A patient your podiatrist saw in February for plantar fasciitis treatments calls your front desk on a Thursday afternoon. She wants "everything" — office notes, the ultrasound report, the physical therapy summary, the orthotic order, and the injection documentation — emailed to her personal Gmail account by Monday. Your scheduler puts her on hold and comes to find you.

That call started a 30-day clock. This article is about running that clock correctly: who verifies the requester, which records you actually hold versus which ones belong to another covered entity, what you may charge, what your release-of-information vendor needs in writing, and how to document a partial denial without generating an OCR complaint. It is an administrative playbook, not clinical guidance.

Why Plantar Fasciitis Treatments Scatter Records Across Four Organizations

Foot pain of this kind is a textbook example of a condition managed across settings. A single episode may involve a primary care visit, a podiatry consult, diagnostic imaging at an outside center, a course of physical therapy at an independent clinic, and a durable medical equipment supplier for custom orthotics. Some patients also see a surgical specialist.

You do not need to understand the clinical reasoning to run the records workflow. You need to understand the consequence: the chart your patient believes is "one file" is really four designated record sets held by four separate covered entities. Your obligation extends only to the protected health information in your own designated record set — including records you received from others and used to make decisions about that patient.

That last clause matters. The imaging report the outside center faxed you is in your designated record set. The PT discharge summary you received and filed is in your designated record set. You cannot tell the patient to "go ask the imaging center" for a report that is sitting in your own system.

The DME and orthotics wrinkle

Custom orthotic suppliers often sit in an ambiguous position. If the supplier is a separate covered entity billing insurance in its own name, it holds its own records and answers its own requests. If it is a division of your practice, its documentation is yours. If it is performing a function on your behalf and handling PHI, it is a business associate and you need an executed agreement on file.

Pull your DME arrangements and classify each one in writing. "We've always just worked with them" is not a classification.

How Long Do You Have to Respond to a Records Request for Plantar Fasciitis Treatments?

Thirty calendar days from receipt of the request. Not thirty business days. Not thirty days from when the chart was located or the provider signed off.

You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give a date by which you will produce the records. You get one extension per request. Several states impose shorter deadlines, and where state law is more protective of the individual, the shorter deadline governs.

The clock starts when the request arrives at your organization — the front desk, the portal inbox, the fax line, the general email address you forgot you published. Train every intake point to date-stamp and route on the day of receipt. HHS has published detailed right of access guidance that your privacy officer should keep printed and current.

Verifying the Requester Without Building an Obstacle Course

You must verify identity before disclosing. You may not turn verification into a barrier that functionally denies access. Those two sentences sit in tension, and OCR has repeatedly landed on the side of the patient.

Reasonable verification for a known, established patient calling about plantar fasciitis treatments might be: confirmation of full name, date of birth, and two additional identifiers on file, plus a callback to the phone number in the chart. For a portal request, the authenticated portal session is itself verification.

Practices get into trouble by requiring more than the rule allows:

  • Demanding an in-person visit when the patient asked for an electronic copy
  • Requiring notarization
  • Refusing to send to an unencrypted personal email after the patient was warned of the risk and chose it anyway
  • Requiring the patient to explain why they want their record
  • Insisting on your own proprietary form when the patient submitted a clear written request

You may offer your form. You may not condition access on it.

Third-party directives versus authorizations

These are different instruments and your staff must be able to tell them apart in ten seconds.

A right-of-access request with a third-party directive is the patient exercising their own access right and directing the copy to someone else — a lawyer, a new podiatrist, an employer's leave administrator. It must be in writing, signed by the individual, and clearly identify the designated recipient and where to send it. The 30-day clock applies.

A HIPAA authorization is a broader instrument, typically initiated by the third party, with its own required elements: description of information, purpose, expiration, revocation language, and the required statements about redisclosure. Attorney and insurer requests usually arrive as authorizations.

Mislabeling one as the other is the single most common cause of fee disputes, because the fee rules diverge. Build a two-question triage into your intake form: Who signed this? and Who is asking?

What You May Charge — and What You May Not

For a patient exercising the right of access, your fee must be reasonable and cost-based, and it may include only:

  1. Labor for copying the PHI, whether paper or electronic
  2. Supplies for creating the paper copy or portable electronic media
  3. Postage, if the patient asked for mailing
  4. Preparing an explanation or summary, if the patient agreed in advance to that format and fee

You may not charge for search and retrieval. You may not charge for the time your staff spent verifying identity, logging the request, or maintaining the system the records live in. You may not charge a per-page fee that has no relationship to actual cost when the record is produced electronically.

A 2020 federal district court decision in Ciox Health, LLC v. Azar vacated the extension of the patient-rate fee limitation to third-party directives beyond what the HITECH Act itself required for electronic copies maintained in an EHR. Practically, that means a request from a law firm under a signed authorization may be billed under your state's ROI fee schedule, while the same patient asking for the same chart for herself is capped by the access rule. Your billing staff needs that distinction written down, not remembered.

