Subclavian Steal Syndrome Records Requests: 30-Day Rules
A patient emails your practice on a Friday afternoon: "Please send me everything you have — the ultrasound, the CT, the specialist's notes, all of it." Their chart carries a diagnosis of subclavian steal syndrome. Your front desk forwards the message to the records inbox, where it sits until Monday. That weekend counted. The 30-day clock under 45 CFR 164.524 started the day the request arrived, not the day someone opened it.
This article is for the person who owns that inbox. It covers how to scope, verify, price, and deliver a records request when the chart is spread across your practice, a vascular specialist, and an outside imaging center — and how to keep your vendor paperwork clean while doing it.
Why Subclavian Steal Syndrome Charts Fragment Across Organizations
You do not need to understand the vascular mechanics to handle the request. You need to understand the paper trail. Conditions like subclavian steal syndrome are typically identified through vascular imaging and frequently involve referral to a vascular specialist, which means the record that a patient thinks of as "my chart" was created by two or three separate covered entities.
That fragmentation is the entire administrative problem. Your practice holds the referral note, the office visits, and whatever imaging reports came back to you. The imaging facility holds the study itself. The specialist holds the consultation and any follow-up. Each of those organizations owes the patient access to its own designated record set — not to the others'.
Where practices get into trouble is the middle ground: the outside report you received and filed. Once you receive a report and use it to make decisions about that patient, it sits in your designated record set. You produce it. You do not get to redirect the patient to the originating facility because the letterhead says someone else's name.
How Fast Must You Respond to a Subclavian Steal Syndrome Records Request?
Thirty calendar days from receipt. One 30-day extension is permitted, but only if you notify the patient in writing within the original 30 days, state the reason for the delay, and give a date by which you will deliver. You get one extension per request — not one per record type, not one per department.
Several states impose shorter deadlines, and state law that is more protective of the individual controls. If your state requires production in 15 business days, that is your operational deadline regardless of what HIPAA permits. Build your workflow around the shortest applicable clock, not the federal ceiling.
The clock runs on receipt, not on triage. A request that lands in a general voicemail, a portal message thread, or a front-desk email counts from the moment it arrives at your organization. HHS's right of access guidance is explicit on this point and worth circulating to every staff member who touches patient communication.
Defining the Designated Record Set Before You Start Pulling
Scope disputes cause more delay than production does. Decide in advance — in writing, in a policy — what your designated record set includes, so that a records clerk is not making that judgment call on a Tuesday afternoon.
Imaging Is Where Hybrid Records Break
A patient with subclavian steal syndrome may ask for "the ultrasound," meaning three different things: the radiologist's narrative report, the images themselves, or the raw acquisition data in the vascular lab system. The report is unambiguously part of the record. Images that you hold and used in care are also part of it. Raw waveform data or proprietary system files that never functioned as a clinical record generally are not.
Write that distinction down. Then confirm with the patient what they actually want, in writing, and note that confirmation in the request log. Clarification does not stop the clock, so do it in the first 48 hours.
What You Can Leave Out
Psychotherapy notes maintained separately, and information compiled in reasonable anticipation of litigation, sit outside the access right. Peer review files and quality-improvement documents that were never used to make decisions about the individual are also outside the designated record set. Almost nothing else is. Billing records, itemized statements, and prior authorization correspondence are all in scope if a patient asks.
Verification That Does Not Become an Obstacle
You must verify the identity and authority of the requester under 45 CFR 164.514(h). You may not impose unreasonable barriers to doing so. Those two sentences sit in tension, and OCR has resolved dozens of right-of-access enforcement matters since launching that initiative in 2019 — most of them small practices where the delay traced back to verification theater.
Practices that require notarization, mandate an in-person visit, or refuse to accept an emailed request from a known patient email address are creating an obstacle, not verifying identity. Reasonable approaches include:
- Confirming two identifiers already in the chart (date of birth plus last four of an identifier on file)
- Accepting a signed request through an authenticated patient portal account
- Calling the phone number of record and confirming the request verbally, then logging who called and when
- Accepting a photographed government ID by secure upload — but not requiring the original
For requests made by a personal representative — an adult child managing a parent's vascular care, for example — verify the legal authority once, scan the documentation, and note the scope and expiration in the chart so the next request does not restart the analysis.
Fees: What You Can Charge, and What Draws Complaints
When the patient requests copies for themselves, your fee must be reasonable and cost-based. You may recover labor for copying (including electronic copying), supplies such as media or paper, postage, and the cost of preparing a summary if the patient agreed to one in advance.
You may not charge for search and retrieval, for verification, for data storage, or for the overhead of maintaining your systems. That single sentence accounts for a large share of access complaints. A vascular imaging study is expensive to store; the patient does not fund that storage through a records fee.
