A patient calls your front desk on a Tuesday. She was seen for iliotibial band pain eleven months ago, sent for imaging, referred to a physical therapist down the street, and now her attorney wants "the complete file." Your receptionist takes a message. It sits in a shared inbox for nine days. That nine days is already a third of the clock you have under the HIPAA right of access — and your practice has not yet decided whether the request is even from the patient or from her lawyer, which changes the paperwork, the fee rules, and the delivery method.

This post is about the records workflow, not the condition. If you run a sports medicine, orthopedic, primary care, or physical therapy practice, iliotibial band cases are a useful stress test for your release-of-information process, because they almost always involve more than one organization.

Why Iliotibial Band Encounters Scatter Records Across Four Organizations

A typical musculoskeletal episode of this kind starts in primary care or urgent care, may involve an imaging center, frequently involves a referral to a specialist, and often ends with a course of physical therapy. That is up to four covered entities, each with its own designated record set, its own release-of-information staff, and its own turnaround.

Your patient does not see four organizations. She sees one injury. When she asks for "my records," she means all of it — and when she does not get all of it, she does not blame the imaging center. She blames whoever answered the phone.

Your obligation is narrower than her expectation. You must produce what your practice maintains in its designated record set. But your workflow should include a plain-language line telling her which records live elsewhere and who to contact, because that single sentence prevents most access complaints from escalating.

How Long Do You Have to Fulfill a Records Request?

Thirty calendar days from receipt of the request. Not thirty business days. Not thirty days from when the chart lands on the medical records coordinator's desk.

You may take one 30-day extension, and only one. To use it, you must notify the individual in writing within the original 30 days, state the reason for the delay, and give a date by which you will produce the records. HHS lays this out in its individual right of access guidance.

Two things trip practices up here. First, several states impose shorter deadlines than HIPAA for medical records — where state law is more protective of the individual, it controls, and your policy should reflect whichever clock is tighter. Second, a request received by voicemail, patient portal message, fax, or handed to a nurse at checkout is still a received request. The clock does not wait for the request to reach the right desk.

What Actually Starts the Clock

  • A portal message asking for visit notes
  • A signed authorization faxed by a law firm
  • A verbal request at the front desk, if your policy permits verbal requests
  • A form submitted through your website
  • An email to any published practice address

Pick one intake channel, publish it, and train staff to route everything else into it the same day. Date-stamp on receipt, not on triage.

Verification Without Obstruction

You must verify the identity and authority of the requester. You may not use verification as a stall tactic, and OCR has said so repeatedly in its right-of-access enforcement work, which has produced dozens of settlements with practices of every size since 2019.

Reasonable verification for an established patient looks like this:

  1. Match two identifiers already in the chart — date of birth plus address, or date of birth plus last four of an identifier you already hold.
  2. For portal requests, the authenticated session is your verification. Do not make a portal user re-fax a driver's license.
  3. For phone requests, verify by callback to the number on file, or by mailing to the address on file.
  4. For third-party requests, verify the signature and the scope of the authorization or directive — not the patient's identity a second time.

Unreasonable verification looks like requiring a notarized form, requiring in-person pickup when the patient asked for electronic delivery, or requiring the patient to explain why she wants her iliotibial band records. You cannot ask why. That question alone has landed practices in settlement discussions.

Third-Party Directives Versus Authorizations

These are different instruments and your staff must be able to tell them apart in five seconds.

A right-of-access request with a third-party directive is the patient exercising her own access right and telling you to send the copy somewhere else — her attorney, her employer's return-to-work coordinator, her new physical therapist. It must be in writing, signed by the individual, and clearly identify the recipient and where to send the copy.

A HIPAA authorization under 45 CFR 164.508 is a third party requesting records with the patient's permission. It has required elements: description of information, purpose, expiration, right to revoke, and the recipient. Law firms usually send these.

The distinction matters because the fee rules differ. A 2020 federal district court decision narrowed how the patient-rate fee limitation applies to records directed to third parties. If your billing team is applying the patient rate to attorney-directed requests without checking, or charging full state-schedule copy fees on a patient's own access request, get counsel to review the fee matrix before your next audit.

What Belongs in the Designated Record Set for a Musculoskeletal Episode

The designated record set is not "the EHR chart." It is the medical and billing records you use to make decisions about the individual, wherever they live.

