It's 4:40 p.m. on a Friday when the fax rolls in: a two-page request from a patient's daughter asking for "all diet and nutrition records" from the last eighteen months, addressed to a new cardiology group across town. Your medical records coordinator has already left. The encounter in question was a nutrition counseling visit tied to a sodium restricted diet for heart failure — a routine visit that, on paper, touched a contracted dietitian, a remote monitoring platform, a patient education portal, and a cardiologist's consult letter.

This article is about that request, not about the diet. It covers what belongs in the designated record set, how to verify who is asking, what you may charge, when the 30-day clock starts and stops, and which vendor agreements have to already exist before you can lawfully route any of it. If you sign the release forms or answer the OCR complaint, this is your workflow.

What the Designated Record Set Includes When the Anchor Is a Sodium Restricted Diet for Heart Failure

The designated record set is defined by function, not by folder. It's the medical and billing records your practice uses, in whole or in part, to make decisions about that individual — wherever those records live and whatever system holds them.

For an encounter built around a sodium restricted diet for heart failure, that typically sweeps in more than the progress note. Practices routinely find the following scattered across three or four systems:

  • The clinician's encounter note and any dietitian or nutrition counseling documentation, including notes authored by a contracted (non-employed) dietitian on your behalf
  • The cardiology consult letter or referral response, once it has been incorporated into your chart
  • Patient-reported data your practice actually uses clinically — weight logs, home blood pressure readings, symptom check-ins — if a remote monitoring or portal vendor feeds them into your workflow
  • Education materials assigned to the patient, where a record of assignment and completion is retained in the chart
  • Billing and claims records for the visit, including denials and appeals correspondence
  • Scanned intake forms and any signed dietary or care-plan acknowledgments

The trap is the vendor-hosted data. If the readings your team reviews sit in a third-party dashboard and never sync back to the chart, they're still part of the designated record set when you use them to make decisions. Your export process has to reach them. Decide this before a request lands, not during it.

What You May Leave Out

Psychotherapy notes kept separately, information compiled in reasonable anticipation of litigation, and quality-improvement work product that isn't used to make decisions about the individual sit outside the access right. Almost nothing in a routine nutrition or cardiology-adjacent encounter falls into those buckets. If your default answer to "is this releasable?" is "no," you are probably wrong and you are definitely creating exposure.

How Long Do You Have to Fulfill the Request?

Thirty calendar days from receipt. Not thirty business days, and not thirty days from when the records coordinator got around to it. You may take one 30-day extension, but only if — within the original 30 days — you give the requester a written statement of the reason for the delay and the date by which you will deliver. One extension. No second bite.

Three details that decide compliance cases:

  1. The clock starts on receipt by the practice, including a fax sitting in a tray, a portal message, or a letter opened at the front desk. Internal routing delay is your problem, not the patient's.
  2. Verification does not pause the clock. Reasonable verification is required, but it runs inside the 30 days.
  3. Format follows the request. If the individual asks for an electronic copy of records you maintain electronically, you must provide it in the requested form and format if readily producible — including a specific delivery method, if it's reasonable.

HHS's individual right of access guidance is the controlling reference here, and it is worth printing for your records staff rather than paraphrasing from memory.

Verifying the Requester Without Building a Wall

HIPAA requires reasonable verification of identity and authority. It does not permit you to invent friction. Requiring an in-person appearance, a notarized signature, or a proprietary form as the only accepted path is the fastest way to turn a records request into a complaint.

Set a written verification standard and apply it uniformly:

  • Patient, in person: photo ID check, logged.
  • Patient, by phone or mail: two matching identifiers from the chart plus a callback to the number on file.
  • Patient, via portal: authenticated session is sufficient verification; do not layer a second form on top.
  • Anyone else: documented authority — see below.

Personal Representatives and the Daughter on the Fax

Heart failure management often involves a family caregiver who handles logistics, and that caregiver frequently makes the records request. Being involved in someone's care is not the same as being their personal representative.

A personal representative has authority under state law — a healthcare power of attorney, guardianship order, or executor appointment. Get the document, scan it into the chart, and note the scope and expiration. If the daughter has no such authority, she needs a signed HIPAA authorization from the patient, which is a different instrument with different content requirements than a right-of-access request. Train your front desk to tell the two apart on the phone, because the timelines and fee rules diverge.

Third-Party Directives

A patient can direct you in writing to send their records to a third party — the new cardiology group, an attorney, a health plan. Since a 2020 federal district court ruling narrowed part of the 2013 expansion of that right, the safe operating posture is this: honor the directive, keep it in writing and signed by the individual, and treat the fee analysis as separate from the patient-rate analysis. Document which lane each request is in on the request log itself. Auditors and complaint investigators will ask.

