Dificid Records Requests: Timelines and Verification
A fax comes in Monday morning: an attorney wants "the complete record" for a patient your GI practice treated last spring for a recurrent C. difficile infection. The prescription was Dificid, filled through a specialty pharmacy after a prior authorization fight, and the treatment plan was shaped by an infectious disease consult your practice never employed. Your EHR holds maybe sixty percent of what that requester expects. This article is about the other forty percent — where it lives, who is legally on the hook to produce it, and how to close the request inside the 30-day window without accidentally disclosing something you had no right to send.
If you run records at a practice that treats these patients, this is a workflow problem, not a clinical one. Nothing below tells you anything about therapy. It tells you what to do when the request lands.
Why a Dificid Encounter Scatters Records Across Five Organizations
Dificid is a brand-name oral antibiotic dispensed through a limited pharmacy channel and, in most commercial and Medicare plans, subject to prior authorization. That single administrative fact is what fragments the chart. The clinical decision may happen in your office, but the paperwork trail immediately leaves it.
A typical episode generates records in at least five places:
- Your practice EHR — office notes, orders, lab results you ordered, patient communications.
- The hospital or urgent care that saw the patient first, if the episode started there. Discharge summary, inpatient labs, imaging.
- The infectious disease or GI consultant, if the patient was referred out. Consult notes may or may not have come back into your chart as a scanned PDF.
- The specialty pharmacy and any manufacturer-sponsored hub handling benefits investigation, copay assistance enrollment, or shipment tracking.
- Your prior authorization vendor or clearinghouse, which holds the submitted clinical justification, payer correspondence, and appeal documentation.
Your obligation under the right of access covers the designated record set you maintain — not every record that exists about the patient anywhere in the healthcare system. But "maintain" is broader than "stored in the EHR." If your prior auth vendor holds the appeal packet on your behalf, that packet is yours. If your billing service holds the claim and the denial correspondence, that is yours too.
Draw the boundary before the request arrives, not after
Write down, in one page, what your designated record set includes and which system holds each component. Include the shared drive where scanned outside consults land, the secure messaging archive, and the billing platform. Practices lose right-of-access disputes not because they refused, but because they produced the EHR export and stopped there while a scanned consult sat in a network folder nobody inventoried.
The 30-Day Clock on a Dificid Records Request: The Short Answer
Under 45 CFR 164.524, you must act on a patient's access request within 30 calendar days of receipt. "Act" means one of three things: provide the records, provide them in part with a written explanation of what was withheld, or deny in writing with the reason and the patient's review and complaint rights.
You may take one 30-day extension, but only if you notify the patient in writing within the original 30 days, state the reason for the delay, and give the date by which you will complete the request. There is no second extension. The clock starts when the request reaches your organization — not when it reaches the correct department, and not when your release-of-information vendor gets around to queueing it.
State law may be shorter. Several states require production in 15 or 21 days for certain record types. The shorter deadline controls. Check yours and put the number, not "30 days," in your policy.
HHS's right of access guidance is the authoritative reference here, and OCR has brought dozens of enforcement actions under its Right of Access Initiative since 2019 — most of them against small practices, most of them for delays measured in months, most settling in the five-figure range with a corrective action plan attached.
Verification: Confirming Identity Without Building a Wall
You must verify the identity and authority of the requester before disclosing. HIPAA does not prescribe a method. It requires that your method be reasonable and documented. That flexibility cuts both ways — you can use it to move fast, or you can misuse it to stall, and OCR treats unreasonable verification hurdles as a denial of access.
Practical rules that hold up:
- Do not require a notarized signature for a patient requesting their own record. It is not required and it functions as an access barrier.
- Do not require an in-person visit when the patient submitted the request by phone, portal, or mail.
- Do not require the patient to explain why they want the records. You may not condition access on a stated reason.
- Do verify by matching two identifiers against the chart for phone requests, or by portal authentication, or by a copy of ID for mailed requests.
- Do document the verification method in the request log with a timestamp and the staff member's name.
Personal representatives
A spouse calling about a patient's records for a Dificid episode is not automatically a personal representative. You need documentation of authority — a healthcare power of attorney, guardianship order, or executor appointment. For adult patients, a spouse's authority is not presumed. Train the front desk to route these to the privacy officer rather than making a judgment call at the window.
Third-party directives
A patient may direct you to send their records to a third party — an attorney, a new provider, a disability examiner. That direction must be in writing, signed by the patient, and must clearly name the recipient and where to send it. Verbal third-party directives do not satisfy the rule. Note the distinction: a patient-directed transmission and a third party's own subpoena or authorization-based request are different transactions with different fee rules and different timelines.
