A patient who was seen in your office in March calls on a Tuesday morning and says: "I need everything you have about my heel." That single sentence starts a 30-calendar-day clock, and the chart behind it is almost never in one place. Workups for heel tenderness causes tend to generate an office note, a radiology order, images held by an imaging center, a physical therapy episode at a separate entity, and sometimes an orthotics fabrication record. This post is for the person who has to assemble that, verify the requester, price it correctly, and log it — not for the patient making the call.

Nothing here is clinical guidance. The clinical detail matters only because it explains why the records for this kind of encounter are unusually scattered, and why scattered records are where access complaints get made.

Why Charts Documenting Heel Tenderness Causes Fragment Across Four Organizations

Foot and ankle complaints are referral-heavy by nature. A primary care visit often produces a referral to podiatry or orthopedics; that specialist frequently orders imaging performed elsewhere; therapy is typically delivered by a separate practice or hospital outpatient department; custom devices may be fabricated by an outside lab from measurements or a scan your office captured.

From a records standpoint, that means one "episode" in the patient's mind is four designated record sets held by four legal entities. The patient does not know that. Your front desk has to.

Practically, you need a standing answer to three questions before the request ever arrives:

  • Which of these records live in your designated record set, including anything a business associate maintains on your behalf?
  • Which belong to another covered entity, requiring you to tell the patient where to go rather than silently omitting them?
  • Where do imaging objects physically sit — your PACS, a vendor-hosted archive, or the imaging center's system?

The most common access failure in this scenario is not refusal. It is a partial production that the patient later discovers was partial. That is the fact pattern that turns a phone call into an OCR complaint.

The 30-Day Clock That Starts When a Patient Asks for Their Chart

Under the HIPAA Privacy Rule, you must act on an individual's access request no later than 30 calendar days after receipt. Not 30 business days. Not 30 days from when your release-of-information vendor gets around to it.

You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give the date you will complete the request. There is no second extension.

Three clock rules people get wrong:

  1. The clock starts at receipt by your organization, including a fax that sat in a tray or a portal message nobody triaged. Route-to-owner has to happen same day.
  2. Using a vendor does not toll the clock. If your copy service takes 25 days, you have five.
  3. An incomplete request still starts the clock if you can identify the individual and what they want. Clarifying a date range is not a reset button.

HHS maintains detailed guidance on all of this in its individuals' right of access materials, and OCR's Right of Access Initiative has produced dozens of publicly announced settlements since 2019 — nearly all of them turning on delay rather than on some exotic privacy theory.

What "Act On" Actually Means

Acting on the request means providing the access, or providing a written denial that states the basis and the individual's review and complaint rights. Sending an invoice is not acting on the request. Leaving a voicemail is not acting on the request.

Verification: Enough to Be Defensible, Not Enough to Be an Obstacle

You are required to verify the identity and authority of a requester before disclosing. You are not permitted to build a verification process so heavy that it functions as a barrier to access. Both things are true at once, and the line between them is where most front desks get uncomfortable.

Write your verification standard down and apply it uniformly. A defensible baseline for a routine patient request:

  • In person: government photo ID, logged by initials and date, no copy retained unless your policy says otherwise.
  • Portal: the authenticated session itself is your verification. Do not layer a notarization requirement on top of it.
  • Phone or mail: match two or three chart data points (date of birth, address on file, date of last visit), then deliver to the address or email already in the record — or to a new address confirmed through a separate channel.
  • Email delivery to an unencrypted address: permitted at the individual's request after you warn them of the risk. Document the warning and the response. You do not get to refuse on security grounds alone.

Personal Representatives and Third-Party Directives

A parent requesting a minor's therapy records, a spouse with a healthcare power of attorney, and an attorney's office all get different treatment. Personal representatives step into the individual's shoes and get the individual's rate and rights, but you must verify the legal authority document and note it in the file.

A patient can also direct you to send their records to a third party. That directive must be in writing, signed by the individual, and clearly identify the recipient and where to send it. Note that following the 2020 federal court decision in Ciox Health, LLC v. Azar, the patient-rate fee cap no longer applies to third-party directives in the way the 2013 rule contemplated, and the mandatory third-party directive right is limited to electronic PHI in an EHR. Your fee schedule should distinguish the two request types explicitly.

Also learn to spot the request that is not an access request at all. An attorney letter with a signed authorization attached is a disclosure under an authorization, priced under state law, on your state's timeline. A subpoena is a third thing. Mislabeling these is how practices end up charging a patient $85 for their own chart.

