HIPAA Right of Access: The 30-Day Clock and Fee Limits
A patient emails your front desk at 4:51 p.m. on a Friday: "Please send me everything in my chart." No form, no notarized signature, no explanation. That message started a 30-day clock under the HIPAA right of access, and the clock does not care that your records clerk is part-time or that your release-of-information vendor has a five-day queue.
This article is for the person who owns that clock — practice owner, office manager, privacy officer, compliance lead. It covers what you must produce, in what format, by when, what you may charge, the narrow grounds for refusing, and the documentation that proves you did it right when the Office for Civil Rights asks.
What the HIPAA Right of Access Actually Obligates You To Do
Under 45 CFR 164.524, an individual has the right to inspect and obtain a copy of protected health information about them held in your designated record set. That set is broader than most staff assume. It includes the medical record and the billing record, plus any other records your practice uses to make decisions about that patient.
Practically, that means the chart, lab and imaging reports you received, consult letters, medication lists, immunization history, claims and billing detail, and — this one surprises people — records you obtained from other providers and now maintain. If it lives in the designated record set, it is fair game regardless of who authored it.
Two carve-outs matter. Psychotherapy notes, as narrowly defined by the rule (a mental health professional's separately maintained session notes), are excluded. So is information compiled in reasonable anticipation of litigation. Everything else in the set is presumptively accessible.
The request does not need to be on your form. It can arrive by email, letter, portal message, or fax. You may require it in writing and you may require reasonable identity verification, but you cannot require the patient to appear in person, cannot require them to explain why they want the records, and cannot force them to use only your patient portal.
The 30-Day Clock and the One Extension You Get
Your practice must act on a HIPAA right of access request no later than 30 calendar days after receipt. Acting means one of two things: provide the access requested, or send a written denial that meets the rule's content requirements. You get one 30-day extension, and only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give the date by which you will complete the request. One extension per request. There is no second bite.
Three details that trip practices up:
- The clock starts when the request reaches your organization, not when it reaches the right person. A request sitting in a shared inbox is a running clock.
- Calendar days, not business days. Holidays do not pause anything.
- State law can be shorter, and where it is shorter, it governs. Several states set deadlines as tight as 15 days for copies. Build your workflow to the shortest deadline that applies to you, not to the federal 30.
OCR has repeatedly said 30 days is an outer limit, not a target. If your EHR can export a CCD in four minutes, taking 29 days looks bad in a complaint investigation.
What You Can Charge — and the Four Things You Cannot Bill For
Fees are where most practices drift out of compliance without noticing, usually because a legacy fee schedule from a state statute is still taped inside the records desk.
You may charge a reasonable, cost-based fee limited to:
- Labor for copying the PHI, whether paper or electronic;
- Supplies — paper, toner, a CD or USB drive if the patient asked for that media;
- Postage, when the patient asks for mail delivery;
- Preparing an explanation or summary, but only if the patient agreed in advance to the summary and the fee.
You may not charge for searching for or retrieving the records, for labor spent verifying identity or documenting the request, for maintaining or licensing your systems, or for overhead, capital costs, or "data storage" line items. Per-page fees are not permitted for records you maintain electronically.
You may calculate the fee three ways: actual cost per request, an average cost schedule you can defend, or a flat fee of up to $6.50 for electronic copies of PHI maintained electronically. That $6.50 figure is an option that keeps you safe, not a ceiling on the other two methods — and not a floor you must charge. Whichever method you use, tell the patient the approximate fee in advance.
Write your method down. When OCR asks how you arrived at $22.40, "that's what our copy service bills us" is not an answer; a documented average-cost calculation is.
Form, Format, and the Unencrypted Email Question
If the patient requests a specific form and format, you must produce it if it is readily producible. Asked for a PDF by email? If your system can generate a PDF and your email can send it, that is readily producible. Asked for paper when everything is electronic? Print it.
If the requested format is not readily producible, you must offer a readable alternative electronic format and reach agreement with the patient. "We only do paper" is not an agreement.
On unencrypted email: patients may ask you to send records to a personal email address that offers no encryption. You may honor that. Warn the patient of the risk in a way you can document, confirm they still want it sent that way, and send it. If the message later gets intercepted, that documented instruction is what stands between you and a breach analysis.
Directing a copy to a third party
A patient may direct you to transmit a copy to a person or entity they designate. The request must be in writing, signed by the individual, and clearly identify the recipient and the delivery destination. Note that following the 2020 Ciox Health litigation, the fee limitations described above apply to copies going to the individual; third-party transmissions requested by the patient sit on different footing, and many practices handle non-electronic third-party directives through a standard HIPAA authorization instead. Whatever route you pick, apply it consistently and put it in your policy.
