Scaphoid Records Requests: Timelines and Verification
A patient who injured a wrist in March calls your orthopedic practice on a Tuesday in June. She wants "everything" — the urgent care note from the night of the fall, the initial radiographs that read as negative, the repeat imaging two weeks later, the MRI, your surgeon's operative report, and the physical therapy notes. Three of those items were never generated by your organization. Your 30-day clock started the moment she asked, and it does not pause while you sort out who holds what.
That is the administrative reality of a scaphoid case. This post is for the person at your practice who owns records requests: what the timeline actually requires, how to verify a requester without inventing obstacles, how to price copies, and where the imaging piece creates exposure most practices don't see coming. No clinical guidance here — just the workflow.
Why Scaphoid Records Fragment Across Four Organizations in Three Weeks
The administrative problem is structural. A wrist injury of this type frequently produces a first encounter somewhere other than the treating specialist's office — an emergency department, an urgent care, a school or workplace clinic. Imaging is often performed at a separate facility. Repeat or advanced imaging follows at a different interval, sometimes at a third site. Specialist evaluation and any follow-up care land with you.
By the time a request arrives, the designated record set the patient believes exists is actually four partial record sets held by four covered entities, plus whatever your business associates are storing on your behalf. You are responsible for yours. You are not responsible for producing the urgent care's note simply because it is referenced in your intake — but you are responsible for producing the copy of that note if it sits in your chart as part of the designated record set you maintain.
That distinction is where most delays start. Staff read "everything" and freeze, or they call the imaging center and wait. Train them to a simpler rule: produce what you hold, on time, and tell the requester in writing where the rest lives.
How Long Do You Have to Respond to a Scaphoid Records Request?
Under the HIPAA Privacy Rule at 45 CFR 164.524, a covered entity must act on an individual's request for access no later than 30 calendar days after receipt. "Act on" means one of three things: provide the access requested, provide a written denial that meets the rule's content requirements, or provide a written extension notice.
You get one extension of no more than 30 additional calendar days. The extension notice must be delivered within the original 30 days, must state the reason for the delay, and must state the date by which you will complete the request. You cannot take a second extension. Several states impose shorter windows, and where state law is more protective of the individual, the shorter window governs.
Two operational notes that trip practices up:
- The clock runs from receipt, not from the date your release-of-information vendor picks up the queue. If your vendor has a three-day intake lag, you have 27 days, not 30.
- Requests that arrive by phone, in person, by portal message, or by email all count. There is no requirement that a patient use your form. You may offer one; you may not condition access on it.
HHS maintains detailed guidance on these obligations in its individuals' right of access materials, and OCR's Right of Access Initiative has produced a long series of settlements since 2019 — most of them small practices, most of them for the same failure: a request sat unanswered for months.
Verification: Enough Friction to Be Safe, Not Enough to Be a Denial
Section 164.514(h) requires you to verify the identity of a person requesting PHI and their authority, if you do not already know them. It does not prescribe a method. That flexibility is a gift and a trap — staff invent requirements that function as barriers, and barriers become complaints.
What reasonable verification looks like
For an established patient requesting their own records: match two identifiers against the chart (name plus date of birth plus one of address, phone, or member ID), and deliver to a channel the patient has already confirmed. For portal requests, authentication into the portal is itself verification. For phone requests, verify by knowledge-based questions and mail or portal-deliver rather than reading records aloud.
What you should not do: require an in-person visit, require notarization, require a specific form, or require the patient to explain why they want the record. Any of those, applied as a blanket rule, is a defensible-sounding practice that OCR has repeatedly treated as an unreasonable barrier.
Personal representatives and the teenage athlete
A meaningful share of scaphoid cases involve adolescents — sports injuries, falls. That means parent requests, and it means your front desk needs a written answer to: who is the personal representative, and does that change at 18? Build a one-page desk reference keyed to your state's minor-consent rules, and put a named clinical or privacy staffer on the escalation path for custody disputes. Do not leave this to the person at the check-in window at 4:45 p.m.
Three Requesters, Three Rule Sets
The same scaphoid chart can be requested three ways in the same month, and each one follows different law. Post this on the wall of your records area.
1. The patient (or their personal representative)
Right of access applies. 30-day clock, extension available, fee limited to a reasonable cost-based amount — labor for copying, supplies, postage, and preparation of an agreed summary. You may not charge for search and retrieval time. State fee caps may be lower than what HIPAA permits; the lower number wins.
2. A third party, at the patient's direction
A patient can direct a copy to an attorney, employer, or another provider — but this now runs through a valid HIPAA authorization under 164.508 for anything beyond the narrow electronic-copy directive that survived the 2020 Ciox Health v. Azar decision. Practically: get a signed, complete authorization, and understand that the patient-rate fee limitation does not extend to these third-party requests in the way the 2016 guidance once suggested. State copy-fee schedules apply.
