Category: HIPAA Privacy Rule

  • HIPAA Compliance: Timely Medical Records Access

    As a healthcare provider or business associate, you likely spend a massive amount of energy protecting patient data from unauthorized eyes. But are you equally focused on giving patients access to their own data?

    Under the HIPAA Privacy Rule, patients have a legal right to review and obtain copies of their protected health information (PHI). The HHS Office for Civil Rights (OCR) has aggressively ramped up its Right of Access Initiative, leveling heavy fines against organizations that delay or deny these requests.

    Below, we break down exactly what you need to do to stay compliant, avoid OCR penalties, and fulfill medical records requests efficiently.

    What is the HIPAA Right of Access Standard?

    The Core Rule: The HIPAA Right of Access standard requires covered entities to provide individuals (or their designated personal representatives) with access to inspect or obtain a copy of their PHI in a designated record set.

    This right applies regardless of whether the records are stored electronically (e.g., in an EHR system) or physically in paper files.

    How Quickly Must a Provider Respond to a Medical Records Request?

    According to guidelines from the U.S. Department of Health and Human Services (HHS), covered entities must provide the requested health information within 30 calendar days of receiving the request.

    Can You Get an Extension?

    Yes, but only under strict conditions:

    • If the records are archived off-site or otherwise not readily accessible, you may request a one-time, 30-day extension.
    • To legally claim this extension, you must provide the patient with a written explanation of the delay and the exact date they can expect their records.

    The Real Cost of Non-Compliance: OCR Enforcement Trends

    Many organizations mistakenly believe that minor administrative delays won’t trigger federal scrutiny. However, the OCR has made it clear that ignoring the 30-day window can lead to steep penalties.

    In one notable Right of Access enforcement actionโ€”the 19th case resolved under the initiativeโ€”a provider took nearly two years to deliver a childโ€™s medical records to their parent. The result? The organization was forced to implement a strict corrective action plan and pay a $5,000 settlement for a single potential violation. Bigger organizations have faced six-figure fines for similar delays.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI). Specifically, 45 CFR ยง 164.524(b)(2) dictates the 30-day response timeline and the strict conditions required for a one-time, 30-day extension. HHS OCR Enforcement Guidance: The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Business Associate Agreements Under HIPAA

    Business Associate Agreements Under HIPAA: Regulatory Necessity and OCR Enforcement Lessons

    The HIPAA Privacy Rule permits covered entities to use vendors and service providers that create, receive, maintain, or transmit protected health information (PHI). However, this permission is conditional. Federal law requires covered entities to obtain written โ€œsatisfactory assurancesโ€ that such third partiesโ€”known as business associatesโ€”will appropriately safeguard PHI. These assurances must take the form of a Business Associate Agreement (BAA) that meets the regulatory requirements established by the U.S. Department of Health and Human Services (HHS).

    Under 45 C.F.R. ยง 164.502(e), a covered entity may not disclose PHI to a business associate unless it first obtains these assurances in writing. The regulation is unequivocal: in the absence of a compliant BAA, disclosures of PHI to a business associate are impermissible under HIPAA, regardless of whether a breach or misuse ultimately occurs. HHS guidance further clarifies that covered entities are prohibited from sharing PHI with a business associate until such an agreement is in place. [

    Required Elements of a HIPAAโ€‘Compliant Business Associate Agreement

    The mandatory content of a BAA is prescribed directly by regulation at 45 C.F.R. ยง 164.504(e)(2). To satisfy the Privacy Ruleโ€™s requirement for โ€œsatisfactory assurances,โ€ a Business Associate Agreement must include the following provisions:

    1. Permitted and Required Uses and Disclosures of PHI

    The agreement must establish the permitted and required uses and disclosures of PHI by the business associate and may not authorize conduct that would violate the HIPAA Privacy Rule if done by the covered entity.

    2. Safeguards to Protect PHI

    The agreement must require the business associate to use appropriate safeguards to prevent unauthorized uses or disclosures of PHI, including compliance with the HIPAA Security Rule for electronic PHI.

    3. Reporting Obligations

    The business associate must be required to report to the covered entity any use or disclosure of PHI not permitted by the contract, including breaches of unsecured protected health information.

    4. Subcontractor Flowโ€‘Down Requirements

    The agreement must require the business associate to ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions.

    5. Access to Records by HHS

    The agreement must permit the business associate to make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with HIPAA.

    6. Return or Destruction of PHI Upon Termination

    Upon termination, the agreement must require the return or destruction of PHI when feasible or require continued protection of the information if destruction is not feasible.

