A patient calls your front desk on a Tuesday afternoon. She has a hepatology appointment in eleven days and wants every liver enzymes result your practice has on file for the past two years, plus the consult note from the gastroenterologist you referred her to last spring. She wants it emailed. She does not want to use the portal because she never finished enrolling.

That single call starts a 30-day clock, raises a verification question, implicates at least two fee rules, and may pull in a vendor you signed a contract with three years ago. This article walks the administrative workflow — who owns each step, what the deadlines are, and where practices most often get written up. It is not clinical guidance and says nothing about interpreting results.

The 30-Day Clock Starts When the Request Arrives, Not When You Notice It

Under 45 CFR 164.524, a covered entity must act on an individual's access request within 30 calendar days of receipt. One 30-day extension is available, but only if you notify the individual in writing within the original 30 days, state the reason, and give a date certain for completion. You get one extension, not a rolling series.

"Receipt" is the operative word. If the request arrives by voicemail Friday at 4:50 p.m. and nobody retrieves the message until the following Wednesday, you have already burned five days. If it comes to a general info@ inbox that a part-time staffer checks weekly, same problem.

Practical fix: name a single intake point and a single owner. Front desk, records clerk, and billing all need to know where a request goes the moment they recognize one. Then log the arrival date on the day it arrives.

  • Day 0 — request received, logged, date-stamped, assigned to a named person.
  • Day 1–3 — identity and authority verified; scope clarified in writing if ambiguous.
  • Day 3–10 — records assembled from all internal sources; fee estimate communicated if a fee applies.
  • Day 10–25 — production and delivery in the requested format.
  • Day 30 — hard deadline, or written extension notice sent with a specific completion date.

Clarifying scope does not pause the clock. If you email the patient on day 4 asking which date range she wants and she replies on day 12, you still owe production by day 30. Build your internal targets around day 20, not day 29.

Where Liver Enzymes Results Actually Live in Your Designated Record Set

Panels that include liver enzymes are among the most commonly ordered lab tests in primary care, which is exactly why the records trail is messy. A single patient's results can sit in four places at once, and all four are usually in scope.

Discrete interface results

Results that arrived through a lab interface land as structured data in your chart. These are the easy ones — they export cleanly and they belong in the designated record set.

Scanned and faxed reports

Not every result comes through an interface. Reports faxed from an outside draw site, an urgent care visit, or a hospital lab often live as scanned PDFs. They are still records you maintain, and records you received from another organization are part of your designated record set once you keep them to make decisions about the individual. "We didn't generate it" is not an exclusion.

Specialist correspondence

Because abnormal liver enzymes results frequently prompt a specialist referral, the chart often contains a consult letter or a hepatology summary. If you hold it, the patient can request it from you. You do not get to redirect her to the specialist as your only answer.

What sits outside the designated record set

A short list, and it is shorter than most staff assume: psychotherapy notes as defined by the Privacy Rule, information compiled in reasonable anticipation of litigation or a proceeding, and certain research-related records under specific conditions. Quality-improvement analyses and internal peer review that are not used to make decisions about the individual generally sit outside as well. Everything else you use to treat, bill, or make decisions about that patient is in.

Two things that are never grounds for withholding: an unpaid balance, and a clinician's preference that the patient discuss results at a visit first.

Quick Answer: How Long Do You Have to Fulfill a Liver Enzymes Records Request?

Thirty calendar days from the date you receive the request, with one available 30-day extension if you send the patient written notice inside the first 30 days explaining the delay and giving a completion date. Some states impose shorter deadlines, and the shorter timeline controls. Lab results are not exempt — since 2014, CLIA-certified laboratories must also release completed test reports directly to patients on request, and your practice's own copies of those reports remain subject to the HIPAA right of access.

Check your state statute before you rely on 30 days. Several states run 15 or 20 business days for records held by a provider, and a few impose separate deadlines for records requested in connection with a pending appointment.

Verification Without Building a Wall

You must verify the identity of the requester and the authority of anyone claiming to act for the patient. Section 164.514(h) requires reasonable verification. It does not authorize obstacles.

Reasonable: matching name, date of birth, and address on file; a callback to the number in the chart; a copy of a photo ID for a mail or email request; a signed request form for third-party directives.

Unreasonable, per OCR's right of access guidance: requiring the patient to appear in person when she asked for electronic delivery, requiring portal enrollment as the only pathway, requiring notarization, or requiring her to explain why she wants the records. She is going to a specialist. That is not your business, and you cannot condition release on hearing it.

Personal representatives and adult children

An adult son calling about his mother's records is not automatically a personal representative. You need documentation — a healthcare power of attorney, guardianship order, or equivalent authority under state law. Train the front desk to say "I can take the request and we'll verify authority" rather than either refusing outright or releasing on the strength of a confident voice.

