Lipase Levels: Sharing Lab Results Between Providers
At 3:40 on a Tuesday, your urgent care sends a chemistry panel with lipase levels, a CT report, and two pages of nursing notes to a gastroenterology group forty miles away. The referral coordinator calls your front desk twenty minutes later asking for the rest of the chart. Your medical assistant puts her on hold and asks you whether the patient signed anything.
Nobody signed anything, and nobody needs to. Provider-to-provider disclosure for treatment is permitted under HIPAA without patient authorization. The compliance exposure in this scenario is not the legal authority — it's the plumbing: which fax line, which portal, which vendor, which log entry, and who verified the receiving party before pressing send.
Why a Pancreatic Workup Generates So Much Records Traffic
Elevated lipase levels are a common trigger for specialist referral, and specialist referral is a records event. The receiving gastroenterologist wants the serial lab values, the imaging report, the medication list, and often the prior year of encounter notes. Some of that lives in your EHR, some in a reference lab's system, some in a hospital's imaging archive.
That means a single clinical question produces disclosures from three or four organizations, frequently within the same 48 hours. Each disclosure has its own channel, its own vendor, and its own way of failing. Your job is not to evaluate the lab result — it's to make sure the record arrives at the right organization, intact, with an audit trail you can reconstruct eleven months later when someone asks.
Do You Need Authorization to Send Lipase Levels to a Specialist?
No. Under 45 CFR 164.506, a covered entity may use and disclose protected health information for treatment, payment, and health care operations without patient authorization. Sending lipase levels and supporting records to a specialist you referred the patient to is a treatment disclosure. Additionally, the minimum necessary standard at 45 CFR 164.502(b)(2)(i) does not apply to disclosures to another provider for treatment purposes — you may send the full relevant record. State law, patient-requested restrictions under 164.522, and 42 CFR Part 2 substance use records can narrow this; check those before you assume a blanket yes.
HHS publishes a plain-language fact sheet on this exact scenario in its permitted uses and disclosures guidance. Print it. Put it in the front-desk binder. The single most common workflow drag in a specialty referral is a staff member who believes an authorization form is required and holds the packet for three days waiting on a signature that was never necessary.
Four Channels, Four Sets of Controls
Every practice I have audited sends referral records four ways, and most have written policy for only one of them.
Fax and eFax
Still the default for specialist referrals, and still the leading source of small-scale misdirected-PHI incidents. Controls that actually work: a maintained directory of verified destination numbers owned by one named person, a mandatory cover sheet, a confirmation page retained with the referral log entry, and a rule that no number is dialed manually if a stored entry exists.
If you use a cloud fax service, that vendor is a business associate. It stores images of your records. It needs a signed BAA and it needs to be on the vendor inventory you review annually.
Direct Secure Messaging and HIE Query
Better authentication, better audit logs, and a much lower misdirection rate — but only if your staff can find the receiving provider's address. Assign someone to maintain a referral address book inside the EHR for the ten specialists you send to most often. That single task removes more risk than most annual training modules.
If you participate in a health information exchange or a TEFCA-connected network, know what your participation agreement says about query responses. Another organization may pull records containing lipase levels without a phone call to your office. That is by design; your obligation is to have configured the disclosure settings deliberately rather than by default.
Patient Portal and Third-Party Apps
Patients now route their own records constantly, including to apps that are not covered entities and not your business associates. Once the patient directs the disclosure to an app of their choosing, HIPAA protections generally do not follow the data — but the FTC's Health Breach Notification Rule may apply to that app. Your staff should not be talking patients out of using apps; they should be documenting that the patient directed the transmission.
Phone, Courier, and the Hand-Carried Envelope
Verbal disclosure to a treating provider is permitted. Verbal disclosure to someone who says they are a treating provider is a breach waiting for a report number. Adopt a callback rule: if an unfamiliar office calls for records, your staff takes the request, ends the call, and dials the practice's published main number. Two minutes, and it defeats the most common social engineering attempt in ambulatory care.
