Physiotherapy Treatment Tennis Elbow: Records Workflow
A workers' compensation adjuster faxes your front desk at 4:40 on a Friday asking for "the complete file" on a patient nine visits into physiotherapy treatment tennis elbow care. The fax names the employer and the claim number. It does not include a patient authorization. Your receptionist has twenty minutes left in her shift and no script taped to the fax machine.
This article is about that moment and the fifty other administrative moments that surround a multi-visit musculoskeletal episode. It is written for practice managers, privacy officers, and release-of-information staff — not for patients, and not for clinicians. Nothing here tells you how to treat anyone. It tells you what to capture, who touches it, how long you keep it, and which requests you can fill without an authorization.
What a physiotherapy treatment tennis elbow episode deposits in your record system
Lateral epicondylitis episodes are administratively interesting because they are rarely one visit and rarely one organization. A patient typically arrives with a referral from primary care, occupational medicine, or orthopedics, attends a series of visits over several weeks, and generates correspondence with a payer and often an employer. That means records move into your organization and back out of it repeatedly.
The half you did not create
Inbound documents pile up fast: the referral or prescription, a consult note, imaging or diagnostic reports, prior therapy notes from another clinic, payer authorization letters, and workers' compensation claim correspondence. Every one of those is protected health information the moment it lands in your fax queue or portal inbox.
Two failure points show up in audits constantly. First, inbound faxes sitting in a shared tray or an unattended network folder for days. Second, records received from another provider that never get indexed into the designated record set, so they are invisible when a patient later asks for "everything you have."
The half you did create
Your own output for a physiotherapy treatment tennis elbow course typically includes the initial evaluation, the plan of care, a visit note per encounter, outcome measure scores, home program materials given to the patient, phone or portal messages, discharge documentation, and billing records. Under Medicare Part B outpatient therapy rules, plans of care require certification and progress reporting at defined intervals — commonly every tenth treatment day — and commercial payer rules differ. Confirm the current requirement in your payer's own manual rather than in a blog post, including this one.
Administratively, the point is that the documentation cadence is predictable. That means you can build a checklist rather than react. A practice that knows a typical episode runs eight to sixteen visits can pre-schedule its certification checkpoint, its authorization renewal, and its chart-completion audit instead of discovering all three at denial time.
Who touches the chart between referral and discharge
Write these role assignments down. Ambiguity here is where disclosures go wrong.
- Front desk: intake demographics, insurance card images, Notice of Privacy Practices acknowledgment, scheduling and reminder preferences.
- Clinical staff: evaluation, visit documentation, outcome measures, communication back to the referring provider.
- Billing: claim submission, authorization tracking, denial correspondence, patient statements.
- Release of information (often the same person as billing in a small clinic): logging requests, verifying identity, applying minimum necessary, tracking the response clock.
- Privacy officer: approving unusual disclosures, maintaining the disclosure accounting log, reviewing access reports.
If one person holds three of those roles, that is normal for a five-person clinic. What is not acceptable is that nobody knows which hat they are wearing when the adjuster calls.
Quick answer: what must you release when a patient requests a physiotherapy chart?
When a patient requests their own record, you must provide access to the designated record set — evaluations, visit notes, plans of care, outcome measures, correspondence, and billing records used to make decisions about that patient — including records you received from other providers. You must respond within 30 days, with one 30-day extension if you give the patient written notice of the delay and the reason. You must provide the record in the form and format requested if you can readily produce it, including electronically. You may charge only a reasonable, cost-based fee for labor to copy, supplies, and postage. You may not require the patient to explain why they want it, and you may not condition release on payment of an outstanding balance. HHS maintains detailed guidance on the individual right of access.
Workers' comp, employers, and attorneys: three requests that look alike and are not
The workers' compensation adjuster
HIPAA permits disclosure of protected health information as authorized by and to the extent necessary to comply with workers' compensation laws, without patient authorization. That permission is not unlimited — it is bounded by what your state's workers' comp statute actually authorizes, and minimum necessary still applies to what you send. Sending the entire chart because the fax said "complete file" is the error. HHS summarizes the framework in its workers' compensation guidance, and your state's rules control the scope.
Practical control: keep a one-page cheat sheet at the release desk listing what your state's comp law lets you send without authorization, who signs off, and where the disclosure gets logged.