The Only Lawful Reasons to Say No
Denials fall into two buckets, and the difference determines what you must tell the patient.
Unreviewable grounds
These include psychotherapy notes, information compiled in anticipation of a legal proceeding, certain requests by inmates, records subject to the Clinical Laboratory Improvements Amendments where access would be prohibited, and research records where the individual agreed to suspend access for the duration of the study. The patient has no right to internal review of these denials.
Reviewable grounds
A licensed health care professional at your practice must determine, in the exercise of professional judgment, that access is reasonably likely to endanger the life or physical safety of the individual or another person. There are narrow parallel grounds when the record references another person, or when a personal representative is the requester. "The physician thinks it will upset the patient" is not a lawful ground. Emotional distress is not physical endangerment.
When you deny, the denial must be in writing, in plain language, within the same 30-day window. It must state the basis, explain the patient's right to have a reviewable denial reviewed by a designated licensed professional who was not involved in the original decision, and explain how to complain to your practice and to OCR. And you must still release everything else that was requested — a partial denial is never a total refusal.
Your Workflow, Role by Role
Assign these in writing. Unassigned steps are the ones that miss deadlines.
- Front desk / anyone with inbox access: date-stamp and forward any access request to the records queue the same business day. Train them to recognize a request that arrives as a casual email or portal message.
- Records staff: log the request (date received, requester, scope, format, delivery method, fee quoted), verify identity per your policy, compile from the designated record set, and fulfill.
- Privacy officer: monitor the queue against day 15 and day 25 checkpoints, sign extension notices, and review any proposed denial before it goes out.
- Clinician: the only person who can make a professional-judgment endangerment determination, and the determination gets documented.
- Billing: confirms that the access fee posted matches the documented cost-based method — not the fee schedule used for attorney or insurer requests.
If your access policy, your fee methodology, and your denial letter templates do not exist as current, dated documents, that gap is the same gap that shows up in a risk analysis. Tools that generate your HIPAA risk analysis and the supporting policy set make quick work of the paper layer, so your team can spend its time on the operational habits instead of drafting from scratch.
The Documentation OCR Asks For
When a patient complains — and access complaints are among the most common OCR receives — the investigation is largely a paperwork exercise. Have these ready:
- Your written right-of-access policy and procedure, with an effective date and revision history.
- The request log showing date received and date fulfilled for the complainant, plus a sample of others.
- Any extension notice sent, with proof of the date.
- The fee calculation worksheet or average-cost schedule, and the actual invoice.
- Any denial letter and the clinician's documented determination.
- Workforce training records showing front-desk and records staff were trained on access requests specifically.
Retain access-related documentation for six years, consistent with the HIPAA documentation retention requirement. OCR launched a dedicated Right of Access enforcement initiative in 2019 — the first resolution, with Bayfront Health St. Petersburg, settled at $85,000 — and has resolved dozens of access cases since, most involving small and mid-sized providers who simply did not send the records. You can review the settlements yourself in the HHS enforcement agreements list, and the controlling guidance sits in the OCR right of access guidance.
Where Practices Actually Fail
The vendor is slow and you are still liable. If a release-of-information company or copy service handles your requests, that vendor is a business associate and its turnaround is your compliance exposure. Put the 30-day obligation — and an internal target well inside it — in the contract. If your agreement predates your current workflow or does not exist in signed form, a six-step business associate agreement builder will get a signature-ready document in front of them faster than a redline cycle with counsel.
Portal-only fulfillment. Your portal may not contain the whole designated record set. If a patient asks for everything and you point at the portal, you have partially fulfilled at best.
Blocking on unpaid balances. You cannot withhold records because the patient owes money. Full stop.
Confusing access with authorization. An attorney's subpoena, an insurer's request, and a patient's own request travel different tracks with different fee rules. Staff who use one form for all three will overcharge patients.
Ignoring information blocking. Separate from HIPAA, the 21st Century Cures Act information blocking rules apply to providers, and practices that slow-walk electronic health information face exposure there too. ONC's information blocking resources explain how the two regimes interact.
Your Next Step
Pull your last ten access requests this week. For each one, find the date received, the date fulfilled, the fee charged, and the method used to compute it. If you cannot reconstruct all four for every request, the HIPAA right of access is not yet a controlled process at your practice — it is a habit that happens to have worked so far.
Fix the paper first: a documented access policy, a defensible fee methodology, a denial template, and a request log. If you would rather not draft those from a blank page, build your compliance document set and risk analysis in one pass and spend the saved hours training the people who actually answer the phone.