A patient seen in March for back heels pain calls your front desk on a Tuesday in July and says: "I need everything you have, and send it to my attorney." You now have 30 calendar days — not 30 business days — to respond. The clock started when the request was received, not when your release-of-information queue got around to it.

This post is for the person who owns that queue. It covers what the designated record set actually includes for a multi-provider musculoskeletal episode, how to verify identity without burning days, what you may and may not charge, how third-party directives differ from patient-directed copies, and which vendors in that chain need a signed agreement before they touch the file.

Why Back Heels Pain Records Live in Four Places at Once

Heel and hindfoot complaints are a referral-heavy category. A single episode routinely produces a primary care note, a podiatry or orthopedic consult, imaging from a freestanding radiology center, a physical therapy plan of care with visit notes, and sometimes DME documentation for orthotics.

That's the only clinical fact you need for this workflow, and it's the one that makes records requests messy. The patient experiences one problem. Your systems hold four record sets across four legal entities, each with its own designated record set, its own release process, and its own 30-day obligation.

When a patient asks your practice for their back heels pain records, they usually mean the whole story. Your obligation is narrower: you owe what your practice maintains in its designated record set, including records you received from others that you used to make decisions about that patient. You do not owe records that live only at the imaging center.

Set the scope in the first phone call

Train front desk and ROI staff to ask two clarifying questions before logging the request: which date range, and does the patient want records your practice created, or also the outside reports in the chart? Documenting the answer narrows the pull and prevents a second request three weeks later.

Then tell the patient plainly which other organizations hold the rest. Give them the names. That is not a deflection — it is the fastest path to the patient getting what they want, and it prevents your practice from being blamed for gaps you never controlled.

How Long Do You Have to Fulfill a HIPAA Records Request?

Thirty calendar days from receipt of the request. You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give a specific date by which you will deliver. Only one extension is permitted.

Three qualifiers your staff should memorize:

  • State law may be shorter. Several states require production in 15 days or fewer, and the shorter deadline controls.
  • The clock does not pause while you verify identity. Verification is part of the 30 days, not a prerequisite to starting it.
  • Off-site storage is not an excuse. HHS has been explicit that records held in archives or with a storage vendor still fall under the same deadline.

HHS maintains detailed guidance on the individual right of access at hhs.gov, and it is the single document your privacy officer should print and keep in the ROI binder.

Verifying Identity on a Back Heels Pain Request Without Stalling the Clock

The rule requires reasonable verification. It also prohibits verification procedures that create unreasonable barriers or unreasonably delay the individual. Those two sentences are in tension, and most access complaints filed with OCR live in that gap.

Practical standard: match the requester to identifiers already in the chart, use a method proportionate to the delivery channel, and never require an in-person visit when a remote method would do.

The four requester types and what each needs

  1. The patient. Government ID for in-person pickup; for mail or portal delivery, matching date of birth plus two chart identifiers is generally sufficient. Do not require notarization.
  2. A personal representative. A parent of a minor, a guardian, a healthcare power of attorney, or an executor. You verify the authority document once, scan it into the chart, and note its scope and expiration.
  3. An attorney with a signed authorization. This is a disclosure under an authorization, not a right-of-access request. Different form, different fee rules, and you verify the signature against the chart.
  4. An attorney or third party named in a patient's written directive. The patient signs, names the recipient, and specifies where to send it. Verify the patient's signature, not the recipient's identity.

Number three and number four look identical at the fax machine and are governed differently. Build the distinction into your intake form as a checkbox, because your fee calculation depends on it.

Fees: What You Can Charge and What Gets Practices in Trouble

For a patient exercising the right of access, you may charge only a reasonable, cost-based fee limited to labor for copying, supplies such as media or paper, postage, and — if the patient agreed in advance — the cost of preparing a summary or explanation.

You may not charge for search and retrieval. You may not charge for the labor of reviewing the request. You may not charge a per-page rate borrowed from your state's subpoena schedule and call it compliant.

Note the wrinkle created by Ciox Health v. Azar in 2020: the flat-fee approach and the broader third-party directive provisions were narrowed by that decision. The individual's right to direct a copy to a third party now applies to electronic PHI in an EHR, and the access fee limits apply to copies going to the individual. Requests routed through an authorization signed for a law firm's benefit are a different animal, and your state's fee schedule may apply.

