Charcot Foot Disease Referrals: Records-Sharing Rules
A patient with suspected charcot foot disease shows up at your primary care office on a Monday. By Friday, your front desk has fielded a records request from a podiatry group, faxed imaging orders to a hospital-based radiology department, sent a wound care summary to a hospital outpatient clinic, and received a call from a DME supplier asking for chart notes to support an offloading device. Four organizations, one week, zero patient authorizations signed. If that last part made you uneasy, this article is for you. It maps the permitted disclosures, the vendor boundaries, and the timelines that govern a referral-heavy encounter — from the administrator's chair, not the exam room.
Why This Diagnosis Generates So Much Cross-Organization Records Traffic
The clinical context matters only insofar as it explains the paperwork. Charcot foot is a complication associated with diabetic neuropathy, and care typically involves more than one specialty: podiatry, endocrinology, orthopedics, wound care, imaging, and durable medical equipment suppliers. That is the entire clinical claim this article makes.
The administrative consequence is what you manage. Each of those handoffs is a disclosure of protected health information from your organization to another. Each one has a legal basis, a routing method, a staff member responsible for it, and a log entry — or it should. Multi-specialty conditions are where records workflows break, because the volume is high and the requests arrive from parties your front desk has never spoken to before.
Practices that handle these referrals well have written down three things: who assembles the packet, what goes in it by default, and how it leaves the building. Practices that handle them badly discover the gap during a breach investigation or a patient complaint.
Do You Need a Patient Authorization to Send Charcot Foot Disease Records to a Specialist?
No. Under the HIPAA Privacy Rule, a covered entity may disclose protected health information to another covered entity for that entity's treatment activities without patient authorization. That permission sits at 45 CFR 164.506(c)(2). A referral packet sent from your practice to a treating podiatrist, endocrinologist, imaging facility, or wound care center is a treatment disclosure and needs no signed release.
Two qualifications your staff should memorize:
- State law may be stricter, and stricter state law wins. Behavioral health, HIV status, and substance use records carry separate rules in many states, and 42 CFR Part 2 applies independently to federally assisted SUD treatment programs.
- Psychotherapy notes always require authorization, with narrow exceptions.
HHS maintains plain-language guidance on permitted uses and disclosures for treatment, payment, and health care operations. Print it. Put it in the front-desk binder. The single most common failure in referral workflow is a staff member stalling a legitimate treatment disclosure because nobody told them it was allowed.
Minimum Necessary Does Not Apply Here
The minimum necessary standard at 45 CFR 164.502(b) explicitly excludes disclosures to or requests by a health care provider for treatment. When the receiving podiatrist asks for the full relevant history rather than a two-page summary, you are permitted to send it.
That is a permission, not a mandate. Your practice can still adopt an internal default packet — recent progress notes, imaging reports, relevant labs, medication list, problem list — and expand it on request. Document the default in your policies so releases are consistent between the person who has worked the desk for nine years and the temp covering vacation week.
Building the Referral Packet: Roles, Contents, Timeline
Assign the work explicitly. "Whoever picks up the phone" is not a role assignment.
Who Does What
- Front desk or referral coordinator: verifies the requesting organization is a treating provider, confirms the fax number or direct address against a maintained contact list, logs the request.
- Clinical staff: confirms the record set is complete and correctly attributed to the right patient.
- Privacy officer: handles anything nonstandard — an attorney letter, a request that names a family member, a request from an organization that is not a provider.
A Working Timeline
- Same day: inbound referral request logged with requester name, organization, callback number, and date.
- Within one business day: requester identity verified through an independent channel — the number on your contact list, not the number printed on the incoming fax cover sheet.
- Within two business days: packet assembled and transmitted through your approved channel.
- Same day as transmission: disclosure noted in the chart. Treatment disclosures are excluded from the formal accounting of disclosures requirement, but an internal note costs nothing and answers the "did we send it?" question two months later.
Charcot foot disease referrals often arrive with urgency attached. Urgency is exactly when verification gets skipped. A two-minute callback to a known number is the cheapest control you own against a fax-based social engineering attempt.
Where the Business Associate Line Actually Falls
Referral traffic pulls in vendors, and staff routinely misclassify them. The test is not "do they touch PHI." The test is whether they create, receive, maintain, or transmit PHI on your behalf to perform a function for you.
Not Business Associates
- The podiatry group you refer to. They are a covered entity receiving PHI for their own treatment purposes.
- The hospital imaging department reading a study.
