A patient calls your front desk on a Tuesday and asks for "everything from my prolactin workup." That single sentence triggers a 30-day clock, a verification decision, a fee calculation, and probably a hunt through three systems. Records tied to a galactorrhea disease workup rarely live in one place: the office note is in your chart, the lab results came from a reference lab, the imaging report came from an outside center, and the consult letter came from endocrinology. This post is about the administrative machinery of that request — who does what, by when, and what gets your practice a corrective action plan if you get it wrong.

The 30-Day Clock Starts When the Request Arrives, Not When You Find the Chart

Under the HIPAA Privacy Rule, you have 30 calendar days from receipt of the request to act. Not 30 business days. Not 30 days from when the release-of-information queue gets to it.

You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give a date by which you will complete the request. One extension. Not two, and not a rolling series of "we're still working on it" phone calls.

Several states impose shorter deadlines — 15 or 21 days is common — and the shorter timeline governs. Your privacy officer should have the applicable state figure written on the intake form, not stored in someone's memory. HHS keeps the federal framework and its FAQs on the individuals' right of access guidance page, and it is worth re-reading annually with your ROI staff.

The practical failure mode is receipt logging. If the request arrives by fax on a Friday, sits in a tray, and gets stamped the following Wednesday, you have quietly burned five days and created a record that contradicts your own timeline. Date-stamp on arrival, log to a tracking sheet the same day, assign an owner.

What "The Record" Actually Includes for a Galactorrhea Disease Workup

The right of access reaches the designated record set — the medical and billing records you use to make decisions about the individual. For a patient who went through a workup involving lab draws, imaging, and a specialist referral, the designated record set usually includes more than the encounter note.

  • Office and telephone notes, including nurse triage entries
  • Lab results received from the reference laboratory and filed into the chart
  • Imaging reports received from the outside center
  • The endocrinology or OB/GYN consult letter sent back to you
  • Secure portal messages between the patient and your clinicians, if you retain them as part of the record
  • Medication lists, orders, and referral authorizations
  • Billing records and claims detail

Outside records matter here. Once the specialist's letter lands in your chart and your clinician uses it, it is part of your designated record set. "That came from another practice, request it from them" is not a valid answer.

Reports Versus Images

You hold the radiology report. The imaging center holds the DICOM study. If the patient wants the actual images, tell them plainly who holds them and how to reach that organization — and release the report you do hold, immediately, rather than holding the whole request hostage to the image question.

What You Can Leave Out

Psychotherapy notes kept separate from the chart are excluded. So is information compiled in anticipation of litigation and certain quality-assurance material that is not used to make care decisions. Everything else in the designated record set goes. If your staff are excluding items for any other reason, that is a training problem, not a legal position.

Verification That Confirms Identity Without Becoming an Obstacle

You must verify identity before releasing. You may not turn verification into a barrier. That distinction is where most access complaints originate.

Reasonable: matching name, date of birth, and address against the chart; confirming a portal-authenticated request; a callback to the phone number on file; a photo ID for in-person pickup.

Not reasonable: requiring notarization, requiring the patient to appear in person when they asked for an emailed copy, requiring your own proprietary form when the patient submitted a clear written request, or asking the patient to explain why they want the record. The reason is never your business, and asking has shown up repeatedly in enforcement narratives.

Third-Party Directives

If the patient directs the copy to someone else — an attorney, a new endocrinologist, a disability insurer — the direction must be in writing, signed, and must clearly identify the recipient and where to send it. Keep that signed direction in your access log.

Be aware that a 2020 federal court decision narrowed HHS's rules on third-party directives, including the scope of the patient-rate fee cap when records go to a third party. Your ROI policy should distinguish between a request the patient makes for themselves and one directing records elsewhere, because the fee treatment is not identical. If your policy has not been reviewed since then, review it.

How Long Do You Have to Fulfill a Galactorrhea Disease Records Request?

Thirty calendar days from receipt, with one available 30-day extension that requires written notice to the patient stating the reason and the new completion date. Shorter state deadlines override the federal one. The clock runs from the date the request arrives at your organization, regardless of which department received it, and it does not pause while you gather records from a lab, imaging center, or specialist.

Within that window you must either produce the records in the form and format requested (if readily producible), or issue a written denial that explains the basis and the patient's review and complaint rights.

Fees: Cost-Based, Documented, and Disclosed Up Front

You may charge a reasonable, cost-based fee covering labor for copying, supplies such as media or paper, postage, and — if the patient agreed in advance — preparation of an explanatory summary.