If your ROI vendor invoices patients directly, audit three of those invoices this quarter. Vendor billing practices are your liability, not theirs, when the patient files a complaint.

Every Hand That Touches the File Needs a Signed Agreement

Walk the path of one back heels pain record request through your practice and count the outside parties: the EHR host, the scanning service that digitized the 2019 paper chart, the release-of-information company, the secure file transfer tool, the courier or e-fax provider, and possibly an offsite storage facility.

Each of those is a business associate. Each needs a Business Associate Agreement executed before PHI moves, with breach notification timelines, subcontractor obligations, and termination-and-return provisions spelled out. A referral to the podiatrist is different — that's a treatment disclosure between covered entities and needs no BAA. The vendor moving the file does.

If your vendor list has grown faster than your contract file — and after two years of adding portal tools and transcription services, it usually has — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription, which matters when you're papering six vendors in an afternoon rather than budgeting for a platform.

The two agreements people forget

The first is the copy service used only for large-volume litigation requests, engaged twice a year and never formally contracted. The second is the answering service or after-hours triage line that takes records requests by voicemail. Both handle PHI. Both need paper.

A Worked 30-Day Timeline

Request received Tuesday, July 7. Deadline: Thursday, August 6.

  • Day 0 (Jul 7): Front desk logs the request in the access register with timestamp, requester type, scope, and delivery format. Assigns a tracking number.
  • Day 1–2: ROI coordinator verifies identity and confirms scope by phone if ambiguous. Documents the verification method used.
  • Day 3–8: Pull from EHR, plus any archived or scanned material. Flag outside reports from the imaging center and PT clinic that sit in your chart — those go out too, because you used them.
  • Day 9–12: Privacy officer reviews only for the narrow denial grounds. This is not a clinical re-read. Most requests need no review at all.
  • Day 13: Fee calculated and communicated in advance. Patient consents to the amount and the format.
  • Day 14–18: Delivery via the patient's requested method. If they asked for unencrypted email and were warned of the risk, that request is honored.
  • Day 19: Register updated with delivery date, method, and content inventory. Closed.

Notice that the schedule finishes with 18 days of slack. That slack is the point. It absorbs a staff absence, a corrupted PDF, or a second call from the patient — without you ever needing the extension letter.

Denials, Partial Fulfillment, and the Information Blocking Overlay

The grounds for denying access are narrow: psychotherapy notes, information compiled for legal proceedings, and a small set of reviewable denials tied to substantial harm. "The patient owes us money" is not a ground. "Our billing system is separate" is not a ground. "The physician who saw them left the practice" is not a ground.

When you do withhold something, you must provide the rest, give a written denial explaining the basis, and describe how the individual may seek review or file a complaint.

Layer on the information blocking rules under the Cures Act. Practices are actors under those rules, and a delay or condition on electronic health information that isn't covered by an exception can trigger a separate enforcement path. HealthIT.gov keeps the current exception framework at healthit.gov/topic/information-blocking. A records workflow that satisfies HIPAA but adds unnecessary friction to electronic access can still draw a claim.

What OCR Enforcement Tells You About Small-Practice Risk

OCR's Right of Access Initiative, running since 2019, has produced dozens of resolutions. The pattern is consistent and worth reading aloud at your next staff meeting: the entities are usually small — solo practices, small specialty groups, single-location clinics — and the failure is usually not sophisticated. A patient asked. Nothing happened. The patient complained. Records still didn't arrive. OCR opened a file.

You can review the published resolution agreements on the HHS enforcement page. Read three of them. The narrative is nearly identical each time, and none of them involve a hacker.

The operational fix is boring and effective: a single logged intake point, a named owner, a calendar reminder at day 20, and a monthly review of open requests by the privacy officer. Four controls. No software required.

Your Next Three Actions

First, pull your access register — if you don't have one, that's the finding. Count open requests older than 20 days. Second, check whether your ROI intake form distinguishes a right-of-access request from an authorization-based disclosure; if it doesn't, you are almost certainly overcharging someone. Third, reconcile the vendors that touch records against your executed agreement file.

If that third item turns up gaps, produce the missing Business Associate Agreements before your next request cycle rather than after your next complaint. And if the register itself doesn't exist, the broader risk analysis and policy document set is where that gap gets documented and closed on record.