Eating Disorder Test Records: A Practice Workflow Guide
A parent calls your front desk on a Thursday afternoon. Their 16-year-old completed an intake questionnaire two days earlier, the results are already visible in the parent's proxy portal account, and the parent wants to know who authorized the screening. Your receptionist has about eleven seconds to decide whether to answer. That decision — not the clinical encounter — is the part that ends up in a complaint file.
This article covers the records and documentation workflow surrounding an eating disorder test encounter: what your staff captures at intake, where those artifacts live in the chart, who may request them, how fast you must respond, and which vendors touch the data along the way. It is written for practice administrators, privacy officers, and compliance leads. It contains no clinical guidance and is not a substitute for your clinicians' judgment.
What an Eating Disorder Test Encounter Actually Produces in Your Record System
Administrators tend to picture one document. In practice, a single screening encounter generates four or five distinct artifacts, and each one has a different retention, access, and release profile.
- The completed instrument itself — a scored questionnaire, either on paper, in an EHR template, or submitted through a patient-facing web form.
- The score or result value — often stored as a discrete data element, which means it flows into reporting, quality measures, and portal feeds independently of the narrative note.
- The clinician's note interpreting the encounter and documenting next steps.
- Referral correspondence — outbound faxes, direct messages, or referral-platform submissions to specialists, dietitians, or higher levels of care.
- Payer documentation — prior authorization forms, appeal letters, and attached clinical justification.
All of these sit inside your designated record set as defined at 45 CFR 164.501, which means the patient has a right of access to them. The one common exception is psychotherapy notes — a clinician's private process notes maintained separately from the rest of the chart. If your practice stores those notes in the same encounter tab as the questionnaire score, you have lost the separation the exception requires. Audit that before you rely on it.
Instrument Licensing Is a Records Problem, Not a Clinical One
Some validated screening instruments carry copyright and licensing terms that restrict reproduction, translation, or embedding in an electronic form. Before your EHR analyst builds a template, someone in your organization should confirm the license permits electronic use and permits storing completed copies. This is a contracts question that lands on the administrator's desk, not the clinician's.
Who Can Request Records From an Eating Disorder Test Encounter?
Four categories, and your release-of-information staff should be able to recite them:
- The patient. Under the HIPAA right of access, you must act within 30 calendar days of the request, with one permitted 30-day extension if you notify the individual in writing of the reason and the new date. Fees must be reasonable and cost-based.
- A personal representative. Usually a parent or guardian for a minor, or a person with legal authority for an adult. HIPAA generally defers to state law on whether a parent is the personal representative for a specific service.
- Another provider, for treatment. Permitted without authorization under the treatment disclosure provisions, though your state may impose stricter rules for behavioral health information.
- A third party the patient directs you to, in a signed, written request that identifies the recipient and where to send the copy.
Everyone else — schools, coaches, employers, attorneys, non-custodial relatives — needs a valid authorization or a specific legal exception. HHS maintains detailed guidance on the individual right of access that your ROI staff should have bookmarked, not summarized on a laminated card someone made in 2019.
The Minor Patient Question That Breaks Most Front Desks
Screening encounters for eating concerns frequently involve adolescents, and adolescent records are where HIPAA hands the decision to state law. Under 45 CFR 164.502(g), a parent is generally the personal representative of a minor child — except when the minor consented to the care themselves under state law, when a court authorized the care without parental consent, or when the parent agreed to a confidential relationship between the minor and the provider.
That means the correct answer to "can this parent see the score?" is jurisdiction-specific and sometimes service-specific. HHS's guidance on personal representatives explains the framework, but you need a written internal policy that names your state's rule for behavioral health services and adolescent consent.
Build the Rule Into the Portal, Not Into Staff Memory
The failure mode is almost never a policy gap. It is a proxy account that was created when the patient was nine and never adjusted at thirteen or fifteen, silently forwarding every discrete result to a parent's inbox. Assign one person ownership of proxy account transitions, define the age thresholds in writing, and run a quarterly report of active proxy accounts for patients above your threshold age. Reconcile it. Document that you reconciled it.
Release Timing, Information Blocking, and the Narrow Exception You Probably Cannot Use
Since the Cures Act rules took effect, providers are "actors" subject to the information blocking regulations at 45 CFR Part 171, and HHS finalized disincentives for providers found to have engaged in information blocking. Delaying release of electronic health information without a regulatory basis is a real exposure, not a theoretical one.
Two exceptions matter most here. The Preventing Harm Exception permits practices that are reasonable and necessary to reduce a risk of harm, but it requires a specific determination and cannot be applied as a blanket policy across an entire result category. The Privacy Exception covers situations where releasing the information would violate a privacy law — which is exactly the mechanism you rely on when state law restricts what a parent may see in an adolescent's behavioral health record.
