Splinting Carpal Tunnel: Referral and Records Rules
A patient leaves your primary care office on a Tuesday with two things: a referral to a hand specialist and an order for a wrist orthosis. By Friday, four organizations hold some piece of that chart — your practice, the specialist, the durable medical equipment supplier who fabricates the splint, and possibly a workers' compensation carrier. Nobody signed an authorization form. In most of those transfers, nobody needed to. Splinting carpal tunnel is a routine encounter that quietly triggers a multi-organization records workflow, and the administrative side of it goes wrong more often than the clinical side.
This post is for the person who owns that workflow: the practice administrator, privacy officer, or office manager who decides what goes in a referral packet, which vendors need agreements, and who answers when a patient asks why their employer got a copy.
The Four Organizations That Touch One Splinting Carpal Tunnel Referral
Map the disclosure path before you write a policy about it. For a typical conservative-management pathway, the chart moves like this:
- Your practice to the specialist or hand therapist. Treatment disclosure between two covered entities.
- Your practice to the orthotics or DME supplier. Usually a treatment or payment disclosure to another covered entity — not a business associate relationship.
- Your practice to the health plan. Payment disclosure, often including clinical notes if prior authorization applies.
- Your practice to a workers' compensation carrier or employer. A different rule entirely, and the one that generates complaints.
Four destinations, four legal bases, four different sets of limits on what you send. Front-desk staff who treat all four as "send the chart" are the source of most avoidable problems here.
Do You Need Patient Authorization to Send Records to the Hand Specialist?
No. Under the HIPAA Privacy Rule, a covered entity may disclose protected health information to another covered entity for that provider's treatment purposes without patient authorization. The disclosure is permitted at 45 CFR 164.506(c)(2). Your practice does not need a signed release, and you do not need to document the disclosure in an accounting of disclosures, because treatment, payment, and health care operations disclosures are excluded from that accounting requirement.
State law can be stricter — several states impose consent requirements on the transmission of behavioral health, HIV, or substance use records, and some require written consent for any release. Your policy should say which rule your practice follows, and it should name the state.
Practical version for the front desk: for a treatment referral, no signature is required under HIPAA. For a disclosure to an employer, a signature almost always is. If the request came from anyone other than a treating provider or a plan, stop and route it to the privacy officer.
Minimum Necessary Doesn't Apply Here — Your Packet Still Needs a Definition
The minimum necessary standard does not apply to disclosures to a health care provider for treatment. HHS is explicit on this point in its minimum necessary guidance. You may legally send the entire record to the consulting specialist.
That is a permission, not an instruction. Dumping a 400-page longitudinal chart on a hand specialist creates three operational problems: the receiving office cannot find the relevant documentation, your staff spend twenty minutes per referral on a task that should take three, and any transmission error now exposes far more data than the encounter warranted.
Define a default referral packet and let staff override it
Write a standing packet definition for upper-extremity referrals and put it in your referral policy so nobody improvises. A reasonable default:
- The referring note and reason for referral
- Relevant prior encounter notes from the past 12 months
- Any diagnostic study reports on file
- Current medication and allergy list
- Insurance and demographic face sheet
Then add the override rule: if the receiving provider requests more, send more, and log the request. The point of the definition is that staff never have to guess, and your audit trail shows a consistent practice rather than a hundred individual judgment calls.
The Splint Supplier Is Probably Not Your Business Associate
This is where practices sign agreements they don't need and skip ones they do. A durable medical equipment or orthotics supplier that fabricates or fits a wrist splint is furnishing health care to the patient. When you send them an order and supporting documentation, you are disclosing PHI to another provider for that provider's treatment and payment activities. They are acting on their own behalf, not performing a function for you. That makes them a covered entity in their own right — not a business associate — and no BAA is required.
Vendors sometimes ask for a BAA anyway, out of caution or because their own compliance checklist demands one. Signing an unnecessary agreement isn't a violation, but it does clutter your vendor inventory and create obligations you then have to monitor. Know why you signed each one.
When a splint-related vendor is a business associate
The relationship flips when the vendor is doing something on your behalf rather than treating the patient:
- A release-of-information company that fulfills records requests for your practice
- An e-fax or secure-messaging service that transports referral packets
- A referral-management or care-coordination platform that stores your outbound referrals
- A billing company that submits the orthosis claim under your NPI
- A transcription or ambient documentation vendor that handles the encounter note
Each of those needs a signed agreement before PHI moves. If you have vendors on that list operating on a handshake or an outdated form, a six-step business associate agreement wizard will get you a signature-ready document faster than routing a request through counsel for a low-risk transport vendor.