The Vendor Layer Behind a Single Referral Packet
Trace one referral containing lipase levels and count the organizations that touch it:
- Your EHR host and its interface engine
- The reference lab (a covered entity in its own right — not your business associate when it performs the test)
- The lab's results-delivery portal vendor, if separate
- Your eFax or Direct messaging provider
- Your referral management or care coordination platform
- Any scanning, transcription, or release-of-information service
- Your backup and archive vendor
Six or seven agreements for one packet. The distinction that trips people up: a clinical laboratory performing a test at your order is acting as a covered entity providing treatment, so no BAA is required for that relationship. The vendor that hosts the results interface, or that scans results into your chart, is a business associate and does require one.
If your vendor inventory is a spreadsheet nobody has opened since the last owner left, start there. A practice can close the common gaps in an afternoon using a signature-ready business associate agreement generator rather than emailing a fifteen-year-old Word template to a vendor whose legal team will redline it into something you don't recognize.
Right of Access and Information Blocking Collide at the Results Release
Two obligations sit on top of the referral workflow, and they run on different clocks.
Right of access: when the patient asks for their own records, you have 30 days, with one 30-day extension if you notify them in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. OCR has treated access delays as an enforcement priority for years and has resolved dozens of cases under its right of access initiative. The HHS right of access guidance is the reference your ROI staff should be working from.
Information blocking: under the 21st Century Cures Act rules, electronic health information — including lab results — must be released to the patient without delay unless an exception applies. "We hold results for 72 hours so the physician can call first" is not an exception. Practices still running that policy in 2026 are exposed. Review the current exceptions on healthit.gov's information blocking page and align your release settings to them.
The practical consequence: a patient may see lipase levels in the portal before the ordering clinician has reviewed them. Your front desk needs a script for the call that follows. The script covers scheduling and message routing — not interpretation. Nobody at the desk explains a number.
A Five-Day Worked Example
- Day 0, 3:40 p.m. — Clinician places referral in EHR. Referral queue task auto-assigns to the coordinator. Results, including lipase levels, are released to the portal per the standing configuration.
- Day 0, 4:15 p.m. — Coordinator assembles the packet: labs, imaging report, med list, last two encounter notes. Sends via Direct message to the stored address for the receiving practice. Logs date, time, recipient address, and document list in the referral log.
- Day 1 — Specialist's office calls requesting prior-year notes. Coordinator confirms the caller against the stored practice number, sends the supplement, appends the log entry.
- Day 2 — Patient calls asking for a copy for a second opinion. This is a right-of-access request, not a treatment disclosure. It goes into the ROI queue with the 30-day clock, and the patient's chosen delivery method is documented.
- Day 5 — Privacy officer's weekly review: any fax confirmations missing, any log entries lacking a verified recipient, any packet sent to an address not in the directory. Three minutes per referral, and it produces the evidence you need if an incident surfaces later.
Four Failure Modes Your Referral Log Should Catch
Wrong recipient. Transposed fax digits, a stale Direct address, a specialist who moved practices. Caught by directory discipline and confirmation review.
Wrong patient. Two charts with the same surname, one open tab. Caught by requiring two identifiers on the cover sheet and a final match check before send.
Silent drop. The interface fails, the packet never arrives, the specialist assumes you didn't send, the patient waits three weeks for an appointment. Caught by tracking receipt confirmation, not just transmission.
Undocumented verbal disclosure. A nurse reads values over the phone to an office nobody verified. Caught by the callback rule and by logging verbal treatment disclosures even though the accounting-of-disclosures requirement at 164.528 exempts treatment disclosures. You log it for your own reconstruction, not for the patient's accounting report.
Put the Referral Path Into Your Risk Analysis
The Security Rule requires an accurate and thorough risk analysis, and OCR's enforcement record is full of organizations whose analysis never mentioned the systems where PHI actually moved. A referral pathway that carries lipase levels and every other lab value out of your building through four channels and seven vendors belongs in that document by name — with the threats, the existing controls, and the residual risk written down.
If your last risk analysis is a PDF from a prior owner with a different EHR listed on page two, it will not survive a records request from OCR. Tools that generate a current risk analysis and the supporting policy set get a small practice to a defensible baseline in days rather than the quarter it takes to build one from scratch. Note that no product — including any compliance platform — confers government certification; HHS does not certify or endorse compliance vendors. What you get is documentation you can hand to an investigator.
Pick one referral from last week. Trace it end to end: channel, recipient verification, log entry, vendor, BAA. If any link is missing, that's your next task — before the next packet leaves the building.