Adnexal Mass Records: What Your Practice Must Retain
A patient comes in for abdominal discomfort on a Tuesday. By Friday, her chart contains an outside ultrasound report describing an adnexal mass, a lab panel, a referral packet sent to a gynecologic oncology group two counties over, and a fax cover sheet from an imaging center your practice has never contracted with. Four organizations now hold pieces of that record. Nobody at your front desk decided that would happen — the clinical pathway decided it.
This article is about the administrative side of that pathway: what your staff must capture, how long you keep it, who you can release it to, and which of those four organizations needs a signed agreement on file. No clinical guidance here. Just the records workflow that surrounds the encounter.
The Four-Organization Paper Trail an Adnexal Mass Encounter Creates
Adnexal masses are frequently found incidentally on imaging ordered for something else, and they commonly route to a specialist for evaluation. That single administrative fact — imaging first, specialist second — is why the records move fast and in multiple directions.
Map the typical flow for your own practice. Ours looks like this:
- Originating clinic — orders imaging, receives the report, generates the referral.
- Imaging center or hospital radiology — produces the report and the study itself, often through a teleradiology reading group the patient never sees.
- Reference laboratory — returns results that land in your interface, your fax queue, or both.
- Receiving specialist — requests the full prior record, not just the referral summary.
Each hop is a disclosure. Each disclosure has a permitted basis, a minimum-necessary judgment, and a place it should be logged. Staff who route these documents on autopilot are the reason breach reports say "paper/films" and "misdirected fax" more often than anyone likes to admit. The OCR breach portal is worth reading for an afternoon just to see how ordinary the failure modes are.
What Records Must a Practice Retain for an Adnexal Mass Workup?
For a records request or audit, your chart should be able to produce, at minimum:
- The order — who ordered the imaging or lab, when, and with what clinical indication documented.
- The narrative report — the radiologist's or pathologist's signed report as received, unaltered, with the source organization identifiable.
- The images or the pointer to them — if your practice does not store DICOM, document where the study lives and who to contact for it.
- The referral packet — exactly what you sent, to whom, on what date, and by what transmission method.
- Outside records received — filed into the chart with source and receipt date, not left in a scanning queue.
- Every disclosure that wasn't treatment, payment, or operations — logged for the accounting of disclosures, which patients can request going back six years.
- Signed authorizations — retained six years from creation or last effective date, per the HIPAA documentation rule.
That list is administrative, not clinical. It is also the list that determines whether you can answer a subpoena, a payer audit, or a patient's access request without a week of archaeology.
The 30-Day Clock, and the Report Your Patient Reads Before You Call
Under the HIPAA right of access, you have 30 calendar days to act on a patient's request for their record, with one 30-day extension if you notify the patient in writing of the reason and the new date. Not 30 business days. Not 30 days from when your scanning vendor gets around to it. OCR's right of access guidance remains the clearest single document on fees, formats, and third-party directives, and it has driven a long run of enforcement settlements against small practices.
Fees must be reasonable and cost-based: labor for copying, supplies, postage, and preparing an explanation if the patient requested one. Not search time. Not retrieval time. Not a per-page schedule you inherited from a prior administrator in 2011 and never revisited.
Portal Release Timing Is Not a Clinical Judgment Call
Here is where adnexal mass encounters generate the most front-desk friction. Radiology reports release to the patient portal on a schedule your system administrator configured, and the patient often reads the impression line before the ordering clinician has reviewed it.
Deliberately delaying that release to "soften" the news is where practices get into information blocking territory. The information blocking regulations restrict practices that interfere with access, exchange, or use of electronic health information, and the exceptions are narrow and specific — they are not a general permission to hold results. Review the current exception set on HealthIT.gov and document, in policy, which exception your release configuration relies on.
The right operational answer is usually a communication protocol, not a delay: a defined process for who calls, how fast, and what the after-hours coverage looks like when a significant finding posts on a Friday afternoon. That protocol belongs in writing, with a named role attached.
Release of Information: The Requests That Arrive After the Referral
Once a patient is referred out for an adnexal mass, your release-of-information volume for that chart goes up for roughly ninety days. Expect these categories, and train staff to sort them before touching the chart:
Treatment Requests From the Receiving Specialist
Permitted without authorization. But "permitted" doesn't mean "send everything." Minimum necessary technically doesn't apply to treatment disclosures — still, sending a 400-page chart when the specialist asked for imaging, labs, and the last two office notes creates search burden on their end and expands your exposure. Define a standard referral packet and let staff deviate only on a documented request.
Patient Directives to Send Records to a Third Party
A patient may direct you to transmit her record to another person or entity. Following the 2020 Ciox Health decision, the individual-rate fee limitation applies to requests where the patient obtains the copy herself; third-party directives beyond electronic health information in the EHR fall outside the narrowed access right. Practically: keep two request forms, two fee schedules, and one written policy explaining which applies. Staff should never have to reason this out at the window.