Workers' Compensation Changes the Analysis Completely
Repetitive-strain complaints frequently arrive attached to an open workers' compensation claim, which means the same splinting carpal tunnel encounter generates a request from an adjuster, a third-party administrator, or the employer directly. Handle these differently.
HIPAA permits disclosure of PHI as authorized by and to the extent necessary to comply with workers' compensation laws — 45 CFR 164.512(l). The scope of what you may release is set by your state's workers' compensation statute, not by your judgment. Some states permit broad disclosure of records related to the claimed injury; others require a signed claimant authorization or a specific form.
Three operating rules for your staff:
- Limit to the claimed condition. A comp disclosure covers the work injury. It does not cover the patient's unrelated conditions, medications for other diagnoses, or historical notes with no bearing on the claim.
- Verify who is asking. An employer's HR representative is not automatically entitled to what an adjuster is entitled to. Ask which capacity they're writing in and get it in writing.
- Log it. Unlike treatment disclosures, workers' comp disclosures made under 164.512(l) are subject to the accounting of disclosures requirement. If a patient later asks for an accounting, this is what has to be in it.
Assign these requests to one named person. Comp requests are the single most common source of over-disclosure in orthopedic and primary care settings, and they are almost always the result of a well-meaning staff member sending the whole chart to be helpful.
The 30-Day Clock When the Patient Asks for the Splint Order
Patients request their own records constantly in this pathway — usually because a new employer, a second-opinion specialist, or an insurer wants the order and the supporting note. Under the individual right of access, you must act on the request within 30 calendar days, with one 30-day extension available if you notify the patient in writing of the reason and the expected date.
Two details staff get wrong. First, a patient may direct a copy to a third party, and that direction has to be in writing, signed, and clear about the recipient. Second, your fee has to be reasonable and cost-based; you cannot charge for search and retrieval time. HHS keeps its right of access guidance current, and OCR has pursued enforcement in this area consistently. Print the fee schedule and post it where the records clerk sits.
Slow Referral Fulfillment Is Now an Information Blocking Question
The old failure mode — a referral packet sitting in a queue for two weeks because one staff member handles releases and she's on vacation — is no longer just a service problem. Information blocking regulations under the 21st Century Cures Act prohibit practices that interfere with the access, exchange, or use of electronic health information, and health care providers face disincentives when the Office of Inspector General determines blocking occurred.
Delay without a valid exception is a plausible theory of blocking. Review the exceptions on the federal information blocking resource and make sure your written referral procedure has a stated turnaround time, a named backup, and a documented reason whenever the practice declines or delays a release.
A workable service level
Set an internal target and measure against it. Something like: routine referral packets transmitted within two business days of the order; urgent packets same day; patient access requests acknowledged within five business days and fulfilled within 30. Pull a monthly count of exceptions and look at why they happened. The number matters less than the fact that you can produce it.
Who Owns Each Step: A Role Assignment You Can Copy
Ambiguity is the actual risk. Write names next to these functions and post it in the back office.
- Referral coordinator — builds the packet from the standing definition, confirms the receiving provider's secure address, transmits, logs completion.
- Records clerk — handles patient access requests and third-party directions, applies the fee schedule, tracks the 30-day clock.
- Privacy officer — reviews every workers' comp, employer, and attorney request before release; maintains the accounting log.
- Practice administrator — owns the vendor inventory, confirms every business associate has a current signed agreement, and reviews transport methods annually.
- Backup for each role — named, trained, and not the same person for all four.
Every one of these steps should trace back to a written policy and an annual risk analysis that accounts for how PHI actually leaves your building. If your policy binder was assembled years ago and predates your current e-fax vendor, referral platform, and documentation tool, the gap will surface during an audit or a breach investigation. Tools that generate a current risk analysis and the full policy set are a faster path than rebuilding the documentation by hand — and they force you to inventory the vendors you forgot you had.
Three Things to Check This Week
- Pull five recent upper-extremity referral packets. Did they contain roughly the same documents, or did each staff member decide independently?
- Pull the last three workers' comp releases. Were they limited to the claimed condition, and are they in the accounting log?
- Open your vendor list. Does every entity that transports, stores, or processes referral records have a signed, current agreement on file?
If any of those three checks comes back uncomfortable, start with the vendor list — it's the fastest to fix and the most likely to be examined after an incident. Build the risk analysis and policy set that documents this workflow, then train the two people who actually run it. The referral for splinting carpal tunnel will keep coming through the door either way; the difference is whether you can explain, in writing, where the chart went and why.