Category: Medical Records

  • HIPAA Compliance: Timely Medical Records Access

    As a healthcare provider or business associate, you likely spend a massive amount of energy protecting patient data from unauthorized eyes. But are you equally focused on giving patients access to their own data?

    Under the HIPAA Privacy Rule, patients have a legal right to review and obtain copies of their protected health information (PHI). The HHS Office for Civil Rights (OCR) has aggressively ramped up its Right of Access Initiative, leveling heavy fines against organizations that delay or deny these requests.

    Below, we break down exactly what you need to do to stay compliant, avoid OCR penalties, and fulfill medical records requests efficiently.

    What is the HIPAA Right of Access Standard?

    The Core Rule: The HIPAA Right of Access standard requires covered entities to provide individuals (or their designated personal representatives) with access to inspect or obtain a copy of their PHI in a designated record set.

    This right applies regardless of whether the records are stored electronically (e.g., in an EHR system) or physically in paper files.

    How Quickly Must a Provider Respond to a Medical Records Request?

    According to guidelines from the U.S. Department of Health and Human Services (HHS), covered entities must provide the requested health information within 30 calendar days of receiving the request.

    Can You Get an Extension?

    Yes, but only under strict conditions:

    • If the records are archived off-site or otherwise not readily accessible, you may request a one-time, 30-day extension.
    • To legally claim this extension, you must provide the patient with a written explanation of the delay and the exact date they can expect their records.

    The Real Cost of Non-Compliance: OCR Enforcement Trends

    Many organizations mistakenly believe that minor administrative delays won’t trigger federal scrutiny. However, the OCR has made it clear that ignoring the 30-day window can lead to steep penalties.

    In one notable Right of Access enforcement actionโ€”the 19th case resolved under the initiativeโ€”a provider took nearly two years to deliver a childโ€™s medical records to their parent. The result? The organization was forced to implement a strict corrective action plan and pay a $5,000 settlement for a single potential violation. Bigger organizations have faced six-figure fines for similar delays.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI). Specifically, 45 CFR ยง 164.524(b)(2) dictates the 30-day response timeline and the strict conditions required for a one-time, 30-day extension. HHS OCR Enforcement Guidance: The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Rules for Paper Records in 2026

    Reviewed by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    While modern healthcare compliance heavily focuses on cybersecurity and electronic Protected Health Information (ePHI), physical security remains a critical vulnerability. The Department of Health and Human Services (HHS) and the Office for Civil Rights (OCR) continue to penalize organizations for failing to safeguard physical documents.

    Improperly handled paper records, such as files left on desks, unkeyed filing cabinets, or un-shredded documents thrown into standard recycling binsโ€”account for a massive portion of easily avoidable HIPAA violations.

    Whether your team operates in a traditional clinic or a hybrid office environment, understanding your responsibility to safeguard paper records is essential to protecting patient privacy and avoiding costly penalties.

    What Does HIPAA Require for Paper Records?

    The HIPAA Security Rule primarily governs electronic data, but the HIPAA Privacy Rule strictly mandates that Covered Entities and Business Associates apply appropriate administrative, technical, and physical safeguards to protect PHI in any form, including paper.

    To remain compliant, your organization must ensure physical records are protected throughout their entire lifecycle: creation, storage, usage, and disposal.

    Core Safeguards for Physical Files:

    • The “Clean Desk” Principle: Employees must not leave documents containing PHI exposed on desks, counters, or workstations when they step away.
    • Dual-Lock Custody: Paper charts, intake forms, and billing statements should be stored behind locked doors and inside locked filing cabinets when not in active use.
    • Strict Access Controls: Access to file rooms should be restricted only to authorized personnel who require the information to perform their specific job duties.

    The Remote & Hybrid Work Blindspot

    The shift toward remote and hybrid work environments has introduced significant new risks for physical PHI. When administrative or billing staff work from home, the boundaries of your secure facility disappear.

    If your employees handle paper records remotely, your compliance policies must adapt:

    1. No Home Printing: Prohibit the printing of patient schedules, medical notes, or billing details on personal home printers unless explicitly authorized and monitored under a strict remote work agreement.
    2. Secure Home Storage: If paper PHI must be taken home, it cannot be left on kitchen counters or shared desks where family members or visitors can see it. It must be locked away.
    3. Prohibited Disposal: Employees must never discard paper PHI in home trash cans or residential recycling bins. Documents must either be brought back to the office for secure destruction or shredded at home using an approved cross-cut shredder.

    Proper Disposal: The “Shred-All” Solution

    The absolute highest risk associated with paper records occurs during disposal. Dumpster-diving incidents and accidental exposure of intact records are viewed severely by federal investigators.

    Under HIPAA, acceptable methods for destroying paper records include burning, pulverizing, melting, or shredding so that the PHI is rendered essentially unreadable and cannot be reconstructed.

    Implementing a “shred-all” policy across your organization removes the guesswork for your staff. If every document goes into a secure, locked shredding bin, the risk of a human error leading to a breach drops dramatically.

    Are Your Physical & Digital Safeguards Audit-Ready?

    Leaving paper records vulnerable is one of the fastest ways to fail a routine compliance check or trigger an OCR investigation. Don’t wait for an accidental exposure to discover the gaps in your practice’s physical security.

    Schedule your 30-Minute HIPAA Risk Review. Our experts will help you identify hidden vulnerabilities in your workflow and ensure your safeguards are completely defensible.

    Sources & Legal References:

    • U.S. Department of Health and Human Services (HHS)
    • Office for Civil Rights (OCR)ย 

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal or regulatory compliance advice. Reading this article does not establish a consulting relationship with Colington Consulting. For specific guidance regarding your organization’s unique HIPAA obligations, please consult directly with a compliance professional.ย 

  • OCR Settles Multiple Complaints Regarding Patient Right of Access

    by Jay Hodes โ€“ President, Colington Consulting

    In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would โ€œnot impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.โ€ The April notice specified OCR โ€œwill not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.โ€

    It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.

    Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.

    As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individualsโ€™ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.

    The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.

    The OCR listserv email regarding these cases states โ€œOCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.โ€ Message sending indeed as OCRโ€™s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”

    Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.