Carotid Endarterectomy Referrals: The Records Workflow
It's 4:10 on a Tuesday. A vascular surgery scheduler calls your front desk and says the surgeon wants the duplex ultrasound report, the last two office notes, the medication list, and the anesthesia clearance before Thursday. Your receptionist puts the caller on hold and asks the office manager whether the patient has to sign something first. That pause — repeated a few hundred times a year — is where referral workflows quietly break.
A carotid endarterectomy referral is a useful stress test for your records operation because it pulls documents from at least three organizations on a compressed timeline: a primary care or neurology practice, an imaging facility, and a hospital or ambulatory surgery center. This article is about the disclosure rules, role assignments, and transmission choices behind that packet. It is not clinical guidance, and nothing here should inform a care decision.
Do You Need Patient Authorization to Send Records for a Carotid Endarterectomy Referral?
No. Under 45 CFR 164.506, a covered entity may use and disclose protected health information for treatment, payment, and health care operations without a patient authorization. Sending office notes, imaging reports, and lab results to a vascular surgeon who will evaluate the patient is a treatment disclosure. It is permitted the moment the referral exists.
Three practical corollaries your staff should be able to recite:
- The receiving surgeon does not have to be part of your organization, your network, or your HIE.
- You may disclose to another covered entity for that entity's treatment activities, not only your own.
- Minimum necessary does not apply to treatment disclosures to a provider — but it does apply when the same records go to a payer for prior authorization.
HHS states this directly in its guidance on disclosures for treatment, payment, and health care operations. Print it. Put it in the front-desk binder. The number one cause of referral delay in small practices is not a privacy violation — it's a staff member who believes a signed release is required and holds the fax for two days chasing one.
Where an Authorization Actually Is Required
Keep the exceptions short and specific so staff don't overcorrect. You need a valid authorization when the patient asks you to send records to a non-provider third party (an attorney, a disability insurer, a family member's email), when psychotherapy notes are involved, or when the disclosure is for marketing or sale of PHI. Substance use disorder records governed by 42 CFR Part 2 carry their own consent requirements even inside a treatment referral. State law may add protections for HIV status, genetic testing, or reproductive health — and where state law is stricter, it controls.
The Records Packet a Carotid Endarterectomy Referral Actually Requires
Build the packet as a standing template in your EHR rather than assembling it by hand each time. A typical surgical evaluation packet includes:
- Referral letter or order with the referring provider's contact information and NPI.
- The most recent one or two relevant office notes.
- Vascular imaging reports — and separately, the imaging study itself if the surgeon's facility requests it.
- Current medication and allergy lists.
- Problem list and relevant history.
- Recent lab results the surgical facility routinely requests.
- Insurance and demographic face sheet.
Note the split at item three. A radiology report is a text document your EHR handles. The underlying imaging is a DICOM study that usually moves through a separate image-exchange platform, a CD burned at the imaging center, or a cloud link. Those are two different transmission paths, two different logs, and often two different vendors — which means two different places a disclosure can go wrong.
Assign the Packet to a Person, Not a Department
"Records" is not an owner. Name one release-of-information (ROI) coordinator and one backup. Give them a written SLA: outbound referral packets go within one business day of the referral order, and rush requests from a surgical scheduler go same day. Log the send in the chart with date, recipient, method, and document list. That log is what saves you eight months later when the surgeon's office claims nothing arrived.
Fax, Direct, Portal, or Encrypted Email: Pick Two and Document Them
Most practices still run four transmission methods simultaneously and govern none of them. Narrow it.
Fax remains legally permissible and operationally common. Your control is a verified number list, a cover sheet, and a confirmation page filed to the chart. Misdirected faxes are one of the most mundane and most frequent small-practice incidents — a transposed digit sends a full surgical packet to a car dealership. If your fax runs through a cloud service, that service is a business associate and needs a signed agreement.
Direct secure messaging is the cleaner path for provider-to-provider exchange and produces a machine-readable delivery record. If both organizations have Direct addresses, use them. ASTP/ONC's material on interoperability and health information exchange is the reference to hand your EHR support contact when you ask whether your instance is configured for it.
Portal-to-portal or HIE query works when the surgeon is on the same network or your regional exchange. Confirm what your HIE participation agreement actually permits — some allow treatment query but restrict bulk push.
Unencrypted email to another provider is where practices get sloppy. Encrypt it, or don't use it. The one carve-out worth knowing: a patient may request records by unencrypted email to themselves after being warned of the risk. That right belongs to the patient, not to a surgeon's scheduler who prefers Gmail.
The Return Trip: Records Coming Back After the Procedure
Referral workflows fail more often on the inbound side. The surgery happens, the operative note and discharge summary are generated at the hospital, and your practice needs them for follow-up care. Nobody owns retrieval.
