By Fisher, JD, CHC, CCEP
OCR Enforcement Action Underscores HIPAA Risk for Failing to Provide Patient Access to Records
Client Alert
The U.S. Department of Health and Human Services’ Office for Civil Rights continues to treat patient access to medical records as a significant HIPAA compliance priority. A recent enforcement matter involving a mental health provider illustrates that covered entities cannot satisfy the HIPAA Privacy Rule merely by allowing a patient to review records in person when the patient has requested a copy of records maintained in a designated record set.
In the matter described by OCR, the provider was a mental health center that allegedly failed to provide a patient with a copy of her medical record after she requested access. OCR found that the center gave the patient an opportunity to review her medical record, including psychotherapy notes, with her therapist. That opportunity to inspect the record, however, did not resolve the patient’s separate right to obtain a copy of the accessible portions of her protected health information. As part of the resolution, the center provided the patient with a copy of her medical record and revised its policies and procedures to ensure timely access for individuals going forward.
HIPAA Right of Access: Key Rule
Under the HIPAA Privacy Rule, individuals generally have the right to inspect and obtain a copy of protected health information about them that is maintained in a designated record set. Covered entities must respond to access requests in a timely manner and provide records in the requested form and format if readily producible. The rule contains limited exceptions, including for psychotherapy notes and information compiled in reasonable anticipation of, or for use in, litigation or other proceedings.
Psychotherapy Notes Require Careful Handling
Psychotherapy notes are treated differently from ordinary treatment records under HIPAA. They are narrowly defined as notes recorded by a mental health professional documenting or analyzing the contents of a counseling session and maintained separately from the rest of the patient’s medical record. HIPAA excludes properly maintained psychotherapy notes from the individual right of access. However, routine clinical information—such as diagnoses, treatment plans, symptoms, prognosis, progress notes, medication information, session times, treatment modalities, and clinical test results—is not psychotherapy notes merely because it relates to mental health treatment.
The practical lesson is that covered entities should not deny or delay an entire records request simply because the file contains psychotherapy notes or other sensitive behavioral health information. Instead, providers should determine which materials are subject to the right of access, which materials fall within a recognized exception, and whether any denial must be documented and communicated consistent with HIPAA’s requirements.
Why This Matters for Covered Entities
OCR’s position in patient-access matters is straightforward: a covered entity’s internal process, staffing challenges, record location, or preference for in-person review generally will not excuse failure to provide access required by the Privacy Rule. Providers should expect OCR to examine whether the organization had workable policies, trained staff, reliable tracking, and escalation procedures to ensure that requests are completed within the required timeframes.
The issue is particularly important for behavioral health providers, integrated health systems, academic medical centers, physician practices, and any organization that maintains mixed records containing both standard treatment information and specially protected material. A misclassification of records, an overbroad denial, or a failure to separate psychotherapy notes from the designated record set can create avoidable regulatory exposure.
Recent OCR Case Examples
Memorial Healthcare System. In January 2025, OCR resolved a right-of-access matter with South Broward Hospital District d/b/a Memorial Healthcare System. OCR’s settlement materials state that the complaint involved a patient request for access to protected health information in a designated record set and reiterate that covered entities must act on access requests no later than 30 days after receipt. The matter is a useful reminder that large health systems remain subject to close scrutiny when access processes do not produce timely results.
Oregon Health & Science University. In March 2025, OCR imposed a $200,000 penalty against Oregon Health & Science University for failure to provide timely access to patient records. The penalty underscores that OCR may pursue civil money penalties, not only negotiated settlements, where it concludes that access violations warrant formal enforcement.
American Medical Response. In 2024, OCR announced a civil money penalty against American Medical Response after allegations that the provider failed to provide a patient timely access to medical records despite multiple written requests. Public summaries of the matter describe a delay of approximately 121 days before the patient received a response requiring payment before production. The case illustrates the risk of treating invoices, business associate handoffs, or decentralized request intake as reasons to delay access.
Phoenix Healthcare. In 2024, OCR announced right-of-access enforcement against an Oklahoma multi-facility nursing care organization, including a $100,000 civil money penalty. The matter, together with other skilled nursing facility access cases announced around the same period, highlights that personal representative requests must be handled promptly and that verification of authority should not become an open-ended barrier to access.
Taken together, these matters show that OCR’s access enforcement is not limited to one type of provider, one size of organization, or one record system. The recurring themes are familiar: missed deadlines, incomplete escalation, confusion over request authority, fee-related delays, and failure to produce copies even when records are maintained electronically.
Compliance Takeaways
- Review HIPAA right-of-access policies to confirm they address requests to inspect records, obtain copies, receive electronic copies, and direct records to third parties where applicable.
- Confirm that staff can distinguish psychotherapy notes from treatment records and understand that mental health treatment records are not automatically excluded from access.
- Maintain psychotherapy notes separately from the medical record if the organization intends to treat them as excluded from the right of access.
- Implement a centralized tracking process for access requests, including request date, scope, responsible personnel, due date, extension notices, production date, and any basis for denial.
- Ensure request workflows cover personal representatives, including how staff verify authority without creating unnecessary delay.
- Review fee practices to confirm that payment procedures do not operate as a barrier to timely access.
- Train front-desk, clinical, health information management, privacy, and business associate oversight personnel on when to escalate complex or sensitive requests.
- Audit access-request files periodically to identify delays, inconsistent responses, excessive fees, or recurring operational barriers.
Bottom Line
Patient-access requests remain a high-risk area for HIPAA compliance. Covered entities should ensure that policies and day-to-day practices align with the Privacy Rule’s access requirements, particularly when records involve behavioral health information or psychotherapy notes. Organizations that can quickly identify accessible records, document any lawful exclusions, and produce copies on time will be better positioned to reduce complaint risk and respond effectively if OCR investigates.
