A patient calls your front desk on a Tuesday. She had a hemorrhoidectomy at your affiliated surgery center seven weeks ago, she is moving out of state, and she wants the operative note, the pathology report, and the post-op visit notes sent to a colorectal surgeon in another city. Your scheduler tells her to come in and sign a release. Your clock started the moment she asked — not the moment she signs your form.

That is the whole problem in one sentence. This post is for the person who owns records requests in a practice or ambulatory surgery center: the deadlines, the identity verification script, the fee rules, the vendor contracts, and the specific ways a routine surgical chart request turns into an OCR complaint. No clinical content here — a hemorrhoidectomy is simply a good example of an encounter whose records scatter across several organizations at once.

Why a Hemorrhoidectomy Chart Lives in Four Systems at Once

These procedures typically move through a referral chain: primary care or gastroenterology identifies the problem, a surgeon evaluates, the procedure happens in an ASC or hospital outpatient department, and follow-up returns to the referring office. That is normal care delivery. It is also a records-management headache.

By the time a patient asks for "my hemorrhoidectomy records," the designated record set is spread across at least four custodians:

  • The surgeon's office — consults, H&P, post-op visits, correspondence to the referring provider
  • The facility — operative note, nursing notes, consent, discharge instructions, implant or device logs if any
  • The anesthesia group — its own record, often a separate covered entity with separate billing
  • The pathology lab — specimen reports, sometimes held by a reference lab you do not control

Your obligation runs only to the protected health information you maintain in your designated record set. But your reputation with the patient runs to the whole thing. Build a hand-off script: "We hold X. The surgery center holds the operative note — here is their records line and address." Documenting that referral in the request log takes ninety seconds and prevents the complaint that says "they refused to give me my records."

Decide, in writing, what your designated record set includes

Most practices have never written this down. They should. Your DRS policy should name the systems — EHR, practice management, scanned document repository, secure messaging archive, imaging viewer — and state which content is inside the set and which is not. Quality-improvement worksheets and peer review materials generally sit outside. Billing records generally sit inside. If your policy is silent, your staff will improvise, and improvisation is what produces both over-disclosure and wrongful denial.

How Long Does a Practice Have to Fulfill a Hemorrhoidectomy Records Request?

Thirty calendar days from receipt of the request. You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give the date you will deliver. There is no second extension. The clock starts when the request arrives — by phone, portal, email, letter, or in person — not when the patient returns a form, not when the fee is paid, and not when the requested records finish scanning. Some states impose shorter deadlines; the shorter timeline wins.

HHS lays this out plainly in its right of access guidance, which remains the single most useful document your records staff can read. Print it. Put it in the front-desk binder.

What "receipt" actually means at your front desk

Receipt is not a defined workflow milestone in your software. It is a legal fact created by a patient's words. If a patient tells your medical assistant during a post-op call that she wants a copy of her operative report, you have received a request. If it lands in the general practice inbox on a Friday at 6 p.m., you received it Friday.

Give every staff member who touches a phone or an inbox one instruction: log it the same day, then route it. A shared request log with date received, requester, records sought, delivery method, and date fulfilled is the cheapest defense you will ever build. When OCR asks for evidence of timeliness, that log is what you produce.

Verification Without an Obstacle Course

You must verify the identity and authority of the requester. You may not use verification as a delay tactic, and you may not impose unreasonable barriers — requiring a notarized signature, an in-person appearance, or a visit to a portal the patient has never enrolled in are the classic examples HHS has flagged.

A workable standard for a request arriving by phone or email:

  1. Confirm two static identifiers already in your record — date of birth plus address on file, or DOB plus last four of the account number.
  2. Confirm the delivery destination independently. Read the email address or fax number back and get an explicit yes.
  3. Note in the log who verified, how, and when.
  4. If the request is for a third party, capture the written, signed direction — see below.

For a sensitive procedure, patients are more likely to ask that nothing be mailed to the home address on file. Honor reasonable alternative-means requests. That is not a favor; it is part of the confidential communications right, and denying it generates complaints faster than almost anything else in the records workflow.

Third-party directives versus authorizations

These are two different instruments and your staff must be able to tell them apart. A patient directing you to send her own hemorrhoidectomy records to her new surgeon is exercising a right of access with a third-party directive: it must be in writing, signed, and clearly identify the recipient and where to send the copy. A law firm or life insurer requesting the same records is operating under a HIPAA authorization with its own content requirements.

The distinction matters for fees. Following the 2020 federal court decision in the Ciox Health litigation, HHS acknowledged that the patient-rate fee limitation no longer applies to requests that a third party directs to you, and that the third-party directive requirement was narrowed to electronic copies of PHI held in an EHR. If your ROI vendor is charging patient rates to attorneys, or state-permitted retrieval fees to patients, you have a billing problem sitting on top of a compliance problem.

