Pain in the Heel Foot Referrals: Records Sharing Rules
Count the organizations that touch one chart. A patient presents to your primary care office with pain in the heel foot. Within ten business days, the record has moved to an imaging center, a podiatry group, possibly a physical therapy clinic, and — if custom orthotics enter the picture — a durable medical equipment supplier. That's five entities, four transmissions, and at least three different transport channels. This article is about that pipeline: who may receive what, which partners need a signed agreement, and where the workflow breaks.
Nothing here is clinical guidance. The clinical detail matters only insofar as it explains why this referral pattern generates so much records traffic: heel pain is a high-volume complaint that frequently crosses organizational lines, which means your staff runs this disclosure sequence dozens of times a month, often without a written procedure behind it.
Do You Need Patient Authorization to Send Records to a Podiatrist?
No. Under 45 CFR 164.506, a covered entity may use and disclose protected health information for treatment, payment, and health care operations without a patient authorization. Disclosing a chart to another provider for that patient's treatment is a permitted disclosure. Three practical consequences:
- No authorization form is required for a treatment-purpose referral to another covered provider — including one outside your organization.
- The minimum necessary standard does not apply to disclosures to a health care provider for treatment purposes (45 CFR 164.502(b)(2)(i)). You may send the complete relevant record.
- You do not need a Business Associate Agreement with the receiving provider. Provider-to-provider treatment exchange is not a business associate relationship.
HHS states this plainly in its guidance on permitted uses and disclosures for treatment exchange. The recurring failure in practices isn't over-disclosure — it's staff demanding authorization forms that HIPAA never required, delaying care and creating an information blocking exposure. Train to the rule, not to folklore.
Mapping the Recipients on a Pain in the Heel Foot Referral
Before you can write a procedure, list who actually receives data. For a typical pain in the heel foot workup, the downstream recipients fall into three legal buckets, and your staff must be able to sort them on sight.
Bucket 1: Covered entities receiving PHI for treatment
The podiatry or orthopedic group. The imaging center. The physical therapy clinic. A DME supplier furnishing orthotics is generally a covered entity in its own right when it bills electronically. No authorization. No BAA. Send what the receiving clinician needs to treat.
Bucket 2: Business associates handling PHI on your behalf
Your referral management platform. Your fax-to-email gateway. Your release-of-information vendor. Your transcription service. Your document scanning contractor. Your EHR host. Each of these creates, receives, maintains, or transmits PHI for you — and each requires a signed agreement before the first record moves. If your BAA inventory is a folder of PDFs nobody has opened since 2022, you can generate a signature-ready Business Associate Agreement and close the gap the same day rather than waiting for legal review cycles.
Bucket 3: Everyone else — authorization territory
The patient's attorney. A disability insurer. An employer. A life insurance underwriter. A research registry. These requests arrive on the same fax line as legitimate treatment referrals, often on letterhead designed to look official. They require a valid, patient-signed authorization meeting the elements in 45 CFR 164.508, and your front desk must not process them as routine referrals.
Workers' compensation is its own carve-out. Disclosures for workers' comp are permitted under 45 CFR 164.512(l) to the extent authorized by and necessary to comply with state workers' comp law. If a heel injury is claimed as work-related, your privacy officer — not the front desk — should be the one confirming what your state statute allows.
Build a Standard Referral Packet Instead of an Ad Hoc Pull
Ask five medical assistants to assemble a referral packet and you will get five different packets. That variance is where PHI over-disclosure and under-disclosure both live. Define the packet once, in writing, and make it a template in your EHR.
A defensible standard packet for a musculoskeletal referral typically includes the referral order and stated reason, relevant encounter notes, the problem list, the medication and allergy list, relevant imaging reports and the link or accession for the images themselves, prior related records from the same body region, and current demographics and insurance. What it does not include: unrelated behavioral health notes, unrelated specialty consults from other body systems, or the patient's entire twelve-year history because "send everything" was easier than curating.
Minimum necessary doesn't legally bind treatment disclosures, but professional judgment still applies. Sending 400 irrelevant pages is not a HIPAA violation; it is a workflow failure that buries the receiving clinician and increases the blast radius if that transmission goes to the wrong destination. HHS's minimum necessary guidance is worth circulating to staff so they understand where the standard applies and where it doesn't.
Assign the roles by name
- Front desk: verifies patient identity and current demographics, routes non-treatment requests to the privacy officer, never assembles clinical packets.
- Medical assistant or referral coordinator: assembles the standard packet from the template, confirms the destination against a maintained directory, logs the transmission.
- Privacy officer: owns the recipient directory, reviews authorization-required requests, investigates every misdirected transmission within 24 hours.
- Practice administrator: owns the BAA inventory and the annual vendor review.
