It's Tuesday. A patient at your family doctor practice needs a cardiology referral. Your front desk hands her a records release form, tells her it takes five to seven business days, and schedules the specialist visit three weeks out. The cardiologist's office calls twice for the ECG and the medication list. Nobody sends anything until the signed form comes back.

Every step of that is unnecessary. HIPAA has permitted provider-to-provider treatment disclosures without patient authorization since the Privacy Rule took effect, and your delay is now also an information blocking exposure. This article walks through the referral and records-sharing workflow a primary care office should actually run: what you can send, what you must segment, which vendors in the path need a Business Associate Agreement, and how to document it so an audit doesn't hurt.

What HIPAA Permits When a Family Doctor Refers a Patient Out

Short answer, for the person who is about to argue with a front-desk supervisor:

A covered health care provider may disclose protected health information to another health care provider for that provider's treatment activities without patient authorization. That is 45 CFR 164.506(c)(2). No signed release. No authorization form. The disclosure does not go in an accounting of disclosures, because treatment, payment, and health care operations disclosures are excluded from the accounting requirement under 164.528.

The minimum necessary standard does not apply to disclosures to a provider for treatment purposes. That's 164.502(b)(2)(i). You are not required to trim the chart down to the referral question.

HHS spells this out in its guidance on permitted uses and disclosures for treatment and care coordination. If your policy manual still says "obtain written authorization prior to releasing records to a referred provider," that policy is wrong and it is costing your practice referral turnaround time.

Two things that are still true

You may require reasonable verification of the requester's identity and authority under 164.514(h). A fax that says "send everything on this patient" from a number nobody recognizes is not verified. A referral confirmation from a practice already in your directory, or a query through a network you've onboarded, is.

You may also apply a stricter internal standard than HIPAA requires. Many practices choose to send a focused packet rather than a 400-page chart, for practical reasons — the specialist won't read 400 pages, and every extra page is extra exposure if the fax misroutes. That's a business decision, not a legal requirement, and you should write it down as such so staff don't confuse policy with law.

The Referral Packet: What Moves, Who Assembles It, and When

Assign this explicitly. In most small practices the referral coordinator owns it; in larger ones it's split between the clinical assistant and a release-of-information (ROI) clerk. Ambiguity here is why packets sit.

A workable standard packet for an outbound referral from a family doctor office:

  • Referral reason and the ordering clinician's note for the relevant encounter
  • Active problem list and medication list
  • Allergy list
  • Relevant labs and imaging reports from a defined lookback window your practice sets in policy
  • Insurance and demographic face sheet
  • Advance directive status, if on file

Set a service level: packet assembled and transmitted within two business days of the referral order, or same day if the specialist appointment is inside 72 hours. Track exceptions. If your average is nine days, that number will show up in patient complaints long before it shows up in an audit.

Who does what

Clinical assistant: confirms the referral order, flags anything that requires segmentation (below).
Referral coordinator: assembles, verifies destination, transmits, logs.
Privacy officer: owns the policy, reviews the misdirected-transmission log monthly, retrains on repeat destinations.

The Records You Cannot Send Under the Treatment Exception

The treatment permission is broad, but it is not the whole chart in every case. Three carve-outs matter in primary care.

Psychotherapy notes

Psychotherapy notes as defined at 164.501 — the separately maintained process notes of a mental health professional — require a specific authorization even for treatment disclosures. Note the definition is narrow: it excludes medication prescription and monitoring, session start and stop times, modalities, frequency, results of clinical tests, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress. If your practice keeps behavioral health notes inside the general chart rather than separately, they generally aren't psychotherapy notes at all. Confirm how your system stores them before you build the rule.

Part 2 substance use disorder records

If any part of your organization is a federally assisted Part 2 program, 42 CFR Part 2 governs those records. The 2024 final rule aligned Part 2 more closely with HIPAA — including allowing a single patient consent for future treatment, payment, and operations disclosures — and the compliance date passed in February 2026. If you receive Part 2 records from a treatment partner, you inherit redisclosure restrictions and notice obligations. Do not let a referral coordinator make that call on the fly. Route Part 2 material to the privacy officer.

State law that is more protective

HIPAA is a floor. A number of states impose additional consent requirements for HIV status, genetic test results, reproductive health information, and minors' records. Your policy needs a state-specific appendix maintained by someone who actually reads the statute, reviewed annually. If you operate in more than one state, maintain it per state.