The Vendor Gap: Specialty Pharmacy, Hubs, and Prior Auth Platforms
Here is where practices get exposed. When your staff calls the specialty pharmacy or the manufacturer hub to check on a Dificid shipment, or uploads clinical notes into a prior authorization portal, PHI is moving to an outside organization. Some of those organizations are business associates of your practice. Some are not — a dispensing pharmacy is a covered entity in its own right, and a payer receiving a prior auth is a covered entity too. Neither of those relationships requires a BAA.
But the prior authorization platform, the e-fax service, the release-of-information vendor, the transcription service, the scanning contractor, and the patient communication tool that sends refill reminders — those are business associates, and each one needs a signed agreement on file before PHI moves.
Run this test on your vendor list this week: for every organization that touched a record in the last Dificid episode you processed, can you produce a signed BAA in under five minutes? If the answer is no for any of them, you have a gap that predates any breach. If you need to close it quickly, you can generate a signature-ready Business Associate Agreement through a guided six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you're papering three vendors at once rather than buying a platform.
Also confirm what the BAA says about record retrieval. If your ROI vendor holds scanned outside consults and takes eleven business days to respond to your retrieval request, your 30-day clock is already half gone. Put a turnaround obligation in the agreement.
What You Can Charge, and What You Cannot
For a patient requesting their own records, you may charge a reasonable, cost-based fee limited to labor for copying, supplies, postage, and the cost of preparing a summary if the patient agreed to one. You may not charge for search and retrieval time. You may not charge a per-page fee that exceeds actual cost, even if state law authorizes a higher schedule — the federal limit controls where it is more protective.
When a third party requests records under a HIPAA authorization rather than a patient's access request, the patient-rate fee limit does not apply, and state fee schedules generally govern. Attorneys' offices know this distinction. Train your ROI staff to classify the request correctly at intake, because misclassifying an access request as an authorization request and billing a state-schedule fee is a common and easily proven violation.
Information Blocking Sits on Top of All of This
The right of access rule is not the only obligation in play. Under the information blocking regulations, delaying or conditioning access to electronic health information can trigger a separate enforcement track. A practice that responds on day 29 to every request, every time, is technically compliant with 164.524 and still potentially exposed if the delay has no legitimate basis. ONC's information blocking resources lay out the exceptions — and "we were busy" is not one of them.
The practical implication: if the EHI is available for electronic export, send it electronically and promptly. Reserve the full 30 days for genuinely complex assemblies — the ones requiring outside consult retrieval, scanned document review, and vendor coordination.
A Worked 14-Day Timeline for a Complex Episode
Assume a request arrives for a patient whose Dificid episode involved a hospital admission, an ID consult, and a specialty pharmacy fill. Here is a timeline that closes well inside the window:
- Day 0 — Front desk date-stamps the request and enters it in the access log within four business hours. No triage decisions at the window.
- Day 1 — Privacy officer classifies: patient access request or third-party authorization? Determines fee track. Assigns verification method.
- Day 2 — Verification completed and documented. If documentation of personal representative authority is missing, written request goes out the same day, and the clock is noted as running regardless.
- Day 3 — Records coordinator pulls EHR export, checks the scanned-document folder, and issues a retrieval request to the ROI vendor and prior auth platform.
- Day 7 — Vendor materials received. Coordinator assembles the packet and flags anything that may fall outside the designated record set, such as internal quality review materials or psychotherapy notes.
- Day 9 — Privacy officer reviews the packet against the designated record set map. Confirms nothing belonging to another patient has been swept in — a leading cause of small-scale breach reports.
- Day 11 — Delivery in the requested format, by the requested method. If the patient asked for unencrypted email and was warned of the risk, document the warning and the patient's confirmation.
- Day 12 — Log closed with the delivery date, format, fee charged, and staff initials.
Two days of slack remain before an extension would even be contemplated. That slack is the entire point of the design.
Denials, Partial Denials, and the Review Right
Some material is excluded from the designated record set — psychotherapy notes maintained separately, information compiled for legal proceedings, and certain lab records subject to specific restrictions. Some denials are reviewable, meaning the patient can request review by a licensed professional who was not involved in the original decision.
Whatever you withhold, the denial must be in writing, in plain language, and must state the basis, the review rights if applicable, and how to file a complaint with your practice and with OCR. Produce everything you can and deny narrowly. Blanket denials draw scrutiny; the public OCR breach portal is a reminder that small practices are visible in the enforcement record too.
Three Things to Fix Before the Next Request Lands
First, produce a written designated record set map naming every system and folder. Second, audit your BAA file against every vendor that touched a record in your last five complex episodes. Third, add a date-stamp field and an owner field to your access log, because "we think it came in around the middle of June" is not a defense.
If your policy set, risk analysis, and vendor documentation have drifted apart, automating the risk analysis and policy document set gets the paperwork current faster than rebuilding it by hand. And if the immediate gap is an unsigned agreement with a records or prior auth vendor, build the BAA now and get it into the file before the next request forces the question.