HIPAA Right of Access Enforcement: 45+ Settlements
OCR's ongoing initiative enforcing patient rights to access their medical records
Quick Answer
OCR has pursued 45+ enforcement actions against healthcare providers and health plans for denying patients' right to access their medical records, with settlements ranging from $15,000 to $200,000, demonstrating that right of access is a priority enforcement area.
Case Overview: Right of Access Initiative
The HIPAA Privacy Rule grants individuals a fundamental right to access their own protected health information (PHI). Specifically, 45 CFR § 164.524 requires covered entities to provide individuals with access to their medical records within 30 days of request, or document a valid reason for denial.
Despite this clear requirement, OCR has identified right of access violations as a significant and recurring issue in healthcare. Beginning in 2016 and continuing through the present, OCR has initiated an enforcement initiative specifically focused on organizations that deny or delay patient access requests without valid legal justification. This initiative has resulted in over 45 settlements, demonstrating OCR's commitment to protecting patient rights.
Enforcement Initiative Background
OCR's enforcement effort targets providers and health plans that systematically deny access requests, charge excessive fees, or fail to provide records in a timely manner. The settlements cover hospitals, health systems, health insurance companies, mental health providers, and other healthcare organizations of varying sizes.
Common Violations Identified
Denial Without Valid Legal Basis
- Denying access requests without documented reason or valid legal exception
- Using invalid grounds for denial (administrative burden, cost concerns, information outdated)
- Claiming psychiatric notes are not accessible when HIPAA permits access with possible delay
- Denying access to certain record categories without valid justification
Excessive Delays in Providing Records
- Failing to respond to requests within 30-day HIPAA deadline
- Claiming delays due to voluminous records without reasonable effort
- Extended delays without notification of reasons or timeline for fulfillment
- Ignoring patient follow-up requests or appeals
Excessive or Unreasonable Fees
- Charging fees beyond the cost of copying and postage
- Charging per-page fees that exceed reasonable cost estimates
- Requiring prepayment before providing records
- Charging fees for electronic records that exceed cost of copying
Lack of Access Procedures
- No documented procedures for receiving and processing access requests
- No tracking mechanism for requests and response timelines
- Failure to acknowledge receipt of requests
- No process for responding to appeals of denials
Failure to Provide in Requested Format
- Refusing to provide records in electronic format when individual requests
- Failing to provide records in format that individual can use
- Not accommodating reasonable requests for portable formats
OCR Enforcement Standards
Under the HIPAA Privacy Rule and OCR enforcement actions, covered entities must comply with the following access requirements:
Response Timeline
- 30-Day Standard: Individuals must receive access or written denial within 30 days of request
- Extension for Delay: Single 30-day extension permissible with written notice of reasons and expected completion date
- No Additional Delays: Extensions beyond 60 days are not permitted under HIPAA
Valid Grounds for Denial
- Information created in litigation process under specific conditions
- Psychiatric notes in certain limited circumstances with right to appeal
- Inmate records may be denied when access poses security risk
- Information from third parties where release would violate privacy
Invalid Reasons for Denial
- Administrative burden or inconvenience
- Cost of copying and transmitting records
- Patient debt or unpaid bills
- Litigation threat or attorney referral
- Provider preference that patient receive records through physician
Fee Standards
- Fees may include cost of copying, binding, and postage
- Fees must be reasonable and consistent with actual costs
- Entities should provide cost estimate upon request
- Excessive per-page fees (over reasonable market rates) are violations
- No fees for electronic records beyond administrative cost
Acceptable Denial Procedures
- Written denial identifying specific legal basis for denial
- Written explanation of right to appeal or request for independent review
- Identification of contact for appeal or question
- Timely notification to individual within 30-day window
Settlement Patterns and Trends
Penalty Calculation
OCR's penalties for right of access violations typically reflect:
- Number of individuals affected: Larger settlements involve multiple violated requests or systemic patterns
- Duration of violation: Longer periods of noncompliance result in higher penalties
- Degree of unreasonableness: Outright denials result in higher penalties than simple delays
- Organization's prior compliance: History of violations increases penalty severity
Corrective Action Patterns
Most right of access settlements require:
- Development of documented access request procedures
- Implementation of tracking system for requests and timelines
- Training for staff handling access requests on HIPAA requirements
- Audit procedures to ensure compliance with 30-day deadline
- Appeal procedures for access request denials
- Fee schedule documentation and review of charging practices
Emerging Issues
- Electronic Health Records: EHR systems increasingly create technical barriers to patient access that must be overcome
- Aggregated Records: Disputes over what must be provided when records span multiple systems
- Special Format Requests: Increasing requests for interoperable formats or portable health records
- Timeline Pressures: 30-day timeline increasingly challenging for organizations with complex records systems
Lessons Learned
Right of Access is Fundamental, Not Optional
While other HIPAA violations involve data security failures, right of access violations involve organizational decisions to deny or delay patient rights. These decisions are conscious and deliberate, which may explain OCR's heightened focus on this area. Organizations that deny access for convenience or administrative burden face enforcement action.
