A patient emails your front desk on Monday, December 1, asking for a copy of her last two years of visit notes and labs. Your patient records request timeline started that day — not when the request reached your release-of-information queue, not when someone verified her identity, not when your copy vendor got around to it. You have until December 31 to put the records in her hands or send her a written extension notice. If you do neither, you have a violation of 45 CFR 164.524, and it is the single easiest violation for a patient to report and for OCR to prove.

This article is the operational version of that rule: who does what, on which day, and what the file should look like when someone asks you to prove it.

The Patient Records Request Timeline in One Answer

Under the HIPAA Privacy Rule, a covered entity must act on an individual's request for access to their protected health information within 30 calendar days of receiving the request. "Act on" means one of three things:

  • Provide the access requested — the copy, in the form and format asked for, if you can readily produce it that way.
  • Deny the request in whole or in part, in writing, in plain language, with the basis for denial and review rights.
  • Send a written extension notice that states the reason for the delay and the date by which you will act — a single extension of no more than 30 additional calendar days.

The clock counts calendar days, not business days. Weekends and holidays do not pause it. There is no second extension. The old 60-day allowance for records stored offsite was removed years ago; if your policy still references it, your policy is out of date.

HHS maintains detailed guidance on this obligation in its Individuals' Right under HIPAA to Access their Health Information materials, and it is worth having your privacy officer read the FAQ section annually.

Is 30 Days a Target or a Ceiling?

It is a ceiling, and OCR has said repeatedly that covered entities should provide access as soon as possible. A proposed rulemaking published in early 2021 would have shortened the standard to 15 calendar days; as of December 2025 it has not been finalized, so 30 days remains the enforceable outer limit. Practices that build workflows around 30 days tend to miss. Practices that target 10 business days almost never do.

Day Zero: When the Clock Actually Starts

The clock starts when your practice receives the request — including at the front desk, in a portal message, by fax, or in a voicemail your staff transcribes. It does not start when the request lands on the correct desk.

This is where most practices quietly lose a week. A request arrives at reception on the 1st, sits in a shared inbox until the 8th, and reaches the medical records coordinator on the 10th. Your team believes it has 30 days from the 10th. It does not. It has 21.

Requests You Can Require in Writing

You may require requests to be in writing, as long as you told patients that in your Notice of Privacy Practices. You may not require a patient to use your specific form, appear in person, or explain why they want the record. You may not condition access on payment of an unrelated balance, and you may not route them through a portal they cannot access.

Verification of identity is permitted and required — but it must be reasonable and it does not extend the deadline. A two-week wait for a notarized signature is not reasonable verification; it is a delay.

A Working Timeline You Can Assign to Real People

Here is the schedule most mid-sized practices can sustain. Adjust the roles, keep the days.

  1. Day 0 — Intake (front desk or portal monitor). Log the request in a single tracking sheet or ticketing queue: date received, requester name, patient name, records requested, format requested, delivery method, whether it is a third-party directive. Timestamp is the whole point.
  2. Day 0–2 — Verification (medical records coordinator). Confirm identity and, if a personal representative is asking, confirm authority. Document what you verified and how.
  3. Day 1–5 — Scope and assembly. Pull the designated record set. Include clinical notes, labs, imaging reports, billing records, and — critically — records you received from other providers that are part of the designated record set.
  4. Day 5–10 — Review for denial grounds (privacy officer or licensed provider). Most requests have none. If psychotherapy notes are involved, they are excluded from the right of access entirely and must be handled separately.
  5. Day 10–15 — Fee calculation and patient contact. If a fee applies, tell the patient the amount in advance. Do not surprise them at pickup.
  6. Day 15–25 — Delivery. Send in the requested form and format. If the patient asked for unencrypted email and you warned them of the risk, you must honor that request.
  7. Day 25 — Escalation trigger. Any open request hits your privacy officer's desk. If it cannot close by day 30, the extension notice goes out that day, not on day 30.

The escalation trigger at day 25 is the part practices skip, and it is the part that prevents the violation. An extension notice sent on day 32 is not an extension. It is documentation of your own lateness.

What Your Extension Notice Must Contain

A compliant extension notice is short and has three required elements: it is in writing, it states the reason for the delay, and it gives a specific date by which you will act. "We are experiencing delays" is not a reason. "The requested imaging is archived with a prior vendor and retrieval requires ten business days" is.

Keep a copy in the patient's file and a note in your tracking log. When OCR opens a right-of-access complaint, the first document they ask for is the log, and the second is the notice.

Fees: What You Can Charge Without Creating a Second Problem

You may charge a reasonable, cost-based fee limited to: labor for copying (electronic or paper), supplies such as media or paper, postage if the patient asks for mailing, and preparing a summary or explanation if the patient agreed to one in advance.

