Cervical Myelopathy Records: A Practice Workflow Guide
A spine surgeon's office faxes your practice a records request on a Tuesday afternoon. They want everything you have on a patient your physicians referred out fourteen months ago for suspected cervical myelopathy — office notes, the outside MRI report you scanned in, the physical therapy discharge summary, and the functional questionnaires your MA administered at three visits. Your release-of-information coordinator finds the office notes in the EHR, the imaging report in a scanned-document folder nobody has indexed since 2023, and the questionnaires on paper in a filing cabinet. That is a three-system scavenger hunt, and the clock is already running.
This article is for the administrator, privacy officer, or ROI lead who has to make that request repeatable instead of heroic. It covers what your staff must capture at intake, what belongs in the designated record set, how long you have to respond, which trading partners need a Business Associate Agreement, and how to handle attorney and insurer requests without over-disclosing. No clinical guidance here — the condition is context for the paperwork, not the subject.
Why Cervical Myelopathy Charts Fragment Across Organizations
The administrative reality is simple: these encounters rarely stay inside one building. A patient typically presents to primary care, gets sent for advanced imaging at an outside facility, is referred to neurology or orthopedic spine, may cycle through physical therapy, and — if surgery happens — accumulates a pre-op and post-op record at a hospital or ASC. Each hop is a disclosure event. Each disclosure event is either permitted for treatment, requires an authorization, or requires a contract.
Add a second layer: these are often longitudinal charts. Serial imaging, repeat functional assessments, and follow-up visits stretch across years. Employers ask for work-status letters. Disability carriers ask for records. Personal injury attorneys ask for everything. Your file becomes the reference copy for four other organizations, and your retention decisions determine whether comparison documents still exist when someone asks.
None of that is a clinical problem. It is a records governance problem, and it fails in predictable places.
The Designated Record Set in a Cervical Myelopathy Chart
Your staff cannot fulfill a request correctly if they cannot define the boundary of the record. Under the Privacy Rule, the designated record set (DRS) is the medical and billing records your practice uses, in whole or in part, to make decisions about the individual. That definition is functional, not physical — location and format are irrelevant.
For a spine-related encounter, the DRS routinely includes:
- Office and telehealth encounter notes, including addenda and amendments
- Outside imaging reports and CDs you received and relied on, once incorporated
- Referral letters sent and consult reports received back
- Functional and symptom questionnaires administered by your staff
- Portal messages and documented telephone encounters that informed care
- Prior authorization correspondence with the health plan, where it sits in the billing record
- Work-status and accommodation letters your clinicians signed
What Sits Outside the Boundary
Peer review files, quality assurance work product, incident reports routed to your risk function, and business planning documents are not part of the DRS. Neither is the raw audit log of your EHR. Draft notes are a gray zone — once a note is signed and used for decision-making, treat it as in scope. Write your position down in policy rather than deciding case by case at the front desk.
Imaging Is the Common Failure Point
If your practice does not perform imaging, you still hold the report, and often the disc or a link to a shared study. Decide explicitly whether your practice releases outside images, releases only the report, or redirects the requester to the originating facility. All three are defensible. What is not defensible is three different answers from three staff members in the same month.
How Long Does a Practice Have to Fulfill a Records Request?
Thirty calendar days from receipt. If you cannot meet that, you may take one extension of up to 30 additional days, but you must notify the individual in writing within the original 30 days, stating the reason and the date you will deliver. There is no second extension.
Additional rules your ROI staff should have memorized:
- Format: If the individual requests an electronic copy and you maintain it electronically, you must produce it electronically if readily producible.
- Fees: Only a reasonable, cost-based fee — labor for copying, supplies, postage, and preparing an explanation if requested. Search and retrieval time is not chargeable to the individual.
- Third-party direction: An individual may direct a copy to a third party in a signed, written request that clearly identifies the recipient and delivery destination.
- State law: Several states impose shorter deadlines or tighter fee caps. The stricter standard governs.
HHS keeps its access guidance current at the Office for Civil Rights right of access page. Print the fee section and tape it above the ROI desk.
Map Every Organization That Touches the Chart
Sit down with your ROI coordinator and list every external party that handled a single cervical myelopathy episode from referral to post-op follow-up. A typical list runs longer than administrators expect:
- Referring or receiving specialty practice
- Outside imaging center
- Physical therapy group
- Hospital or ambulatory surgery center
- Image-exchange or cloud PACS platform
- Transcription or ambient documentation vendor
- E-fax and secure messaging provider
- Release-of-information outsourcing company
- Billing company and clearinghouse
- Document scanning or offsite storage vendor
- Records-retrieval firms working for attorneys or disability carriers
Which Ones Need a BAA and Which Ones Do Not
Items 1 through 4 are covered entities receiving PHI for treatment. Provider-to-provider treatment disclosures do not require a Business Associate Agreement, and minimum necessary does not apply to treatment disclosures. Do not let a vendor talk you into a BAA where the relationship is actually a treatment exchange — it muddies your inventory.