The Vendor Chain Behind a Single Records Release

Walk one request for plantar fasciitis treatments records through your actual environment and count the third parties that touch PHI along the way. In a typical small specialty practice, the list looks something like this:

  • The release-of-information vendor that pulls, redacts, and ships the copy
  • The scanning or document-management service holding pre-conversion paper charts
  • The e-fax provider that received the outside imaging report
  • The secure messaging or encrypted email platform used for delivery
  • The transcription service that produced the office notes
  • The offsite storage facility holding records from before your last EHR migration
  • The IT managed service provider with administrative access to all of it

Every one of those is a business associate and every one requires a signed agreement that survives an audit. When a records request goes wrong — wrong patient, wrong recipient, unencrypted transmission — OCR's first document request is almost always the BAA. Practices that discover a missing or decade-old agreement mid-investigation do not have a good week.

If your vendor inventory has gaps, close them before the next request lands. A signature-ready Business Associate Agreement generated through a six-step wizard produces PDF and DOCX output for a one-time purchase, which is faster and cheaper than routing a one-off contract through outside counsel for every scanning vendor and fax provider on your list.

A Worked Example: 27 Days, Four Sources, One Requester

Here is how a clean file looks when the request from that Thursday afternoon call is handled properly.

Day 0 (Thursday). Front desk logs the request in the access tracker with a timestamp, requester name, delivery format requested (email), and scope ("everything related to foot pain"). Scheduler does not promise Monday.

Day 1. Privacy officer calls the patient back at the number on file. Verifies identity, clarifies scope, confirms she wants unencrypted email to a personal address, delivers and documents the risk warning, records her election. Confirms delivery date will be within 30 days.

Days 2–8. ROI coordinator assembles: podiatry office notes, the outside ultrasound report received by fax, the PT discharge summary in the chart, the orthotic order, and the injection procedure note. She flags one item — a psychotherapy note is not present, but a scanned letter from another provider marked confidential is, and it goes to the privacy officer for review rather than being pulled unilaterally.

Day 10. Privacy officer confirms the letter is part of the designated record set and is releasable. No denial needed.

Day 12. Fee calculated: labor for producing the electronic copy only, itemized. Patient notified of the amount in advance. She approves.

Day 14. Copy sent. Delivery confirmation captured. Access tracker closed with the date, the fee, the format, and the name of the staff member who released it.

Elapsed: fourteen days, with thirteen in reserve. The tracker entry is the artifact that proves compliance if anyone asks two years from now.

Denials, Partial Productions, and the Paper You Must Generate

Grounds for denying access are narrow. Psychotherapy notes, information compiled for legal proceedings, and a small set of reviewable denials involving risk of harm — that is close to the whole list. "The patient owes us money" is not on it. "The provider has not signed the note yet" is not on it either; unsigned documentation in the designated record set is still accessible.

When you deny in part, produce everything you can and issue a written denial covering the rest. The notice must be in plain language and must explain the basis, the patient's review rights if the denial is reviewable, and how to complain to you and to HHS. Keep the denial letter for six years.

Delay is also a compliance failure with teeth. Under the information blocking framework, a provider who unreasonably interferes with access to electronic health information faces disincentives; ASTP/ONC maintains current information blocking guidance and exceptions that your privacy officer should review alongside the access rule, since the two regimes overlap but are not identical.

What Regulators Actually Look At

OCR's Right of Access Initiative has produced dozens of settlements since 2019, and the fact patterns are boringly consistent: a patient asked, the practice did not respond, the patient complained, the practice still did not respond, and a five-figure settlement plus a corrective action plan followed. Small practices are not exempt. Several settlements have involved solo and small specialty offices.

Separately, records-release mistakes surface on the HHS breach portal as misdirected disclosures — the wrong patient's chart in an envelope, a fax to a stale number, an attachment sent to the wrong recipient. These are workflow failures, not hacking incidents, and they are entirely preventable with a second-set-of-eyes check before release.

Build the Runbook Before the Next Request Lands

Assign these five things by name this month:

  1. Intake owner. Every channel — phone, portal, fax, email, walk-in — routes to one tracker with one timestamp.
  2. Verification standard. Written, proportionate, and identical for every requester type.
  3. Fee schedule. Two columns: patient access rate and third-party authorization rate, each defensible as cost-based.
  4. Vendor map. Every third party that touches a released record, each with a current signed agreement.
  5. Quality check. One named person confirms patient identity and recipient address before anything leaves the building.

Records for plantar fasciitis treatments are not special. They are just a common, multi-source, multi-vendor example of the request your practice will handle a hundred more times this year. The runbook is what makes the hundredth one as clean as the first.

Start with the gap that costs the most to fix under pressure: your agreements. Generate the business associate agreements your ROI, scanning, fax, and transcription vendors need in an afternoon, then move on to your broader documentation set — risk analysis and policy automation covers the rest of the file OCR will ask for. Neither is a government certification, because no such thing exists; both are the paperwork you will wish you had finished before the complaint arrives.