Patellofemoral Syndrome Records: A Practice Admin Guide
A patient comes in Tuesday afternoon with anterior knee pain. Your provider documents the encounter, orders imaging at an outside facility, sends a referral to a physical therapy group, and prints a two-line note for the patient's employer. That single visit for patellofemoral syndrome just created a chart entry, an outbound referral packet, an inbound imaging report, a disclosure to a third party, and at least four vendor touchpoints. Three weeks later the patient's attorney faxes a records request, and your front desk has to figure out what belongs in the release and what doesn't.
This article is about that administrative trail — what your staff must capture, how long you hold it, who you can hand it to, and which contracts have to exist before any of it moves. Nothing here is clinical guidance.
What One Patellofemoral Syndrome Encounter Actually Generates
Knee-pain encounters are administratively noisy because they almost always involve someone outside your four walls. Conservative management commonly routes through physical therapy, imaging often happens at a separate facility, and the patient frequently needs documentation for an employer, a school, or a coach. Every one of those is a records event.
Inventory what a typical encounter of this type produces at your practice:
- Intake forms, including any activity or symptom questionnaire your staff scans in
- The provider's encounter note and any templated exam documentation
- An imaging order, plus the returned report and sometimes a disc or DICOM link
- A referral packet to PT or orthopedics — usually demographics, insurance, the note, and the order
- Prior authorization correspondence with the payer
- A work, school, or activity restriction note
- Portal messages between the patient and clinical staff about scheduling or symptoms
- Billing records, superbills, and claim files
Only the first several live in the chart by default. The rest — the fax confirmations, the portal thread, the note your medical assistant handed the patient at checkout — end up scattered unless someone assigned ownership of them. Assign it. Name the role, not the person, in your policy: the front desk lead scans third-party correspondence into the encounter within one business day.
Which Patellofemoral Syndrome Records Must You Release to a Patient?
Short answer: everything in the designated record set, in the form and format the patient asks for if you can readily produce it, within 30 days.
The designated record set includes medical and billing records used to make decisions about the individual. For a knee-pain workup, that means the encounter note, the imaging report you received back, the referral you sent, lab or diagnostic results in your possession, and the claims and payment records. It also includes information you obtained from other providers if you're using it in your decision-making — an outside PT progress report you filed in the chart is releasable.
You may withhold psychotherapy notes kept separately and information compiled for legal proceedings. Those exclusions rarely apply to an orthopedic-type encounter. "The patient might misread it" is not a permitted reason to withhold, and neither is an unpaid balance.
You get one 30-day extension of up to 30 additional days, and you must tell the patient in writing why, before the original deadline expires. HHS has published detailed right of access guidance that your privacy officer should keep bookmarked — OCR's enforcement history on access complaints is long and unglamorous, and the cases are almost always about a practice that simply didn't respond.
Fees and Format
For copies going to the patient, you may charge only a reasonable, cost-based fee — labor for copying, supplies, postage. Not retrieval. Not per-page search time. Requests the patient directs to a third party have been treated differently since the 2020 federal court ruling that vacated part of HHS's fee guidance, so keep two fee schedules and make sure your release clerk knows which one applies.
If the patient asks for an electronic copy and your system can produce one, produce one. Refusing to send a PDF because "we only mail paper" is the kind of friction that draws both an access complaint and, under the ONC rules, an information blocking inquiry.
The Referral Handoff: Treatment Disclosures Without Authorization
Your staff does not need a signed authorization to send a referral packet to the PT clinic or the orthopedic group. Treatment disclosures between covered entities are permitted. What trips practices up is the second half of the sentence: the minimum necessary standard does not apply to treatment disclosures, but it absolutely applies to everything else you attach out of habit.
Watch for these in your outbound referral packets:
- The patient's entire problem list and full medication history when the referral is for a single joint complaint — defensible for treatment, but ask whether your template is dumping the chart because it's easy
- Scanned insurance cards and driver's licenses attached to clinical referrals
- Prior unrelated encounter notes pulled in by a "send last 5 visits" macro
Review the HHS explanation of the minimum necessary standard and then audit ten of your own outbound referrals. Most practices find at least one template sending more than anyone reads.
Fax Numbers and Direct Addresses Go Stale
PT clinics move, merge, and change fax lines. Misdirected faxes are a recurring, entirely preventable breach category. Verify the destination for any referral partner you haven't sent to in six months, and log the verification. Two minutes of confirmation beats a breach risk assessment.
Third-Party Requests: Employers, Schools, Attorneys, and Insurers
Here is where knee-pain encounters get administratively interesting. Patients with activity-limiting conditions frequently need documentation for someone who is not a healthcare provider, and that changes the rules.
