eventually release the wrong one.

What Your Staff Must Capture at Intake

None of the following is a clinical field. Every one of them determines what you may lawfully do with the record six weeks later.

Payer and event fields

  • How the patient arrived: self-referral, emergency department referral, employer-directed, or attorney-directed. Employer-directed visits carry different disclosure expectations, and staff must not assume the employer is entitled to results.
  • Which coverage is being billed: group health plan, workers' compensation, auto med-pay, or self-pay. Workers' compensation disclosures follow 45 CFR 164.512(l) and applicable state comp law; a group health claim does not.
  • Whether a third-party event is involved: flag the chart. This is your early warning that release-of-information volume is coming.

Patient rights fields

  • Confidential communications request under 164.522(b): alternate phone, alternate mailing address, and an explicit instruction on whether voicemail is permitted. Log it in a field your front desk actually reads before dialing.
  • Restriction request under 164.522(a)(1)(vi): if the patient pays in full out of pocket for the encounter, you must honor a request not to disclose that item to their health plan. Capture the payment method and the restriction on the same screen so they cannot drift apart.
  • Personal representative status: who, under what authority, and with what documentation on file.
  • Authorization inventory: which forms were signed, which version, which date, and what expiration each carries.

The referral trail

When you refer out, log the receiving organization, the date, the transmission method, and exactly what left your office. Treatment disclosures do not require authorization under HIPAA, but several states impose stricter rules on mental health records, and a referral packet you cannot reconstruct is a request you cannot answer. Keep a copy of the packet itself, not just a note that one was sent.

Psychotherapy Notes: The One Segment With Its Own Authorization Rule

HIPAA gives psychotherapy notes special status only if you actually maintain them separately from the rest of the record. That is a configuration decision, not a clinical one, and it is the single most common place practices lose the protection they think they have.

Psychotherapy notes exclude medication prescription and monitoring, session start and stop times, modalities and frequencies, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. Those excluded elements live in the designated record set and are subject to the patient's right of access like anything else.

Disclosure of true psychotherapy notes requires a specific authorization that cannot be combined with an authorization for anything else, with narrow exceptions. HHS maintains a plain-language overview of HIPAA and mental health information sharing that your privacy officer should keep bookmarked and your front desk should never have to interpret alone.

Practical instruction for your EHR administrator: confirm there is a distinct note type or module for psychotherapy notes, confirm it is excluded from bulk chart exports and portal release, and confirm that release-of-information staff cannot select it in a standard packet build. Test this with a dummy chart before you rely on it.

Can You Release Acute Stress Disorder Records to an Employer or Insurer?

Short answer: not to an employer without a valid, signed HIPAA authorization from the patient, and not to a liability insurer without one either. Two narrow exceptions apply. Under 45 CFR 164.512(l), you may disclose to the extent necessary to comply with workers' compensation laws. Under 164.512(b)(1)(v), you may disclose to an employer in defined workplace medical surveillance or work-related injury situations, when you provide the service at the employer's request and give the individual written notice that the information will go to the employer.

Everything else — HR asking about fitness for duty, a supervisor calling about a work note, a liability adjuster requesting the full chart — requires an authorization that meets the elements in 164.508. A subpoena is not an authorization. A claim number is not an authorization. A phone call from someone who says the patient told them to call is not an authorization.

The 30-Day Clock and the Third-Party Directive

When the patient requests their own record, you have 30 calendar days to act, with one 30-day extension available if you give written notice stating the reason and the date you will complete the request. That clock runs from the date of the request, not the date it lands on the right desk. Front desk misrouting is the leading cause of missed access deadlines, and it is entirely a workflow problem.

You must provide the record in the form and format requested if it is readily producible, including electronic copies of electronic records. Fees are limited to a reasonable, cost-based amount. If the patient directs you to send the copy to a third party, that direction must be in writing, signed, and must clearly identify the recipient and the destination. HHS publishes detailed right of access guidance covering timelines, permitted fees, and format obligations.

One trap specific to these encounters: a patient-directed transmission and a third-party authorization are different instruments with different requirements. Attorneys sometimes submit the cheaper patient-directed form to obtain records they would otherwise need a full authorization for. Your release-of-information designee should be able to explain the difference on request.

Subpoenas, Court Orders, and Why the Front Desk Never Decides

An acute stress disorder encounter tied to a workplace incident or a motor vehicle collision will attract legal process. Write the routing rule down: any document bearing a case caption goes to the privacy officer unopened by clinical staff, same day.

