Pull last Tuesday's schedule. Count the visits that ended with a referral to ENT, an audiology order, or a note faxed to a school nurse. In a general pediatrics or family medicine practice, ear complaints are one of the highest-volume reasons a chart leaves your building. This post is about that outbound traffic — who may receive it, what paperwork is required, and what your staff has to document. It is an administrative post. Every time a patient walks in asking why does my ear hurt, your organization triggers a records workflow, and that workflow is where privacy officers get burned.

The Referral Stack a Single Ear Complaint Produces

One encounter rarely produces one disclosure. Trace a routine ear-pain visit that gets escalated and you will typically see four to six separate transfers of protected health information, each moving through a different channel with a different owner.

  • A referral packet to an otolaryngology practice — chart notes, problem list, medication list, sometimes prior visit history.
  • An order and demographic block to an audiology group, which may or may not be part of the ENT organization.
  • An imaging order to a radiology center, plus insurance information for authorization.
  • A prescription transmitted electronically to a pharmacy.
  • A prior-authorization submission to the health plan, often through a clearinghouse.
  • A parent asking for a note for daycare or school — the one request in this list that is not a treatment disclosure.

Each of these sits in a different legal bucket. Your front desk treats them as one task called "the referral," which is exactly why the school note gets faxed with the same casual keystrokes as the ENT packet.

Can You Send Records to a Specialist Without Patient Authorization?

Yes. Under the HIPAA Privacy Rule, a covered entity may disclose protected health information to another health care provider for that provider's treatment of the patient without obtaining an authorization. That permission lives at 45 CFR 164.506(c)(2). It covers the referral packet, the phone call between the pediatrician and the ENT, and the records the specialist requests back from you three weeks later.

Three things follow from that, and staff routinely get all three wrong:

  1. No business associate agreement is required with the specialist. The receiving provider is a covered entity acting on its own behalf, not performing a service for you. A BAA with an ENT group is not wrong so much as legally meaningless — and it confuses your vendor inventory.
  2. The minimum necessary standard does not apply to disclosures to a health care provider for treatment purposes. You may send the complete record. HHS explains the boundaries of that standard in its minimum necessary guidance.
  3. Permitted is not the same as unlimited. The disclosure must actually be for treatment. Sending a patient list to an ENT practice that referred business to you is not treatment. That is marketing or a business arrangement, and it needs a different analysis entirely.

HHS publishes plain-language material on permitted uses and disclosures for treatment, payment, and health care operations. Print it. Put it in the release-of-information binder. Your staff will consult a one-page HHS handout long before they open the regulation.

What Still Applies Even When Authorization Doesn't

Verification of identity. Before your medical records clerk faxes a chart to "Dr. Nguyen's office," she needs a reasonable basis to believe the requester is who they claim to be. A callback to a number your practice looked up independently — not the number printed on the incoming fax cover sheet — is the standard control. Social engineering against front desks is not exotic; it is a phone call and a confident tone.

Safeguards during transmission also still apply. The Security Rule follows the data whether or not authorization was required.

Why Does My Ear Hurt Turn Into a Multi-Organization Records Problem?

Because ear complaints are a triage funnel. The initial evaluation happens in primary care or urgent care; persistent or recurrent presentations often route to otolaryngology, audiology, and sometimes imaging. That is the entire clinical context this post needs. The administrative consequence is what matters: a patient who asks why does my ear hurt at a walk-in clinic on Monday may have their chart touched by four organizations by Friday, none of which share a legal entity, and at least two of which will call your front desk for records.

That fan-out is where your exposure sits. Not in the exam room — in the fax queue, the portal outbox, and the unencrypted attachment your MA sent from a personal phone because the referral coordinator was out sick.

The Transport Layer: Four Channels, Four Different Risks

Fax

Still the default in specialty referral. HIPAA does not prohibit fax. It requires reasonable safeguards. Practical controls: a verified fax directory maintained by one named owner, confirmation sheets retained, the machine located away from the waiting area, and a documented misdirected-fax procedure that includes calling the recipient and requesting confirmed destruction. Log the incident even when you get that confirmation — a misdirected fax is a potential breach that you evaluated and, in most cases, determined to be low probability of compromise. The evaluation has to exist in writing.

Direct secure messaging and HIE

Cleanest path when both organizations support it. Confirm your EHR vendor's Direct address provisioning is under your control and that departed staff addresses are deprovisioned on the same day as network access. Referral inboxes owned by a departed employee are a recurring finding.

Patient portal and patient-mediated exchange

When the patient carries their own records to the specialist, you are fulfilling a right of access request, not making a treatment disclosure. Different clock, different rules — see below.