Six Transport Channels, Six Different Risk Profiles
Most misdirected-PHI incidents in outpatient practices are transport failures, not policy failures. Rank your channels honestly.
Direct secure messaging or EHR-to-EHR exchange is the lowest-risk option: addressed, encrypted, and logged. Use it whenever the receiving practice supports it. Query-based exchange through an HIE or a TEFCA-participating network shifts the retrieval burden to the specialist and eliminates one transmission entirely — but only if your participation agreement and your patient notice are current.
The patient portal works when the patient is the intermediary and wants to hand-carry records. Fax remains dominant in specialty referral and remains the single largest source of wrong-recipient disclosures. If you fax, enforce a stored-destination list with no free-typed numbers, require a second person to verify any new number, and reconcile confirmation pages daily.
Email to an outside provider requires encryption in transit or a documented patient request to receive unencrypted communication. Courier and hand-carried paper require a chain-of-custody log — a signature at pickup and a signature at delivery, retained for six years.
Every one of these channels needs to appear in your security risk analysis with an actual likelihood-and-impact rating, not a checkbox. If your risk analysis hasn't been touched since your last EHR upgrade, an automated HIPAA risk analysis and policy generator will produce the assessment, the transport policies, and the supporting document set faster than reconstructing it in a spreadsheet. Note that no product, including any compliance platform, confers government certification — HHS does not certify or endorse compliance vendors. What you're buying is documentation and defensible process.
The 30-Day Clock When the Patient Asks for the Same Records
The referral pipeline is only half the traffic. The patient with pain in the heel foot who wants a second opinion will ask you directly for the chart — or direct you to send it to a specific third party.
Under the right of access, you must act on the request within 30 calendar days, with one 30-day extension available if you notify the patient in writing of the reason and the expected date. Fees are limited to a reasonable, cost-based amount covering labor for copying, supplies, and postage. You may not charge for search and retrieval time. HHS's right of access guidance is the authority to keep bookmarked at the front desk, and OCR has pursued a long series of enforcement actions under its Right of Access Initiative against practices that missed these deadlines.
Two operational rules that prevent most access complaints: a patient's written direction to send records to a third party is still an access request, subject to the same clock and the same fee limits — not a commercial ROI transaction. And if you deny any portion of a request, the denial must be in writing, in plain language, and must describe the review rights available.
The Self-Pay Restriction Your Front Desk Will Get Wrong
Here is the case that catches practices. A patient with pain in the heel foot pays cash in full for a visit or for a pair of orthotics and asks you not to tell the health plan. Under 45 CFR 164.522(a)(1)(vi), you must agree to that restriction when the disclosure is to a health plan for payment or operations and the item or service has been paid in full out of pocket.
That obligation is mandatory, not discretionary. Operationally, it means: a flag on the encounter that suppresses claim submission, a note in the chart, and a documented conversation with the patient about downstream referrals — because if the specialist bills the same plan, the restriction you honored provides limited practical protection. Your staff should know how to set that flag in your system before a patient asks, not while one is standing at the counter.
Refusing to Send Is Also a Risk
Compliance leads are trained to fear over-disclosure. The information blocking rules invert part of that instinct. Unreasonably interfering with the access, exchange, or use of electronic health information can expose a practice to disincentives, and "we require a signed authorization for all outbound records" is not a recognized exception when the disclosure is a permitted treatment exchange.
Review the actual exceptions on healthit.gov's information blocking resources and document which ones you rely on and why. A practice that delays a specialist referral for a week while chasing an unnecessary form has created a clinical delay and a regulatory exposure at the same time.
A Ten-Item Audit for Your Next Referral Cycle
- Pull twenty outbound referrals from the last 60 days. Was a standard packet used, or did content vary by staff member?
- Confirm every destination fax number and Direct address against your maintained recipient directory.
- Identify any referral that was delayed pending an authorization that HIPAA did not require.
- Verify signed, current BAAs for the referral platform, fax gateway, ROI vendor, and transcription service.
- Confirm no BAA exists — and none is needed — with the receiving treating providers.
- Check that non-treatment requests (attorney, employer, insurer) were routed to the privacy officer with valid authorizations on file.
- Measure turnaround on the last ten patient access requests against the 30-day clock.
- Review your access fee schedule for any search-and-retrieval charge.
- Test the self-pay restriction flag end to end in your billing system.
- Confirm each transport channel appears in the current risk analysis with a documented safeguard.
If more than two items fail, the problem is documentation infrastructure rather than staff diligence. Start by generating a current risk analysis and the supporting policy set, then rebuild the referral procedure on top of it — so the next time a pain in the heel foot referral leaves your office, every hop in the chain is already accounted for.