LPR Reflux Records: What to Capture, Keep, and Release
A patient calls Thursday at 4:40 p.m. She was seen in your office for hoarseness and throat clearing, referred to ENT, scoped there, and sent for a pH study at a third location. She wants "everything" — including the scope video — sent to a specialist in another state, and she wants it before her Monday appointment.
Your front desk has no idea where the video lives, whether it counts as part of the chart, or who signs off on sending it. That is the actual administrative problem behind an lpr reflux encounter: the clinical work is somebody else's job, but the records trail is yours. This post covers what your staff captures, what you must retain, what you must release, and which vendors need a signed agreement before any of it moves.
Why One LPR Reflux Workup Produces Records in Three Systems
Laryngopharyngeal reflux presentations commonly move between primary care, otolaryngology, and gastroenterology, and often involve speech-language pathology. That is uncontroversial context, and it is the only clinical fact you need here. The administrative consequence is that a single episode of care generates protected health information in organizations you do not control, in file formats your EHR was not built to hold.
Typical artifacts from one of these episodes:
- Referral letters and consult notes moving in both directions between primary care and ENT
- Laryngoscopy stills and video, frequently stored in a scope capture appliance or image archive that sits beside the EHR, not inside it
- Study reports generated in a device manufacturer's cloud portal and delivered as PDFs
- Speech-language pathology evaluations and session notes, sometimes on a separate schedule and separate template set
- Swallow study imaging in a radiology PACS at an imaging center
- Patient-completed symptom questionnaires and voice-use diaries, often collected on paper or through a portal form
- Employer or school accommodation paperwork for patients whose occupation depends on their voice
Seven artifacts, potentially five custodians. When a request arrives, someone in your office has to know which of those you hold, which you received, and which you never had.
Deciding What Belongs in the Designated Record Set
The designated record set is the medical and billing records your practice maintains, plus any other records you use to make decisions about the individual. It is not "whatever the EHR prints."
Media files and outside-source documents
If a clinician looked at a laryngoscopy still or video and documented a finding from it, that image is part of the record set. So is a consult letter you received from ENT and filed. So is the device vendor's study report you scanned in. Records you received from another provider and used in your own decision-making do not get excluded because you did not author them.
What sits outside the set: quality-assurance and peer-review material not used to make care decisions, information compiled in anticipation of litigation, and psychotherapy notes as narrowly defined by the Privacy Rule. Everything else in the chart is presumptively releasable to the patient.
Write it down before you are asked
Produce a one-page inventory that names every system holding record-set content for these encounters, the owner of each system, and how to export from it. Include the scope capture box in the procedure room, the device vendor portal, the fax archive, and the scanning queue. Review it whenever you add a device or a portal. If your release-of-information staff has to improvise this on a Thursday afternoon, you will miss something.
The 30-Day Clock on an LPR Reflux Records Request
How long do you have? Under the HIPAA right of access, you must act on an individual's request no later than 30 calendar days after you receive it. You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason, and give a date by which you will act. There is no second extension. Several states impose shorter deadlines, and the shorter deadline wins.
Format: you must provide the records in the form and format the individual requests if it is readily producible — including electronic copies, and including sending them to a third party the individual designates in a signed, written direction that identifies the recipient and where to send it.
Fees: you may charge a reasonable, cost-based fee limited to labor for copying, supplies, postage, and preparation of an agreed-upon explanatory summary. You may not charge for search and retrieval. HHS guidance on the individual right of access is the document to hand your ROI staff, and OCR has pursued a long series of enforcement actions specifically about access delays and inflated fees.
Also relevant: information blocking. Withholding or delaying electronic health information that a patient or their new provider is entitled to receive can implicate the Cures Act rules unless an exception applies. The federal information blocking materials spell out the exceptions, including content and manner. "The video is in a different system and we don't usually send those" is not one of them.
