A fax lands at 8:40 on a Tuesday. A law firm wants "the complete file" for a patient your allergy clinic saw four times over two years for vasomotor rhinitis. The signature block is the patient's. The delivery address is the firm's. Your records coordinator is out until Thursday, and the clock started the moment that fax hit the machine — not when someone gets around to reading it.

This post is a records workflow, not a clinical one. It covers how to verify the requester, how to count the 30 days, what you may charge, and which vendor contracts have to be in place before you release anything. If you run the front desk, the release-of-information queue, or the privacy program, this is your operational checklist.

Why Vasomotor Rhinitis Charts Scatter Across Three Organizations

The administrative problem here has a simple root: this is a diagnosis of exclusion that frequently travels. A patient with chronic nasal symptoms often passes through primary care, allergy testing, and an ENT consult before anyone settles on a label. That means the "complete record" a requester imagines is actually four record sets held by three covered entities plus whatever your imaging partner keeps.

You are only obligated to produce what you maintain in your designated record set. But your staff will spend real time explaining that boundary, and if you explain it badly, the patient files a complaint with the Office for Civil Rights and describes it as a refusal. The distinction between "we don't have it" and "we won't give it to you" needs to be in writing, every time.

Define your designated record set before the request arrives

Your designated record set includes medical and billing records used to make decisions about the individual. For a practice managing vasomotor rhinitis follow-up, that typically pulls from more systems than people expect: encounter notes, the symptom questionnaires the front desk scans in, referral letters from ENT, outside test results you filed into the chart, the patient portal message thread, and the billing ledger.

Write that list down. Have the privacy officer approve it. When a records clerk is deciding at 4:45 p.m. whether portal messages are included, you do not want that to be a judgment call.

How Long Do You Have to Fulfill a Vasomotor Rhinitis Records Request?

Thirty calendar days from receipt. Under 45 CFR 164.524, a covered entity must act on an individual's access request within 30 calendar days — not business days — of receiving it. You may take one 30-day extension if you notify the individual in writing within the original window, stating the reason for the delay and the date you will deliver. There is no second extension. Several states impose shorter deadlines, and the shorter deadline controls.

HHS has published detailed guidance on the individual right of access that your privacy officer should keep bookmarked. OCR has brought a long series of enforcement actions specifically over access failures, and the fact patterns are almost always the same: a request sat in a queue, nobody sent an extension letter, and the patient waited months.

What starts the clock

Receipt by your organization — not receipt by the correct person in your organization. A request handed to a medical assistant, left as a portal message, mailed to a closed satellite office, or faxed to a line nobody monitors still starts the count.

Fix this with routing, not with training alone. One intake channel, one shared mailbox, one log entry per request, timestamped on arrival. If your fax line forwards to a general inbox, someone must check it daily and log anything that looks like a records request the same day.

Verification That Is Reasonable, Documented, and Not a Wall

The rule requires you to verify the identity and authority of the requester. It does not permit you to build an obstacle course. Requiring a notarized signature, an in-person appearance, or a proprietary form as the only accepted method are the classic ways practices turn a verification duty into an access denial.

Pick a verification method proportional to the delivery channel:

  • Authenticated patient portal request: the login is your verification. Do not ask for a photo ID on top of it.
  • Mailed or faxed written request: match name, date of birth, and two other chart identifiers; call the number on file to confirm.
  • Phone request: confirm identifiers, then deliver to a method already on file — not to a new address given over the phone.
  • Personal representative: collect the legal document (power of attorney, guardianship order, parental status per state law) and scan it into the file with the request.

Document what you did. "Verified by callback to number on file, 8/18/26, 10:12 a.m., staff initials JR" is enough. An undocumented verification is, from an auditor's perspective, no verification.

Patient-directed transmission versus a third-party authorization

This trips up more practices than any other part of the workflow. If the patient asks you to send their record to someone else, treat it as a right-of-access directive: it must be in writing, signed by the individual, and clearly identify the recipient and where to send it. If a third party — an attorney, a disability insurer, an employer — is requesting records on their own behalf, that is a HIPAA authorization under 164.508, with its own required elements and its own fee rules.

Train your team to ask one question of every inbound request: who is asking? The answer determines the deadline, the fee ceiling, and the form you need. Log it as a field, not as a note.

Fees You May Charge, and the Ones That Draw Complaints

For individual access requests, you may charge a reasonable, cost-based fee limited to labor for copying (including electronic copying), supplies such as media, postage, and — only if the individual agreed in advance — preparation of a summary or explanation. HHS guidance also describes a flat fee option of up to $6.50 for electronic copies of PHI maintained electronically, which many practices adopt because it removes arguments entirely.

