Patient Access to Medical Records Created by Another Provider

By Fisher, JD, CHC, CCEP

 

 Private Practice Provides Access to All Records, Regardless of Source

Patient access to medical records is one of the core rights protected by the HIPAA Privacy Rule. When a health care provider maintains protected health information about an individual in a designated record set, the patient generally has the right to inspect or obtain a copy of that information, even if parts of the record originated somewhere else. This principle was reinforced in a case involving a private practice that denied a patient access to portions of his records because those portions had been created by a physician who was not associated with the practice.

Case Overview

A private practice denied an individual access to his records on the basis that a portion of the individual’s record was created by a physician not associated with the practice. The practice appeared to treat the origin of the information as a reason to withhold it. However, the right of access under the Privacy Rule focuses on whether the information is maintained by the covered entity in a designated record set, not on whether the covered entity personally created every item in that record.

To resolve the matter, the Office for Civil Rights required the private practice to revise its access policies and procedures. The revised policy had to affirm that patients may access their records regardless of whether another entity created some of the information contained in those records.

The Legal Principle: Access Is Broader Than Authorship

Under the HIPAA Privacy Rule, individuals generally have a right to inspect and obtain a copy of protected health information about themselves that is maintained in a designated record set. This right applies for as long as the information is maintained in that record set, subject to limited exceptions such as psychotherapy notes and information compiled in reasonable anticipation of, or for use in, a legal proceeding.

The key point is that the access right is tied to possession and maintenance of the patient’s protected health information in a designated record set. A provider cannot avoid its access obligations simply by saying that another physician, facility, or organization originally created part of the record. If the practice maintains that information as part of the patient’s record, it must evaluate the access request under the Privacy Rule’s access standards.

Access Requests Are Different From Amendment Requests

The case also highlights an important distinction between two separate patient rights: the right to access records and the right to request an amendment. The Privacy Rule allows a covered entity to deny an amendment request in certain circumstances, including when the covered entity did not create the information that the patient wants amended, unless the originator is no longer available to act on the request.

That limitation does not apply in the same way to access requests. A patient asking to see or obtain a copy of information is not necessarily asking the practice to change, correct, or validate that information. The practice’s duty is to provide access to the protected health information it maintains, unless a specific Privacy Rule exception permits denial. Confusing the amendment standard with the access standard can lead to improper denials and compliance risk.

Why the Distinction Matters for Patients

Patients often receive care from multiple providers, specialists, hospitals, laboratories, and outside facilities. As a result, a single medical record may include consultation notes, test results, referral documents, imaging reports, medication histories, and other information that originated outside the practice currently maintaining the record. If providers could deny access whenever a record contained outside information, patients would face fragmented and incomplete access to their own health information.

Complete access supports continuity of care, informed decision-making, second opinions, insurance and disability matters, and the ability to identify potential errors. The Privacy Rule’s access framework helps ensure that patients are not forced to track down every original source when a covered entity already maintains the relevant information in its own designated record set.

Key Statistics That Show Why Access Matters

  • As of October 31, 2024, the Office for Civil Rights reported receiving 374,322 HIPAA complaints and resolving 370,578 of them, meaning 99% of complaints had been resolved.
  • OCR reported 46,752 investigated complaint resolutions as of October 2024, including 31,191 cases in which corrective action was obtained and 15,561 cases in which no violation was found.
  • OCR identified lack of patient access to protected health information as one of the five most frequently alleged HIPAA compliance issues since the Privacy Rule’s compliance date.
  • In calendar year 2024, OCR received 30,256 new HIPAA complaints, resolved 28,228 complaints, initiated 730 compliance reviews, and completed 797 compliance reviews.
  • ONC reported that in 2022, about 3 in 5 individuals were offered and accessed their online medical records or patient portals, reflecting the growing importance of timely, complete access to health information.
  • ONC also reported that more than half of individuals who were offered online access used their records at least three times in 2022, and nearly one in three accessed them six or more times.