You may not charge for search and retrieval, storage, record maintenance, or general administrative overhead. A flat fee of up to $6.50 is available as a safe harbor for electronic copies of records maintained electronically, and many practices use it precisely because it eliminates arguments.

Tell the patient the fee in advance. Surprise invoices generate complaints. So does refusing to release until payment clears when the patient has already agreed to pay — build the approval step into your workflow so nothing sits.

OCR has pursued right-of-access cases steadily since launching that enforcement initiative in 2019, and the pattern is consistent: small practices, straightforward facts, a patient who waited months, and a resolution agreement with a corrective action plan attached. HHS publishes those agreements on its enforcement and resolution agreements page. Read three of them before your next staff meeting; they are short and specific.

Why Galactorrhea Disease Records Live in More Than One Vendor's System

Because this kind of workup commonly involves laboratory testing, imaging, and referral to a specialist, the record trail crosses organizational boundaries by design. That means your access workflow depends on entities you do not control — and on contracts you may or may not have current.

Walk your own map. For a typical galactorrhea disease encounter, the parties touching PHI often include:

  • Your EHR host and any cloud storage underneath it
  • A reference laboratory and its results-delivery interface
  • An outside imaging center and the archive vendor holding studies
  • A transcription or documentation service
  • Your release-of-information or copy-service vendor
  • Secure messaging, e-fax, and patient portal providers
  • The billing company handling claims for the visit and any referral

Each of those relationships needs an executed Business Associate Agreement, and the copy-service vendor is the one practices most often miss — precisely because it only shows up when a request arrives. If you find a gap during this exercise, close it before the next request lands; you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX in a single sitting, with no subscription attached.

NIST's revised guidance on implementing the HIPAA Security Rule, SP 800-66r2, is a useful companion when you are documenting how those vendor connections are secured and monitored.

A Worked Timeline, Day 0 to Day 30

Day 0. Request arrives by portal, fax, mail, or in person. Front desk date-stamps it, scans it into the access log, and routes it to the ROI owner the same day. No clinical staff involvement yet.

Day 1–2. ROI owner verifies identity against the chart, confirms the requested scope and format, and calls the patient if scope is ambiguous — "everything from my workup" may mean the full chart or may mean the last six months. Document what the patient clarified.

Day 2–3. Fee quoted in writing if any fee applies. Patient confirms format: portal download, encrypted email, USB, or paper.

Day 3–10. Assemble. Pull office notes, filed lab results, filed imaging reports, consult letters, portal messages, and billing detail. Flag anything sourced from another organization so you can tell the patient who holds the originals.

Day 10–14. Privacy officer or designee reviews the compiled set against the designated record set definition. This review checks for over-withholding as hard as it checks for over-disclosure.

Day 14–18. Release in the requested format. Log the release date, method, and recipient. If the patient asked for unencrypted email and you warned them of the risk in writing and they still want it, honor the request and keep the warning on file.

Day 25 checkpoint. Anything still open gets an extension letter drafted and sent before day 30. That checkpoint belongs on a recurring calendar item owned by a named person, not on a shared inbox.

Denials Are Narrow — and Must Be Written

Grounds for denial are limited. A few are unreviewable, such as psychotherapy notes or information compiled for legal proceedings. A few are reviewable, such as a licensed professional's determination that access is reasonably likely to endanger the life or physical safety of the individual or another person — a determination that requires a licensed clinician and triggers the patient's right to have it reviewed by another licensed professional who was not involved in the original decision.

Unpaid balances are not a ground. Refusal to state a reason is not a ground. An outstanding malpractice inquiry is not a ground.

When you deny in part, release the rest within the deadline. The written denial must be in plain language, explain the basis, describe review rights where they apply, and tell the patient how to complain to you and to OCR.

Documentation That Holds Up When OCR Asks

Your access log should capture, for every request: date received, requester, verification method, scope requested, fee quoted and collected, format delivered, date fulfilled, and the name of the person who released it. Retain access-related documentation for six years.

Two more habits worth building. First, run a monthly aging report on open requests — anything past day 20 gets escalated to the privacy officer by name. Second, review your policies against actual practice once a year; the most common finding in a records-request investigation is a policy that says one thing while the front desk does another.

If your policy set, risk analysis, and workforce training documentation are scattered across shared drives and half-finished templates, automating the compliance document set is a faster path to a defensible file than rewriting each one by hand.

Start With the Vendor List

Pick one recent chart involving a specialist referral and trace every organization that touched the record. Then check each one against your BAA file. If the copy service, the transcription vendor, or the imaging archive is missing an executed agreement, build and export the BAA today — one-time purchase, signature-ready, done before the next request arrives at your fax machine.