Obtainer
Use case

HIPAA Right of Access: Patient Right of Access Requests, Answered Inside 30 Days

A patient right of access request looks simple until you go looking for the records. The chart is in the EHR, but the billing detail is in the practice management system, the images are with a radiology vendor, the portal messages are somewhere else again, and the 30-day clock in 45 CFR 164.524 started the day the request arrived. Obtainer finds where a person's data actually lives across your systems, compiles one reviewable manifest, keeps the deadline, and leaves a timestamped record of what was searched and when.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The HIPAA right of access, at 45 CFR 164.524, gives an individual the right to inspect and obtain a copy of the protected health information about them held in a designated record set by a covered entity. You must act on the request no later than 30 days after you receive it. You may take one extension of no more than 30 additional days, and only one, and only if you give the individual a written statement of the reason for the delay and the date by which you will act. Two categories fall outside the right entirely: psychotherapy notes, and information compiled in reasonable anticipation of or for use in a civil, criminal, or administrative action or proceeding. Beyond those, denials split into unreviewable grounds (such as certain research data during an active study, information obtained under a promise of confidentiality where disclosure would reveal the source, and specific correctional and Privacy Act situations) and reviewable grounds (a licensed health care professional's judgment that access would endanger life or physical safety, references to another person where access would cause substantial harm, and certain personal representative requests). A reviewable denial has to be reviewed by a licensed health care professional who was not involved in the original decision, if the individual asks for that review. You must provide the copy in the form and format the individual requests if it is readily producible that way, and if the information is maintained electronically and an electronic copy is requested, you must provide it electronically. Any fee has to be reasonable and cost-based, limited to labor for copying, supplies, postage, and preparing a summary or explanation if the individual agreed to one in advance. Since Ciox Health v. Azar in January 2020, the patient-rate fee limit applies when an individual requests their own records but not when the individual directs the copy to a third party, and the third-party directive requirement is limited to electronic protected health information in an electronic health record. OCR has treated this as an enforcement priority since it launched the Right of Access Initiative in late 2019, and it had imposed 54 financial penalties under that initiative as of December 2025, ranging from $3,500 for a small psychiatric practice to $240,000 for a nonprofit health system. To be direct about what Obtainer is: it is not a release of information system bolted onto your EHR, and it does not pull charts. It handles the part that sits outside the chart. It runs intake, discovers where a person's data lives across the systems that are not the EHR, compiles a source-system manifest so nothing gets missed, drafts the response, tracks the 30-day HIPAA clock and the 45-day state clocks side by side, and keeps an evidence trail. Nothing is disclosed automatically: a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so scope, exemption, and denial calls stay with your team. Self-serve from $49/mo.

// THE FIT

Why it fits

Privacy officers and compliance leads at hospitals and health systems, medical and dental groups, behavioral health providers, health plans, and business associates, plus health information management and release of information teams that need the non-EHR half of a request tracked, and digital health, telehealth, and wellness companies that need to know exactly where HIPAA ends and the state privacy laws begin.

OCR counts days, and the cases show how few it takes to get expensive

The Right of Access Initiative has been running since late 2019 and had produced 54 financial penalties by December 2025. In January 2025 OCR settled with South Broward Hospital District, doing business as Memorial Healthcare System, for $60,000 after a patient made repeated requests through the portal, by mail, and by phone and waited roughly nine months. In December 2025 Concentra, Inc. paid $112,500 over a request made in February 2018 that was not fulfilled until March 2019. Neither case involved a breach or an allegation of harm. They involved a calendar. The pattern in these files is almost never a refusal. It is a request that arrived somewhere nobody was watching and moved between departments until the window closed.

HIPAA does not exempt your whole company in every state

This is the assumption that quietly creates exposure. Nine states with comprehensive privacy laws exempt HIPAA covered entities and business associates at the entity level: Connecticut, Florida, Indiana, Iowa, Montana, Tennessee, Texas, Utah, and Virginia. Six do not. California, Colorado, Delaware, Minnesota, New Jersey, and Oregon exempt the protected health information rather than the organization holding it, so your marketing lists, website and app analytics, donor records, gift shop and retail pharmacy customers, and in California your own employees all sit inside the state law with full access, correction, and deletion rights on a 45-day clock. New Jersey widened its carve-out on January 20, 2026 through Assembly Bill A5017, which exempts certain non-PHI handled to HIPAA standards, and that is still a data-level test, not a blanket pass.

