It is 4:40 p.m. on a Thursday and your front desk has three open requests for the same quantiferon result. The patient wants a copy emailed. A staffing agency has faxed a signed form asking you to send it to their credentialing inbox. A school nurse called and said she "just needs to confirm it was negative." All three are about one lab report sitting in one chart, and all three are governed by different rules.

This post is about that workflow — the release-of-information mechanics, the deadlines, the identity checks, and the vendor contracts behind them. It is not clinical guidance. QuantiFERON is a blood-based tuberculosis screening test, and the only clinical fact that matters here is an administrative one: the result almost always has to leave your building. It goes to employers, schools, health departments, occupational health programs, and future providers. That movement is what turns one lab report into a records problem.

How Long Does Your Practice Have to Fulfill a QuantiFERON Records Request?

Thirty calendar days from receipt of the request. Under 45 CFR 164.524, a covered entity must act on an individual's access request within 30 days. You may take one 30-day extension, but only if you notify the individual in writing within the original 30 days, state the reason for the delay, and give a date certain by which you will produce the records.

  • The clock starts when the request arrives — not when your ROI staff opens it, and not when a signature is verified.
  • Weekends and holidays count. Thirty days means 30 days.
  • Only one extension is allowed per request.
  • Many states impose shorter deadlines. The stricter rule controls.
  • Separately, CLIA rules at 42 CFR 493.1291 require laboratories to furnish completed test reports to a requesting patient within 30 days, so the reference lab that ran the quantiferon assay carries its own obligation.

A 2021 HHS proposal would have shortened the standard to 15 days. It has not been finalized. Build your process around 30 days and you are covered either way — but build it so it usually finishes in five.

Why QuantiFERON Results Generate More Requests Than Most Lab Reports

Most lab results live and die inside one chart. TB screening results do not. They are attached to employment onboarding, clinical rotations, licensure files, congregate-living intake, immigration paperwork, and public health follow-up. A single result may be requested five times in eighteen months by five different requesters, three of whom are not the patient.

That volume is the operational risk. Your staff sees the same document so often that it starts to feel routine, and routine is where verification steps get skipped. The disclosure that gets you an OCR complaint is rarely the complicated one. It is the fax sent to the number that was on last year's form.

Map the requester types before you build the workflow

  1. The patient, for themselves. Right of access. Thirty days, limited fees, format of their choosing if readily producible.
  2. The patient, directing you to send it elsewhere. A written third-party directive under 164.524(c)(3)(ii). Different fee rules apply — see below.
  3. A third party with the patient's signed authorization. Governed by 164.508, not the access rule. No 30-day access deadline attaches, but your own policy should set one anyway.
  4. Another treating provider. Permitted for treatment under 164.506. No authorization required.
  5. A public health authority. Permitted under 164.512(b) when state law requires reporting.
  6. An employer. The one that trips people. Almost always needs an authorization. Narrow exceptions exist and are described below.

Verification: The Step Your Staff Skips at 4:40 p.m.

Section 164.514(h) requires you to verify the identity and authority of anyone requesting PHI, unless you already know them. The rule does not prescribe a method, which means your policy has to. Write it down or your staff will improvise.

For the patient

Photo ID at the window, or a portal message from an authenticated account, or a callback to the phone number on file paired with two identifiers the caller must supply — not two you read to them. Do not accept an email address as proof of identity. Email addresses are typed by whoever is holding the keyboard.

For a personal representative

Parents of minors, healthcare agents, and guardians all have access rights, but the scope differs and state law on minor consent can carve out categories of records. Keep the supporting document — power of attorney, guardianship order, custody language — scanned into the chart with an expiration flag if one applies.

For a third party holding an authorization

Check the six required elements of a valid authorization: specific description of the information, who may disclose, who may receive, purpose, expiration date or event, and the individual's signature and date. A quantiferon result requested under an authorization that expired in March is a disclosure you cannot make. Also check whether the authorization is broad enough. "TB test results" is specific. "All medical records" is broader than the requester probably needs, and you may release only what is authorized.

Verification is not the same as accuracy. Confirm the destination fax number or email address against the request itself, out loud, before transmitting. Misdirected faxes remain one of the most common small-practice breach patterns, and they are entirely preventable at the keyboard.

Third-Party Directives, Employers, and the Ciox Line

When a patient tells you in writing to send their quantiferon result to a staffing agency, that is a third-party directive. It must be signed by the individual, clearly identify the recipient, and state where to send the copy. A phone call is not enough.

