The HIPAA Right of Access: What Covered Entities Are Required to Do

Patient record access is one of OCR’s most active enforcement areas. Understanding the requirements in detail is essential for any covered entity that fields records requests.

The HIPAA right of access has been a significant and growing enforcement priority for OCR. In 2019, OCR launched its Right of Access Initiative, which has since produced dozens of enforcement actions against covered entities that failed to respond to patient records requests correctly, charged excessive fees, or denied access without a legally recognized basis. The resolution amounts in right of access cases have ranged from a few thousand dollars to over $200,000, and the corrective action plans that accompany them impose compliance monitoring obligations that can last years.

This article explains what the HIPAA right of access requires, what the 30-day timeline means in practice, what fees are and are not permitted, and the most common compliance failures that OCR has cited in enforcement actions.

The Regulatory Basis

The right of access is codified at 45 CFR 164.524. The regulation gives individuals the right to inspect and obtain a copy of their own protected health information that is maintained in a designated record set. A designated record set includes medical records, billing records, and any other records used to make decisions about the individual.

Covered entities may not require individuals to provide a reason for requesting their own records. The right is unconditional within the designated record set, subject only to the limited exceptions discussed below.

The 30-Day Response Requirement

Covered entities must act on a right of access request no later than 30 days after receipt. If the records are not maintained or accessible on-site, a single 30-day extension is permitted if the covered entity notifies the individual in writing within the initial 30-day period, states the reason for the delay, and provides the date by which the action will be completed.

The 30-day clock starts when the request is received, not when it is reviewed by a specific staff member or entered into a tracking system. An organization’s internal routing process does not affect the regulatory timeline. If a request is received in the mail and sits in an inbox for a week before being assigned to the appropriate person, those seven days count toward the 30-day window.

Many covered entities do not track right of access requests systematically, which is the primary reason they miss the deadline. A routine records request that gets handled by front desk staff without a formal tracking mechanism often falls through the cracks when it is complex, involves multiple record types, or lands on a coordinator’s desk during a busy period. The enforcement record is full of cases where the delay was not intentional but the outcome was a missed deadline and a valid OCR complaint.

Format and Delivery of Records

If an individual requests their records in a specific format, the covered entity must provide the records in that format if it is readily producible. If the requested format is not readily producible, the covered entity must provide the records in a readable electronic format, or another format agreed upon by the individual.

When an individual requests electronic access to records that are maintained electronically, the covered entity must provide the records in the electronic format requested or, if not readily producible, in a machine-readable electronic format. Covered entities cannot default to providing paper records when an individual specifically requests electronic records in an accessible format.

If an individual requests that their records be transmitted directly to a designated third party, such as a new provider or a personal health record system, the covered entity must do so if the request is clear, conspicuous, and specific.

Permitted Fees for Record Access

Covered entities may charge a reasonable, cost-based fee for providing access. The fee must be limited to the cost of labor for copying, the cost of supplies for creating the paper copy or electronic media, postage when the individual requests that records be mailed, and the cost of preparing an explanation or summary if the individual has requested one. No other fee components are permitted.

Covered entities cannot charge retrieval fees, processing fees, or search fees as part of the access request cost. They cannot charge for the cost of reviewing records to determine whether they are subject to an exception. The fee calculation must reflect actual costs, not a flat fee that has not been tied to a specific cost analysis.

OCR has specifically cited excessive fee charging as a basis for enforcement action. When a covered entity charges a per-page fee that substantially exceeds the cost of labor and supplies involved, it is not meeting the cost-based fee standard.

Limited Exceptions to the Right of Access

The right of access is broad but not absolute. Covered entities may deny access in limited, specific circumstances defined in the regulation. The most practically significant exceptions are psychotherapy notes, which are specifically excluded from the right of access; information compiled in reasonable anticipation of or for use in civil, criminal, or administrative proceedings; and in certain circumstances, records obtained from someone other than a healthcare provider under a promise of confidentiality if access would reveal the source.

Reviewable grounds for denial exist when a licensed healthcare professional determines that the access is reasonably likely to endanger the life or physical safety of the individual or another person, or if the information makes reference to another person and access is reasonably likely to cause substantial harm to that other person. These determinations require a documented clinical review and the individual must be given a right to have the denial reviewed by another healthcare professional.

Denials outside these enumerated exceptions are violations of the right of access. OCR has consistently taken the position that convenience-based denials, excessive verification requirements that effectively deny access, and impermissible fee structures that deter access are all violations of 45 CFR 164.524.

Documentation Requirements

Covered entities must document right of access requests, the action taken in response, and the basis for any denial. This documentation serves two purposes: it supports the organization’s own quality control for access request handling, and it provides evidence for OCR if a complaint is filed.

A written request tracking process, a standardized patient rights request form, and a log of requests received and completed with dates are the practical tools most covered entities use. The specific format is not prescribed, but the record needs to be sufficient to demonstrate that the 30-day timeline was met and that fees charged were cost-based.

Given OCR’s active enforcement in this area, organizations that do not currently have a documented right of access process should treat this as a priority compliance gap. The combination of a relatively simple regulatory requirement, a clear enforcement mechanism through the complaint process, and OCR’s demonstrated willingness to pursue relatively small organizations makes right of access failures unusually high-risk relative to their operational complexity.

Document Your Patient Rights Process

The HIPAA Essentials Library Privacy Bundle includes a complete Patient Rights Policy and supporting forms covering the right of access, the right to request amendments, the right to an accounting of disclosures, and the right to request restrictions. The patient rights forms are designed to standardize how requests are received, tracked, and documented, addressing the most common process failures that lead to OCR complaints.

For complete privacy documentation coverage, the Privacy Bundle includes all Privacy Rule policies and procedures your covered entity needs. All templates are provided in editable Microsoft Word format, available immediately after purchase.


Ready to get compliant? If your organization fields patient records requests, make sure you have the right policy in place. Our HIPAA Patient Rights Policy gives you a compliant, ready-to-use template covering access rights, timelines, and denial procedures – everything OCR expects to see. Pair it with our Amendment and Access Request Retention Log to document every request you receive and prove you met the 30-day deadline.