Fees: Reasonable, Cost-Based, and Disclosed Up Front

For a patient's own access request, you may charge a reasonable, cost-based fee covering labor for copying, supplies, postage, and preparation of a summary if the patient agreed to one in advance. You may not charge for search and retrieval. You may not charge a per-page fee for records maintained electronically and delivered electronically simply because a state fee schedule allows it.

Two operational rules that keep you out of trouble:

  • Tell the patient the fee, in advance, before you start processing. Surprise invoices generate complaints.
  • Never hold records hostage for payment. Deliver, then bill, unless you have a clear advance agreement and the patient is not being blocked from access.

OCR's Right of Access Initiative has produced dozens of settlements since 2019, most of them small practices, most of them resolving a single complaint about a chart that was never sent or was sent months late. You can review the enforcement pattern yourself in the OCR breach portal and in the resolution agreements HHS publishes. The dollar amounts vary. The fact pattern almost never does: a request arrived, nobody logged it, and the corrective action plan cost more than compliance would have.

The Vendor Layer Nobody Diagrams Until Something Leaks

Walk the path a hemorrhoidectomy operative note travels when your office fulfills a request. It may pass through a release-of-information company, a document scanning or indexing service, a transcription vendor, a cloud fax provider, a secure messaging gateway, a print-and-mail house, and whatever storage sits underneath your EHR. Each of those is a business associate. Each needs a signed agreement that predates the disclosure.

Run this test on your own vendor list this month: pick the three vendors most likely to touch a surgical chart, and try to produce the executed BAA in under five minutes. If you cannot find it, or the version on file is a decade-old boilerplate that never mentions breach notification timelines, subcontractor flow-down, or return-and-destruction at termination, fix it before the next request cycle. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which is roughly the amount of ceremony a BAA deserves.

Delegation does not transfer the deadline

If you outsource release of information, your 30-day obligation does not move to the vendor. Build the service level into the contract — receipt acknowledgment within one business day, fulfillment within fifteen, escalation to you at day twenty — and audit against it quarterly by pulling ten closed requests and checking the dates. A vendor averaging 34 days is putting your practice in violation every single month.

Denials, Reviews, and the Sensitive-Procedure Trap

Grounds for denying access are narrow, and most of the ones staff imagine do not exist. Unpaid balances are not grounds. Disagreement with the patient's reason is not grounds. The patient not telling you why is not grounds — you may not require an explanation. Where a reviewable ground applies, the denial must be in writing, in plain language, and must explain the review right and how to complain to you and to HHS.

The second trap is internal. Records for a procedure like this attract curiosity in a small office. Your access controls and audit log review are the only real defense. Pull a monthly report of who opened surgical charts, compare against schedule and role, and document the review. Snooping cases rarely start with a records request; they start with a patient who recognizes a name on the staff roster and asks who has seen her chart. You want an answer ready.

The Information Blocking Overlay

Right of access is not the only rule in play. Under the 21st Century Cures Act, practices and facilities are also subject to the information blocking prohibition, and HHS finalized disincentives for providers found to have engaged in information blocking in 2024. A slow, form-heavy, fax-only records process that discourages electronic delivery can create exposure under both frameworks at once. ASTP/ONC maintains a plain-language overview of information blocking and its exceptions that your privacy officer should read alongside the access guidance.

Practical translation: if a patient asks for an electronic copy in a form and format you can readily produce, produce it electronically. Do not default to paper because paper is what your log expects.

A Worked Timeline You Can Copy

Request arrives Monday, June 1. Here is what a clean file looks like when someone reviews it two years later:

  • June 1 — Logged same day by front desk. Requester, records sought, delivery method captured.
  • June 2 — Identity verified using DOB and address on file; verifier initials recorded. Third-party directive received and scanned.
  • June 3 — Scope reviewed. Facility and pathology holdings identified as outside your custody; referral information given to patient in writing and noted in log.
  • June 5 — Fee quoted in writing. Patient accepts.
  • June 11 — Records assembled, reviewed for correct patient and correct date range, delivered by the method requested. Delivery confirmation saved.
  • June 11 — Log closed. Ten days elapsed, twenty to spare.

Nothing in that sequence is difficult. All of it is procedural. The practices that get letters from OCR are almost never the ones that made a hard judgment call — they are the ones where a request sat in a voicemail box for six weeks because no one owned it.

What to Do Before the Next Request

Name a single accountable owner for records requests, with a named backup. Write the designated record set policy. Stand up the log. Post the 30-day and 60-day dates where staff can see them. Audit your ROI vendor's turnaround. And confirm that every organization touching a surgical chart on your behalf has a current, executed agreement on file.

If your vendor paperwork is the weak link, start there — build the agreements you are missing this week, and if your broader documentation set is thin, automated risk analysis and policy generation will get the rest of the binder honest. Neither is a certification, because no such government credential exists. Both are evidence that you did the work before somebody asked.