For an iliotibial band episode, that commonly includes:

  • Office visit notes and the referral letter to the specialist
  • Imaging reports you received back, and images if your practice maintains them
  • Physical therapy evaluation and progress notes, if PT is part of your organization
  • Gait or video assessment files stored on a clinic tablet or in a separate exercise-tracking platform
  • Billing records, superbills, and claim adjudication documents
  • Correspondence about work restrictions or activity clearance letters

The Data That Is Not in Your EHR

This is where practices lose. Video gait analysis sitting in a cloud folder, patient-reported outcome scores collected in a survey tool, and photos taken on a clinic-issued phone are all part of the record if you use them for care decisions. If a patient asks for her complete iliotibial band file and you produce only the EHR export, you have under-produced.

Run an inventory once a year: every place clinical content is created or stored, who controls it, and whether a signed agreement covers it. That inventory doubles as the input to your risk analysis.

The Vendor Layer Nobody Maps Until a Request Lands

Trace a single records request and count the outside parties it touches. A release-of-information vendor pulling and mailing the copy. A fax-to-email service. A cloud storage provider holding the gait video. A transcription service. A billing company producing the claims portion. A secure messaging platform delivering the file.

Each one is a business associate. Each one needs a signed Business Associate Agreement in place before it touches protected health information — not after, and not "we have their standard terms in the click-through somewhere." HHS explains the scope of these relationships in its business associate guidance.

If you find a gap during this exercise — and most practices do, usually with a fax service or a small imaging vendor — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription. That is faster than waiting on a vendor's legal department to send you a template they wrote in 2019.

A Worked Timeline: Day 0 to Day 30

Assign these to named roles, not to "the office."

  1. Day 0 — Front desk logs the request in the ROI tracker with a receipt date and channel. Routes to the records coordinator by end of day.
  2. Day 1 — Records coordinator classifies it: patient access, third-party directive, or authorization. Verifies identity or signature. Confirms requested format and delivery method.
  3. Day 2-3 — Coordinator pulls the designated record set, including non-EHR sources from the annual inventory. Flags anything requiring clinical review, such as records originating from another provider.
  4. Day 5 — Fee calculated against the correct schedule. Patient notified in advance of any charge. No advance-payment demand that functions as a barrier.
  5. Day 7-10 — Copy assembled, quality-checked against the request scope, and delivered by the method the patient chose.
  6. Day 25 — If unfulfilled, privacy officer sends the written extension notice with a reason and a firm completion date. This is a hard calendar reminder, not a judgment call.
  7. Day 30 — File closed in the tracker with delivery evidence attached.

Most iliotibial band record sets are small. If yours routinely need the extension, the problem is routing, not volume.

Denials, Partial Production, and Information Blocking

Grounds for denying access are narrow. Psychotherapy notes, information compiled for legal proceedings, and a small set of reviewable denials — that is essentially the list. "The provider hasn't signed the note yet" is not a ground. Neither is an unpaid balance.

If you deny in part, you must produce everything else and give a written denial explaining the basis and the review process. Blanket denials get complaints filed, and complaints land in the public OCR record when they escalate.

Separately, unreasonable delay in releasing electronic health information can implicate the information blocking rules, which reach practices as actors independent of HIPAA. ASTP/ONC maintains current material on information blocking exceptions and obligations. Your access policy and your information blocking posture should be reviewed together, not in separate binders.

Prove It Later: What Your Tracker Must Capture

When OCR asks about a request from eighteen months ago, memory is worthless. Your tracker should record receipt date and channel, requester type, verification method used, scope requested, date and method of delivery, fee charged and the schedule applied, extension notice if any, and the staff member who completed each step.

Six fields, one row per request, reviewed monthly by the privacy officer. Practices that run this discipline resolve access complaints in a single response letter. Practices that don't spend three weeks reconstructing an email thread.

Where to Start This Week

Pull your last twenty records requests. Check three things: the receipt date logged, whether the format the patient asked for is what you sent, and whether every vendor that touched those files has a current signed agreement.

If the third check comes back thin, close the gap first — build the missing Business Associate Agreements and get them countersigned before the next iliotibial band file leaves your building. If the broader documentation set is stale, automating your risk analysis and policy package gets the paperwork current without a consulting engagement. Either way, do it before a request forces the issue.