Your referral coordinator opens the queue on a Monday and finds nineteen outbound referrals pending. One is a patient seen Thursday whose visit note describes symptoms of tonsilloliths — the halitosis-and-throat-irritation complaint that routinely ends with "we're sending you to ENT." The specialist's office has already faxed over a records request, and your medical assistant is standing at the desk asking whether she needs a signed authorization first. She does not. The fact that she isn't sure — and that three people in your practice would give three different answers — is the operational problem this article is about.

This is a workflow post for practice administrators, privacy officers, and release-of-information staff. It covers what HIPAA permits when records move from a primary care or dental office to a specialist, who does what and when, how to verify the requester, and which vendors in that chain need a Business Associate Agreement on file.

Why Symptoms of Tonsilloliths Land in Three Different Charts

Tonsil stones are calcified debris in the tonsillar crypts. Patients rarely present to a single provider about them. The complaint surfaces at a dental hygiene appointment, or at a primary care visit, or at an urgent care after hours — and evaluation frequently ends up with an otolaryngologist. That's the entire clinical context you need for this article, and it's the reason the administrative footprint is larger than the encounter itself.

The result is predictable: one patient, three covered entities, and protected health information crossing organizational boundaries at least twice. A dental office sends a note to primary care. Primary care sends a referral packet to ENT. ENT sends a consult letter back. If imaging was ordered, a fourth organization joins the chain.

Each of those hops is a disclosure. Each one has a rule attached, a staff member responsible, and a place in your log. Multiply it across every low-acuity specialty referral your practice generates in a month and you're looking at the single highest-volume category of PHI movement in an ambulatory setting.

Do You Need an Authorization to Send the Chart to the ENT?

No. Under 45 CFR 164.506, a covered entity may use and disclose protected health information for treatment, payment, and health care operations without patient authorization. Sending a referral packet to a specialist who will treat the patient is a treatment disclosure. No signature required, no authorization form, no delay.

Three qualifiers your staff should memorize:

  • The disclosure must actually be for treatment. "The ENT office asked for it" is not the standard; "the ENT is treating this patient" is.
  • You must reasonably verify the identity and authority of the person requesting it (45 CFR 164.514(h)).
  • State law, and any psychotherapy notes or substance use disorder records in the chart, can impose stricter requirements than HIPAA does.

HHS maintains a plain-language reference on permitted uses and disclosures for treatment, payment, and operations. Print it. Put it in the front-desk binder next to the fax cover sheets.

Where practices get this backwards

The common failure is over-restriction, not over-disclosure. Staff who have been trained to fear HIPAA default to "we need an authorization," the referral stalls for a week, the patient calls angry, and the specialist's scheduler works around your office entirely. That's a service failure with a compliance root cause — and under the information blocking rules, unnecessary delay in sharing electronic health information can also become a regulatory problem. HealthIT.gov's information blocking resources outline the exceptions that do and don't apply.

Minimum Necessary Doesn't Apply Here — Build a Tight Packet Anyway

The minimum necessary standard explicitly does not apply to disclosures to a health care provider for treatment purposes. You may legally send the entire chart to the ENT. HHS confirms this in its minimum necessary guidance.

Legal and advisable are different things. Sending 340 pages when the consulting physician needs eight creates three practical risks: the specialist misses the relevant note, your staff spends twenty minutes on a task that should take four, and every additional page is additional PHI sitting on a fax server you don't control.

Define a standard specialty referral packet in writing. For an ENT referral arising from a complaint like symptoms of tonsilloliths, a defensible default set is the referring note, the problem list, the medication list, allergies, relevant recent labs or imaging reports, insurance and demographic information, and the referral order itself. Anything beyond that goes in only when the referring clinician says so.

Write the packet definition into your release-of-information procedure and name the role that assembles it. "Someone at the front desk" is not a role assignment.

Verify the Requester Before the Packet Leaves the Building

Verification is the step that gets skipped, and it's the one that turns a permitted disclosure into a breach. An inbound fax on letterhead is not verification. A phone call from a person who says they're a scheduler at an ENT office is not verification.

Set a two-tier standard:

  1. Known referral partners. Maintain a list of practices you refer to regularly, with verified fax numbers, direct addresses, and portal identities. Verification means matching the request against that list. Update it quarterly — numbers get reassigned.
  2. Unknown requesters. Call back on a number you look up independently, never the number printed on the request. Confirm the patient is established with that practice. Document who you spoke to and when.

One more control worth the ten seconds it costs: before any transmission, a second person confirms the patient identifiers on the cover sheet match the identifiers on page one of the packet. Misdirected faxes and mismatched packets remain among the most common small-practice incidents reported to OCR, and nearly all of them are caught by that check.

A Ten-Day Referral Timeline With Names Attached

Here is a worked example. Adjust the role titles to your org chart, but keep the structure.