- The DME supplier billing Medicare for an offloading device — they are a covered entity acting for their own payment and treatment purposes.
- A health information exchange operating strictly as a conduit under limited circumstances — though most HIEs do maintain data and most require an agreement. Read the participation terms.
Business Associates
- Your release-of-information vendor, if you outsource records production.
- Your fax-to-email or secure messaging service.
- Transcription services.
- Any IT provider with access to the systems holding the chart.
- Document shredding and offsite storage.
HHS publishes sample business associate agreement provisions that establish the floor. If your vendor list has grown faster than your contract file — and after a year of adding referral and imaging integrations, it usually has — you can produce a signature-ready Business Associate Agreement through a six-step wizard rather than rewriting a template from 2017.
Transmission: The Part Auditors Ask About First
Permission to disclose says nothing about how you disclose. The Security Rule governs the pipe.
Fax remains legal and remains common in podiatry and DME workflows. The risk is misdirection, not interception. Controls that work: a maintained directory of verified numbers, a required confirmation page retained with the request log, and a standing rule that no number is dialed from memory or from a handwritten sticky note.
Email to an outside organization needs encryption in transit or a documented decision about the risk. Direct secure messaging through your EHR is preferable where the receiving practice supports it. Patient portals handle patient-directed transmissions, not provider-to-provider referrals.
All of this belongs in your risk analysis — which is the required Security Rule administrative safeguard at 45 CFR 164.308(a)(1)(ii)(A), and the one OCR asks for most reliably in an investigation. If yours is a spreadsheet last touched during a prior fiscal year, the fastest path forward is a tool that automates HIPAA risk analysis reports, policies, and the full compliance document set so the referral workflow you actually run is the workflow your documentation describes. For the underlying methodology, NIST's SP 800-66 Revision 2 remains the standard reference for implementing the Security Rule.
When the Patient Asks for the Chart Instead
Different rule, different clock. A patient exercising the right of access under 45 CFR 164.524 gets their records within 30 days, with one 30-day extension available if you notify them in writing of the reason and the new date.
Practical points that generate complaints when staff get them wrong:
- The patient may direct a copy to a third party, and that direction must be in writing, signed, and clearly identify the recipient.
- Fees must be reasonable and cost-based. Per-page state fee schedules are not automatically defensible under HIPAA.
- Format follows the request if the record is readily producible in that format.
- You may not require the patient to explain why they want the record.
OCR's right of access guidance is the authoritative reference, and access complaints have driven a long line of enforcement actions. Train to it annually.
Information Blocking: The Other Reason to Send the Record
Privacy compliance answers whether you may disclose. The information blocking regulations under the 21st Century Cures Act address whether you may decline. Health care providers are regulated actors, and practices that slow-walk electronic health information without fitting an exception face consequences separate from HIPAA.
Charcot foot disease care sits squarely in the exposure zone: multiple treating organizations, frequent requests, and a strong operational temptation to deprioritize outbound records when the schedule is full. The exceptions are real and usable — infeasibility, privacy, security, content and manner — but each has conditions, and "we were busy" is not among them. Start with the information blocking overview from ASTP/ONC and confirm your staff know that a request delayed indefinitely is a decision, not a pause.
Five Failure Points, With Fixes
- Fax sent to a number read off an inbound cover sheet. Fix: verify against your maintained directory before dialing. No exceptions for urgent requests.
- Records released to a DME supplier's third-party billing contractor with no verification. Fix: confirm the requesting entity's relationship to the patient's care before transmitting. Route anything ambiguous to the privacy officer.
- Staff refusing a legitimate treatment disclosure and demanding an authorization. Fix: one-page desk reference on permitted disclosures, reviewed at onboarding and annually.
- A new referral-management or scheduling vendor onboarded without a BAA. Fix: procurement checkpoint — no PHI access until the agreement is executed and filed.
- Right-of-access requests handled in the referral queue. Fix: separate intake and separate tracking. The 30-day clock does not care that the request looked like a referral.
Your Next 60 Minutes
Pull the last ten outbound referral packets your office sent. For each one, answer: what was the legal basis, who verified the recipient, what channel carried it, and where is that documented? If you cannot answer all four for at least eight of the ten, the gap is in your written workflow, not in your staff.
Then check the vendor side. Every organization on your referral and records path either has a signed BAA on file or a documented reason it does not need one. Build the risk analysis and policy set that ties those decisions together — generate your current risk analysis and policy documentation here — and the next time a records request arrives on a Friday afternoon, your team will already know exactly what to do with it.