A fax arrives Tuesday at 8:40 a.m.: a personal injury firm wants the "complete file" for a patient your practice saw three weeks ago before she was sent to the emergency department with Ludwig's angina. Attached is a signed authorization. Your front desk scans it, drops it in a folder, and nobody touches it for nine days. Your 30-day clock started on day one, not on day nine.

This post is about the records and disclosure workflow that surrounds a case like that — verification, timelines, fee rules, vendor contracts, and documentation. It is not clinical guidance and contains none. It is written for the person in your office who signs the release-of-information log.

Why a Ludwig's Angina Encounter Splits the Record Across Four Custodians

Ludwig's angina is a deep neck space infection that frequently originates from a dental source and is typically managed emergently in a hospital setting with specialist involvement. That single clinical fact has an enormous administrative consequence: the record of one patient's episode almost never lives in one place.

A realistic custodial map looks like this: a general dentist or primary care office with the initial visit note and imaging, an urgent care with a triage record, a hospital emergency department, an inpatient service, a surgical or ENT service, an anesthesia group billing separately, and a radiology group that read the CT under its own tax ID. Seven potential custodians. Six of them are not you.

Your obligation under the Privacy Rule extends only to the designated record set you maintain. You are not required to chase down the hospital's operative record so a requester can have one tidy PDF. But you are required to produce what you hold — including records you received from other providers and used to make decisions about that patient. A discharge summary faxed back to you and filed in the chart is part of your designated record set. Staff routinely, and wrongly, exclude it.

Build the custodian map before the request lands

For any encounter that ends in an emergent transfer, have the clinical staff note in the chart where the patient was sent and which entity accepted them. When the request arrives, your ROI clerk can then send a two-sentence cover letter naming the other likely custodians. That single habit cuts follow-up calls and complaint risk more than any policy language.

How Fast Must You Respond to a Ludwig's Angina Records Request?

Under 45 CFR 164.524, you must act on an individual's request for access within 30 calendar days of receipt. You may take one 30-day extension, but only if you give the individual a written statement within the original 30 days that explains the reason for the delay and states the date you will complete the request. There is no second extension.

Four operational points your staff get wrong:

  • The clock starts at receipt by your organization, not when your release-of-information vendor opens the ticket. A fax sitting in a tray on Friday started running on Friday.
  • Calendar days, not business days. Holidays do not toll anything.
  • State law can be shorter and often is. Texas and California, among others, impose tighter deadlines. The shorter clock governs.
  • "Acting on" means providing access or issuing a written denial with the required content — not sending an acknowledgment letter.

HHS maintains detailed guidance on an individual's right of access under HIPAA, and the Office for Civil Rights has resolved a long series of enforcement matters arising from nothing more complicated than practices that answered slowly or not at all. Access complaints are cheap for a patient to file and expensive for you to defend.

Verification: Who Is Actually Asking, and Under What Authority

45 CFR 164.514(h) requires you to verify the identity and authority of a requester before disclosing. In a Ludwig's angina case, the requester is frequently not the patient, and the reason is administrative rather than sinister: the patient may have been hospitalized and unable to sign anything for several days.

Personal representatives

A spouse, parent, or agent under a health care power of attorney may stand in the patient's shoes as a personal representative under 45 CFR 164.502(g). Scope is defined by state law. Your file should record three things: the identity of the representative, the document or legal relationship establishing authority, and the date staff confirmed it. "Wife" written on a sticky note is not verification.

Note the asymmetry your staff must learn: a family member who was present during an emergency and legitimately received a verbal update under 45 CFR 164.510(b) does not automatically have standing to request the written chart six weeks later.

Attorney requests and third-party directives

An attorney letter with a signed HIPAA authorization is a disclosure under 164.508 — a different animal from a patient's right-of-access request. A patient may also direct you to send a copy to a third party, but that directive must be in writing, signed by the individual, and clearly identify the recipient and delivery address.

The distinction matters financially. The 2020 Ciox Health v. Azar decision vacated the extension of the patient-rate fee cap to third-party directives and limited the statutory third-party directive requirement to PHI maintained in an electronic health record. Practically: when the patient asks for a copy for herself, the cost-based fee limits apply. When a law firm requests records under authorization, your state's copying fee schedule generally governs. Train your ROI clerk to sort inbound requests into those two buckets on arrival, because the wrong bucket produces either an overcharge complaint or lost revenue.