Day 0 — visit. Clinician documents the encounter and enters the referral order, specifying the packet contents if they deviate from the standard set. Front desk gives the patient the specialist's contact information and a one-page notice explaining that records will be shared with the treating specialist.

Day 1 — assembly. Referral coordinator assembles the standard packet, runs the identifier check, and confirms the destination against the verified partner list.

Day 2 — transmission. Packet goes out by the practice's designated secure channel. Coordinator logs the date, destination, method, and packet contents in the disclosure log.

Day 3–7 — confirmation. Coordinator confirms receipt. No transmission confirmation within five business days triggers a resend and a note in the log.

Day 7–10 — loop closure. Coordinator verifies the appointment was scheduled. If the patient never scheduled, that's a care-coordination flag, not a privacy issue — but the same person catches it because they're already looking.

Inbound. When the consult letter comes back, it is filed to the chart within one business day and routed to the referring clinician's inbox. Unfiled inbound consult letters sitting in a shared fax folder are PHI stored outside your designated record set. Auditors notice.

When the Patient Asks for the Records Instead

Different rule, different clock. If the patient requests a copy of their own record — or directs you to send it to a third party — you are operating under the HIPAA right of access at 45 CFR 164.524, not the treatment exception.

You have 30 days to act, with one permitted 30-day extension if you notify the patient in writing of the reason and the new date. You may charge only a reasonable, cost-based fee. You may not require the patient to explain why they want the records, and you may not require them to come in person if they've asked for electronic delivery in a format you can readily produce. HHS's individuals' right of access guidance is the authoritative reference, and OCR's enforcement history in this area is long and unforgiving.

Train the front desk to distinguish the two paths by asking one question: who is asking? Provider asking for treatment purposes takes the referral path. Patient asking, or patient directing, takes the access path with the 30-day clock. Everything else — attorneys, insurers, employers — goes to the privacy officer.

The Vendors Sitting in the Middle of Every Referral

Trace one referral packet from the exam room to the specialist's inbox and count the third parties that touch it. In most practices the list includes an EHR or practice management host, an e-fax or secure messaging provider, possibly a transcription service, possibly a referral management platform, and whoever backs up the file server.

Every one of those is a business associate. Every one needs a signed BAA on file before PHI flows, and every one belongs in your risk analysis as a place where PHI lives or transits. If you cannot produce a current, countersigned agreement for each vendor in that chain within ten minutes, you have a documentation gap that a records request or an OCR inquiry will find. Practices that need to close that gap quickly can generate a signature-ready Business Associate Agreement through a guided wizard rather than routing every vendor through outside counsel.

The BAA is the paperwork. The risk analysis is the substance — and it's the requirement OCR cites most often. A referral workflow like this one puts PHI on fax servers, in cloud inboxes, and inside third-party portals, and your Security Rule risk analysis has to reflect that reality rather than a generic template. If yours is a three-year-old spreadsheet that predates your current referral platform, automating your risk analysis and policy document set is a faster path to current than another round of committee meetings.

Log the Disclosures You Aren't Required to Account For

Treatment, payment, and operations disclosures are excluded from the accounting of disclosures a patient can request under 45 CFR 164.528. You are not legally obligated to track the ENT referral.

Track it anyway. A simple log — date, patient identifier, destination, method, packet contents, staff initials — costs about fifteen seconds per referral and answers three questions you will eventually be asked: did we send it, what exactly did we send, and who sent it. When a patient calls in April claiming the specialist never got their chart, the log ends the conversation in one lookup. When something does go to the wrong fax number, the log is the first artifact of your breach risk assessment.

Five Failure Points to Audit This Quarter

  • Stale destination list. Pull ten referral destinations and verify each fax number and direct address against a source you look up independently.
  • Authorization confusion. Ask three staff members whether a treatment referral needs a signed authorization. If you get inconsistent answers, retrain this week.
  • Oversized packets. Sample five outbound referrals and measure them against your written standard packet.
  • Unfiled inbound consults. Open the shared fax folder. Count documents older than five business days.
  • Missing BAAs. List every vendor that touches a referral packet. Match each to a signed, current agreement.

None of these takes more than an hour. All five find problems in most practices the first time they're run.

The Point of All This

An encounter involving symptoms of tonsilloliths is clinically unremarkable and administratively representative. It generates a specialist referral, a records transfer between two covered entities, a consult letter coming back, and a handful of vendor systems in between — the exact pattern that describes most of what your release-of-information staff does all day.

Get the pattern right once and it scales across every specialty referral you send. Get it wrong and you're producing both service failures and disclosure risk from the same broken process.

If your policies, risk analysis, and vendor documentation haven't been refreshed since your referral workflow changed, start there — build the current document set, then walk one live referral end to end against it and see where the two disagree.