Practically: your organization should document, in policy form, which categories of results release immediately, which are held under a named exception, and who makes and records the determination. The ONC information blocking resources are the authoritative starting point. "We hold all behavioral health results for 72 hours so the doctor can call first" is the kind of unwritten habit that becomes a finding.
Referral Packets: The Moment the Record Leaves Your Building
Screening encounters commonly end in referral — to a specialist, a dietitian, a therapist, or a structured program. That means records move between organizations, often within days, often by whatever method the receiving office prefers.
Set a standard referral packet so staff are not improvising under time pressure. A workable default:
- Demographics and insurance
- The completed instrument and score
- The referring clinician's note for the encounter
- Relevant problem list, medication list, and recent vitals
- A cover sheet naming the sender, the recipient, and a callback number
Apply minimum necessary to non-treatment disclosures. Treatment disclosures are exempt from the minimum necessary standard, but payer and administrative disclosures are not — and a referral packet forwarded to a utilization reviewer is not a treatment disclosure.
Log every outbound referral in a form you can search. When a patient later asks for an accounting of disclosures, or when a records request arrives from an attorney, "we faxed it somewhere in March" is not an answer.
One Note on Co-Occurring Substance Use Records
Eating disorder records are not automatically 42 CFR Part 2 records. Part 2 attaches to records from federally assisted substance use disorder programs. If your practice operates or receives records from such a program, and a patient has co-occurring conditions, Part 2's consent and redisclosure rules apply to those records and your general HIPAA authorization form will not carry them. Segregate accordingly and train ROI staff to spot the flag.
Your Vendor List Is Longer Than Your BAA Folder
Count the third parties that touch a single screening encounter. A digital intake platform. The EHR. A transcription or ambient documentation tool. A patient engagement or reminder service. A referral network. A release-of-information outsourcer. A cloud backup provider. A shredding company for the paper copies your front desk still prints.
Every one of those that creates, receives, maintains, or transmits PHI on your behalf needs a business associate agreement executed before data flows. The most common gap in practices I review is not a missing BAA with the EHR vendor — it is a missing BAA with the small screening or forms tool a clinician found useful and started using without telling anyone. Screening instruments are exactly the kind of lightweight tool that gets adopted informally.
If your inventory turns up a vendor operating without a signed agreement, close it now rather than after the next incident. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — which is faster than routing a redline through counsel for a vendor handling a few hundred intake forms a month.
Two adjacent points worth checking. First, a patient-facing app that a patient chooses independently, with no relationship to your practice, is not your business associate — but it may be subject to the FTC's Health Breach Notification Rule, and patients sometimes assume otherwise. Second, if your practice advertises or embeds analytics on pages where patients complete screening forms, tracking technologies can transmit identifiable information to third parties. That is a vendor and configuration problem you own.
Retention: How Long, and What "Delete" Actually Means
HIPAA itself requires six years for required documentation such as policies, authorizations, and BAAs. It does not set a medical record retention period — that is state law, and for minors most states run the clock from the age of majority, not the date of service. For a screening completed at 15, you may be holding the record well into the patient's twenties.
Three retention traps specific to screening workflows:
- Scanned paper. If the patient completed a paper form and staff scanned it, confirm the paper original's destruction is logged and the scan is legible at full resolution. A screening form with an illegible handwritten section is a records deficiency.
- Vendor-side copies. Your intake platform may retain submissions independently of your EHR. Your BAA should specify return or destruction at termination, and someone should verify it happened.
- Email and fax queues. Referral correspondence sitting in a shared inbox for three years is unmanaged PHI in an uninventoried location.
A Six-Item Audit You Can Run This Week
- Pull five recent screening encounters. Confirm every artifact listed above is findable in under two minutes by someone who was not in the room.
- Run the active proxy portal accounts report. Reconcile against your age threshold policy.
- List every vendor that touches intake forms. Match each to a signed, dated BAA.
- Read your release-timing policy. Confirm it names the specific information blocking exception it relies on, if any.
- Ask your ROI lead to state your state's rule on parental access to adolescent behavioral health records. If they hesitate, write it down and post it.
- Check that psychotherapy notes, if your clinicians keep them, are stored in a genuinely separate location.
None of this touches clinical judgment. All of it determines whether the encounter is defensible six months later, when the only evidence is what your systems captured.
Close the Gaps Before the Request Arrives
Records requests tied to sensitive screening encounters arrive with more urgency and more emotion than routine chart requests. The practices that handle them well are the ones that decided the rules in advance and wrote them down.
Start with the vendor gap, because it is the fastest to fix and the most common. If a tool in your intake workflow is handling PHI without a signed agreement, put a BAA in place today. If your broader documentation set — risk analysis, policies, workforce training records — has not been refreshed in the last year, automating the full compliance document set is a reasonable next step. Neither substitutes for the internal decisions above, but both remove the excuses for not making them.