The HIPAA right of access gives an individual the right to inspect and obtain a copy of their protected health information (PHI) held in a designated record set. A covered entity must act on the request within 30 days, with one permitted 30-day extension if it gives written notice of the delay. In practice, the enforcement actions the HHS Office for Civil Rights (OCR) has brought under its right-of-access initiative are strikingly mundane: they are overwhelmingly about records that were requested and simply never arrived, arrived far too late, or were held behind a fee or a format the rule does not permit. This is compliance failure by neglect, not by conspiracy — which is exactly why it is so common.
What the right of access covers
Under 45 CFR 164.524, an individual has a right of access to inspect and obtain a copy of PHI about them in a designated record set, for as long as the PHI is maintained in that set. The right is broad. It is not limited to a "medical record" narrowly defined, and it survives unpaid bills, missed appointments, and interpersonal disputes with the practice.
Two categories are carved out of the right entirely:
- Psychotherapy notes, as defined by the Privacy Rule.
- Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding.
Everything else in the designated record set is presumptively accessible to the individual.
The 30-day clock
The covered entity must act on a request for access no later than 30 days after receipt. "Act" means one of two things: grant the request and provide the access, or deny it in whole or in part with a written denial that meets the rule's content requirements.
If the entity cannot act within 30 days, it may extend by no more than 30 additional days, and only if — within the original window — it gives the individual a written statement of the reasons for the delay and the date by which it will complete its action. The rule permits only one such extension per request. There is no second bite, and silence is never a permitted response.
Form, format, and sending records to a third party
The entity must provide access in the form and format the individual requests, if the PHI is readily producible in that form and format. If it is not, the entity must produce it in a readable hard copy or another format the two agree on.
The electronic case is stricter. If the PHI is maintained electronically in one or more designated record sets and the individual asks for an electronic copy, the entity must provide it in the electronic form and format requested if readily producible — and if not, in a readable electronic form and format agreed to by the entity and the individual. "We only release paper" is not a lawful default position for records you hold electronically.
An individual may also direct the entity to transmit a copy of their PHI directly to a person they designate. That direction must be in writing, signed by the individual, and clearly identify the designated person and where to send the copy. Requests of this kind are frequently mishandled — treated as third-party disclosures requiring a full authorization, and slowed or refused on that basis.
What you may charge
A covered entity may impose a reasonable, cost-based fee. The regulation enumerates what that fee may include, and the list is closed:
- Labor for copying the PHI, whether in paper or electronic form.
- Supplies for creating the paper copy, or electronic media if the individual asked for the copy on portable media.
- Postage, if the individual asked for it to be mailed.
- Preparing an explanation or summary, but only if the individual agreed in advance to it and to the fee.
What is conspicuously absent from that list is as important as what is on it. Search-and-retrieval time is not there. Neither is the cost of maintaining your records system. State-law "per-page" schedules for records requests are frequently written for other purposes and do not automatically authorize a fee under HIPAA when the request comes from the individual exercising their right of access.
Grounds for denial
Denials are permitted, but they are narrow, and they split into two categories.
Unreviewable grounds include psychotherapy notes and litigation-compiled information; certain inmate requests at correctional institutions; temporary suspension during research the individual consented to on those terms; certain Privacy Act records; and information obtained from someone other than a health care provider under a promise of confidentiality where access would likely reveal the source.
Reviewable grounds require a licensed health care professional's judgment that access is reasonably likely to endanger the life or physical safety of the individual or another person; or, where the record references another person, that access is reasonably likely to cause that person substantial harm; or that access by a personal representative is reasonably likely to cause substantial harm. If you deny on a reviewable ground, the individual has a right to have the denial reviewed by a licensed professional who was not involved in the original decision.
Any denial must be timely, in writing, in plain language, and must state the basis, the review rights if any, and how to complain to the entity or to the Secretary. And if only part of the record is deniable, you must still release the rest.
What actually draws enforcement
OCR runs a dedicated right-of-access enforcement initiative, and its published resolution agreements are the clearest available guide to what the agency treats as actionable. Read across them and a short list of recurring fact patterns emerges:
- No response at all. The individual requested records, heard nothing, complained to OCR, and often still did not receive records until OCR intervened.
- Records provided, but months or years late. The 30-day clock is objective and easy for a regulator to measure against a dated request letter.
- Access conditioned on something the rule does not permit — an unpaid balance, an in-person visit, a notarized form, a specific proprietary request form.
- Fees outside the cost-based list, or fees quoted so high that they function as a refusal.
- Refusing an electronic copy of a record the entity plainly maintains electronically.
- Ignoring a valid individual-directed transmission to a third party.
Notably, these cases are not confined to large systems. OCR's right-of-access settlements have repeatedly involved small practices — individual physicians, small dental and psychiatric practices, single-location providers. A small compliance footprint is not a shield.
Building an access workflow that holds up
- Name the intake channels and monitor them. Portal message, email, fax, front desk, mail. Every one of them can carry a valid request.
- Date-stamp on receipt. Your defense is a dated log, not a memory.
- Train staff to recognize a request without magic words. "Can I get a copy of my labs?" is a request for access. It does not have to say HIPAA.
- Default to electronic delivery where the record is electronic and the individual asked for it.
- Publish a fee schedule you can defend line by line against the four permitted cost categories.
- Escalate denials. Only a licensed professional can supply a reviewable-ground denial, and every denial needs the written content the rule requires.
- Track the clock at day 20. If you are going to need the extension, the written notice has to go out inside the original 30 days.
The bottom line
The right of access is the most operationally boring corner of the Privacy Rule and one of the most heavily enforced. OCR is not, in the main, catching sophisticated schemes to withhold records. It is catching requests that fell into a gap between the front desk and the records clerk and stayed there. Fix the intake, date the clock, keep the fee honest, and put the electronic copy in the format the patient asked for — and the enforcement risk here mostly evaporates.
Common questions
How long does a provider have to respond to a HIPAA records request?
No later than 30 days after receiving the request. The covered entity may take one 30-day extension, but only if it provides the individual a written statement of the reason for the delay and the date it will complete its action, delivered within the original 30-day window. Only one extension is permitted.
Can a provider withhold records because the patient owes money?
No. An unpaid bill is not a ground for denying an individual's right of access under 45 CFR 164.524. The grounds for denial are specifically enumerated and financial balances are not among them. Conditioning access on payment of an outstanding balance is a fact pattern that has drawn OCR enforcement.
What can a covered entity charge for copies of records?
Only a reasonable, cost-based fee limited to labor for copying, supplies for paper copies or portable media, postage if mailing was requested, and preparation of an explanation or summary the individual agreed to in advance. Search and retrieval time is not a permitted component of the fee.
Must records be provided electronically if the patient asks?
If the PHI is maintained electronically in a designated record set and the individual requests an electronic copy, the covered entity must provide it in the electronic form and format requested if it is readily producible, and otherwise in a readable electronic form and format agreed to by the entity and the individual.