Release of Information
HIPAA, Release of Information

Right of Access Compliance

A Contemporary Risk Management and Regulatory Imperative 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The HIPAA Right of Access (ROA) provision continues to stand as a vital patient-rights protection and a persistent enforcement focus for OCR. Since 2022, the OCR has escalated enforcement activity—issuing multiple monetary settlements ranging from small practices to large organizations, including significant penalties such as $200,000 against Oregon Health & Science University (OHSU) in 2025. This article updates the scholarly discussion with recent data, reviews enforcement activity, and underscores strategic imperatives for compliance through inclusive workforce education, robust policy frameworks, centralized oversight, and ongoing auditing.

Introduction

Since its introduction, HIPAA’s Right of Access—which empowers patients to access their protected health information (PHI)—has been elevated by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as a leading enforcement priority. OCR’s Right of Access Initiative, instituted in 2019, has remained dynamically active, with continued resolution of complaints and repeated emphasis across enforcement years 2022 through 2025.

Regulatory Framework of the Right of Access

Under HIPAA, individuals are entitled to access their PHI in “designated record sets” (45 C.F.R. § 164.524). Covered entities must provide this access within 30 days of receiving a request, with a single 30-day extension permitted if documented and communicated to the patient.

Key requirements include:

  • Timeliness: Records must be provided within the prescribed timeframes.
  • Reasonable fees: Covered entities may charge only cost-based fees for labor, supplies, and postage.
  • Format: Information must be provided in the form and format requested, if readily producible.
  • Exceptions: Access may be denied under limited circumstances, such as if disclosure is reasonably likely to endanger life or safety.

Failure to meet these requirements can result in HIPAA violations, OCR investigations, and reputational harm.

Recent Enforcement Activity (2022–2025)

OCR’s enforcement record demonstrates an ongoing pattern of provider noncompliance with the Right of Access. Key examples include:

2022:
- Multiple ROA settlements involving dental practices, including one finalized in December 2022.
- Memorial Hermann Health System settled for $240,000 over delayed access requests.

2023:
- OCR resolved 13 enforcement actions totaling $4.18 million, nearly doubling 2022’s penalties.
- Life Hope Labs was fined $16,500 for delayed records release.

2024:
- OCR imposed $170,000 in penalties against a dental practice and a Los Angeles County mental health program.

2025:
- Oregon Health & Science University (OHSU) was fined $200,000 for failing to provide timely access to a patient’s representative.
- OCR also continued settlements tied to ransomware incidents, such as the Comstar breach affecting over 585,000 individuals.

Enforcement Trend Analysis

Recent enforcement illustrates key trends:

  • Widespread focus: ROA cases involve providers of all sizes and types.
  • Significant financial liability: Penalties range from modest fines to $200,000+.
  • Business associate accountability: Covered entities are liable for their partners’ noncompliance.
  • Cybersecurity overlap: Breaches and ransomware are increasingly tied to ROA violations.

Compliance Challenges in Healthcare Organizations

Despite regulatory clarity, many organizations continue to struggle with operationalizing the Right of Access. Common barriers include:

  • Lack of workforce training: Staff may be unaware of timelines, fee structures, or documentation requirements.
  • Decentralized recordkeeping: PHI may be stored across multiple EHR platforms, making access requests cumbersome.
  • Inconsistent policies: Outdated or incomplete policies may lead to variable practices across departments.
  • Cultural barriers: Some providers remain reluctant to share full records, particularly behavioral health information, despite HIPAA requirements.

These challenges highlight the need for strong compliance frameworks that integrate policy, training, and oversight.

Risk Mitigation Through Compliance Programs

Right of Access compliance should be viewed not only as a legal requirement but as a risk management strategy. By embedding compliance into organizational culture, healthcare leaders can reduce the likelihood of OCR investigations and enhance patient satisfaction.

Effective strategies include:

1.  Policy development  

     Create and regularly update written policies aligned with HIPAA and state privacy rules.