Items 5 through 11 are business associates. They create, receive, maintain, or transmit PHI on your behalf, and each one needs an executed agreement before the first byte moves. The gaps I see most often in practice audits: the ambient documentation tool a physician adopted independently, the image-sharing portal the imaging center invited you into, and the records-retrieval firm that a plaintiff's attorney engaged and your staff started emailing. That last one is subtle — if the firm is acting as the attorney's agent, it is not your business associate, and you should be disclosing under a valid authorization rather than a contract.
If your inventory turns up a vendor operating without paper, close it before your next audit cycle. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is usually faster than routing a redline through counsel for a low-risk transcription or fax vendor. Save legal review for the platforms holding your imaging.
Intake Capture: Six Fields That Prevent Downstream Chaos
Most release problems trace back to what your front desk did not collect on day one. Add these to your intake and referral-in workflow:
- Referral source and destination, recorded as structured data, not free text in a note
- Confidential communications request — where the patient wants calls, mail, and portal notifications sent
- Personal representative status, with the supporting document scanned and its scope recorded
- Restriction requests, including the mandatory restriction for services paid out of pocket in full
- Employer or carrier involvement, flagged so staff know a work-comp or disability channel may exist
- Preferred delivery format for any future records copies
These six fields answer roughly 80 percent of the questions your ROI coordinator would otherwise chase by phone.
Attorney, Insurer, and Employer Requests
A cervical myelopathy chart draws third-party interest because the encounter often involves work capacity, imaging, and long timelines. Train staff on the three lanes:
Lane 1: Individual Right of Access, Directed to a Third Party
The patient signs, names the recipient, and the fee limitations apply. This is the lane requesters prefer because it is cheap. It is legitimate — but the request must come from the individual, not be a HIPAA authorization form filled out by a law firm with a patient signature at the bottom. Read the document, not the cover letter.
Lane 2: HIPAA Authorization
A valid authorization needs a specific description of the information, the named discloser and recipient, purpose, expiration date or event, signature and date, revocation language, and the redisclosure notice. Missing elements make it invalid — reject and explain, in writing, within your standard turnaround. Fee caps do not apply here.
Lane 3: Permitted Disclosures Without Authorization
Workers' compensation disclosures as authorized by state law, court orders, and certain subpoenas with satisfactory assurances. Apply minimum necessary rigorously in this lane and log every disclosure for accounting purposes. HHS's minimum necessary guidance is worth circulating to anyone who touches these.
Retention: Do Not Purge the Comparison Documents
HIPAA itself imposes a six-year retention requirement on compliance documentation — policies, risk analyses, BAAs, authorizations, notices — not on medical records. Medical record retention is set by state law and payer contract, and for longitudinal spine charts the practical answer is longer than the statutory minimum.
Reason: outside imaging reports you received years ago frequently become the reference point for a later request. If your scanning vendor's retention schedule quietly deletes at seven years while your state requires ten for adults, you have a gap you will discover at the worst moment. Reconcile your vendor's schedule to your policy in writing.
While you are there, confirm your risk analysis actually covers the imaging exchange platform and the scanned-document repository. NIST SP 800-66 Revision 2 is the practical implementation reference, and the enforcement record on the OCR breach portal shows how often incomplete risk analysis appears in resolution agreements.
Information Blocking and the Portal Release Timer
Since the Cures Act rules took effect, delaying release of results and notes without a permitted exception carries regulatory exposure — HHS has finalized disincentives for providers found to have engaged in information blocking. Practically, this means imaging reports and consult notes hit the patient portal on your system's configured schedule, not when a clinician gets around to calling.
Your job is not to decide the clinical communication approach. Your job is to make sure the release configuration is documented, applied consistently, matches an actual exception if you delay anything, and that front-desk staff know what a patient may have already seen before they walk in. ASTP/ONC maintains current guidance on information blocking, including the exception framework.
A Ninety-Minute Self-Audit You Can Run This Month
Pull five closed referral episodes involving spine specialty consults. For each one, answer:
- Can one person assemble the complete DRS in under 20 minutes, from a written index?
- Was every outbound disclosure logged with date, recipient, and legal basis?
- Does every non-treatment recipient in the chain have a current, executed BAA on file?
- Were access requests fulfilled inside 30 days, with extension notices in writing where used?
- Did any fee charged exceed a defensible cost-based calculation?
- Are outside imaging reports indexed and findable, or sitting in an unlabeled scan folder?
Two failures out of five is common on a first pass. Fix the index and the vendor inventory first — they resolve the largest share of downstream delay.
If the audit turns up missing agreements, build and export the BAAs you need before your next vendor onboarding, and if your policy set and risk analysis are equally stale, the full compliance document workflow covers the rest. Neither is a substitute for judgment about which vendors belong in your chain — but both remove the excuse that the paperwork was too slow to produce.