    7. Termination for Cause

    The agreement must authorize the covered entity to terminate the contract if the business associate violates a material term.

    If any of these elements are missing, the agreement does not meet HIPAA requirements.

    OCR Enforcement and Lessons Learned

    The HHS Office for Civil Rights (OCR) has repeatedly enforced the BAA requirement through resolution agreements and corrective action plans. OCR has taken the position that disclosures of PHI made in the absence of a compliant BAA violate the HIPAA Privacy Rule, even when no breach has yet occurred. OCR resolution agreements routinely require covered entities to identify all business associates, execute compliant BAAs, and implement processes to prevent disclosures of PHI without prior agreement.

    HHS regulations and OCR enforcement actions make one principle unmistakably clear: a Business Associate Agreement is a prerequisite to lawful disclosure of PHI. Covered entities that fail to execute and maintain compliant BAAs expose themselves to enforcement action, corrective obligations, and significant regulatory risk. In HIPAA compliance, the existence of a valid BAA is not optional, it is required.

    Colington Consulting

    HIPAA Compliance, Risk Assessment & Management

    Our company specializes exclusively in HIPAA compliance, with a focus on helping covered entities and business associates identify risk, implement compliant Business Associate Agreements, and align their operations with HHS and OCR regulatory expectations. Drawing on direct regulatory requirements and realโ€‘world OCR enforcement patterns, we assist organizations with business associate identification, BAA drafting and remediation, vendor management programs, and auditโ€‘ready compliance documentation. Book a free initial consultation to evaluate your current BAA posture, identify gaps that may expose your organization to enforcement risk, and outline practical, defensible steps to strengthen HIPAA compliance before issues arise.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • OCR Settles Another HIPAA Right of Access Case

    On December 15, The HHS Office for Civil Rights (OCR) announced another settlement of their HIPAA Right of Access Initiative. According to the information released through the OCR Listserv, “Health Specialists of Central Florida Inc. paid $20,000 to OCR and agreed to implement a corrective action plan (CAP) to resolve this investigation.” The CAP will be monitored by OCR for two years. This is the 42nd HIPAA Right of Access Initiative case to be settled by OCR.

    The release stated “In August 2019, a complaint was filed by a daughter acting as a personal representative on behalf of her deceased father, who had been a patient of Health Specialists of Central Florida Inc. The complainant alleged that Health Specialists of Central Florida Inc. had failed to provide her with timely access to the requested medical records, despite multiple requests.

    OCRโ€™s investigation determined that Health Specialists of Central Florida Inc.’s failure to provide timely access to the requested medical records was a potential violation of the HIPAA right of access standard, which requires a covered entity to take action on an access request within 30 days of receipt (or within 60 days if an extension is applicable). As a result of OCR’s investigation, the daughter finally received all of the requested records, nearly five months after her initial request.”

    See the full Resolution Agreement and CAP.

  • Use of Healthcare Related Tracking Technologies

    On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a bulletin to highlight the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. OCR administers and enforces the HIPAA Rules, including by investigating breach reports and complaints about regulated entitiesโ€™ noncompliance with the HIPAA Rules. A regulated entityโ€™s failure to comply with the HIPAA Rules may result in a civil money penalty.

    The bulletin states, “Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules.”

    According to the bulletin, “a tracking technology is a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app. After information is collected through tracking technologies from websites or mobile apps, it is then analyzed by owners of the website or mobile app (โ€œwebsite ownerโ€ or โ€œmobile app ownerโ€), or third parties, to create insights about usersโ€™ online activities.” These insights could be used in beneficial ways to help improve care or the patient experience. However, this tracking information could also be misused to promote misinformation, identity theft, stalking, and harassment.

    If your organization is utilizing these technologies, it is important to fully read the entire bulletin.

    Since this blog article was posted in December of 2022, a federal court vacated parts of the HHS Office for Civil Rights (OCR) bulletin that classified an IP address combined with visits to unauthenticated public health pages as Protected Health Information. While this struck down the strict guidance, healthcare entities must still navigate strict federal privacy and consumer laws.

    Current Legal & Regulatory Reality

    • The Court Ruling: In American Hospital Association v. Becerra, a Texas federal judge ruled that HHS overstepped its authority under HIPAA by treating general website visitor metadata (like IP addresses linked to public unauthenticated webpages) as individually identifiable health information.
    • What Remains in Effect: Healthcare providers are still strictly prohibited from using tracking tools (like pixels or session replay) on authenticated pages (e.g., patient portals) without robust safeguards and Business Associate Agreements (BAAs).

    This post was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Can the Government Review PHI During a HIPAA Investigation?