Subpoenas and payer requests

A subpoena that is not accompanied by a court order requires satisfactory assurances under 164.512(e) — notice to the individual or a qualified protective order. Do not let a process server's confidence substitute for that check. Payer requests for the encounter, by contrast, generally fall under payment activities and do not require authorization; HHS explains the boundaries of disclosures for treatment, payment, and health care operations.

Your Copy Service, Fax Platform, and Courier Are Business Associates

Fulfilling a Ludwig's angina request usually touches vendors: an outsourced release-of-information company, a cloud fax or secure email provider, a scanning or document imaging service, a transcription vendor, a courier, and sometimes a translation service. Every one of them creates, receives, maintains, or transmits PHI on your behalf. Every one of them needs a Business Associate Agreement in place before the first record moves.

The gap I see most often in small dental and primary care offices is the copy service engaged years ago by a former office manager, with no executed agreement anyone can locate. If you cannot produce the contract during an OCR data request, the practical answer is not to argue — it is to paper the relationship immediately. A six-step wizard that generates a signature-ready Business Associate Agreement with PDF and DOCX export closes that gap in an afternoon, as a one-time purchase rather than another subscription line item.

Then reconcile the list. Pull your ROI log for the last quarter, list every external party that received or handled a record, and match each against your executed BAAs. Anything unmatched is either a business associate without an agreement or a disclosure you cannot explain.

Denials, Redactions, and the Records You Must Still Send

Grounds for denying access are narrow. Unreviewable grounds include psychotherapy notes and information compiled in reasonable anticipation of litigation. Reviewable grounds — chiefly a licensed health care professional's determination that access is reasonably likely to endanger someone — require you to offer review by a licensed professional who was not involved in the original denial.

Three things that are not valid grounds for denial or delay:

  1. An outstanding balance on the account.
  2. The patient has not signed your intake or arbitration paperwork.
  3. The chart contains records originally created by another provider.

If part of the record is properly withheld, you must still provide the remainder and issue a written denial explaining the basis and the review and complaint rights. Note also that if the chart contains substance use disorder treatment records governed by 42 CFR Part 2 — a real possibility in dental and emergency records — the alignment rule finalized in 2024, with a compliance date in February 2026, changed how consent and redisclosure notices operate. Route those charts to the privacy officer rather than the front desk.

A Worked 30-Day Timeline

Assign names, not departments.

  • Day 0: Request received. Front desk date-stamps, scans, and enters it in the ROI log within one business day. Log captures requester type, date received, and due date calculated automatically.
  • Day 1–2: ROI clerk verifies identity and authority. Sorts request into right-of-access or authorization bucket. Flags anything involving a personal representative, subpoena, or Part 2 content to the privacy officer.
  • Day 3–7: Chart assembled, including outside records received and filed. Clinician review only if a denial ground is genuinely in play — not as a routine step, because routine clinical review is the single largest cause of missed deadlines.
  • Day 8–12: Fee calculated against the correct schedule. Patient notified of fee in advance if applicable.
  • Day 13–20: Records transmitted in the form and format requested if readily producible. If the patient asked for unencrypted email and was warned of the risk, that request is honored.
  • Day 25 at the latest: If the request will not be completed, the extension letter goes out — with a reason and a firm completion date.
  • Day 30 or 60: Close the log entry with the delivery method and confirmation.

Documentation That Survives an OCR Complaint

Assume every access request may become a complaint. Your defense is a contemporaneous log, not a recollection. Keep the request itself, the verification evidence, the fee calculation, the transmission confirmation, and any denial letter for six years.

Separately, maintain your accounting of disclosures under 164.528 for disclosures outside treatment, payment, and operations — the subpoena response, the public health report, the law enforcement disclosure. Patients rarely ask for it. When they do, it is usually because a lawyer told them to, and the request arrives on the same day as everything else.

If a record goes to the wrong fax number or the wrong attorney, run the four-factor risk assessment and document it before deciding whether notification is required. Reportable breaches of 500 or more records appear on the public OCR breach portal, and misdirected disclosures from records departments are a recurring category there.

Start With the Two Documents You Can Fix This Week

Pull your ROI log and check whether due dates are calculated at intake. Then pull your vendor list and confirm an executed agreement exists for every party that touches a chart on its way out the door. If one is missing, generate a signature-ready BAA and get it countersigned before the next Ludwig's angina request — or any request — reaches your fax tray. For the broader policy set and risk analysis documentation that OCR asks for in the same breath, automated compliance document generation covers the rest of the file.