Osteochondritis Dissecans Referrals: Records Workflow
A 14-year-old presents to your family medicine clinic on a Monday with knee pain. By Friday, that chart has been touched by six organizations: your practice, the imaging center that performed the MRI, the pediatric orthopedic group 60 miles away, the payer processing a prior authorization, the image-exchange vendor moving the DICOM study, and the physical therapy clinic that got a heads-up call. That is the administrative reality of an osteochondritis dissecans referral — a condition that routinely involves advanced imaging and specialist evaluation, and therefore routinely moves protected health information across organizational boundaries.
This post is not about the condition. It is about the disclosure decisions your front desk, your release-of-information (ROI) staff, and your privacy officer make in that same week — which ones are permitted without authorization, which ones require paper, and which ones quietly create liability nobody notices until a complaint arrives.
Why an Osteochondritis Dissecans Referral Touches So Many Organizations
Referral-heavy encounters share a common administrative signature: multiple imaging studies, at least one out-of-network specialist, a payer authorization step, and frequently a non-clinical third party — a school, a sports program, a parent's employer — asking for something.
Osteochondritis dissecans cases fit that profile squarely. Most of these patients are adolescents, which layers minor-consent and personal-representative questions on top of everything else. The imaging is often the deciding artifact, which means large binary files move between organizations that may not share an EHR. And the referral frequently crosses state lines in rural service areas, which pulls in state-law variation on minor records.
Each of those characteristics maps to a specific control. Skip one and you get the classic pattern OCR sees repeatedly in complaints: records sent to the wrong specialist, imaging burned to a disc and handed to a parent without documentation, or a coach receiving clinical detail nobody authorized.
Do You Need an Authorization to Send Records to the Specialist?
No. Under 45 CFR 164.506(c)(2), a covered entity may disclose protected health information to another covered entity for that entity's treatment activities without patient authorization. Sending the office note, imaging report, and relevant history to the orthopedic specialist you are referring to is a permitted treatment disclosure. You do not need a signed release, and refusing to send it without one can create its own problems.
Two qualifiers your staff must internalize:
- Minimum necessary does not apply to treatment disclosures. HHS is explicit that the minimum necessary standard does not restrict disclosures to or requests by a provider for treatment purposes. Sending the full relevant record to the consulting specialist is appropriate. See the HHS minimum necessary guidance.
- Permitted is not the same as unverified. You still must confirm the recipient is who they claim to be and that the destination address, fax number, or direct address is correct. Verification failures — not authorization failures — drive most misdirected-record complaints.
The HHS overview of permitted uses and disclosures is worth printing and taping inside the ROI workstation. Front-desk staff who have read it stop asking patients to sign forms that HIPAA never required, which removes friction and reduces the odds of a delay complaint.
What the Treatment Exception Does Not Cover
The exception ends at the edge of treatment, payment, and health care operations. It does not cover:
- The high school athletic trainer or coach asking for clearance details
- The club sports organization requesting the MRI report for its participation file
- A parent's employer asking for documentation to support leave
- An attorney handling an injury claim
- Any life or disability insurer
Each of those requires a valid authorization under 45 CFR 164.508, signed by the patient or the personal representative, naming the recipient and describing the information with specificity. "All records" on an authorization from a third party is a signal to slow down, not to comply faster.
The Minor Patient Problem: Who Signs and Who Sees
Because osteochondritis dissecans is most often evaluated in adolescents and young adults, your ROI staff will spend real time on personal-representative questions. HIPAA generally treats a parent as the personal representative of an unemancipated minor, with exceptions tied to state law and to categories of care the minor may consent to independently.
Build a decision aid, not a memory test. Your one-page internal reference should answer:
- Age of majority in your state, and the date the chart flips.
- Which parent may request records when custody documents exist in the chart, and where those documents are stored.
- What happens at 18 — specifically, the portal-access transition. Proxy access granted to a parent when the patient was 14 must be terminated or re-authorized, and someone owns that task.
- Which state-law protections apply to portions of the record that may travel with an orthopedic referral (behavioral health notes, substance use records under 42 CFR Part 2, reproductive health entries under your state's rules).
The portal proxy issue is the one practices miss most consistently. A parent with lingering proxy access to a 19-year-old's chart is an impermissible disclosure occurring continuously, in writing, with a timestamp. Audit it quarterly.
Imaging Is the Weak Link in the Chain
The MRI report travels easily. The images do not. Practices default to one of three methods, and only one of them is clean.