A court order permits disclosure of exactly what the order specifies, and nothing more. A subpoena that is not accompanied by a court order requires satisfactory assurances under 164.512(e) — either documented notice to the individual with an opportunity to object, or a qualified protective order. Your policy should specify who verifies those assurances and where the verification is filed.

Separately, your policy should name the individuals authorized to evaluate any disclosure to avert a serious threat under 164.512(j). That determination belongs to a licensed clinician operating under your policy, and the workflow requirement is simply that the front desk knows to escalate rather than answer.

Every Vendor That Touches the File Needs a Signed BAA

Walk the path a single acute stress disorder chart takes through your practice and count the outside companies. A typical list: the EHR host, the transcription service, the telehealth platform used for the follow-up, the e-fax provider that transmitted the referral packet, the secure messaging tool, the interpreter service, the release-of-information copy vendor, the appointment reminder system, the cloud backup provider, and the shredding company.

Each of those is a business associate, and each needs an executed agreement on file before it handles protected health information — not after. Practices are frequently caught out by the vendors they added quickly: the interpreter line, the answering service, the referral coordination portal a specialist asked them to join.

If your vendor inventory has gaps, close them methodically. HHS publishes sample business associate agreement provisions as a baseline, and you can produce a signature-ready agreement in a few minutes using a six-step BAA generator that exports to PDF and DOCX — a one-time purchase rather than another subscription line item. Whichever route you take, the agreement should be executed and filed before the first record moves.

Retention, Amendment, and the Accounting of Disclosures

Keep the two retention clocks separate. HIPAA requires six years for documentation the Privacy Rule itself mandates — policies, authorizations, notices, and disclosure records — under 164.530(j). How long you keep the medical record is governed by state law and payer contract, and it is usually longer.

Maintain an accounting of disclosures covering six years. Treatment, payment, and operations disclosures are excluded, but the ones these encounters actually generate are not: law enforcement, judicial proceedings, public health, and workers' compensation disclosures all belong in the log. If your log is a shared spreadsheet that only one person updates, assume it is incomplete.

Amendment requests carry a 60-day deadline with one 30-day extension. Patients who dispute how an event was characterized in the chart will ask. You may deny on specified grounds, but you must respond in writing and permit a statement of disagreement to be filed with the record.

A 90-Day Worked Example

  1. Day 0: Encounter documented. Intake flags workers' compensation coverage and a confidential communications request for a mobile number only.
  2. Day 3: Referral packet transmitted to a behavioral health group. Contents copied to the chart; transmission method and recipient logged.
  3. Day 21: Plaintiff's attorney requests the full record with a signed form. Privacy officer verifies it meets 164.508 elements; one element is missing, so the request is returned with a compliant form and the date is logged.
  4. Day 34: Comp carrier requests records. Released under 164.512(l), limited to the compensable condition, logged in the accounting.
  5. Day 40: Patient submits a portal access request. Thirty-day clock starts. Psychotherapy note module confirmed excluded from the export.
  6. Day 58: Subpoena arrives without a court order. Routed to the privacy officer; satisfactory assurances requested in writing; nothing released pending documentation.
  7. Day 71: Employer HR calls asking for a return-to-work determination. Front desk declines and offers the authorization form. Call logged.

Notice how much of that sequence is clerical discipline rather than judgment. That is the point. A misdirected fax to an employer's general HR line is a reportable disclosure, and reportable disclosures land in the public OCR breach reporting portal where your referral partners can read them.

Role Assignments to Write Down This Week

Name a person, not a department, for each of these: intake flagging, referral packet logging, right-of-access intake and clock-tracking, legal process routing, accounting of disclosures maintenance, and vendor agreement inventory. Post the list. Cross-train a backup for each role, because these deadlines do not pause for vacation.

Then run one test. Pick a closed chart from an encounter with a third-party event and ask your release-of-information designee to build the packet an attorney would receive. Check whether psychotherapy notes appear, whether the restriction flag is visible, and whether the disclosure log entry was created automatically or requires someone to remember. What you find is your remediation list.

If the exercise surfaces gaps that reach beyond records handling — missing policies, an out-of-date risk analysis, an unmapped vendor list — you can generate the full compliance document set and risk analysis rather than rebuilding it from templates. Start with the vendor inventory, though: get every business associate agreement signed and filed before the next acute stress disorder encounter walks in, because that is the gap that costs the most and takes the least time to close.