The employer calling directly
An employer's HR manager asking whether a patient can return to keyboard work is not the same as a comp adjuster. Absent a workers' comp pathway or a narrow occupational-medicine surveillance arrangement, an employer request generally requires a signed patient authorization. Train the front desk to say one sentence: "We'll need a signed authorization from the patient before we can confirm or discuss anything." Confirming that someone is a patient is itself a disclosure.
The attorney and the subpoena
A plaintiff's attorney with a valid, current authorization signed by the patient gets what the authorization describes. A subpoena that is not accompanied by a court order requires satisfactory assurances — proof the patient was notified and had a chance to object, or that a qualified protective order was sought. Do not let a fax cover sheet with a case caption substitute for either. Route every subpoena to the privacy officer, no exceptions, and give staff permission to say "our privacy officer handles those" without further explanation.
The vendor list nobody updated
Map the vendors that touch a single physiotherapy treatment tennis elbow episode. In a typical outpatient clinic that list includes the practice management and documentation platform, the appointment reminder service, the clearinghouse, the transcription service if you use one, the fax-to-email provider, the outcome-measure or patient-reported-outcome tool, the home exercise program platform, the IT support firm with remote access, offsite storage or shredding, and the billing company.
Every one of those is a business associate if it creates, receives, maintains, or transmits PHI on your behalf. Every one needs a signed agreement on file, and you should be able to produce it in under five minutes. HHS publishes sample business associate agreement provisions, but sample language in a Word file is not the same as an executed, dated, countersigned agreement covering the vendor you onboarded last quarter.
If your BAA folder has gaps — and after a decade of onboarding vendors ad hoc, most do — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, no subscription, which is the right shape for a clinic that needs four agreements this month and none for the next eighteen.
The home exercise app problem
Home program platforms are the vendor category most often missed, because clinicians adopt them directly and nobody in administration ever signs anything. If the platform stores patient names, exercise assignments, or adherence data, it holds PHI. Ask three questions before it goes live: is there an executed BAA, where is the data hosted, and can you export and delete a patient's record on request. If the answer to any is unclear, it does not go live.
Retention: two clocks, not one
HIPAA does not set a medical record retention period. That comes from state law, your professional licensing board, and payer contracts — and for pediatric patients, it usually runs from the age of majority rather than the date of service.
HIPAA does impose a separate six-year retention requirement on compliance documentation: policies and procedures, risk analyses, business associate agreements, training records, sanction records, disclosure accountings, and breach determinations. Six years from creation or last effective date, whichever is later. These two clocks are independent. Practices that shred everything on a single schedule routinely destroy the BAA they needed to produce during an investigation.
Information blocking: the delay your front desk invents
Health care providers are actors under the information blocking rules, and CMS finalized disincentives for providers found to have engaged in information blocking. The most common practical exposure in a small clinic is not malice — it is a policy that says "records requests are processed on Fridays" or a portal configured to hold notes for a manual review period that has no clinical basis.
Review your delay defaults. If electronic health information is available and the patient or their designated app is entitled to it, an artificial hold needs to fit a defined exception. The information blocking resources from ASTP/ONC lay out the exception structure.
A 30-minute self-audit for your next staff meeting
- Pull one closed physiotherapy treatment tennis elbow chart at random. Can you produce the complete designated record set, including inbound records from the referring provider, in one export?
- Check the last five records requests. Was each logged with date received, date fulfilled, and scope released? Did any exceed 30 days without a written extension notice?
- List every vendor that touched that chart. Match each to a signed, dated BAA. Note the gaps.
- Ask your front desk what they say when an employer calls about a patient. Listen to the actual sentence.
- Confirm where subpoenas go and that at least two people know.
- Verify your retention schedule distinguishes clinical records from HIPAA compliance documentation.
Anything that fails becomes a dated corrective action item with an owner. That log is itself evidence of a functioning program.
Where to start Monday
Close the vendor gap first, because it is the fastest fix with the clearest paper trail. Pull your vendor list, identify who holds PHI without a current agreement, and produce the missing Business Associate Agreements before the next audit or breach inquiry forces the question. If your broader documentation set — risk analysis, policies, training records — is equally thin, automating the full compliance document set is a reasonable next step once the agreements are signed.
Records requests do not wait for a convenient week. Build the workflow now, while the only thing on the fax machine is a routine authorization.