3. A workers' compensation carrier or employer
Wrist injuries generate workers' comp claims. The Privacy Rule permits disclosure without authorization as authorized by and to the extent necessary to comply with workers' compensation laws — see HHS's workers' compensation guidance. This is the exception your staff most often over-applies. An employer calling to ask when the patient can return to keyboard work is not automatically covered. Route every comp request to a single trained owner and document the statutory basis in the disclosure log.
Imaging Is Where Scaphoid Requests Go Wrong
Right of access includes a form-and-format obligation: if the individual requests an electronic copy and you maintain the PHI electronically, you must provide it in the requested electronic form and format if readily producible. Radiographs, CT, and MRI in a scaphoid workup are maintained electronically. "We only mail printed reports" is not a compliant answer when the patient asks for images.
Decide now, in writing:
- Can you export DICOM to encrypted media or a secure download link? Who does it, and within what internal SLA?
- If your PACS vendor performs the export, is that vendor under a current business associate agreement covering exactly that activity?
- What do you charge for media, and does that charge survive scrutiny as cost-based?
- If the images were performed elsewhere and only the report is in your chart, does your response letter say so explicitly?
Ambiguity on item four is the most common source of a follow-up complaint. Patients assume you have the pictures because you have the report.
Your ROI Vendor, PACS Vendor, and Courier Are Business Associates
Every organization that touches a scaphoid record on your behalf — the release-of-information company, the transcription service, the image-sharing platform, the scanning contractor digitizing your legacy paper, the courier moving discs to a hand surgeon across town — is a business associate. Each needs a signed agreement in force before PHI moves, and each needs to be findable when OCR asks for your vendor inventory.
Practices routinely discover during an access complaint that the ROI vendor handling their overflow requests has been operating for two years on a services contract with no BAA attached, or on an agreement signed under a prior corporate name. If you are staring at that gap right now, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — rather than waiting on a legal review cycle while records sit in a queue.
Then go one step further: add a column to your vendor register recording the vendor's own response SLA. If your BAA says nothing about how fast the vendor must return a fulfilled request, your 30-day obligation is being managed by someone with no contractual deadline.
Information Blocking Exposure You Probably Aren't Tracking
Right of access is not your only timeline risk. Under the 21st Century Cures Act information blocking rules, practices that interfere with the access, exchange, or use of electronic health information can face disincentives; HHS finalized the provider disincentives framework in 2024. A refusal to release imaging electronically, an unnecessary delay while you "review" a request, or a policy of routing all electronic requests to paper can all read as blocking rather than as prudence.
The information blocking resources at HealthIT.gov lay out the exceptions. Two are worth knowing cold: the Preventing Harm exception and the Infeasibility exception. Both require documented, contemporaneous reasoning. "We were busy" is neither.
A 30-Day Response Timeline You Can Actually Staff
Assign names, not roles, to each step. This is what a defensible cadence looks like for a mid-size specialty practice.
- Day 0: Request received by any channel. Front desk logs it in the access register with date, requester, channel, and scope. No triage decisions at the desk.
- Day 1–2: Records owner verifies identity and authority. Classifies as patient access, third-party authorization, or workers' comp. Logs the classification.
- Day 3–5: Scope assembled: encounter notes, imaging reports, imaging studies, outside records held in your chart, billing records if requested. Gaps identified.
- Day 6–10: Vendor tasks issued with an internal due date of Day 18. Fee estimate calculated and communicated in advance if any charge applies.
- Day 18–22: Quality check — right patient, complete date range, images readable, no other patient's PHI mixed in. This step catches the misdirected-disclosure breach before it happens.
- Day 23–28: Delivery through the requested channel, with a cover letter naming any records you do not hold and where they likely reside.
- Day 29–30: If not delivered, written extension notice with a stated completion date. Extension logged and calendared.
Audit ten closed requests a quarter against that register. You are looking for one number: median days to fulfillment. If it drifts past 20, your 30-day compliance is luck, not process.
Five Fixes Worth Doing This Quarter
- Write the access register if you don't have one. A spreadsheet with date received, requester type, verification method, fee charged, and date fulfilled is enough to answer an OCR data request.
- Kill any blanket requirement for notarization, in-person pickup, or a proprietary form.
- Confirm a BAA exists, in current legal-entity names, for every vendor in the records path — including the imaging platform.
- Publish an internal fee sheet with the cost basis documented, and check it against your state cap.
- Give one named person authority to approve extensions, so nobody quietly lets Day 31 arrive.
If the audit turns up broader gaps — missing policies, a stale risk analysis, no documented workforce training on access procedures — you can automate the risk analysis and policy set rather than rebuilding those documents by hand. And if the immediate gap is a vendor operating without paper, close it first: a signature-ready BAA you can export and send today costs less than the letter you'd otherwise write to OCR explaining why one was never in place.