Fix it with a tickler. When the ROI coordinator sends the outbound packet, they set a follow-up task dated three weeks out. If the operative report and discharge summary haven't arrived by then, the coordinator requests them — again, a permitted treatment disclosure, no authorization needed in either direction. Scan them to the correct chart section, not to a general "outside records" dump that nobody can search.
Track inbound completeness as a metric. If 30% of your surgical referrals come back without a discharge summary within 30 days, that's a care-coordination problem your medical director should see, and it's also a documentation gap that will bite you during a payer audit.
Your Vendor List Grows Every Time a Referral Crosses an Organizational Line
Walk the path of a single carotid endarterectomy referral and count the third parties touching PHI: the cloud fax provider, the image-exchange platform, the transcription service, the ROI outsourcing company if you use one, the courier that moves CDs, the release-tracking software, and the EHR vendor hosting all of it. Every one of them is a business associate.
A referring provider is not a business associate. That distinction trips people up. The surgeon receiving records for treatment is a covered entity acting in their own right — no BAA required, and asking for one signals you don't understand the rule. But the vendor that transmits the records on your behalf absolutely is.
If your BAA inventory is a folder of PDFs with no expiration tracking, start by generating clean agreements for the vendors you missed. A signature-ready Business Associate Agreement built through a guided wizard takes minutes and gives you a consistent template instead of six versions negotiated by six different people over four years.
What the Risk Analysis Has to Cover
Every one of those transmission paths belongs in your Security Rule risk analysis under 45 CFR 164.308(a)(1)(ii)(A). Not "the EHR" as a single line item — the fax gateway, the image link, the scanner that emails PDFs to the front desk, the ROI vendor's web portal. OCR's enforcement pattern for years has been consistent: the risk analysis is thin, generic, or three years stale, and the settlement language says so. The proposed Security Rule overhaul circulated for comment in early 2025 pushes even harder toward complete asset inventories and documented encryption decisions.
If you are rebuilding that documentation, automated HIPAA risk analysis and policy generation will produce the asset inventory, the risk register, and the matching policy set in a fraction of the time a consultant takes — and it keeps them versioned so next year's update isn't a from-scratch project.
Two Things Staff Get Wrong That Cost You
Sending Everything
Minimum necessary doesn't apply to provider-to-provider treatment disclosures, so a full-chart send isn't a violation. But it's still bad practice. Dumping 400 pages on a surgical scheduler buries the imaging report, wastes their time, and increases the blast radius if the transmission misfires. Send the referral packet, and send more when asked.
The rule changes the moment the destination changes. When the same records support a prior authorization request to a payer, minimum necessary applies fully. HHS's minimum necessary guidance is the standard your ROI coordinator should be trained against for payer-bound disclosures.
Logging Treatment Disclosures as Accountable Disclosures
Under 45 CFR 164.528, disclosures for treatment, payment, and operations are excluded from the patient's accounting of disclosures. You should still log the send internally for operational and audit reasons — but if a patient requests an accounting, treatment referrals don't populate it. Staff who don't know this either over-report or panic. Put the exclusion in the ROI procedure in one sentence.
The Patient's Own Request Runs on a Different Clock
A referral disclosure has no statutory deadline. A patient's request for their own records has a hard one: 30 days, with a single 30-day extension if you notify the patient in writing with a reason. Fees are limited to a reasonable, cost-based amount. Right-of-access enforcement has been OCR's most consistent small-dollar, high-volume activity — dozens of resolutions, most against small practices, most involving nothing more exotic than ignoring a request for months.
Patients preparing for surgery often want a copy of their own imaging and notes. Route those through the access process, not the referral process. Different clock, different fee rules, different documentation.
A Thirty-Day Cleanup for Your Referral Workflow
- Week 1: Name the ROI coordinator and backup in writing. Build the surgical referral packet template in the EHR.
- Week 2: Inventory every path PHI takes out of your office for a referral. Match each to a signed, current BAA. Flag the gaps.
- Week 3: Retrain the front desk on the treatment exception, the authorization exceptions, and the accounting-of-disclosures carve-out. Fifteen minutes, documented.
- Week 4: Add the inbound tickler for operative notes and discharge summaries. Pull a sample of ten referrals from the last quarter and check whether records came back.
Check your own footprint on the OCR breach portal against similar-sized practices while you're at it. The recurring entries are unencrypted devices, misdirected transmissions, and vendor incidents — all three of which live squarely inside the referral workflow you just mapped.
A carotid endarterectomy referral is one anchor. The same packet template, the same transmission controls, and the same vendor inventory carry over to every specialty handoff your practice makes. If the documentation underneath it — risk analysis, policies, BAAs — is what's actually holding you up, generate the full compliance document set and spend your time on the workflow instead of the paperwork.