2.  Workforce training  

     Ensure all staff—front desk, nursing, HIM, billing, IT—understand their responsibilities.

3.  Monitoring and auditing  

     Conduct regular internal audits of access requests, timeliness, and fees.

4.  Centralized oversight  

     Designate a privacy officer or compliance team to oversee all Right of Access processes.

5.  Patient engagement  

     Communicate clearly with patients regarding their rights, timelines, and any applicable fees.

6.  Cybersecurity integration  

     Align ROA procedures with breach and ransomware response protocols.

Conclusion

The HIPAA Right of Access reflects a core principle of modern healthcare: empowering patients with information to participate in their care. Recent enforcement actions from 2022–2025 highlight the continued priority OCR places on this right, with penalties applied to providers of all sizes.

Healthcare leaders must proactively address this risk by developing robust policies, ensuring comprehensive workforce training, monitoring compliance, and integrating cybersecurity protections. In doing so, organizations protect themselves from regulatory enforcement while upholding the trust and dignity of the patients they serve.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Comply with Privacy Rights to Avoid Unconsented Intimate Exams

Written by Gabriella Neff, RHIA, CHA, CHC, CHRC, CHPC 

This past year, in 2024, revisions were made to clarify hospital guidelines related to informed consent specifically addressing UIEs (unconsented intimate exams) to patients while under anesthesia.  This article addresses how these privacy rights extend beyond rules designated under HIPAA and States passing rules banning unauthorized pelvic exams.

Revised Guidance for Teaching Hospitals and Medical Schools on Informed Consent

Privacy rights extend beyond the rules On April 1, 2024, the Centers for Medicare & Medicaid Services (CMS) released revisions and clarifications to the Hospital Interpretive Guidelines for Informed Consent simultaneously with a letter by the Department of Health and Human Services (HHS) to address medical professionals performing Unconsented Intimate Exams (UIEs), particularly on patients under anesthesia.[1],[2]  UIEs are training and education-related examinations, including, but not limited to, pelvic, breast, prostate, and rectal examinations. These revisions resulted from recent articles, media reports, and concerns from nurses, some physicians, and medical students opposing these exams.[3],[4] These examinations have been known “to occur over the past thirty (30) years, for training and diagnostic purposes, mostly during gynecological surgeries but also during prostate examinations and abdominal surgeries.” [5]  

In the letter, HHS reminded providers that the Office of Civil Rights (OCR) investigates complaints of impermissible use and disclosure of a patient’s Protected Health Information (PHI) in violation of the HIPAA Privacy Rule (Health Insurance Portability and Accountability Act), including scenarios where the patient may be unconscious during a medical procedure. OCR recently issued an FAQ focusing on this right.[6] The letter also notes that obtaining informed consent for sensitive examinations is the standard of care and that OCR will continue to focus on provider compliance with HIPAA and proper informed consent.

Many state regulators have legalized protections echoing this as well. As of November 2023, twenty-five (25) states passed legislation banning unauthorized pelvic exams. [7]

Pelvic Exam Laws in the US

Informed consent is the process where a provider educates a patient about the risks, benefits, and alternatives of a procedure or intervention, which ultimately results in the patient’s agreement or refusal of the procedure or intervention. It further includes the patient's participation in the development of his/her plan of care during and after discharge from the hospital and providing consent to, or refusal of, medical or surgical interventions, including the right to refuse consent for sensitive examinations conducted for teaching purposes.

“Informed consent is the law and essential to maintaining trust in the patient-provider relationship and respecting patients’ autonomy.” [8] Requirements related to informed consent for hospitals may be found in the Hospital Conditions of Participation (CoPs):

  • The Patient’s Rights CoP at 42 CFR 482.13(b)(2);  
  • The Medical Record Services CoP at 482.24(c)(4)(v);
  • The Surgical Services CoP at 482.51(b)(2)    [9]
  • The State Operations Manual Appendix A, tag A-0955 – A properly executed informed consent.