Method 1: The Patient-Carried Disc
Handing imaging to the patient or parent is permitted — it is a disclosure to the individual. It is also the method with the least documentation. If you use it, log what was released, to whom, on what date, and who verified identity. When a specialist later claims they never received a study, that log is your only defense.
Method 2: Point-to-Point Transfer Between Facilities
Direct messaging, an HIE connection, or a query-based exchange under a national framework. Cleanest option when it exists. Confirm your imaging center actually participates before you promise the specialist's scheduler that images are on the way.
Method 3: A Third-Party Image Exchange Platform
This is where practices create unsigned business associate relationships. The cloud image-sharing service, the referral coordination platform, the secure file transfer tool your MA found — every one of them creates, receives, maintains, or transmits PHI on your behalf. Every one needs a signed BAA before the first study moves.
Run your referral pathway end to end and list every intermediary. If any of them lacks a current executed agreement, you can generate a signature-ready Business Associate Agreement and close the gap this week rather than after an incident forces the question.
The Requests That Arrive Two Weeks Later
The referral itself is the easy part. The follow-on requests are where practices lose control, because they arrive by phone, from people who sound legitimate, to staff who want to be helpful.
Script the three you will actually receive:
The school or athletic program. Route to authorization. If the record originated with your practice, HIPAA governs it; once it lands in a school's education records maintained by a school-employed provider, FERPA may govern the copy the school holds. Your obligation concerns the copy you hold. Do not let a school nurse's assurance substitute for a signed authorization.
The payer. Prior authorization and utilization review are payment activities. Disclosure is permitted without authorization, but minimum necessary does apply here. Send what the review requires, not the entire longitudinal chart. Train staff to read the payer's request and match it, then document what was sent.
The attorney or claims adjuster. Authorization or a qualifying legal process. Nothing goes out on a letterhead request alone. Log every one of these in your accounting-of-disclosures process where applicable.
A Five-Step Workflow You Can Assign by Role
Assign owners by title, not by name — staff turn over.
- Referral coordinator, day 0: Confirms the receiving practice's exact name, address, direct address or fax, and the specific clinician. Verifies against a maintained list, not against what a patient remembers. Documents the verification.
- Referral coordinator, day 0: Assembles the treatment packet — relevant notes, imaging report, medication list, prior conservative-care documentation. No authorization needed. Sends via the approved channel only.
- Imaging liaison, day 0–2: Confirms the study transferred and is readable at the destination. A failed transfer discovered at the specialist visit becomes a patient complaint about your office.
- Billing, day 1–5: Handles payer authorization under minimum necessary. Records what was disclosed and to whom.
- Privacy officer, monthly: Samples five completed referrals. Checks verification documentation, channel compliance, authorization presence for non-TPO disclosures, and portal proxy status for patients who turned 18 that month.
The 30-Day Clock, Separately
If the patient or parent asks for a copy of the record — including asking you to transmit it to the specialist — the right of access applies. You have 30 days, with one 30-day extension available if you notify them in writing of the reason and the expected date. Fees are limited to a reasonable, cost-based amount. HHS maintains detailed right of access guidance, and access failures have been the most consistently enforced category of HIPAA violation in recent years.
Information Blocking Sits on Top of HIPAA
HIPAA tells you what you may disclose. The information blocking rules tell you what you may not unreasonably withhold. A referral workflow that delays sending electronic health information because staff are waiting on an unnecessary form is not a privacy safeguard — it is a potential blocking practice, and it is the kind of routine delay that generates complaints from receiving practices and patients alike.
Review the current exceptions and definitions at healthit.gov, and make sure your written referral policy references them. Practices with a clean policy but a bottleneck at the fax machine are the ones that get caught.
What This Means for Your Documentation Set
Every element above should exist in writing before an incident forces you to reconstruct it: a referral and ROI policy, a verification procedure, a current business associate inventory with executed agreements, a portal proxy termination procedure, and a security risk analysis that actually names the image-exchange pathway as a system that transmits ePHI. That risk analysis is the single most commonly cited deficiency in OCR resolution agreements, and "we use a certified EHR" has never satisfied it.
If your documentation set is scattered across a shared drive and three former employees' email, automating your HIPAA risk analysis and policy documentation gets you to a defensible, dated, complete set faster than rebuilding it by hand. No product confers a government credential — HHS does not certify or endorse compliance software — but a current, written, organization-specific document set is exactly what an investigator asks for first.
Pick one recent osteochondritis dissecans referral out of your files this week. Trace it: every organization it touched, every channel it used, every signature that should exist. Whatever gaps that single trace exposes are the gaps in every referral you send. Fix the workflow, then fix the paper that describes it.