Email

If you send PHI by email to outside providers, encryption is an addressable implementation specification, which means you either implement it or document why an equivalent alternative is reasonable. "The ENT's office prefers plain email" is not that documentation. Configure transport encryption, or don't use the channel.

The Six Requests That Are Not Treatment Disclosures

Train your front desk on this list specifically, using ear-pain scenarios because they occur weekly:

  • A school or daycare note beyond a simple attendance excuse the parent hand-carries. Written authorization from the personal representative.
  • An employer asking whether an employee's absence was legitimate. Authorization.
  • An attorney handling an injury claim. Authorization, or a valid subpoena with the required assurances.
  • A hearing aid retailer asking for a patient list of audiology referrals. This is marketing. Do not entertain it without a full analysis and, almost certainly, authorization.
  • A relative calling to check on an adult patient's appointment. Professional judgment applies for people involved in care; a blanket "yes" from the front desk does not.
  • A research coordinator at the referral center recruiting for a study. Authorization or IRB waiver — not your call to make at the check-in desk.

The Pediatric Wrinkle Your Referral Coordinator Will Hit This Month

Ear complaints skew young. That means most of these referrals involve a personal representative rather than the patient, and personal representative status is governed by state law layered on top of HIPAA.

Your policy needs written answers to: which parent may authorize when custody is split, what documentation you require for a legal guardian or foster placement, and what happens when a non-custodial parent requests the chart. "We ask the physician" is not a policy. Put the decision tree in the release-of-information procedure and name the owner — usually the privacy officer, with the practice manager as backup.

The 30-Day Clock When the Parent Asks for the Chart Instead

Half the time, the family bypasses your referral coordinator and asks for a copy to take to the specialist themselves. That is a right of access request. You have 30 days from receipt, with one 30-day extension available if you notify the requester in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount. HHS maintains detailed individual right of access guidance, and access failures have driven a long-running OCR enforcement initiative — the resolutions are searchable in the public HHS breach and enforcement portal.

Separately, delaying or discouraging electronic access can raise information blocking questions. The federal framework and its exceptions are summarized at HealthIT.gov, and HHS finalized disincentives for providers found to have committed information blocking in 2024. If your standard answer to a parent requesting records is "come back in two weeks," you have two problems, not one.

What You Have to Document — and What You Don't

Treatment, payment, and health care operations disclosures are excluded from the accounting of disclosures requirement. You do not need to log every referral packet for accounting purposes. You do need to log the disclosures that fall outside TPO — the subpoena response, the public health report, the disclosure to law enforcement — and retain that log for six years.

You also need retention of the authorizations themselves, the Notice of Privacy Practices acknowledgments, and any incident evaluations. When a records request goes sideways eighteen months later, the file is the only thing standing between you and a bad afternoon.

If your policy set still describes a fax-only workflow while your staff routes referrals through three electronic channels, the gap shows up in the first document request an investigator sends. Practices that need current, consistent policies and a defensible risk analysis without building the whole set by hand can generate the full HIPAA policy and risk analysis document set and then adapt it to how the referral desk actually operates.

Where BAAs Actually Belong in This Workflow

Not with the ENT group. Not with the audiologist treating your patient. Do sign one with:

  • Your release-of-information outsourcing vendor, if you use one.
  • Your cloud fax provider.
  • Your transcription service.
  • Your billing company and any clearinghouse that is not acting solely as a conduit under your plan contracts.
  • Your EHR and patient communication vendors.
  • Your document shredding and offsite storage vendors.

Audit that list quarterly against accounts payable, because vendors get added by clinicians and practice managers who have never heard the phrase "business associate." When you find a gap, a signature-ready business associate agreement closes it faster than routing a redline through counsel for a $200/month vendor.

A 20-Minute Audit of Your Referral Desk

  1. Pull ten ear-related referrals from the past 60 days. Identify the transmission channel for each.
  2. For each, confirm a destination verification step is documented — callback, verified directory entry, or Direct address on file.
  3. Check whether any of the ten included an authorization that wasn't needed (harmless friction) or omitted one that was (a finding).
  4. Confirm your fax directory has a named owner and a last-reviewed date within 12 months.
  5. Time three recent right-of-access requests from receipt to fulfillment. Anything over 30 days needs a written extension in the file.
  6. Match the vendors touching those ten referrals against your BAA inventory.

Six steps. One morning. Most practices find at least two issues, and none of them are clinical.

Start With the Documents

The workflow behind every why does my ear hurt encounter is ordinary, high-volume, and almost entirely administrative — which is exactly why it drifts. Written policies that match reality, a current risk analysis, and a clean BAA inventory are what turn a records request into a filing task instead of an incident. If yours are out of date, build the current document set, then walk it past the referral coordinator and see whether it describes the job she actually does.