CMS stated that they revised the interpretive guidance in the State Operations Manual Appendix A for hospitals at tag A-0955 under the section entitled “Properly Executed and Well-designed Informed Consent Form Examples” and under the section entitled “Hospital’s Policy and Process for Informed Consent. The revision is below in red:

“Whether physicians other than the operating practitioner, including, but not limited to, residents, medical, advanced practice providers (such as nurse practitioners and physician assistants), and other applicable students, will be performing important tasks related to the surgery, or examinations or invasive procedures for educational and training purposes, in accordance with the hospital’s policies. Important surgical tasks include opening and closing, dissecting tissue, removing tissue, harvesting grafts, transplanting tissue, administering anesthesia, implanting devices, and placing invasive lines. Examinations or invasive procedures conducted for educational and training purposes include but are not limited to, breast, pelvic, prostate, and rectal examinations, as well as others specified under state law.”[10]

Teaching hospitals and medical schools must understand the expectations outlined by CMS and take proactive steps to transform their institutional culture. Teaching hospitals need to establish guidelines addressing this matter, while medical schools should revise their curriculum to encourage a culture where healthcare providers and trainees consistently obtain and appropriately document informed consent from patients before conducting any sensitive examinations.

About the Author

Gabriella Neff, RHIA, CHA, CHC, CHRC, CHPC is a Research Compliance Officer for H. Lee Moffit Cancer Center and also serves as a Board Member for the American Institute of Healthcare Compliance.

Reference

[1] CMS Revisions and Clarifications to Hospital Interpretive Guidelines for Informed Consent. April 1, 2024. Retrieved from https://www.cms.gov/files/document/qso-24-10-hospitals.pdf

[2] HHS Letter to the nation’s teaching hospitals and medical schools.  April 1, 2024. https://www.hhs.gov/about/news/2024/04/01/letter-to-the-nations-teaching-hospitals-and-medical-schools.html

[3] Friesen P, Wilson RF, Kim S, Goedken J. Consent for Intimate Exams on Unconscious Patients: Sharpening Legislative Efforts. Hastings Cent Rep. 2022 Jan;52(1):28-31. doi: 10.1002/hast.1337. PMID: 35143067

[4] Wilson RF. Unauthorized practice: teaching pelvic examination on women under anesthesia. J Am Med Womens Assoc (1972). 2003 Fall;58(4):217-20; discussion 221-2. PMID: 14640251

[5] Bruce L. A Pot Ignored Boils On: Sustained Calls for Explicit Consent of Intimate Medical Exams. HEC Forum. 2020 Jun;32(2):125-145. doi: 10.1007/s10730-020-09399-4. PMID: 32152870; PMCID: PMC7223770

[6] HHS.  FAQ.  Retrieved from https://www.hhs.gov/hipaa/for-professionals/faq/can-an-individual-restrict-who-has-access-to-their-protected-health-information-during-a-medical-procedure/index.html

[7] https://www.news5cleveland.com/news/local-news/investigations/it-felt-like-a-violation-ohio-does-not-require-consent-for-pelvic-exams-on-unconscious-patients

[8] HHS Letter to the nation’s teaching hospitals and medical schools.  April 1, 2024. https://www.hhs.gov/about/news/2024/04/01/letter-to-the-nations-teaching-hospitals-and-medical-schools.html

[9] Hospital Conditions of Participation. April 3, 2024. Retrieved from https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-482?toc=1

[10] CMS State Operations Manual. Appendix A. – Survey Protocol. Regulations and Interpretive Guidelines for Hospitals.  Retrieved from https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_a_hospitals.pdf


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Reproductive Health & the New Final Rule

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS of the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare education organization.       

HIPAA Reproductive Health Provisions Now Vacated

In June 2025, a Texas court struck down most of the new HIPAA rules protecting reproductive health information, meaning those specific prohibitions and disclosure requirements are largely gone. 