    When the U.S. Department of Health and Human Services (HHS) investigates a potential privacy violation, healthcare providers often wonder about the rules regarding Protected Health Information (PHI). Does the HIPAA Privacy Rule allow organizations to turn over sensitive patient health data to government investigators?

    The short answer is yes. The HIPAA Privacy Rule explicitly allows covered entities to disclose PHI to the government during compliance reviews and investigations. However, this access is not an open-ended blank check.

    Here is exactly how federal investigators access PHI, what triggers these reviews, and how the “minimum necessary” standard applies.

    Why the HHS Office for Civil Rights (OCR) Reviews PHI

    An essential part of enforcing HIPAA compliance is the government’s responsibility to investigate patient complaints and follow up on data breaches. To determine whether an organization has violated the Privacy or Security Rules, the HHS Office for Civil Rights (OCR) must routinely review specific patient medical records and internal documentation.

    However, the Privacy Rule strictly limits OCRโ€™s access to information that is “pertinent to ascertaining compliance.” Depending on the nature of the allegation, investigators will only look at data directly related to the potential violation. In some cases, no personal health information is required at all. For example, if the OCR is checking whether a health plan properly vetted an outside vendor, they may only need to review a Business Associate Agreement (BAA) rather than individual patient charts.

    Examples of Investigations Requiring PHI Access

    There are several common scenarios where the OCR must review actual patient records to verify compliance:

    • Patient Right of Access Violations: If a patient alleges that a healthcare provider refused to provide copy of their medical records, or failed to note a requested correction in their file, investigators must review the patient’s record and access logs to verify the timeline and actions taken.
    • Unauthorized Marketing and Disclosures: If a provider is accused of using patient data for marketing purposes without explicit authorization, the OCR will audit marketing department records containing PHI to check for valid patient signatures.
    • Data Breaches and Ransomware Incidents: Following a cyberattack or data leak, investigators review affected PHI data sets to determine the scope of the breach and evaluate if proper technical safeguards were in place.

    How to Prepare Your Organization for an OCR Audit

    The best defense against an enforcement action is a proactive compliance strategy. Identifying gaps early prevents standard compliance reviews from turning into costly penalties.

    1. Conduct Regular Security Risk Assessments

    Regular risk assessments are the foundation of a defensible HIPAA program. They help you identify administrative, physical, and technical vulnerabilities before a breach occurs.

    2. Implement Clear Policies and Procedures

    Ensure your staff is trained on handling patient requests, managing vendor relationships with proper Business Associate Agreements, and executing proper protocols during data requests.

    3. Seek Expert Compliance Guidance

    HIPAA violations often stem from small, overlooked gaps in documentation or staff training.

    Need Help Evaluating Your Risk? Get a free 30-minute HIPAA risk review with our regulatory experts to evaluate your current program and identify gaps before they turn into federal violations. Schedule your HIPAA Risk Review Now.

    Frequently Asked Questions

    Does HIPAA prevent the government from looking at my medical records?

    No. Under the HIPAA Privacy Rule, healthcare providers are permittedโ€”and requiredโ€”to share relevant Protected Health Information (PHI) with the HHS Office for Civil Rights (OCR) during an official compliance investigation or audit.

    What information can the OCR request during a HIPAA investigation?

    The OCR can only request information that is pertinent to determining compliance. This can range from internal administrative contracts (like Business Associate Agreements) to specific patient medical records, depending entirely on the nature of the alleged violation.

    What triggers an OCR HIPAA investigation?

    Most OCR investigations are triggered by patient complaints regarding privacy violations, data breaches affecting 500 or more individuals, or self-reported compliance gaps.

    • Updated and Reviewed on June 4, 2026, by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources:

    The Core Compliance Directive: 45 CFR ยง 160.310. This is the specific regulation that mandates covered entities and business associates to hand over information to federal investigators.

    • Section 160.310(b): Expressly states that organizations must cooperate with complaint investigations and compliance reviews led by the Secretary of HHS.
    • Section 160.310(c)(1): Mandates that organizations permit access to their facilities, books, records, accounts, and “other sources of information, including protected health information, that are pertinent to ascertaining compliance.”

    The General Privacy Rule Exception: 45 CFR ยง 164.502(a)(2)(ii). While 45 CFR ยง 164.502 generally prohibits disclosing PHI without explicit patient authorization, it lists precise exceptions where a disclosure is required.

    • Under 45 CFR ยง 164.502(a)(2)(ii), a covered entity or business associate is required to disclose PHI to the Secretary of HHS specifically when requested to investigate or determine compliance with the HIPAA Privacy and Security Rules
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.