Stenosis Aorta Records: What Your Practice Must Keep
Count the organizations that will touch a single stenosis aorta workup before the chart goes quiet: your practice, the imaging center that performed the echocardiogram, the cardiology group you referred to, the hospital that may perform a procedure, and whatever image-exchange service moves the DICOM study between them. That is five custodians, four interfaces, and at least three chances for a records request to land on the wrong desk. This post is about that administrative trail — what your staff captures, how long you hold it, who is allowed to release it, and which vendor contracts have to exist before any of it moves.
Nothing here is clinical guidance. The only clinical fact that matters for your workflow is a structural one: this category of encounter almost always involves outside imaging and specialist referral, which means records leave your building and come back in formats your EHR did not generate.
What a Stenosis Aorta Encounter Actually Deposits in Your Chart
Your front desk sees a referral. Your record sees six or seven distinct artifacts, each with a different retention rule and a different release pathway.
- The originating note from your provider, with the referral order and the reason for it.
- An imaging report — narrative text, usually delivered by interface, fax, or portal from an outside facility.
- The imaging study itself — DICOM objects that often never enter your EHR at all, and instead sit in a vendor-hosted archive you access by link.
- Consult correspondence from the cardiology group, sometimes as a structured C-CDA, sometimes as a PDF someone scanned.
- Prior authorization documentation and payer correspondence.
- Scheduling and transport records, which are PHI even when they contain no clinical content.
The failure most practices discover during a records request is that item three is not theirs. When a patient asks for "everything," your staff produces the report and misses the study, because the study lives with a vendor. That gap is a records problem, an information blocking problem, and — if the vendor relationship was never papered — a Business Associate problem all at once.
Decide Now Whether the Images Are In Your Designated Record Set
The designated record set is the group of records your practice maintains and uses to make decisions about the individual. If your provider reviewed the images to make a referral decision, and you hold access to them, treat them as in-scope and write that determination into your policy. Do not leave it to a front-desk judgment call at 4:40 on a Friday.
Write a one-page inventory that maps each artifact type to: where it physically lives, who the custodian is, whether it is in the designated record set, and which staff role can release it. Review it whenever you add an imaging partner.
The 30-Day Clock on a Stenosis Aorta Records Request
How long does a practice have to release records after a cardiology workup? Under the HIPAA right of access, you must act on an individual's request for their PHI within 30 calendar days of receipt. You may take one 30-day extension, but only if you give the individual a written statement within the original 30 days explaining the delay and the date you will deliver. You must provide the records in the form and format requested if you can readily produce them, including electronically. You may charge only a reasonable, cost-based fee — labor for copying, supplies, postage, and preparing an explanation if the individual asked for one. You may not charge for search and retrieval time, and you may not condition release on payment of an unrelated balance.
OCR has published extensive guidance on this, and the HHS right of access guidance remains the operative reference for fee structure, format, and third-party directives. Note that a 2020 federal court decision narrowed the third-party directive requirement so that it applies to electronic copies of PHI held in an EHR — your policy should reflect that distinction rather than treating every "send it to my attorney" request as a right-of-access request.
The Clock Starts on Receipt, Not on Triage
This is where practices lose. The request arrives at the front desk on the 1st, sits in a folder until the records clerk works Wednesdays, and gets logged on the 9th. Your clock started on the 1st. Build a single intake point — one email address, one form, one physical inbox — and date-stamp on arrival, not on assignment.
Role Assignments: Who Touches the Chart and Who Signs Off
A referral-heavy chart needs named owners, not a shared responsibility. Assign these four roles by name in your policy manual and re-confirm them at every annual review.
- Intake owner. Date-stamps every records request, verifies identity, and routes. Cannot decide scope.
- Scope owner. Usually the records supervisor. Determines what falls inside the designated record set, including outside imaging, and documents the determination.
- Release owner. Executes the disclosure, applies minimum necessary where the disclosure is not to the patient, and logs it in the accounting of disclosures.
- Escalation owner. The privacy officer. Handles denials, partial denials, requests involving psychotherapy notes or another provider's records, and any request that will miss 30 days.
For a stenosis aorta chart specifically, add one instruction: the scope owner must check the imaging archive, not just the EHR document tab. Make it a checkbox on the request form so the omission is visible.
The Vendor Chain Nobody Papers Until an Audit
Every entity that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate and needs an agreement in place before the first byte moves. In a cardiology referral workflow, that list is longer than most administrators expect:
- The image-exchange or cloud PACS service that stores or routes echo studies
- Your transcription vendor, if consult letters are dictated
- The release-of-information contractor, if you outsource records fulfillment
- The fax-to-email gateway that delivers outside reports
- Any referral-management or care-coordination platform sitting between you and the specialist
- Your document-scanning or offsite-storage vendor
Note what is not on that list: the cardiology group you referred to. Provider-to-provider disclosure for treatment does not create a Business Associate relationship, and no BAA is required. Practices routinely waste weeks chasing signatures from referral partners while the actual image-hosting vendor operates on a clickwrap terms-of-service page with no HIPAA language in it.