The designated record set is bigger than the chart

The right of access reaches the designated record set, which includes medical and billing records used to make decisions about the individual, not just the clinical chart. In practice that means the EHR plus the practice management and billing system, itemized statements, the patient portal message history, scheduling notes, imaging held by a radiology vendor, lab results at a reference lab, and records sitting with business associates. The $240,000 case in this initiative was about an itemized billing statement, not a chart. Discovery, not drafting, is where the 30 days go, and an incomplete production is treated as a failure to provide access rather than a partial success.

Two clocks now run on the same organization

A health system in California or Colorado can receive a HIPAA access request on a 30-day clock and a state privacy request about non-PHI on a 45-day clock in the same week, from the same person, through different intake paths, with different verification standards and different denial grounds. Running them as two disconnected processes is how one of them gets missed. Obtainer keeps both clocks, the search record, and the approval trail in one place, so the answer to "what did we do about this request and when" is a record you export rather than an email thread you reconstruct.

// FAQ

Questions

Common questions about this

What is the HIPAA right of access?

It is the right, at 45 CFR 164.524, for an individual to inspect and obtain a copy of the protected health information about them that a covered entity holds in a designated record set. It covers medical and billing records used to make decisions about that person, and it applies whether the records sit in an EHR, a billing system, or with a business associate. The covered entity must act within 30 days of receiving the request.

How long does a provider have to respond to a request for medical records?

Thirty days from receipt. A covered entity may take one extension of up to 30 more days, and only one, and only if it gives the individual a written statement of the reason for the delay and the date by which it will act. That statement has to go out inside the original 30 days. There is no separate allowance for records stored off-site, and time spent locating records across systems comes out of the same window.

What records are covered by the HIPAA right of access?

The designated record set, which is broader than the clinical chart. It includes medical records, billing and payment records, enrollment, claims, and case management records, and any other records the covered entity uses in whole or in part to make decisions about the individual. Two things are excluded: psychotherapy notes kept separately from the rest of the record, and information compiled in reasonable anticipation of or for use in a legal or administrative proceeding.

Can a provider deny a patient access to their medical records?

Only on the specific grounds the rule lists, and the burden is on the covered entity. Unreviewable grounds include research data during an active study the individual agreed to, information obtained under a promise of confidentiality where disclosure would identify the source, and certain correctional and Privacy Act situations. Reviewable grounds turn on a licensed professional's judgment that access would endanger someone's life or physical safety. A reviewable denial must be reviewed on request by an uninvolved licensed health care professional.

How much can a provider charge for medical records under HIPAA?

A reasonable, cost-based fee only. It may include labor for copying, supplies such as paper or portable media, postage, and preparing a summary or explanation if the individual agreed to that in advance. It may not include search and retrieval time or general overhead. A covered entity may instead offer a flat fee of up to $6.50 for electronic copies of records maintained electronically. After Ciox Health v. Azar in 2020, that patient-rate limit does not apply when the individual directs the records to a third party.

Is HIPAA exempt from the CCPA?

Not as an organization. The CCPA exempts protected health information collected by a covered entity or business associate, and information a provider maintains in the same manner as PHI, but it does not exempt the company. Personal information a health system holds that is not PHI stays in scope: marketing and website data, retail and gift shop customers, prospective patients, and since January 1, 2023, its own employees, applicants, and contractors. Colorado, Delaware, Minnesota, New Jersey, and Oregon take the same data-level approach.

What is the HIPAA Right of Access Initiative?

It is the enforcement program OCR announced in late 2019 to pursue complaints that individuals were denied timely access to their records. It had produced 54 financial penalties as of December 2025, from $3,500 against a small psychiatric practice to $240,000 against a nonprofit health system. The cases are notable for how ordinary they are: no breach, no bad actor, just a request that took months instead of days. OCR has signaled that timely access remains a 2026 enforcement priority.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.