Vendors Who Touch These Files and Need a Signed BAA
Every organization in the chain that creates, receives, maintains, or transmits PHI on your behalf is a business associate. For this encounter type, run down the list honestly:
- The scope capture or image archive vendor, including any remote support arrangement
- The pH or impedance monitoring device manufacturer, if study data lands in their cloud portal
- Transcription services and ambient documentation tools used during ENT and SLP visits
- Your fax or direct-messaging service and any referral network you route consults through
- Outsourced release-of-information vendors
- Large-file transfer or secure link services used to move video that will not fit through email
- Interpretation and translation services present during the visit or on the phone
- Cloud backup and offsite storage, including encrypted backup where the vendor holds no key
The conduit exception is narrow — think postal service and couriers. A cloud storage provider that maintains PHI is a business associate even if it never views the data. HHS publishes sample business associate agreement provisions, but sample language still has to be turned into an executed document with your entity names, your termination terms, and your return-or-destroy requirement.
If you found a vendor on that list without a countersigned agreement — most practices do, usually the imaging appliance or the file-transfer tool — you can generate a signature-ready Business Associate Agreement through a six-step wizard and have a PDF or DOCX in front of the vendor the same afternoon. One-time purchase, no subscription. Close the gap while you are still looking at it.
The clause that decides your retention problem
Scope video is large. Vendors manage that with storage tiers and overwrite cycles you never see. Before renewal, get written answers to three questions: how long are studies retained in the platform, what happens to them at contract termination, and what export format do you get if you leave. Then reconcile those answers with your own retention schedule. A vendor purge cycle that runs shorter than your state's chart retention requirement is a compliance problem hiding in a technical setting.
Releasing to Employers, Insurers, and Attorneys
Patients whose work depends on their voice — teachers, clergy, performers, call-center staff — often need accommodation or leave paperwork after this kind of workup. That request is not a right-of-access request, and it does not travel on the same paperwork.
Disclosure to an employer requires a valid, specific authorization: named recipient, described information, purpose, expiration, signature, and the required statements about revocation and redisclosure. "Send my file to HR" scrawled on a sticky note is not an authorization. Assign one owner for these — usually the practice manager or privacy officer — and route every employer, insurer, disability carrier, and attorney request through that person.
Two distinctions your staff will get wrong if you do not train them:
- Access directed to a third party is still a right-of-access request and keeps the access fee limits. An authorization-based disclosure to an attorney is not, and may be billed under your state's schedule.
- Minimum necessary does not restrict disclosures to another provider for treatment, so a full referral packet to ENT is fine. It absolutely does apply to the disability carrier, which should get the specific documentation the form requests and nothing else.
A Worked Ten-Day Sequence
Same Thursday call, handled properly. Day 0: front desk logs the request in the ROI tracker with date and time received, and captures the patient's signed direction naming the out-of-state specialist and delivery method. Do not let the clock start informally in someone's inbox.
Day 1: ROI staff verify identity per policy, then pull from the inventory — EHR chart, scanned ENT consult, scanned study report, and the scope media from the capture system. Day 2: privacy officer reviews for anything outside the designated record set and confirms the video export format the receiving practice can actually open.
Day 3: delivery. If the video exceeds your secure email limit, it goes through the file-transfer vendor you have a BAA with — not a personal cloud drive. Day 4: log what was sent, to whom, in what format, on what date, and the fee charged if any. Day 5 onward: if any piece is still outstanding, the written extension notice goes out well before day 30, not on day 29.
Two more clocks worth posting on the wall. Amendment requests: 60 days, with one 30-day extension. HIPAA documentation retention — policies, authorizations, notices, risk analyses: six years. Chart retention itself comes from state law and payer contracts, and varies sharply for minors.
Where This Workflow Usually Fails
Not in the policy binder. It fails at the procedure room appliance nobody inventoried, the device portal login shared among four staff, and the referral coordinator who forwards packets from a personal email account when the fax jams.
Those are risk analysis findings, and they belong in a document you can hand to an auditor. NIST's SP 800-66r2 maps Security Rule requirements to practical safeguards and is a reasonable frame for the technical side. If you would rather not build the risk analysis, policy set, and supporting documentation from scratch, automated HIPAA risk analysis and policy generation will get you a defensible baseline faster than a consultant's first invoice.
Start with the inventory. Then fix the vendor agreements — if any system holding these records is missing a signed BAA, build the agreement and send it for signature today rather than waiting for the next records request to surface the gap.