HHS publishes sample Business Associate Agreement provisions, but sample provisions are not a contract — they are clauses you still have to assemble, scope, and get signed. If you are closing gaps across an imaging and referral chain, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase with no subscription, which matters when you need four agreements this quarter and none next quarter.
Audit the Chain Once a Year, in Writing
Pull your vendor list. For each name, record: BAA on file (yes/no), date signed, breach notification window specified, subcontractor flow-down clause present, and termination/return-of-data provision. Any "no" gets a 30-day remediation date and an owner. This document is the first thing OCR asks for when a complaint involves a vendor, and the OCR breach portal makes clear how many reported incidents originate with business associates rather than the covered entity itself.
Retention: Two Clocks That Are Not the Same Clock
Administrators conflate these constantly. Separate them in your policy.
The HIPAA documentation clock. HIPAA requires you to retain required documentation — policies, procedures, risk analyses, authorizations, BAAs, notices of privacy practices, disclosure accountings, sanction records — for six years from creation or from the date it was last in effect, whichever is later. HIPAA does not set a retention period for medical records themselves.
The medical record clock. That comes from state law, Medicare conditions of participation, payer contracts, and malpractice statutes of repose. It varies widely by state and by patient age at the time of service. Your retention schedule must cite the specific state statute you are relying on, by section number, so a new administrator can verify it without re-litigating the question.
For imaging specifically, ask a third question: who is retaining. If your image-exchange vendor purges studies after 24 months and your state requires longer, you have a compliance gap that lives entirely inside a vendor's default settings. Put retention duration in the BAA or the underlying service agreement, not in a support ticket.
Information Blocking: The Rule That Punishes Slow, Not Just Wrong
Under the 21st Century Cures Act information blocking regulations, practices that interfere with the access, exchange, or use of electronic health information can face consequences even when no HIPAA violation occurred. "We only release records by mail" and "our imaging partner handles that, call them" are the kinds of practices that draw scrutiny. Review the federal information blocking resources and confirm your policy names which exceptions you rely on and who approves invoking one.
Practical translation for a stenosis aorta workflow: if a patient asks for the echo study electronically and you hold it electronically, "we can only give you the report" is a defensible answer only if you can articulate why the images are outside your control — and you should have documented that determination long before the request arrived.
A Worked Example: Day 1 Through Day 22
Day 1. Patient submits a written request at the front desk for "all cardiac records." Intake owner date-stamps, verifies photo ID, logs the request in the tracking sheet, routes to the scope owner. Clock starts.
Day 3. Scope owner assembles: office notes, referral order, imaging report, consult letter from cardiology, payer correspondence. Checks the imaging archive box — the echo study is hosted by your image-exchange vendor and your provider reviewed it. Marked in-scope.
Day 6. Vendor portal export produces the DICOM study. Scope owner confirms the consult letter from the specialist is a record your practice maintains and uses, so it is releasable; no need to redirect the patient to the cardiologist.
Day 9. Release owner prepares a fee estimate: labor for copying and media only. No search-and-retrieval charge. Patient is notified of the amount and chooses electronic delivery to a secure portal account.
Day 14. Release executed. Logged with date, recipient, contents, and delivery method.
Day 22. Privacy officer's monthly review confirms the request closed inside 30 days and that the imaging component was included. Sampling two closed requests per month is enough to catch systemic omissions.
Five Failure Points to Check This Week
- Records requests arriving by more than one channel with no single date-stamp.
- Outside imaging treated as "not our record" without a documented determination.
- An image-exchange or fax-gateway vendor operating with no BAA.
- A retention schedule that cites HIPAA's six-year documentation rule as if it governed medical records.
- No named escalation owner, so requests that will miss 30 days simply miss them.
None of these require new software. They require a written inventory, four named roles, and a monthly sample review — which is the same discipline that carries you through a risk analysis, a breach investigation, or a payer audit.
Next Step
Start with the vendor list, because it is the gap with the shortest remediation path and the longest tail of consequences. Pull every entity that touches imaging, transcription, faxing, or records fulfillment for your stenosis aorta referrals, and confirm a signed agreement exists for each. Where one does not, build the Business Associate Agreement and get it signed before the next study moves. If your broader policy set and risk analysis are also overdue, automating the full compliance document set will close the rest faster than rebuilding templates by hand.