A patient portal message lands at 4:52 p.m. on a Friday: "Please send all my lab work and cardiology notes to my new doctor." The chart belongs to a patient managed for hypertriglyceridemia — six lipid panels across two years, a nutrition consult, a specialist letter, and results from an outside reference lab. Your 30-day clock started the moment that message arrived, not Monday when someone opens the inbox.

This post is about the records workflow, not the medicine. If your practice sees lipid-disorder patients, their charts are unusually distributed — labs, specialists, dietitians, and primary care all hold pieces — and that distribution is where access requests break down. Here is how to run the request cleanly, who owns each step, and which contracts have to exist before you ever hit "send."

Why Hypertriglyceridemia Charts Sit in More Places Than Most

Serial lab monitoring is the administrative signature of this condition. That means recurring result documents, often from more than one laboratory, sometimes routed through an interface and sometimes arriving as a PDF that a staff member indexes by hand.

Add a specialist referral and the record fragments further. A hypertriglyceridemia patient may have a lipid or endocrinology consult, a dietitian note, and a primary care problem list that all reference the same values. Your reader-facing obligation does not change — you owe the patient what is in your designated record set — but the practical work of assembling it does.

Three consequences for the administrator:

  • Requests arrive with vague scope ("all my labs") that spans years of recurring documents.
  • Some documents you hold originated elsewhere, and staff wrongly assume you cannot release them.
  • Outbound copies frequently go to another organization, which triggers a different set of rules than a copy going to the patient.

How Long Do You Have to Fulfill a Records Request?

Thirty calendar days from receipt of the request. You may take one 30-day extension, but only if you give the patient a written notice within the original 30 days that states the reason for the delay and the date you will deliver. You get one extension per request — not one per document, not one per department.

Key timing facts:

  • The clock starts on receipt, including receipt by the portal, front desk, fax line, or a general email box you have told patients to use.
  • "Receipt" is not "assignment." Internal routing delays are your problem, not the patient's.
  • Several states impose shorter deadlines. California, for example, requires copies within 15 days of a written request. The stricter rule governs.
  • Denials must also be timely, in writing, in plain language, and must explain review rights where applicable.

HHS lays out the full standard in its right of access guidance, which remains the single best document to hand a new records clerk on day one.

Verification: Enough to Be Sure, Not Enough to Be a Barrier

The rule requires reasonable verification of identity and authority. It does not authorize you to build an obstacle course. Requiring notarization, in-person pickup, or a proprietary form as the only accepted route is the kind of practice OCR has repeatedly treated as an access failure.

What reasonable verification looks like

For a patient requesting their own hypertriglyceridemia labs through an authenticated portal account, the authentication is the verification. Do not make the portal user also fax a driver's license.

For a request arriving by phone, verify against chart identifiers — date of birth, address on file, recent encounter date — and document who verified, how, and when. For mailed or emailed requests, a signed request plus matching identifiers is standard.

For a personal representative — a parent, a guardian, a healthcare agent, an executor — verify the legal basis and keep a copy. This is where most practices are thin. Write down in your policy exactly which documents you accept for each representative type, so the front desk is not improvising at the counter.

Where practices over-verify

You may require requests in writing if you have told patients so in advance. You may not require a specific form if the patient's own written request contains what you need. You may not delay delivery because the patient declined to explain why they want the record. Reasons are not a condition of access.

What Belongs in the Designated Record Set — and What Does Not

The designated record set is the medical and billing records you use to make decisions about the individual. For a hypertriglyceridemia patient, that ordinarily includes lipid panels and other lab results you hold, clinician notes, problem lists, medication lists, orders, referral letters, imaging reports, and billing records.

It includes results you received from an outside laboratory once those results are part of your chart. Staff often hesitate here. Train them out of it: the source of the document does not determine whether you must produce it.

It generally does not include psychotherapy notes kept separately, information compiled for litigation, or quality-improvement work product that is not used to make decisions about the individual. It also does not include your internal audit logs, though patients may separately request an accounting of disclosures.

Format matters. If the patient asks for an electronic copy and you maintain the record electronically, produce it electronically in the requested form if it is readily producible. "We only print" is not an answer when the chart lives in a database.

Fees: The Three Permitted Methods, and the Costs You Cannot Pass On

You may charge a reasonable, cost-based fee limited to labor for copying, supplies, postage, and — if the patient agreed in advance — preparation of a summary or explanation.

Three permitted approaches:

  1. Actual cost calculated per request.
  2. A published average cost schedule applied consistently.
  3. A flat fee of up to $6.50 for electronic copies of PHI maintained electronically.

You may not charge for search and retrieval, for verifying the requester, for maintaining the system, or for staff time spent locating records. Those are overhead. A records clerk who bills 45 minutes of "chart review" against a request for two years of lipid panels has created an enforcement exposure, not revenue.

