Hip Impingement Referrals: Records Sharing Done Right
A patient sees your primary care physician on a Monday for groin and lateral hip pain. By Friday, a suspected hip impingement case has generated a referral to an orthopedic group, an order to a freestanding imaging center, and a standing question from a physical therapy clinic that wants the ortho's notes before the first visit. That is four organizations touching one chart inside of five business days, and your front desk is the switchboard for all of it.
This post is about the records and privacy workflow around that referral — who may send what to whom, without an authorization, through which channel, and what your staff logs. It is not clinical guidance and contains none. If you run intake, release of information, or vendor oversight for a practice that sends or receives orthopedic referrals, this is your operating checklist.
What Actually Moves in a Hip Impingement Referral
Conditions in this category are evaluated across organizations by design — a primary care encounter, an imaging study read by a radiology group, an orthopedic consult, and often a course of physical therapy. Each stop produces records the next stop wants. Your workflow has to anticipate the package, not assemble it ad hoc every time.
A realistic disclosure inventory for one of these referrals:
- Referral letter or consult request with the reason for referral
- Office notes from the referring visit, plus relevant prior visits
- Imaging orders, radiology reports, and in some cases the DICOM images themselves
- Problem list, medication list, allergies
- Insurance and demographic data for the receiving practice's registration
- Prior authorization documentation, which travels to the payer, not the specialist
- Therapy evaluations and progress notes flowing back toward the ordering physician
Notice that the last item flows the other direction. Referral compliance failures usually happen on the inbound leg, where records arrive by fax at 6:40 p.m. and sit in a tray until someone decides whose chart they belong in.
Treatment Disclosures Don't Need an Authorization — They Still Need a Workflow
Under the Privacy Rule, a covered entity may use and disclose protected health information for treatment, payment, and health care operations without patient authorization. Disclosure to another provider for that provider's treatment of the patient is squarely permitted. HHS says this plainly in its guidance on permitted uses and disclosures for exchange of information for treatment.
Two operational consequences your staff should internalize:
One. The minimum necessary standard does not apply to disclosures to a health care provider for treatment purposes. Your ortho colleague can ask for the whole relevant record, and you are not required to trim it down. The minimum necessary guidance from HHS spells out that carve-out. That does not make everything free game — it means the treatment channel is not where you should be spending your review time.
Two. Permitted is not the same as unverified. The obligation that survives is identity and authority verification: your staff must take reasonable steps to confirm the requester is who they claim to be and that the request is for treatment. A fax cover sheet with a clinic letterhead is not verification. A callback to a number your practice looked up independently is.
Where Staff Get It Backwards
The two most common intake errors run in opposite directions. Front desk staff demand a signed authorization from a specialist's office that is legitimately requesting records for treatment, delaying care and creating an information blocking exposure. Or they release records to a caller claiming to be a therapy clinic without confirming anything, because "it's treatment, so it's fine."
Train against both. The rule permits the disclosure; your procedure decides whether the person on the other end is real.
Do You Need a Signed Authorization to Send Hip Impingement Records to a Specialist?
No. When a physician refers a patient with suspected hip impingement to an orthopedic specialist, imaging center, or physical therapist, the disclosure of relevant records for that provider's treatment of the patient is permitted under 45 CFR 164.506(c)(2) without patient authorization. Minimum necessary does not apply to treatment disclosures. You still must verify the requester's identity and authority, transmit through a reasonably secure channel, and honor any restriction the patient has requested and your practice has agreed to.
Authorization is required when the request is not treatment, payment, or operations — for example, when an employer, an attorney, a life insurer, or a research coordinator asks for the same records.
Who Is a Business Associate in This Chain and Who Is Not
This is where practices sign agreements they do not owe and skip agreements they do. Sort the referral chain into three buckets.
Not Business Associates
The orthopedic group, the radiology group, the imaging center, and the physical therapy clinic are each covered entities acting on their own behalf. Provider-to-provider treatment disclosure does not create a business associate relationship, and you do not need a BAA to fax a consult note to a specialist. If a specialist's office insists on one, you can sign it — but understand you are agreeing to obligations the law did not impose.
Business Associates
Anyone handling PHI on your behalf is in scope: your release-of-information vendor, your cloud fax service, your transcription vendor, your referral management platform, your EHR host, your document scanning contractor, and the answering service that takes after-hours referral calls. Each needs a signed agreement in place before PHI moves. If your BAA inventory is stale — signed by a practice manager who left in 2022, referencing a vendor that has since been acquired — that gap is what an investigator finds first. A signature-ready business associate agreement takes minutes to produce, and there is no defensible reason to run a referral pipeline with unsigned vendors in it.
