HIPAA Privacy Rule: What Your Practice Must Do Now
A patient emails your front desk on a Tuesday asking for a copy of everything in her chart since 2019. Under the HIPAA Privacy Rule, you have 30 calendar days to produce it — not 30 business days, and the clock started the moment that email landed in an inbox your practice monitors. If your release-of-information staffer is out for two weeks, the clock keeps running.
This article is for the person who owns that clock: the practice administrator, the privacy officer, the compliance lead. It covers what the Privacy Rule actually obligates you to do, who in your organization does it, on what deadline, and what the documented proof looks like when the Office for Civil Rights asks.
What the HIPAA Privacy Rule Requires, in One Section
The HIPAA Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) governs how covered entities and their business associates use and disclose protected health information. In practice, it imposes seven standing obligations on your practice:
- Give patients access to their records within 30 days of a request, with one 30-day extension available if you notify them in writing.
- Limit uses and disclosures to the minimum necessary for the purpose, except for treatment, disclosures to the patient, and a short list of other exceptions.
- Obtain a signed authorization before using PHI for anything outside treatment, payment, health care operations, and the specific permitted disclosures the rule lists.
- Maintain a Notice of Privacy Practices, distribute it, post it, and get a good-faith acknowledgment of receipt from patients you treat directly.
- Execute business associate agreements with every vendor that creates, receives, maintains, or transmits PHI on your behalf.
- Designate a privacy official and a contact person for complaints, and train your workforce on your policies.
- Retain documentation for six years from creation or the date it was last in effect, whichever is later.
Everything below is detail on how those seven turn into daily work.
The 30-Day Clock That Starts When a Patient Asks for Their Chart
Right of access is the single most enforced provision of the Privacy Rule. OCR has brought dozens of enforcement actions under its Right of Access Initiative since 2019, most of them against small and mid-size practices, most of them resolved for five-figure sums after a patient waited months for records that should have taken weeks.
The mechanics matter more than the principle.
What starts the clock
Any request from the patient or their personal representative — verbal or written, at the desk, by phone, by portal message, by email. You may require it in writing if your Notice of Privacy Practices says so, but you cannot use the writing requirement to stall. Train your front desk to timestamp and log the request the day it arrives, not the day it reaches the medical records desk.
What you must produce
Everything in the designated record set: clinical notes, labs, imaging reports, billing records, and information you maintain from other providers. In the form and format the patient requests, if you can readily produce it that way. If a patient asks for a PDF by email and your system exports PDFs, you send the PDF — even if you consider unencrypted email risky, provided you warned them of the risk and they still chose it.
What you may charge
A reasonable, cost-based fee limited to labor for copying, supplies, postage, and preparation of an agreed summary. You may not bill for search and retrieval time, for staff time reviewing the request, or for maintaining the record system. Post your fee schedule internally and make sure the person quoting fees is reading from it, not improvising.
HHS maintains detailed guidance on individuals' right to access their health information, and it is worth having your release-of-information staff read it in full once a year.
The evidence that protects you
A request log with four columns: date received, date fulfilled, format delivered, and who handled it. If you invoke the 30-day extension, keep a copy of the written notice with the reason and the new date. When OCR calls about a complaint from eight months ago, that log is the difference between a closed inquiry and a corrective action plan.
Minimum Necessary: The Standard Your Access Controls Have to Prove
The Privacy Rule requires you to limit PHI access to what each role actually needs. This is not an IT setting alone — it is a written policy that maps job roles to categories of information.
Do this concretely. List every role in your practice: front desk, medical assistant, biller, referral coordinator, scribe, provider, practice manager. For each, write one or two sentences describing what PHI that role may access and for what purpose. Then compare that document to your EHR's actual permission groups.
Most practices find at least one mismatch on the first pass. The common one: billing staff with full clinical note access because the system's default template gave it to them, and nobody narrowed it during implementation.
Minimum necessary does not apply to disclosures to a treating provider, disclosures to the patient, disclosures made under a valid authorization, or disclosures required by law. Everything else — payer requests, internal analytics, quality reporting, marketing lists — gets scrutinized.
Business Associate Agreements: The Gap Most Practices Discover Too Late
If a vendor touches PHI on your behalf, you need a signed business associate agreement before they touch it. Not after the first incident. Not at renewal.
Build a vendor inventory and walk it line by line. The obvious entries are your EHR, clearinghouse, billing company, and cloud backup provider. The ones practices miss:
- The answering service that takes after-hours calls and relays symptoms
- The shredding company that hauls away paper charts
- The transcription service, including AI-assisted scribing tools
- The IT contractor with remote admin access to workstations
- The marketing agency managing your patient review requests
- The appointment-reminder texting platform
- The collections agency working your aged receivables
Each of those needs an agreement covering permitted uses, safeguards, subcontractor flow-down, breach notification timing, and return or destruction of PHI at termination. If you are staring at a vendor list with blanks in the BAA column, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which is usually faster than routing a template through outside counsel for a low-risk vendor.