Fees: What You Can Charge for a Foot and Ankle Record

For a patient's own access request, your fee must be reasonable and cost-based, and it may only include:

  • Labor for copying the PHI, whether paper or electronic
  • Supplies — paper, toner, a CD or USB drive if that is the requested format
  • Postage, when the patient asks for mail delivery
  • Preparing an explanation or summary, but only if the patient agreed to it in advance

You may not charge for search and retrieval, for the time a staff member spent locating a scanned outside report, or for the cost of maintaining your systems. If the patient asks for a fee estimate up front, give one. If your production ends up costing less, bill the lower amount.

Imaging is where fee disputes cluster. If a patient asks for the DICOM study rather than a report, and your archive can produce it, the media cost and copy labor are chargeable. The archive subscription is not.

The Vendor Chain Behind One Heel Tenderness Causes Workup

Walk the record backward and count the outside parties that touched PHI in a typical foot-pain episode: the transcription service, the release-of-information vendor, the cloud-hosted image archive, the orthotics lab that received a scan and a patient identifier, the fax-to-email gateway, and the secure messaging platform your staff used to coordinate the referral.

Each of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf, and each needs an executed agreement with the required terms — permitted uses, safeguards, subcontractor flow-down, breach notification timelines, and return or destruction at termination. HHS publishes the baseline requirements and sample provisions, but sample language is a starting point, not an executed contract.

The orthotics lab is the one most practices miss. It feels like a manufacturer, not a health IT vendor, so it never makes it onto the BAA tracker. If you are onboarding one and need a signature-ready document rather than a redlined Word file that circulates for six weeks, you can generate a Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which matters when you are papering a single small vendor relationship.

Tie the BAA tracker to the records workflow directly. When a request comes in and you realize you need to pull images from a vendor-hosted archive, the tracker should already tell you whether that relationship is papered. Discovering a gap mid-production is the wrong time.

Information Blocking Sits on Top of All of This

Right of access is the HIPAA obligation. Information blocking is a separate rule with a separate enforcement path, and health care providers are actors under it. A practice that slow-walks an electronic records request, insists on paper when electronic is readily producible, or imposes conditions not required by law can face disincentives even where the HIPAA timeline was technically met.

Review the current exceptions — particularly Privacy, Infeasibility, and Content and Manner — against your actual intake script. ASTP/ONC maintains the authoritative material on information blocking requirements and exceptions. If your staff has ever said "we only release on paper," you have an exposure.

A Worked Example: Day 0 to Day 18

Day 0. Portal message received at 4:40 p.m. Request logged in the ROI tracker with a timestamp and an assigned owner. Automatic acknowledgment sent.

Day 1. Owner scopes the request: two office notes, one radiology report, one imaging study in the vendor archive, and a therapy episode delivered by an unaffiliated practice. Owner calls the patient to confirm scope and format preference — electronic, delivered to the portal.

Day 2. Patient confirms. Owner sends a written note identifying the therapy practice by name and address so the patient can request those records directly. That written pointer is your evidence you did not silently omit anything.

Day 6. Image retrieval ticket opened with the archive vendor. Owner sets an internal escalation date at Day 14 — well before the statutory deadline.

Day 12. Vendor delivers. Owner assembles the package, runs a completeness check against the scope confirmed on Day 2, and has a second staff member verify the patient identifier on every document.

Day 14. Package released to the portal. No fee charged; electronic delivery of existing records cost nothing to produce.

Day 18. Tracker entry closed with the release date, the delivery method, the verification method, and the name of the second reviewer. That entry is what you hand an investigator.

Denials: The Short List

You can deny access to psychotherapy notes kept separately, to information compiled for legal proceedings, and in a narrow set of reviewable circumstances involving danger. "The account has an outstanding balance" is not on the list. "The provider who wrote the note has left the practice" is not on the list. "Our vendor is slow" is not on the list.

If you deny in part, produce the rest and issue a written partial denial explaining what was withheld and why.

What to Fix This Month

Pick three things. First, timestamp every inbound request at the point of receipt, including faxes and voicemails, and prove it with a sample audit. Second, reconcile your vendor list against your executed BAAs — every party that touched a record in the fragmented workflow above. Third, rewrite the front-desk script so nobody offers paper-only, and nobody quotes a fee before scoping the request.

If your broader documentation set needs the same treatment — risk analysis, policies, workforce training records — the automated HIPAA compliance document platform handles the full set. And if the immediate gap is an unpapered vendor sitting in the middle of your records chain, build the Business Associate Agreement now rather than at the moment a request forces the question.