The court found the rule went beyond HIPAA's scope by trying to achieve political goals, interfering with state laws, and improperly redefining terms like "person" and "public health".  The Court stated that while HIPAA gives authority to HHS to promulgate regulations protecting “individually identifiable health information,” the law does not give authority to “distinguish between types of health information” to accomplish a political agenda. The Court also argued that the Rule unlawfully limits state public health laws.

Impact - The rule's restrictions on sharing reproductive health data for criminal/civil investigations and the requirement for attestations from data requesters were nullified.  Covered entities must remove reproductive health language but must update NPPs to reflect new SUD protections by that 2026 date, as those requirements remain in effect. 

What is this Final Rule?

The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and Disclosures of Information Relating to Reproductive Health Care, aka Final Rule became effective June, 2024.

The Final Rule applies to Protected Health Information (PHI) related to lawful reproductive health care, including care that is protected by federal law, such as the Emergency Medical Treatment and Active Labor Act (EMTALA) or the U.S. Constitution. The rule also applies when care is provided by someone other than the recipient of the request.

As stated by the Office of Civil Rights (OCR), the government HIPAA enforcement agency, access to comprehensive reproductive health care services, including abortion care and other sexual and reproductive care, is essential to individual health and well-being.

Defining Reproductive Health Care

The 2024 HIPAA Final Rule defines reproductive health care as "health care that affects the health of an individual in all matters relating to the reproductive system and to its functions and processes". This definition is broad and intentional, and may include services related to sterilization and fertility, such as vasectomies, male hormone therapy, and erectile dysfunction treatments.

The rule specifically states: “Reproductive Health Care means health care, as defined in this section, that affects the health of an individual in all matters relating to the reproductive system and to its functions and processes. This definition shall not be construed to set forth a standard of care for or regulate what constitutes clinically appropriate reproductive health care.”

Who is Required to Comply with the Final Rule?

Regulated entities are required to comply, which are better known as HIPAA Covered Entities and their Business Associates, such as:

  • Health plans;
  • Health care clearinghouses;
  • Most health care providers; and
  • Their business associates

What are the Deadlines for Compliance?

  • Published at the Federal Register on April 26, 2024.
  • Effective date is June 25, 2024.
  • Compliance date, the date persons subject to this regulation must comply with the applicable requirements of this final Rule, is December 23, 2024, except for the Notice of Privacy Practices.
  • Compliance date for the Notice of Privacy Practices is February 16, 2026.

The rule became effective on June 25, 2024, and those subject to the regulation must comply by December 23, 2024, except for the applicable requirements of the Notice of Privacy Practices (NPP) for Protected Health Information  45 CFR 164.520 in this final rule. The Final Rule requires covered health care providers, health plans, and health care clearinghouses to revise their NPPs to support reproductive health care privacy.

Persons subject to providing an NPP to patients and subject to this regulation, are required to comply with the applicable requirements of 45 CFR 164.520 in this final rule by February 16, 2026.

What are the Key Provisions to the Rule?

It applies to the protection of reproductive health care information which encompasses abortion, birth control, and in vitro fertilization with the goal of strengthening patient-provider confidentiality and promoting trust between individuals and their health care providers. There are several provisions to the Final Rule which are, in short:

  • Presumption of lawfulness - The rule presumes that reproductive health care provided by someone other than the regulated entity is lawful, unless the recipient has actual knowledge that it is not or the requestor can demonstrate unlawfulness.
  • Prohibition on use or disclosure - The rule prohibits covered health care providers, health plans, and health care clearinghouses from using or disclosing protected health information (PHI) to investigate or impose liability on people for seeking, obtaining, providing, or facilitating lawful reproductive health care.
  • Attestation requirement - The rule requires regulated entities to obtain an attestation from the requestor that a requested use or disclosure of PHI is not for a prohibited purpose.