Attorney, Insurer, and Employer Requests
These need a valid authorization with all required elements — specific description of information, named recipient, expiration, signature, and a right-to-revoke statement. An authorization missing the expiration date is not a valid authorization, and your ROI clerk is the last person who will catch it before disclosure. Build a one-page validity checklist and staple it to the scanner.
Subpoenas and Court Orders
A court order signed by a judge is different from an attorney-issued subpoena. The subpoena requires satisfactory assurances that the patient was notified or a protective order was sought. Route every one of these to a single named person. In a ten-person practice, that person is usually the privacy officer, and the policy should say so by title.
The Vendor List Nobody Updates Until an Audit
Count the outside entities that touched the record in the scenario at the top of this article. Imaging center. Teleradiology reading group. Reference lab. Fax-to-email service. Scanning and document-management vendor. Transcription. Referral-management platform. Answering service that took the callback message. Maybe a patient-communication tool that sent the appointment reminder.
Some of those are covered entities exchanging PHI for treatment — no BAA required. Several are business associates, and a signed agreement is required before PHI moves. The distinction trips people up constantly: the imaging center is a covered entity providing treatment, but the fax-to-email service moving that imaging report into your inbox is a business associate handling PHI on your behalf.
Run this exercise this quarter. Pull three completed adnexal mass referrals from the last six months. For each vendor or entity that touched the chart, produce the executed BAA within five minutes. If you can't, you have a gap, and the gap is documented in the chart itself.
When you find a vendor operating without one — and you will — you need a signature-ready agreement faster than legal review typically allows. A six-step wizard that generates a signature-ready Business Associate Agreement with PDF and DOCX export closes that gap the same day, as a one-time purchase rather than another subscription line on your budget. HHS also publishes sample BAA provisions, which are a useful reference for what the required clauses actually have to say.
Retention: State Clocks Govern the Chart, HIPAA Governs the Paperwork
A distinction worth putting in your policy manual verbatim, because staff conflate the two constantly:
HIPAA requires six-year retention of required documentation — policies, authorizations, risk analyses, sanction records, BAAs. It sets no retention period for the medical record itself. That comes from state law, payer contracts, and Medicare conditions.
For an adnexal mass workup, the retention question usually surfaces around imaging. Studies performed elsewhere may live only at the originating facility, on a retention schedule your practice does not control. If your chart contains only a pointer to those images, and the facility purges at seven years while your state requires ten for the record, you have a hole you cannot fill later.
Two fixes, both administrative. First, ingest the report and any key images into your own record rather than referencing them. Second, document in your retention policy which record components you actually hold versus point to, so a future records custodian isn't guessing.
Sensitive-Health Flags: Check What Your Policy Actually Says in 2026
Gynecologic records sit near a regulatory area that shifted recently. HHS finalized special privacy protections for reproductive health care information in 2024, and a federal district court vacated most of that rule in 2025, leaving the pre-existing HIPAA framework plus state law as the operating constraint for most practices.
Do not assume your policy manual caught up. If your privacy policies still reference an attestation requirement for certain reproductive health care disclosures, or your ROI staff are using a form built for it, verify the current status with counsel and update the document set. Many state laws impose their own restrictions that survive regardless of federal changes, and where state law is more protective, it controls.
The practical instruction to your ROI team: route any request touching gynecologic, reproductive, or behavioral health records to the privacy officer before release, and log the decision. That single rule absorbs most of the regulatory volatility without requiring staff to track case law.
A Six-Item Audit You Can Run in an Afternoon
- Pull five referral encounters from the last quarter. Confirm the referral packet contents match your standard and the transmission is logged.
- Time your last ten access requests from receipt to fulfillment. Anything over 30 days needs a documented extension letter on file.
- Compare your ROI fee schedule to the cost-based standard. Remove any search or retrieval charges.
- Verify portal release settings for radiology and pathology, and identify which information blocking exception, if any, your configuration relies on.
- List every vendor that touched those five charts. Match each to an executed BAA with a current effective date.
- Confirm your accounting-of-disclosures log captured any non-TPO disclosures from those encounters.
None of that is glamorous. All of it is what an OCR data request actually asks for.
Where to Start This Week
Pick one encounter type — the adnexal mass referral is a good one, because it exercises imaging, labs, outside records, and a specialty handoff in a single chart — and trace it end to end. Every gap you find in that one pathway probably exists in a dozen others.
If the vendor audit turns up unpapered relationships, generate the Business Associate Agreements you're missing and get them signed before the next referral goes out. If the exercise reveals that your broader policy set and risk analysis haven't been touched since the last administrator, automating the full compliance document set is the faster path back to current. Fix the paperwork while the chart is still in front of you.