Fees are where practices get in trouble. For copies going to the individual, you may charge only a reasonable, cost-based fee: labor for copying, supplies, postage, and preparation of an agreed summary. You may not charge for search and retrieval, and you may not charge for the labor of locating the record. HHS's right of access guidance lays out the permitted components — and also carries a notice about the 2020 federal district court decision in Ciox Health, LLC v. Azar, which vacated the extension of that patient-rate fee cap to third-party directives and narrowed the mandatory directive to electronic health information maintained in an EHR.

The practical translation: bill the patient rate when the copy goes to the patient. Do not assume the same cap applies when a commercial requester is paying. And do not let a fee dispute run your 30-day clock out — the deadline does not pause while accounting sorts it out.

When an employer asks directly

If your practice performs occupational health screening under contract, the resulting records are still PHI held by you as a provider. Sending results to the employer generally requires the employee's authorization. A narrow exception at 164.512(b)(1)(v) permits disclosure to an employer for workplace medical surveillance or evaluation of a work-related illness when the employer needs the findings to comply with OSHA, MSHA, or a similar state law — and the individual must receive written notice of the disclosure.

That exception is narrower than most HR departments believe. If an employer's request does not fit it squarely, route the request back through the employee with an authorization form. Document the redirect. "We told them to get an authorization" is a defensible answer; "the account manager asked nicely" is not.

Public Health Reporting Is Not a Records Request

Depending on your state, positive TB screening results may be reportable to the health department, and reporting requirements for latent infection differ from active disease. Those disclosures are permitted under 164.512(b) and do not require authorization. They also do not belong in your ROI queue.

Keep them in a separate lane with a separate log. Reportable-condition disclosures still need to appear in an accounting of disclosures if a patient requests one, so the log matters. But if your ROI staff are the ones deciding what gets reported, you have merged a compliance function with a public health function and neither will be done well.

The Vendor Layer: Everyone Who Touches the Result Before the Patient Does

Trace one quantiferon result from collection to release and count the outside organizations involved. There is usually a reference lab. Often a courier. A results interface or integration vendor. A patient portal. A release-of-information company or copy service. A fax-to-email service. A print-and-mail house for paper copies. An occupational health platform if you serve employer clients. A secure messaging tool your staff uses to coordinate.

Some of those are covered entities in their own right — the reference lab is one, and disclosures to it for treatment do not require a business associate agreement. Most of the rest are business associates, and every one of them needs a signed BAA on file before it handles a single result. The gap that shows up in audits is almost never the lab. It is the fax service someone added in 2023, or the copy vendor whose contract was signed by a manager who has since left.

If you find a vendor in that chain without a current agreement, close it this week. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than routing a request to outside counsel for a $200-a-month fax vendor. Attach the executed copy to your vendor inventory row, with the effective date and the renewal owner named.

Information Blocking Sits Underneath All of This

The access rule tells you what you must release and when. The information blocking rules under the 21st Century Cures Act tell you what you must not interfere with. A lab result is electronic health information. If your practice delays release, imposes conditions that are not required, or refuses to use an interoperability channel the patient has chosen, you may be looking at an information blocking claim in addition to an access complaint.

ONC maintains a plain-language explanation of the actors, exceptions, and complaint process on healthit.gov. Read the Privacy Exception and the Infeasibility Exception with your ROI lead so they know the difference between a delay you can justify and a delay you cannot.

A Twenty-Minute Audit You Can Run This Month

  1. Pull the last 20 records requests involving TB screening or occupational health results. Record the date received and the date fulfilled. Compute the median and the worst case.
  2. For each, identify the requester category from the six-item list above. Check that the correct legal basis was documented.
  3. Count how many were fulfilled without documented identity verification. Any number above zero is a training item.
  4. Check every fee charged against your posted schedule. Confirm no search-and-retrieval charges appeared on patient-directed copies.
  5. List every outside organization that touched those 20 requests. Match each against your BAA file. Note gaps with a named owner and a due date.
  6. Confirm your extension letter template exists, names a reason, and states a date certain.

Six steps, one afternoon, and you will know whether your quantiferon request workflow is a process or a habit. For background on lab-side obligations, CMS maintains the CLIA program pages, which are worth a skim before your next reference lab contract renewal.

Close the Paperwork Gaps Before the Next Request Arrives

Records requests do not get harder over time — they get more frequent, and the same three failures repeat: a missed 30-day deadline, an unverified requester, and a vendor operating without a signed agreement. The first two are training and tracking. The third is a document you can produce today.

Start with the vendor inventory. Every business associate in your release chain should have a current, executed agreement on file, and you can build and export one in a few minutes rather than letting the gap sit through another quarter. If your broader policy set and risk analysis are also overdue, automated HIPAA documentation tooling will get the rest of the file current.