Vendors Sitting in the Referral Path

Walk your own referral workflow and list every party that touches the packet. In a typical primary care office that list is longer than administrators expect:

  • The EHR or practice management vendor hosting the chart
  • The cloud fax service that transmits to the specialist
  • The health information exchange or network participant you query through
  • The ROI outsourcing vendor, if you use one for bulk requests
  • The transcription service producing the referral letter
  • The scanning or document-imaging contractor digitizing paper receipts
  • The secure messaging platform your clinicians use for curbside coordination

Each of these is a business associate and each needs an executed BAA on file with a current date and a named contact. The provider you are referring to is not a business associate — that's a covered entity–to–covered entity treatment disclosure, and no BAA is required. Staff confuse these constantly.

The old "conduit exception" is narrow. It covers entities like the postal service and telecom carriers that transport data without accessing it beyond what's needed for transport. A cloud fax provider that stores images on its servers is not a conduit. If you're unsure whether a vendor qualifies, assume it doesn't and paper it. If you need one drafted today, you can generate a signature-ready Business Associate Agreement and export it for countersignature without waiting on outside counsel.

This vendor inventory is also the raw material for your Security Rule risk analysis under 164.308(a)(1)(ii)(A). If your last one predates the current referral workflow — new fax vendor, new network connection, new messaging tool — the analysis is stale. Practices that would rather not rebuild it from a blank spreadsheet can automate the risk analysis and the supporting policy set and keep it current as vendors change.

When the Patient Asks for the Records Instead

Different rule, different clock. A patient's request for their own records falls under the right of access at 164.524, not the treatment permission.

You have 30 calendar days from receipt of the request, with one 30-day extension if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount covering labor for copying, supplies, and postage — not search and retrieval, not per-page charges above actual cost, not administrative overhead. HHS maintains detailed right of access guidance, and OCR has resolved a long list of enforcement actions on this exact issue since launching its Right of Access Initiative in 2019.

Two practical points. First, if the patient asks you to send a copy directly to their new family doctor or to a specialist, honor it as a directed access request — get the direction in writing, signed, identifying the recipient and where to send it. Second, your form should not force a patient to sign an authorization when a simple access request would do. Extra paper looks like a barrier, and barriers generate complaints.

Information Blocking: The Second Reason Delay Hurts

Under the 21st Century Cures Act, health care providers are actors subject to the information blocking rules. Failing to release electronic health information when it's requested — including sitting on a referral packet because you're waiting for an unnecessary signature — is potentially an interference practice unless it fits a defined exception. The exceptions are specific and require documented reasoning: preventing harm, privacy, security, infeasibility, content and manner, licensing, fees, and health IT performance. "That's our office policy" is not one of them.

HHS finalized disincentives for providers found to have committed information blocking, applied through CMS payment programs. Review the current information blocking rules and exceptions before you write any policy that restricts data release, and keep a short written record whenever you invoke an exception — who decided, on what basis, on what date.

A Ten-Line Referral Disclosure SOP You Can Adopt This Week

  1. Treatment disclosures to another provider require no patient authorization. Do not request one.
  2. Verify the requesting or receiving practice against the referral order or a maintained directory before sending.
  3. Assemble the standard packet within two business days; same day if the appointment is inside 72 hours.
  4. Screen for psychotherapy notes, Part 2 records, and state-protected categories before transmission. Route flagged charts to the privacy officer.
  5. Transmit through an approved channel only — the network connection, the covered fax service, or direct secure messaging. No personal email, no consumer file-sharing.
  6. Confirm the destination number or endpoint against the directory record, not against a handwritten note.
  7. Log date, recipient, contents, sender, and transmission confirmation.
  8. Report any misdirected transmission to the privacy officer the same day for risk assessment under the breach notification rule.
  9. Route patient-initiated requests to the access workflow with its 30-day clock, not to the referral workflow.
  10. Privacy officer reviews the log monthly and reports exceptions to leadership quarterly.

Post it. Train to it in fifteen minutes at a staff meeting. Document the training with a sign-in sheet — that record is what you'll hand an investigator when someone asks whether your workforce was trained on the policy in effect at the time.

Next Step

Pull your current referral policy and compare it to the ten lines above. If it requires authorization for treatment disclosures, it's out of date and slowing your patients down. If your vendor inventory doesn't include your fax service and your network connection, your risk analysis is incomplete. You can build the risk analysis, policies, and full HIPAA document set for your practice and get the referral workflow documented before the next records request lands on your desk.