These statistics show that access problems are not merely technical or administrative concerns. They are recurring compliance issues with real consequences for patients and regulated entities. For patients, access affects the ability to review test results, share records with other providers, monitor care, and identify possible errors. For covered entities, access failures can lead to complaints, investigations, corrective action, monetary settlements, and reputational harm.

Compliance Lessons for Health Care Practices

Update Access Policies Around Maintained Records

Health care practices should review their access policies to confirm that staff understand the difference between records created internally and records maintained internally. A record’s outside origin does not, by itself, justify withholding it from the patient. Because lack of patient access remains one of the most frequently alleged HIPAA compliance issues, policies should instruct staff to process access requests based on whether the information is part of the designated record set and whether a valid exception applies.

Example: Outside Consultation Notes, Lab Reports, and Imaging Reports

For example, if a patient asks for a complete copy of her chart and the chart includes a cardiology consultation note, a laboratory report, or an imaging report from an outside facility, the practice should not automatically exclude those documents simply because they came from another provider. If the practice maintains those documents in the patient’s designated record set, staff should treat them as part of the access request and provide them unless a specific exception applies.

Example: Referral Records From Specialists

Another example involves referral records. A primary care practice may receive specialist notes after referring a patient to an orthopedic surgeon, neurologist, or dermatologist. Even though the specialist authored those notes, the primary care practice may rely on them to coordinate ongoing treatment. If the notes are maintained in the patient’s record, the practice should include them when responding to a valid access request rather than telling the patient to obtain them only from the specialist.

Train Staff on Access Request Requirements

Practices should also train workforce members who receive, process, or respond to records requests. Training should cover the scope of the right of access, permissible grounds for denial, timelines for responding, fee limitations when applicable, and escalation procedures for complex requests. Clear training reduces the chance that front-office staff, records personnel, or clinical staff will deny access based on assumptions rather than the Privacy Rule.

Example: Role-Specific Training Scenarios

Training should include role-specific examples. Front-desk employees should know how to route requests and avoid giving informal denials. Medical records staff should know how to identify the designated record set, calculate permissible fees, and track response deadlines. Clinical staff should know when to escalate concerns, such as requests involving sensitive information, legal proceedings, or records that may fall within a limited exception.

Example: Checklist-Based Review Before Disclosure

Practices can also use checklists to reduce mistakes. A checklist might ask whether the request identifies the patient, whether the requested information is maintained in the designated record set, whether any narrow exception applies, whether the patient requested a particular format, whether the response deadline has been documented, and whether the disclosure has been completed or properly denied in writing.

Example: Portal Access Does Not Replace Full Access

Technology workflows should also be reviewed. If a patient portal gives access only to internally generated notes while excluding scanned outside records, referral documents, or diagnostic reports stored elsewhere in the electronic health record, the practice should make sure another process exists for providing those materials when requested. Portal access is helpful, but it does not replace the obligation to respond to the full access request.

Document Access Decisions and Requests

Finally, practices should document how access requests are handled. Written procedures, request logs, denial templates, and review processes can help demonstrate compliance if a complaint arises. Documentation is especially important when a practice denies access, because the denial must be tied to a recognized basis under the Privacy Rule rather than a general concern about who authored the information.

Example: Standardized Review Before Denials

For denials, practices should use a standardized review process. For instance, if staff believe a requested item may be excluded, the request should be reviewed by a privacy officer, records manager, or other trained decision-maker before the patient receives a denial. This helps ensure the decision is based on a recognized Privacy Rule basis rather than on convenience, uncertainty, or the mistaken belief that outside-authored records are automatically off limits.

Key Takeaway

The lesson from this case is straightforward: a covered entity that maintains a patient’s protected health information generally must provide access to that information when requested, even if another provider created part of the record. Authorship may matter in the context of amendment requests, but it is not a blanket reason to deny access. Given the volume of HIPAA complaints, the frequency of access-related allegations, and the growing number of patients using portals and apps to view their records, private practices and other covered entities should build policies, training, and workflows around the patient’s right to obtain the full record maintained by the organization, subject only to the limited exceptions recognized by the Privacy Rule.

This entry was posted in Compliance Issues, HIPAA - Health Information Privacy. Bookmark the permalink.