Requests to send records to a third party

When a patient asks you to transmit a copy to someone else — a new gastroenterologist, an attorney, a family member — the request must be in writing, signed by the patient, and clearly identify the recipient and the delivery address. Keep the signed directive in your records-request file. It is the only thing standing between you and an impermissible-disclosure finding if the transmission goes to the wrong inbox.

Fees: The Patient Rate Versus the Third-Party Directive

When records go to the patient, you may charge only a reasonable, cost-based fee. That covers labor for copying (including electronic copying), supplies such as media or paper, postage, and preparation of an explanation or summary if the patient agreed to one in advance.

You may not charge for searching for or retrieving records. You may not charge for staff time spent verifying identity, reviewing for accuracy, or clicking through your system to locate a lab result from eighteen months ago. That distinction is where most fee disputes originate.

Following the 2020 decision in Ciox Health, LLC v. Azar, the patient-rate cap no longer applies as a federal matter to records the patient directs you to send to a third party. State law may still cap those fees, and many states do. Document which rule you applied on each request.

Give the patient a fee estimate before you produce, and be prepared to explain the components. A written fee schedule posted at the front desk and on your website eliminates most arguments before they start.

Format, Delivery, and the Unencrypted Email Problem

If the patient requests an electronic copy and you can readily produce it in that form, you must. If you cannot produce the exact format requested, you and the patient agree on an alternative readable electronic format.

She asked for email. If she requests unencrypted email after you explain the risk, you must honor it. Document the warning and her choice in the request log. Refusing to email results — or steering every request to the portal — is the single most common access complaint OCR has fielded under its Right of Access Initiative, which has produced dozens of settlements with practices of every size since 2019.

Vendors in the Chain: Who Needs a BAA

Walk the path a liver enzymes result travels out of your office and count the third parties.

  • Release-of-information or copy service — business associate. Handles PHI on your behalf.
  • Scanning or document-digitization vendor — business associate.
  • Secure messaging or encrypted email platform — business associate.
  • Courier or records-transport service that handles paper charts — business associate, notwithstanding the conduit argument that vendors sometimes raise.
  • Reference laboratory receiving your order — typically a covered entity in its own right; disclosures for treatment do not require a BAA.
  • Shredding vendor — business associate.

If any name on that list is missing a signed agreement, that gap will surface during an access complaint, because OCR's request letters routinely ask who touched the records. If you need to close a gap this week, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription. That is faster than routing a redline through counsel for a scanning vendor you onboarded in a hurry.

Review the agreements annually against your actual vendor list, not against last year's list. Practices add vendors between reviews and forget.

Information Blocking Sits on Top of the Right of Access

The HIPAA right of access is not the only rule in play. As a healthcare provider, your practice is an actor under the information blocking regulations, and a practice that delays or discourages access to electronic health information may face consequences separate from a HIPAA finding. The eight regulatory exceptions are narrow and fact-specific; "the physician wants to discuss results first" is not among them.

ONC maintains current material on scope, actors, and exceptions on its information blocking resource pages. Have your privacy officer read the exception list once a year and confirm your release practices do not quietly rely on one that does not exist.

Three Artifacts That Prove You Have a Process

When a complaint lands, OCR does not evaluate your intentions. It evaluates documents. Three of them do most of the work.

  1. A request log with date received, requester, verification method, scope, fee charged, format delivered, date delivered, and the name of the person who fulfilled it. One row per request, no exceptions.
  2. A written fee schedule showing your cost-based calculation, with the search-and-retrieval exclusion stated explicitly.
  3. A denial log recording every partial or full denial, the regulatory basis, and whether the patient was given the required written notice and review rights.

Store all three where a surveyor can find them in under five minutes. Your policies, risk analysis, and training records belong in the same place — if that documentation set is scattered or stale, automated HIPAA risk analysis and policy generation is a reasonable way to rebuild it without starting from a blank page.

For the technical safeguards side of electronic delivery — encryption decisions, transmission security, audit logging on records exports — HHS keeps its guidance collected under the Security Rule. And if your practice operates its own CLIA-certified lab, review the patient-access provisions alongside the CLIA program materials CMS publishes, since both frameworks apply to the same test report.

Run the Tuesday Scenario as a Drill

Take the call described at the top and walk it through your actual staff, this month. Who logs it? Who verifies? Who pulls the scanned outside reports, not just the interfaced ones? Who calculates the fee, and can they explain why search time is excluded? Who signs off on emailing an unencrypted copy at the patient's written request?

If the answers are vague at any step, that is your finding — and you found it before OCR did. Close the vendor agreement gaps first, since those take a signature rather than a culture change. Build the missing BAAs this week, then fix the intake point, then write the log.