Third-party directives are a separate legal analysis after the 2020 Ciox Health v. Azar decision, which narrowed how the patient-rate fee limits apply when records go to someone other than the individual. If an attorney requests records under a signed authorization rather than as a patient-directed transmission, your fee schedule and your state's copying statute may govern instead. Train your release-of-information staff to identify which lane a request is in before quoting a price.
The Vendor Chain Behind One Records Request
Trace a single subclavian steal syndrome records request through your systems and count the outside companies that touch protected health information along the way. A typical count:
- The release-of-information vendor that processes and fulfills the request
- The imaging archive or PACS host holding the study
- The transcription service that produced the consultation note
- The secure file transfer or encrypted email platform that delivers the copy
- The cloud backup provider replicating all of the above
- The e-fax service, if the patient asked you to send anything to another clinician
Every one of those is a business associate. Every one needs a current, signed agreement that addresses breach notification timelines, subcontractor flow-down, and — critically for records work — the vendor's obligation to make PHI available so that you can meet your own 30-day deadline. If your ROI vendor takes 25 days to produce a file, you are still the one who missed the clock.
If you find a gap during that inventory, close it before the next request lands. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — which is considerably faster than routing a redline through counsel for a fax vendor you onboarded in 2019 and forgot about.
A Worked 30-Day Timeline
Day 0 (Friday): Request arrives by portal message. Automated acknowledgment fires. Request is logged with a due date calculated by the system, not by a person.
Day 1 (Monday): Records coordinator reviews scope. The patient asked for "everything." Coordinator sends a clarifying message: does the patient want imaging files on disc, or the reports only? Verification method selected — portal authentication satisfies it.
Day 3: Patient responds: reports plus the duplex study images. Coordinator opens a retrieval task with the imaging archive vendor and sets an internal due date of Day 12, well inside the external deadline.
Day 8: Practice-side records assembled — office notes, referral letter, outside consultation report received from the vascular specialist, billing statements.
Day 14: Imaging files delivered by the vendor. Coordinator confirms the files open and are not corrupted. This step gets skipped constantly and produces a second request 10 days later.
Day 16: Fee calculated on the published cost-based schedule. Patient notified of the amount and delivery method.
Day 19: Delivery through the encrypted portal. Delivery confirmation logged, including timestamp, format, and the name of the person who released it.
Eleven days of buffer. That buffer is the point. Practices that target Day 29 have no room when the imaging vendor's contact is on leave.
Denials and Partial Production
Grounds for denial are narrow, and unpaid balances are not among them. You cannot withhold a chart because the patient owes money. You cannot condition access on signing a new financial agreement or completing a satisfaction survey.
If you do deny in part — for example, withholding material compiled for litigation — produce everything else within the deadline and issue a written denial that states the basis, explains the right to have the denial reviewed where that right applies, and describes how to complain to you and to OCR. A silent partial production is worse than a documented denial. OCR publishes its resolution agreements and civil money penalties, and the pattern in access cases is consistent: the practice ignored the request or answered it incompletely without explanation.
Information Blocking Sits on Top of the Privacy Rule
Meeting the 30-day access deadline does not automatically satisfy the information blocking rules under the Cures Act. If a patient requests electronic health information and your organization delays, conditions, or discourages that access without a defined exception applying, you have a second exposure independent of HIPAA. Review the current information blocking guidance alongside your access policy, not separately from it.
Practical translation: if you can release electronically today, releasing on Day 29 by mail because "that is our process" is a defensible HIPAA position and a weak information blocking position.
Five Things to Audit This Quarter
- Intake coverage. Pull every channel a request can arrive through — voicemail, portal, fax, email, walk-up — and confirm each one routes into the same log with the same clock.
- Fee schedule. Read your posted schedule line by line. If it lists retrieval, administrative, or per-page charges above cost, revise it.
- Vendor list. Confirm a signed agreement for every entity that touches records requests, including the ones procured by a single department.
- Extension letters. Count how many requests used an extension last quarter. A rate above roughly one in ten indicates a capacity problem, not a complexity problem.
- Format defaults. Verify that electronic delivery is the default and paper is the exception.
None of this requires understanding subclavian steal syndrome clinically. It requires knowing where the records live, who holds them, and what your deadline is.
Next Step
Start with the vendor inventory, because it is the piece you can finish this week and the piece most likely to be incomplete. List every outside party in your records-request chain, check each against your signed agreements, and produce a compliant BAA for any gap you find before the next request arrives. If your broader documentation set — risk analysis, policies, workforce training records — has drifted since your last review, automating the compliance document set is a reasonable follow-on project once the contracts are current.