What You Can Charge, and What You Can't

Under the patient rate, you may charge a reasonable, cost-based fee limited to labor for copying, supplies, postage, and — if the individual agreed in advance — preparation of a summary or explanation. HHS's access guidance also describes an optional flat fee for electronic copies of electronically maintained PHI; it is an option, not a cap and not a requirement.

You may not charge for search and retrieval, for the time spent verifying identity, for maintaining systems, or for a per-page fee applied to an electronic export. If your clearinghouse or release-of-information vendor is billing patients a per-page rate for a PDF, that is your liability, not theirs, and the correspondence trail runs to your practice.

Post the fee schedule. Give an advance estimate on request. Cost transparency ends more disputes at the front desk than any policy document ever will.

The Vendor Map Behind a Single Nutrition Counseling Note

Trace one visit. The contracted dietitian who wrote the counseling note is a business associate if she isn't on your payroll. The remote weight-log platform is a business associate. The transcription service, the portal host, the release-of-information vendor, the fax-to-email gateway, and the cloud storage where scanned authorizations land are all business associates. So is the IT contractor who can see the file share.

Every one of them needs a signed Business Associate Agreement before PHI moves — and every one of them needs a contractual obligation to return or destroy that PHI at termination, plus a duty to make records available so you can meet your 30-day obligation. That last clause is the one practices forget, and it's the one that strands you when a vendor relationship ends mid-request.

If you inventory your vendor list this week and find gaps, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription. Close the paper gap first; you can negotiate the security addenda afterward. What you cannot do is keep routing chart data to an unpapered vendor while you shop.

HHS publishes sample business associate agreement provisions that set the floor. They are a floor, not a finished contract — they say nothing about breach notification timelines, subcontractor approval, or records-production turnaround, all of which you should specify.

A Worked Timeline: Day 0 to Day 30

Assign these steps to named roles, not to "records."

  1. Day 0 — Front desk. Date-stamp the request on receipt, regardless of channel. Log it in the access tracker with channel, requester, and requested format. Scan and attach the original.
  2. Day 0–1 — Records coordinator. Classify: right-of-access, authorization, or third-party directive. Wrong classification here poisons the fee and timeline decisions downstream.
  3. Day 1–3 — Records coordinator. Verify identity or authority against the written standard. Log the method used.
  4. Day 3–7 — Records coordinator plus clinical lead. Assemble across systems: EHR export, contracted dietitian's notes, cardiology consult correspondence, vendor-held monitoring data your team uses, billing records.
  5. Day 7–10 — Privacy officer. Spot-check for commingled PHI belonging to another individual. This is the single most common redaction failure in family-caregiver requests.
  6. Day 10–14 — Records coordinator. Provide the fee estimate if any charge applies. Do not hold the record hostage to payment beyond your normal, documented practice.
  7. By Day 25 — Privacy officer. If delivery will slip, issue the written extension notice with a specific completion date. Calendar the new date immediately.
  8. By Day 30 — Records coordinator. Deliver in the requested format via the requested method. Log delivery date, method, and recipient confirmation. Retain the log for six years.

Where Practices Actually Lose These Cases

Since launching its Right of Access Initiative in 2019, OCR has announced a long series of enforcement actions against providers of every size — solo practices, dental offices, behavioral health groups, hospital systems. The recurring fact pattern is unglamorous: a patient asked, nobody responded, the patient complained, and the records still weren't produced months later.

Three specific failure modes to check against your own operation:

  • The request never got logged. A voicemail, a portal message, or a note handed to a nurse is a request. If your tracker only captures the paper form, you are already late on requests you can't see.
  • The extension notice was verbal. Verbal doesn't count. Written, within 30 days, with a date.
  • The vendor held the data. A release-of-information or monitoring vendor's backlog is not a defense. Your BAA should obligate them to a turnaround that fits inside your 30 days — put a number in the contract.

You can review published breach and enforcement summaries on the HHS breach portal. Read a few from practices your size. The pattern-matching is more persuasive to a skeptical partner than any policy memo.

A Ten-Minute Self-Audit for This Quarter

Pull your last ten completed records requests and answer, in writing:

  • Is there a date-stamped receipt entry for each, and a delivery date? What was the median turnaround?
  • Did any request touch data held by a vendor rather than your EHR? Did you get it?
  • Does every vendor named in those workflows have a current, countersigned BAA on file with a records-production clause?
  • Was every fee charged traceable to labor, supplies, or postage — with the math documented?
  • Did any request come from a caregiver, and if so, is the authority document scanned into the chart?

If you can't answer all five in ten minutes, the finding isn't a records problem. It's a documentation problem, and it will show up again in your risk analysis. Practices that want that side of the house handled systematically can automate the risk analysis and policy set rather than rebuilding spreadsheets every year.

Start with the vendor list, because that's the dependency everything else sits on. Confirm which business associates touch nutrition counseling, cardiology correspondence, and monitoring data, then put a signature-ready BAA in front of each of them this month. Records requests get easier when the contracts underneath them already say who produces what, and how fast.