Cervical Adenopathy Records Requests: A 30-Day Playbook
A patient your practice saw in March for cervical adenopathy emails your front desk in July: "I need my complete file sent to my new doctor, and a copy for me." That single sentence triggers two different legal pathways, a 30-day clock, and a scavenger hunt across an imaging center, a reference lab, and a specialist's office. This post is a records-and-privacy workflow — not clinical guidance — for the administrator who has to answer that email, document the response, and survive the audit if the patient later complains to OCR.
The reason this particular encounter type is messy is structural, not medical. A cervical adenopathy evaluation frequently generates an outside imaging study, a laboratory or pathology report, and a specialist referral. Three handoffs, three sets of records, three vendors — and one patient who reasonably assumes you have all of it.
What Actually Lands in Your Inbox After a Cervical Adenopathy Encounter
Before you can respond to a request, you need to know what your practice holds versus what it merely saw once. Those are different things, and the distinction drives your entire response.
For a typical workup that started in your office, the records footprint usually includes:
- Your own encounter notes, problem list entries, and orders
- An ultrasound or CT report received back from an imaging facility — plus, sometimes, the actual image files if your practice pulled them into a viewer or PACS
- Laboratory results delivered through an interface or a portal
- A pathology report, if a biopsy occurred
- A specialist consult letter returned to you as the referring provider
- Referral authorizations, prior-auth correspondence, and payer communications
- Portal messages and secure texts about scheduling or results
All of that is in your designated record set if you maintain it and use it, in whole or in part, to make decisions about the individual. Copies of outside reports you received and filed do not stop being yours because someone else created them. The originating imaging center and lab have their own separate obligations to the same patient — they are not your obligations, but the patient rarely knows that, and your response letter should say so plainly.
The 30-Day Clock That Starts the Moment the Request Arrives
Direct answer: how long do you have?
Under 45 CFR 164.524, you must act on a patient's request for access no later than 30 calendar days after you receive it — not 30 business days, and not 30 days after you finish verifying identity. You may take one 30-day extension, but only if you notify the patient in writing within the original 30 days, state the reason for the delay, and give the date you will deliver. There is no second extension. State law may impose a shorter deadline, and where it does, the shorter deadline controls.
"Act on" means provide the records, or deny in writing with the required explanation and review rights. Sending a partial set with a promise to follow up on the imaging "once the outside facility responds" is not compliance. OCR has resolved dozens of right-of-access enforcement matters since launching that initiative in 2019, and the recurring fact pattern is almost never malice — it is a request that sat in a shared inbox while staff waited on a third party.
Practical rule for your team: build an internal service level of 10 business days, not 30 calendar days. The extension exists for genuinely complex sets, not for absorbing your own routing delays.
Verification Without Turning It Into an Obstacle Course
You are required to verify the identity and authority of the requester before disclosing (45 CFR 164.514(h)), but the rule sets no specific method and OCR has been consistent that verification cannot become an unreasonable barrier. Requiring an in-person visit, a notarized signature, or a proprietary form as the only option creates risk on both ends: it delays access and it can look like obstruction.
What works in practice:
- Portal-authenticated requests — the login is your verification. Do not send the patient a paper form.
- Email or phone requests — verify with two data points already in the chart plus a callback to the number on file. Document what you verified and who verified it.
- Mailed requests — match signature and address on file; call if either is off.
Write the accepted methods into your access policy and train the front desk on all of them. The failure mode is a receptionist who knows one path and turns away everyone else.
Minors, parents, and personal representatives
Cervical adenopathy is a common reason for pediatric referral, so a meaningful share of these requests come from a parent rather than the patient. A parent is generally the personal representative of an unemancipated minor and has the same access rights the patient would have — but state law on adolescent confidentiality, and your own state's rules on records a minor consented to independently, can carve out portions of the chart. HHS maintains guidance on personal representatives that your privacy officer should have annotated with your state's overlay.
Keep a documented escalation path: any request involving a minor over the age of adolescent-consent thresholds, a guardianship order, a power of attorney, or a deceased patient goes to the privacy officer before release. Front-desk staff should never adjudicate authority.
Assembling a Record Set That Lives in Four Organizations
Imaging
The report and the images are separate assets. If your practice only received the radiologist's report, that is what you produce, and your cover letter should name the imaging facility as the source for the underlying study. If you ingested the DICOM files into a viewer, they are part of your designated record set and the patient can request them. Decide in advance how you deliver them — encrypted media, a secure link, or a transfer through your image exchange vendor — and price that method in your posted fee schedule before someone asks.
Pathology
If a biopsy was performed, the report is a record. The physical slides and blocks are specimens, retained under CLIA laboratory requirements at 42 CFR 493.1105, and they are not what a patient is entitled to under the access right. Since the 2014 CLIA amendments, laboratories also provide test reports directly to patients on request, so a patient may already hold results you have not yet filed. Your response should not assume you are the only source, and it should not withhold your copy because the lab has one too.