Please reference § 164.512 Uses and disclosures for which an authorization or opportunity to agree or object is not required and review the summary provided below.  This summary is taken from the Office for Civil Rights (OCR) “HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy: Fact Sheet”


What Specific Types of Use & Disclosures are Prohibited?

The Final Rule prohibitions of use/disclosure of reproductive PHI applies to either of the following activities:

  1. To conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care, where such health care is lawful under the circumstances in which it is provided.
  2. The identification of any person for the purpose of conducting such investigation or imposing such liability.

Under the Final Rule, the prohibition applies where a covered health care provider, health plan, or health care clearinghouse (covered entities) or business associate (collectively, “regulated entities”) has reasonably determined that one or more of the following conditions exists:

  • The reproductive health care is lawful under the law of the state in which such health care is provided under the circumstances in which it is provided.
    • For example, if a resident of one state traveled to another state to receive reproductive health care, such as an abortion, that is lawful in the state where such health care was provided.
  • The reproductive health care is protected, required, or authorized by Federal law, including the U.S. Constitution, regardless of the state in which such health care is provided.
    • For example, if use of the reproductive health care, such as contraception, is protected by the Constitution.
  • The reproductive health care was provided by a person other than the covered health care provider, health plan, or health care clearinghouse (or business associates) that receives the request for PHI and the presumption described below applies.

The Final Rule continues to permit regulated entities to use or disclose PHI for purposes otherwise permitted under the Privacy Rule where the request for the use or disclosure of PHI is not made to investigate or impose liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care.  OCR provides the following examples - a regulated entity:

  • Is permitted to continue to use or disclose PHI to defend themselves in an investigation or proceeding related to professional misconduct or negligence where the alleged professional misconduct or negligence involved the provision of reproductive health care.
  • Could continue to use or disclose PHI to defend any person in a criminal, civil, or administrative proceeding where liability could be imposed on that person for providing reproductive health care.
  • Could continue to use or disclose PHI to an Inspector General where the PHI is sought to conduct an audit for health oversight purposes.

Rule of Applicability

The prohibition applies:

  • Where the relevant activity is in connection with any person seeking, obtaining, providing, or facilitating reproductive health care and
  • The regulated entity that received the request for PHI has reasonably determined that one or more of the following conditions exists:
    • The reproductive health care is lawful under the law of the state in which such health care is provided under the circumstances in which it is provided.
    • The reproductive health care is protected, required, or authorized by Federal law, including the U.S. Constitution, under the circumstances in which such health care is provided, regardless of the state in which it is provided.
    • When the Presumption applies.

Presumption - Care Provided was Lawful

The Final Rule includes a presumption that the reproductive health care provided by a person other than the regulated entity receiving the request was lawful. In such cases, the reproductive health care is presumed to be lawful under the circumstances in which it was provided unless one of the following conditions are met:

  • The covered health care provider, health plan, or clearinghouse (or business associates) has actual knowledge that the reproductive health care was not lawful under the circumstances in which it was provided.
    • For example, an individual discloses to their doctor that they obtained reproductive health care from an unlicensed person and the doctor knows that the specific reproductive health care must be provided by a licensed health care provider.
  • The covered health care provider, health plan, or health care clearinghouse (or business associates) receives factual information from the person making the request for the use or disclosure of PHI that demonstrates a substantial factual basis that the reproductive health care was not lawful under the circumstances in which it was provided.
    • For example, a law enforcement official provides a health plan with evidence that the information being requested is reproductive health care that was provided by an unlicensed person where the law requires that such health care be provided by a licensed health care provider.

What is the New Form Requirement About?

Regulated Entities Must Obtain a Signed Attestation from the Requester Now

  • OCR has provided a “Model Attestation” for requested use or disclosure of PHI related to reproductive health care.  Download a copy of the model attestation from OCR. 