Conduits
Traditional telecom carriers and the postal service are conduits, not business associates. A cloud service that stores your faxes, even briefly, is not a conduit. Ask every fax vendor one question in writing: do you retain a copy of transmitted documents, and for how long? The answer decides which bucket they land in.
Choosing the Transmission Channel — And Documenting Why
Rank your channels before the referral, not during it. A reasonable order for most practices:
- Direct secure messaging or an interoperability network query. Structured, logged, encrypted, and it satisfies the receiving practice without a phone call.
- Provider portal upload to the specialist's system, when they offer one and your staff has credentialed accounts.
- Secure fax over an encrypted service, with a verified destination number stored in a maintained directory — not typed from the referral form each time.
- Encrypted email to a verified provider address, if your policy permits it.
- Unencrypted email only to the patient, only after the patient has been warned of the risk and still requests it in writing.
Misdirected faxes remain one of the most common breach reports from small practices, and nearly all of them trace to a wrong digit or an outdated number. Assign one person to own the referral fax directory and to re-verify entries annually.
Delay is its own exposure. Under the information blocking regulations, a practice that unreasonably interferes with access, exchange, or use of electronic health information can face consequences separate from HIPAA. ONC maintains current material on information blocking and its exceptions. "We only release records on Thursdays" is not an exception.
Inbound Records: The Leg Everyone Under-Builds
Records come back from the orthopedist and the therapy clinic. Build a named workflow for them:
- Same-day triage of the inbound queue by a designated staff member
- Patient matching against two identifiers before filing — name plus date of birth, minimum
- Routing to the ordering clinician's review queue, with a defined turnaround
- A quarantine folder for documents that do not match any patient, and a defined process for returning them to the sender
That last item matters. If a therapy clinic faxes you a stranger's evaluation, you have received PHI you had no right to hold. Log it, notify the sender, and destroy or return it per your policy. Do not scan it into a chart to "figure it out later."
One more inbound rule: if a patient asks you to amend a record that originated with the orthopedic group, you handle the request for your own records and direct them to the originating practice for theirs. You do not edit another organization's consult note.
When the Patient Asks — And When Someone Else Does
A patient with a hip impingement workup often wants their own imaging and reports, frequently to carry to a second opinion. That is a right of access request, not a referral. The clock is 30 days from receipt, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS keeps a detailed page on the individual right of access, and OCR's enforcement of that right has produced a long run of settlements against practices of every size, most of them for the same failure: records requested, records not sent.
Different requesters, different rules:
- Employer or team athletic staff — needs a valid authorization. Employment relationship is not treatment.
- Workers' compensation carrier — governed by 45 CFR 164.512(l) and state law; do not improvise, and have your policy written before the first request arrives.
- Attorney — authorization or valid legal process, verified.
- Disability or life insurer — authorization.
- Another treating provider — permitted, verify and send.
What You Log, and What Your Risk Analysis Has to Say About It
Treatment, payment, and operations disclosures are excluded from the accounting of disclosures a patient can request. That does not mean you should keep no record. Your EHR's audit log, your fax confirmations, and your ROI vendor's transmission records are what you produce when a patient asks who saw their chart — and what an investigator asks for first after a complaint.
Every one of these channels also belongs in your Security Rule risk analysis: the fax service, the referral platform, the portal credentials your staff share with a specialist's office, the scanner that drops PDFs onto a network folder. If your risk analysis does not name them, it does not describe your practice. Generating and maintaining that documentation by hand is exactly the work most administrators postpone, which is why automated HIPAA risk analysis and policy generation is worth the hour it takes to set up — the assessment, the policy set, and the supporting documents come out consistent and dated.
A Ten-Line Desk Procedure for Referral Records
- Confirm the request is from a provider for treatment of your patient.
- Verify the requester using a number or address from your own directory.
- Check the chart for any agreed patient restriction on disclosure.
- Assemble the relevant record set; do not withhold on minimum necessary grounds for treatment.
- Send through the highest-ranked available channel and save the confirmation.
- Note the disclosure in the chart: date, recipient, contents, channel, staff initials.
- For non-treatment requesters, stop and route to the privacy officer for authorization review.
- Triage inbound records the same day and match on two identifiers.
- Quarantine and report any misdirected document received.
- Escalate any suspected misdirected outbound transmission to the privacy officer within one business day.
Print it. Tape it to the ROI workstation. Review it with new hires in week one.
Next Step
Pull your last ten referrals out of any orthopedic or musculoskeletal line — hip impingement cases are a good sample because they reliably cross organizational lines — and trace each one end to end. Every vendor that touched the record should have a current signed agreement, every transmission should have a confirmation, and every channel should appear in your risk analysis. Where the paperwork is missing, generate the risk analysis and policy set and close the gap this quarter, before a misrouted fax makes the decision for you.