You may not charge for search and retrieval, for staff time spent verifying identity, for quality-control review, or for the cost of maintaining your systems. If your release-of-information vendor's invoice includes per-page "retrieval" charges and you pass that through to a patient exercising right of access, you have a problem — regardless of what the vendor's contract says.

Post your fee schedule. Give the individual an advance estimate. Note the fee charged in the request log. Those three habits resolve most access complaints before they escalate.

When Someone Else's System Holds the Vasomotor Rhinitis Records

Walk the path a single record takes. The symptom questionnaire was captured by a digital intake vendor. The ENT consult letter arrived through a health information exchange. The transcription of the follow-up note came back from an offshore service. The copy request itself is being fulfilled by a release-of-information company that logs into your EHR remotely.

Every one of those parties creates, receives, maintains, or transmits PHI on your behalf. Every one needs a Business Associate Agreement executed before the first record moves, and your BAA needs to say what happens when a patient sends the access request to the vendor instead of to you. If you are onboarding a release-of-information partner or a new intake tool and need the paperwork done properly, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which is the right shape for a document you sign once per vendor.

The vendor question your BAA should answer explicitly

Add a clause requiring the business associate to forward any individual access request it receives to you within a defined number of business days — three is common — and to cooperate in meeting the 30-day deadline. Without it, a request can sit in a vendor's queue for two weeks and you inherit the delay.

Also confirm the vendor's breach notification timeline. Federal law sets an outer bound for business associates, but you need the notice fast enough to hit your own reporting obligations. Check whether your current vendors are listed on the OCR breach portal before you renew.

Denials, Partial Releases, and Information Blocking

Grounds for denying access are narrow. Psychotherapy notes and information compiled in reasonable anticipation of litigation are unreviewable denials. A small set of reviewable grounds exists, and those require review by a licensed health care professional who was not involved in the original decision. Anything else — an unpaid balance, an unreturned form, a dispute with the patient — is not a lawful basis to withhold records.

If you deny in part, you must still release the rest, in writing, with an explanation and instructions for review and for filing a complaint. "We'll get back to you" is not a denial notice.

Separately, unreasonable interference with access to electronic health information can constitute information blocking, which carries its own regulatory exposure independent of HIPAA. Review the information blocking rules and exceptions and make sure your denial and delay practices map to a recognized exception.

A 30-Day Workflow You Can Assign by Name

Here is a working sequence for a mid-size practice. Assign each step to a role, not a person, so coverage survives vacations.

  1. Day 0 — Intake clerk. Log the request: date received, channel, requester type, records sought, delivery format requested, contact on file. Timestamp it.
  2. Day 0–2 — Records coordinator. Verify identity, document the method, and classify as access request versus authorization.
  3. Day 2–5 — Records coordinator. Assemble from the designated record set list. For a chart involving vasomotor rhinitis workup, that includes outside results filed into the chart and portal messages, not just visit notes.
  4. Day 5 — Privacy officer. Review only if a denial ground, a personal representative issue, or a sensitive-category question exists. Otherwise no review step — it adds delay without adding protection.
  5. Day 5–7 — Records coordinator. Send fee estimate if a fee applies. Do not hold the record hostage to payment beyond your posted policy.
  6. Day 7–15 — Records coordinator. Deliver in the form and format requested if readily producible. Encrypt by default. If the patient insists on unencrypted email, document that you warned them and that they accepted the risk.
  7. Day 25 — Privacy officer. Sweep the log for anything unfulfilled. Send extension letters that day, not on Day 30.

Ten minutes a week on that Day 25 sweep prevents the single most common access complaint.

The Log Is the Evidence

If OCR contacts you about an access complaint, your defense is the log. It should show receipt date, verification method, fulfillment date, format delivered, fee charged, and any extension notice with its send date. Pull a sample of ten closed requests this quarter and check whether every field is populated. If three are blank, your process is oral, not documented.

Access performance also belongs in your annual risk analysis, alongside access controls, vendor inventory, and workforce training records. Practices that keep that documentation current — whether they build it by hand or automate the risk analysis and policy set — spend far less time reconstructing history when a complaint arrives.

Next step: pull your vendor list, identify every party that touches records in a vasomotor rhinitis chart, and confirm each one has a current, signed BAA with a request-forwarding clause. If any are missing, draft and export the agreement before your next records request forces the issue.