Systemic Procedures Are Essential
Organizations that establish documented procedures for receiving, processing, and responding to access requests are significantly less likely to face violations. These procedures should include specific timelines, responsible parties, and escalation procedures.
Staff Training is Critical
Many violations result from staff misunderstanding or misapplying HIPAA requirements. Front-line staff who receive access requests must understand the 30-day requirement and valid grounds for denial. Training should be specific and ongoing.
Tracking Systems Enable Compliance
Without a tracking system, organizations cannot consistently meet the 30-day deadline or ensure all requests are responded to. Simple tracking mechanisms (spreadsheets, specialized systems) can prevent violations if properly implemented and monitored.
Technical Barriers Must Be Managed
As EHR systems become more complex, the burden of compiling records for individual access increases. Organizations must implement technical solutions or processes to efficiently extract and compile records to meet the 30-day deadline.
Fee Denials Are Not Access Denials
Organizations must provide access regardless of cost or administrative burden, though reasonable fees for copying and transmission are permissible. Using cost as a reason to deny or delay access is not permissible under HIPAA.
Right of Access Compliance Checklist
Policies and Procedures
Operational Implementation
Staff Training
Technical Systems
Monitoring and Auditing
Appeal Procedures
Frequently Asked Questions
First, request a written explanation of the denial, which HIPAA requires. Review the stated reason to determine if it's a valid legal exception. If the denial appears invalid or excessive fees are being charged, request appeal within the organization. If the organization does not have an appeal procedure, contact OCR to file a complaint. OCR investigates access denial complaints and can pursue enforcement action if violations are found.
HIPAA permits providers to charge a reasonable fee for copying and postage, but the fee must be reasonable and consistent with actual costs. For electronic records, the fee should be minimal since copying costs are near zero. OCR has found violations where providers charged per-page fees for electronic records or charged excessive administrative fees. Reasonable fees for electronic records typically range from minimal (under $5) to the actual cost of electronic transmission or media.
HIPAA permits a single 30-day extension with written notice explaining the reason for delay and expected completion date. However, the total time (initial 30 days plus extension) cannot exceed 60 days. Valid reasons for extension include voluminous records that cannot be reasonably compiled within 30 days, or need to retrieve archived records. Administrative burden or staff limitations are not valid reasons for extension.
Access denial is a refusal to provide records based on claimed legal exception (psychiatric notes, litigation materials, etc.). Delayed access is failing to provide records within the 30-day (plus possible 30-day extension) timeline. OCR treats both as violations if not properly justified. However, denial requires valid legal basis, while delay requires legitimate operational reasons and a reasonable expectation to meet the extended timeline.
Ensure Your Organization Meets Access Timelines
Audit your access request procedures to verify compliance with HIPAA's 30-day requirement and avoid OCR enforcement action against your organization.
Evaluate Your Access Procedures