You may not charge for search and retrieval, for time spent verifying identity, or for the overhead of maintaining your records system. Per-page fee schedules under state law are frequently higher than what HIPAA permits for an individual's own request — and HIPAA's limit controls when it is more protective.

HHS guidance describes three permissible methods: actual costs, an average cost schedule, or a flat fee of up to $6.50 for electronic copies of PHI maintained electronically. Note that fee rules for requests a patient directs to a third party were narrowed by litigation in 2020, and third-party directives for non-electronic records are treated differently. If your practice routes every request through the same fee schedule regardless of who is asking, have your privacy officer separate the two paths.

When Your Copy Vendor Sits Inside the Timeline

Most practices do not fulfill requests alone. A release-of-information company, a scanning service, a former EHR vendor holding archived data, or a transcription firm often holds a piece of the record. Every one of them is a business associate, and every one of them is inside your patient records request timeline whether or not your contract says so.

Your deadline does not extend because your vendor is slow. If a copy service takes 21 days to return a chart, you have nine days left and no one to blame. That makes two contract terms non-negotiable: a turnaround commitment shorter than your internal escalation trigger, and a written obligation to make PHI available to you so you can meet your access obligations.

If any vendor touching your records lacks a current signed agreement — and archived-data holders and small scanning shops are the usual gaps — close it before your next request arrives. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. It is a one-time purchase, not a subscription, which makes it practical for the one-off vendor you discovered during an inventory.

Denials: Narrow Grounds, Mandatory Paperwork

Denial grounds are limited. Psychotherapy notes and information compiled for legal proceedings are excluded outright. A licensed health care professional may deny access on reviewable grounds — for example, when access is reasonably likely to endanger the life or physical safety of the individual or another person. Discomfort with what the note says is not a ground.

What the Denial Letter Needs

Plain language. The specific basis. A description of how to request review by a licensed professional who was not involved in the original denial, when the ground is reviewable. And instructions for filing a complaint with your practice and with OCR, including contact information. Partial denials still require you to release everything else within the original 30 days.

Information Blocking Sits on Top of the 30-Day Rule

HIPAA sets an outer limit. The information blocking regulations under the 21st Century Cures Act set a different standard: do not engage in practices likely to interfere with access, exchange, or use of electronic health information. A policy of routinely using all 30 days when the record could be released electronically in two is a defensible HIPAA position and a weak information blocking position. ASTP/ONC maintains current material on information blocking requirements and exceptions.

Practical translation: if a patient asks for electronic records that live in your EHR and can be released through the portal, release them in days, not weeks.

What OCR Asks For, and What It Costs to Be Wrong

OCR's Right of Access Initiative has produced a long run of settlements since 2019, hitting solo practices, small groups, hospitals, and behavioral health providers alike. The fact patterns repeat: a patient asked, nobody responded, the patient complained, OCR sent a letter, the practice produced the records months later. Published resolution amounts have ranged from a few thousand dollars for small providers into six figures, and the corrective action plans typically run two years. You can review the published agreements on the HHS resolution agreements page.

The evidence OCR requests is consistent: your access policy, your tracking log, the dated request, the dated response, any extension notice, the fee calculation, and proof of delivery. If your practice cannot produce a log with dates, you are arguing from memory against a patient with an email timestamp.

A One-Hour Self-Audit for Your Next Compliance Meeting

Pull your last ten access requests and answer these in writing:

  • What date did the practice first receive each request — including at the front desk?
  • How many calendar days elapsed until records were delivered or a denial or extension was sent?
  • Were any extensions sent after day 30?
  • What did you charge, and can you show the cost basis?
  • Did any request route through a vendor, and is that vendor's agreement current and on file?
  • Does your Notice of Privacy Practices accurately describe how patients request records?

Any request that took more than 30 days without a timely notice is a documented gap. Write the remediation next to it — that record becomes your evidence of a functioning compliance program, which matters as much as the underlying fix.

One adjacent deadline worth putting on the same agenda: revised Part 2 requirements affecting substance use disorder records and notice content carry a compliance date of February 16, 2026. If your practice handles those records, the notice update and the access workflow should be revised together rather than twice.

Next Step

Fix the two things that break most timelines: the intake timestamp and the vendor who holds part of the record. Assign one person to log every request the day it arrives, set your internal escalation at day 25, and confirm that every service touching your charts has a signed agreement with a turnaround commitment. If you find a gap, build and export the agreement before the next request comes in — and if your broader policy set and risk analysis need the same attention, automated HIPAA documentation covers the rest of the file.