Post your fee schedule and give an advance estimate when a patient asks. OCR's Right of Access Initiative has produced dozens of resolutions since 2019, and a recurring pattern is a small practice that simply never delivered, or delivered late after a fee dispute. The settlements are modest by enforcement standards; the corrective action plans are not.

Third-Party Directives: Where the Rules Split

A patient may direct you to send a copy of their record to a third party — a new physician, a family member, an attorney. The request must be in writing, signed, and clearly identify the recipient and where to send it.

Two things changed after the 2020 Ciox Health v. Azar decision, and staff still get them wrong six years on. First, the patient-rate fee limitation applies to copies going to the individual; it was vacated as applied to third-party directives for records beyond electronic health information. Second, the third-party directive right itself is narrower than many intake scripts assume.

The operational fix is simple: build two lanes. Lane one is "copy to patient" — patient rate, portal delivery preferred, 30-day clock. Lane two is "copy to another entity" — check whether it is a patient directive or a valid authorization, apply the correct fee basis, and document which lane you used. Mixing the lanes is how practices either overcharge patients or under-document disclosures.

The Vendor Layer Underneath Every Records Request

Count the outside parties that touch a single hypertriglyceridemia records request. A release-of-information vendor may assemble and ship it. A lab interface delivered the results. A secure messaging or fax-to-email service moved the file. A cloud backup holds a copy. Possibly a transcription service produced the specialist letter.

Every one of those is a business associate, and every one needs a current, signed agreement that covers subcontractors, breach notification timelines you can actually meet, and return or destruction of PHI at termination. A ROI vendor that misses your 30-day deadline does not shift the obligation off your practice — the request is still yours.

If your vendor list has grown faster than your contract file, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when you need to paper three vendors this week rather than start a procurement project.

While you are in the file, confirm your written access policy, workforce training records, and risk analysis line up with what the records desk actually does. If those documents are stale or missing, automated HIPAA risk analysis and policy generation will get you to a defensible baseline faster than rewriting templates by hand. No product — this one included — makes a practice "HIPAA certified"; HHS does not certify or endorse compliance tools.

A Worked Timeline: Day 0 Through Day 30

Day 0. Request arrives via portal at 4:52 p.m. Friday. Auto-acknowledgment fires. Request is logged in the tracking sheet with a receipt timestamp and a due date of Day 30. Owner: whoever monitors the portal queue — name that person in the policy.

Day 1 (Monday). Records clerk verifies identity via authenticated portal session, notes verification method in the log, and clarifies scope by portal message: date range, whether outside lab results are included, delivery format.

Days 2–5. Assemble. Lipid panels and other results from the chart, clinician notes, referral letter, problem and medication lists. Flag anything arguably outside the designated record set for privacy officer review rather than dropping it silently.

Day 6. Privacy officer reviews the flagged items and the fee calculation. If the patient is receiving an electronic copy of electronically maintained PHI, apply the flat fee or waive it.

Days 7–10. Deliver through the portal. Log delivery date, format, and recipient. If the patient asked for unencrypted email, document the warning you gave and the patient's choice to proceed.

If you will miss Day 30: send the written extension notice by Day 29 at the latest, with a specific completion date, and calendar that date. An extension notice with no follow-through is worse than no notice.

Information Blocking Sits on Top of All of This

The access rule is not your only exposure. Under the information blocking regulations, practices that unreasonably interfere with access, exchange, or use of electronic health information face disincentives applied through Medicare programs. A blanket policy of "we only release records by mail, in 30 days, after a notarized form" is exactly the pattern regulators are looking for.

Review the exceptions before you rely on one — they are narrow and fact-specific. ONC maintains current material on information blocking requirements and exceptions, and it is worth an hour of your privacy officer's time each year.

Five Fixes You Can Make This Month

  1. Timestamp receipt automatically. If your log records the date a clerk opened the request rather than the date it arrived, your clock is already wrong.
  2. Name owners by role in writing. Intake, verification, assembly, review, delivery. Five steps, named roles, one backup each.
  3. Publish the fee schedule at the front desk and in the portal, and give estimates on request.
  4. Split the two lanes — copy to patient versus copy to third party — in your form set and your training.
  5. Audit ten closed requests per quarter against the log: receipt date, verification method, delivery date, fee charged. Ten takes an hour and tells you whether the policy is real.

Breach reporting patterns published on the OCR breach portal show how often disclosure errors involve routine paperwork rather than sophisticated attacks — records sent to the wrong recipient, files handed to the wrong requester. A records workflow with named owners and a real log prevents more incidents than most security spending.

Start With the Contracts

Before your next audit, pull the vendor list for everyone who touches a records request and check whether each agreement is current and signed. If any are missing, build a compliant Business Associate Agreement in a few minutes and get it out for signature this week. The 30-day clock is easy to manage; an unpapered vendor relationship discovered mid-investigation is not.