The consult letter you never received
If the specialist's letter never made it back to you, say so. You cannot produce a document you do not have, and inventing a delay while you chase it burns your 30 days. Note the gap in writing, tell the patient which organization holds it, and close your response on time.
Fees, Formats, and the Third-Party Directive Trap
Two requests came in the same email: send it to the new doctor, and send me a copy. Those are governed differently.
The copy to the patient is a right-of-access request. You may charge only a reasonable, cost-based fee — labor for copying, supplies, postage, and preparing an agreed summary. You may not charge for search, retrieval, or the overhead of maintaining the system. OCR's right-of-access guidance lays out the permitted calculation methods, including a flat-fee option for electronic copies of records maintained electronically. If the patient asks for a readily producible electronic format, you must provide it.
The transfer to the new physician may be a patient-directed transmission or a treatment disclosure, and after the 2020 Ciox Health v. Azar decision, the patient-rate fee cap does not extend to third-party directives the way the 2016 guidance originally described. Get your policy language current on this. A practice still applying pre-2020 assumptions is either overcharging patients or undercharging on attorney and insurer requests, and both create friction.
Watch for the disguised third-party request: a disability carrier or a law firm sends a request on the patient's letterhead-style form. That is an authorization request under 164.508, with different fee and content rules. Route it to a different queue.
Every Handoff in a Cervical Adenopathy Workup Is a Vendor Question
Count the outside parties touching one of these charts: the release-of-information service, the image exchange platform, the transcription vendor, the referral coordination tool, the fax-to-email gateway, the secure messaging provider, the courier. Each one creates, receives, maintains, or transmits PHI on your behalf. Each one needs a signed Business Associate Agreement on file, executed before the first record moves.
The audit finding that shows up most often is not a missing BAA with a major platform — it is a missing BAA with the small, obvious-in-hindsight vendor: the scanning service a staff member hired to digitize a backlog, or the answering service that takes callback numbers for result notifications. If you find a gap, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase, and close it this week rather than putting it on next quarter's list.
Pair each BAA with a one-line entry in your vendor register: what data the vendor touches, which workflow, who owns the relationship internally, and when the agreement was last reviewed. That register is the first document an investigator asks for, and it is the fastest way to answer "who has our records?" when a downstream vendor reports an incident. Breach reports involving business associates appear throughout the OCR breach portal, and the covered entity's name is on the entry too.
Information Blocking Sits on Top of All of This
HIPAA sets your floor. The Cures Act information blocking rules set a second obligation: as a healthcare provider actor, you may not engage in practices that interfere with the access, exchange, or use of electronic health information, unless an exception applies. Charging an unreasonable fee, imposing verification steps beyond what you need, or defaulting to paper when an electronic copy is readily producible can all be examined through that lens. ASTP/ONC maintains current information blocking materials, including the exceptions your policy should reference by name.
The operational translation: your records team should never have to invent a reason for delay. Either an exception applies and you document it, or you release.
A Worked Timeline for One Request
- Day 0 — Request arrives in the portal. Front desk logs it in the request register with a received-date timestamp. No triage judgment, just logging.
- Day 1 — Records coordinator verifies identity (portal-authenticated, so verification is complete) and classifies the request: patient copy plus directed transmission.
- Day 2 — Coordinator pulls encounter notes, labs, the imaging report, and the pathology report. Flags that the specialist consult letter is not on file.
- Day 4 — Fee estimate calculated and communicated in advance. Patient confirms electronic delivery.
- Day 7 — Privacy officer spot-checks the set for other-patient information and for anything requiring the review process.
- Day 9 — Records released through the secure channel. Cover letter names the imaging facility and specialist as separate sources for anything the practice does not hold.
- Day 9 — Register updated with release date, method, fee charged, and the staff member who released. Retain for six years.
Nine days, twenty-one to spare, and a documented trail. That last item — the register entry — is what converts a good outcome into a provable one.
What to Audit This Quarter
- Pull ten closed requests. Measure actual days from receipt to release, using the receipt date, not the date someone opened the message.
- Confirm your posted fee schedule matches what you actually charged on each of those ten.
- Check that every extension letter sent in the last year stated a reason and a delivery date.
- Reconcile your vendor register against accounts payable. Vendors get hired without the privacy officer hearing about it.
- Ask three front-desk staff how a patient can submit a request. If you get three different answers, fix the script before you fix anything else.
A cervical adenopathy workup is ordinary clinical traffic. The records that follow it are not — they cross organizational lines, arrive from vendors you may not have papered, and land in front of a patient with a statutory right and a 30-day expectation. Start with the vendor register and the BAAs, since those take the longest to fix; if you would rather build the broader policy set and risk analysis in one pass, automated HIPAA documentation tooling can produce the underlying compliance document set while your team works the request queue.