Assign a renewal owner. BAAs go stale when the vendor gets acquired, changes subcontractors, or moves data to a new cloud region and nobody updates the agreement.
Your Notice of Privacy Practices Has a 2026 Deadline
The NPP is the document patients actually see, and it is also the document OCR reads first when reviewing a complaint. It must describe your uses and disclosures, the patient's rights, your legal duties, and how to file a complaint with you and with HHS. It must name a contact person and carry an effective date.
Two operational requirements people forget: you must post the current version prominently in your waiting area and on your website, and you must make a good-faith effort to obtain written acknowledgment of receipt from patients you treat directly. If a patient declines to sign, document the attempt.
The Part 2 update coming February 16, 2026
The 2024 rulemaking that aligned 42 CFR Part 2 substance use disorder records with HIPAA carries an NPP compliance date of February 16, 2026. Practices that maintain or receive Part 2 records need updated notice language by then. Separately, a federal district court in Texas vacated most of the 2024 reproductive health care privacy provisions in mid-2025, which changed what many practices had already drafted into their notices. If your NPP was revised in late 2024, have counsel re-read it against current law rather than assuming the 2024 draft still holds.
HHS publishes model Notice of Privacy Practices documents you can adapt. Adapt them — do not adopt them verbatim, because they will not describe your actual disclosure practices.
The Patient Rights Your Staff Will Handle Least Often — and Fumble Most
Amendment requests: 60 days
A patient can ask you to amend a record they believe is inaccurate. You have 60 days to act, with one 30-day extension on written notice. You may deny, but the denial must be in writing, in plain language, and must tell the patient they can submit a statement of disagreement that becomes part of the record. Denying by phone and moving on is a violation.
Restriction requests
You generally may decline restriction requests — with one exception. If a patient pays out of pocket in full for a service and asks you not to disclose that service to their health plan, you must comply. Your billing workflow needs a flag for this, and your staff needs to know it exists before a patient invokes it at the checkout window.
Confidential communications
Patients may request that you contact them by alternative means or at an alternative location. You must accommodate reasonable requests without asking why. "Call my cell, never my home" is reasonable. Build it into the demographic screen so it survives staff turnover.
Accounting of disclosures
Patients may request a list of disclosures going back six years, excluding treatment, payment, and operations. Most practices have never received such a request and have no process. Write one anyway — a one-page procedure naming who pulls it and from where.
Training, Sanctions, and the Paper Trail
Train every workforce member on your privacy policies within a reasonable time after they start, and again whenever you materially change a policy. "Workforce" includes volunteers, students, and contractors under your direct control — not just W-2 employees.
Keep for each session: date, topic, materials used, attendee names, and signed attestations. A training video with no attendance record is not evidence.
You also need a written sanctions policy and proof you apply it. When a medical assistant looks up a coworker's chart out of curiosity, the documented investigation, the disciplinary action, and the retraining are what demonstrate a functioning program. OCR treats an unenforced policy as no policy.
Every one of these documents lives under the six-year retention rule. That includes your policies, NPP versions, BAAs, complaint records, training logs, sanction records, and access request logs. If you want the underlying regulatory text, the HHS Privacy Rule regulations page is the authoritative source.
A 90-Minute Self-Audit You Can Run This Week
- Pull the last ten records requests. Calculate turnaround in calendar days. Anything past 30 without a documented extension is a finding.
- Open your vendor list. Mark every entry with PHI access. Confirm a signed, current BAA exists for each.
- Compare your role-based access policy to your EHR's live permission groups. Note every mismatch.
- Check your NPP's effective date and confirm it is posted in the waiting room and on your website.
- Verify your privacy official is named in writing and that staff know who it is. Ask three people at random.
- Confirm your complaint log exists and that entries include resolution dates.
Findings from that exercise become your remediation plan. Date it, assign owners, and set review dates — an undated plan proves nothing.
Start With the Gap You Can Close Today
The HIPAA Privacy Rule rewards practices that can produce records on demand: the request log, the training roster, the signed agreement. Most enforcement pressure lands on organizations that had reasonable intentions and no paperwork.
If your vendor inventory has empty BAA columns, close that gap first — it is the fastest fix with the clearest evidence. Draft and export a signature-ready business associate agreement for each uncovered vendor, then work down to policies, training records, and your Notice of Privacy Practices refresh ahead of the February 2026 Part 2 deadline. If your broader documentation set needs rebuilding, automated risk analysis and policy generation can shorten that project considerably.