Employers
An employer requesting records needs a valid patient authorization — signed, dated, specific about what's disclosed and to whom, with an expiration. The exception is when you're acting as the employer's occupational health provider under a workplace medical surveillance arrangement, which most primary care and orthopedic practices are not. A work note the patient carries out the door themselves is fine. A packet you fax directly to HR is not, absent authorization.
Workers' Compensation
If the knee complaint is claimed as work-related, state workers' comp law governs how much you disclose to the carrier and the employer, and HIPAA permits disclosures as authorized by and to the extent necessary to comply with those laws. Your privacy officer should have a one-page summary of your state's workers' comp disclosure rule taped inside the release binder. Don't let each release clerk improvise.
Schools and Athletic Trainers
Adolescent athletes make up a meaningful share of these encounters, and a high school athletic trainer will call your office asking for clearance details. Records you hold are HIPAA-protected and require authorization to release to the school. Records the school itself holds about that student are generally FERPA education records, not HIPAA records. Two different regimes, two different answers — and the school's request form is not your authorization form. Use yours.
Attorneys
Personal injury and disability attorneys send high volumes of requests. Verify the authorization is valid and unexpired, confirm the date range requested, and release only what the authorization covers. Log the disclosure. Patients have a right to an accounting of certain disclosures going back six years, and your log is the only way to produce one.
The Vendor List Behind a Single Knee Visit
Count the business associates involved in one patellofemoral syndrome encounter at a typical practice: the EHR host, the fax-to-email service, the imaging center's results portal, the transcription tool, the billing company, the patient communication platform sending appointment reminders, the release-of-information vendor if you outsource records requests, and the offsite shredding company. Eight relationships, each requiring a signed Business Associate Agreement before any PHI moves.
The failure mode is almost never a missing BAA with the EHR vendor. It's the referral coordinator who started using a free scheduling tool, or the practice manager who signed up for an e-fax service on a credit card. Run a quarterly vendor reconciliation: pull the accounts payable list, mark every line that touches patient data, and match it against your executed agreements.
When you find the gaps — and you will — you need a defensible agreement fast, not a six-week legal cycle for a $40/month fax service. A six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export handles the routine ones as a one-time purchase, so your counsel's time goes to the contracts that actually warrant it.
Retention: How Long You Hold the Knee File
HIPAA itself requires six-year retention for documentation the Privacy and Security Rules require — policies, authorizations, disclosure logs, risk analyses, BAAs. It does not set a medical record retention period. That comes from state law, payer contracts, and CMS conditions of participation. For minors, most states run the clock from the age of majority, which matters enormously when your patient was a 15-year-old athlete.
Build a retention matrix with four columns: record type, retention period, legal source, destruction method. Then actually run destruction on schedule. Holding records forever is not conservative — it expands your breach surface and your production burden every year.
Don't Forget the Satellites
Imaging discs in a drawer. Old fax confirmation printouts. The referral log spreadsheet on the front desk workstation. Retention policies that only cover the EHR leave PHI aging out of sight. Include physical media and local files in the matrix.
A Ten-Step Workflow for Your Front Desk
- Scan intake and any outside records into the encounter same-day.
- Verify the referral destination's fax number or direct address before sending.
- Log every outbound referral: date, recipient, contents.
- File returned imaging reports to the encounter, not a general inbox.
- Hand work or school notes to the patient; do not transmit to employers without authorization.
- Route every third-party request to a single named release role.
- Validate authorizations for completeness and expiration before releasing anything.
- Date-stamp patient access requests on receipt and calendar the 30-day deadline.
- Record disclosures in the accounting log at the time of release.
- Flag any new vendor touching PHI for BAA review before first use.
Print it. Laminate it. Review it at your quarterly staff meeting with two real (de-identified) examples from your own request queue.
Where These Files Actually Leak
Not through sophisticated attacks, usually. Through the release clerk who sent the full chart when the authorization covered one date of service. Through the portal message a parent could read on a 17-year-old's account. Through the personal phone a staffer used to photograph a knee note and text it to a colleague. Through the departing employee whose EHR access stayed live for five weeks.
Your audit logs answer the question "who touched this record." Review them on a schedule, not after a complaint. And keep your risk analysis current — it's the document OCR asks for first, and the one most practices can't produce in a usable form. If your policy set and risk analysis are stale, automated risk analysis and policy generation will get you a baseline faster than starting from a blank template.
Start With Your Vendor Gaps
The records workflow around a patellofemoral syndrome encounter is ordinary, high-volume, and exactly the kind of thing that erodes without attention. Pick one thing this week: pull your AP list, circle every vendor that touches patient data, and confirm you hold a signed agreement for each. Close the gaps you find with a ready-to-sign BAA, then move to the retention matrix. Steady beats heroic.