About the implementation of the Attestation Form - To implement the prohibition, the Final Rule requires when the regulated entity receives a request for PHI potentially related to reproductive health care, that the regulated entity obtain a signed attestation that the use or disclosure is not for a prohibited purpose. This attestation requirement applies when the request is for PHI for any of the following:

  • Health oversight activities
  • Judicial and administrative proceedings
  • Law enforcement purposes
  • Disclosures to coroners and medical examiners

Are There Penalties if the Requester Isn’t Compliant?

The requirement to obtain a signed attestation gives the regulated entity a way of obtaining written representations from persons requesting PHI that the request is not for a prohibited purpose.  This also creates a situation of putting the requester “on notice” of the potential criminal penalties for those who knowingly are in violation of HIPAA.  As of October 2023, the criminal penalties for violating HIPAA rules can include jail time and fines:

Tier 1: Reasonable cause or no knowledge of violation, up to 1 year in jail

Tier 2: Obtaining PHI under false pretenses, up to 5 years in jail

Tier 3: Obtaining PHI for personal gain or with malicious intent, up to 10 years in jail

Disclosures to Law Enforcement

The Privacy Rule permits uses or disclosures of PHI without an individual’s authorization only where such uses or disclosures are expressly permitted or required by the Privacy Rule

The Privacy Rule permits, but does not require, certain disclosures to law enforcement and others, subject to specific conditions. Thus, regulated entities such as covered health care providers, health plans, and health care clearinghouses and their business associates, including their workforce members, are only permitted to disclose PHI for law enforcement purposes where they suspect an individual of obtaining reproductive health care (lawful or otherwise) if the covered entity or business associate is required by law to do so and all applicable conditions are met.

Accordingly, under the Final Rule, such disclosure is only permitted where all three of the following conditions are met:

  1. The disclosure is not subject to the prohibition.
  2. The disclosure is required by law.
  3. The disclosure meets all applicable conditions of the Privacy Rule permission to use or disclose PHI as required by law.

45 CFR 164.512(f)(1)(ii) states:

Permitted disclosures: Pursuant to process and as otherwise required by law.  A covered entity may disclose protected health information:

(i) As required by law including laws that require the reporting of certain types of wounds or other physical injuries, except for laws subject to paragraph (b)(1)(ii) or (c)(1)(i) of this section; or

(ii) In compliance with and as limited by the relevant requirements of:

(A) A court order or court-ordered warrant, or a subpoena or summons issued by a judicial officer;

(B) A grand jury subpoena; or

(C) An administrative request for which response is required by law, including an administrative subpoena or summons, a civil or an authorized investigative demand, or similar process authorized under law, provided that:

(1) The information sought is relevant and material to a legitimate law enforcement inquiry;

(2) The request is specific and limited in scope to the extent reasonably practicable in light of the purpose for which the information is sought; and

(3) De-identified information could not reasonably be used.

According to OCR, examples would be:

  • A law enforcement official goes to a reproductive health care clinic and requests records of abortions performed at the clinic. If the request is not accompanied by a court order or other mandate enforceable in a court of law, the Privacy Rule would not permit the clinic to disclose PHI in response to the request. Therefore, such a disclosure would be impermissible and constitute a breach of unsecured PHI requiring notification to HHS and the individual affected. 
  • A law enforcement official presents a reproductive health care clinic with a court order requiring the clinic to produce PHI about an individual who has obtained an abortion. Because a court order is enforceable in a court of law, the Privacy Rule would permit but not require the clinic to disclose the requested PHI. The clinic may disclose only the PHI expressly authorized by the court order.

Disclosures to Avert a Serious Threat to Health or Safety

The Privacy Rule permits but does not require a covered entity, consistent with applicable law and standards of ethical conduct, to disclose PHI if the covered entity, in good faith, believes the use or disclosure is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, and the disclosure is to a person or persons who are reasonably able to prevent or lessen the threat.

According to major professional societies, including the American Medical Association and American College of Obstetricians and Gynecologists, it would be inconsistent with professional standards of ethical conduct to make such a disclosure of PHI to law enforcement or others regarding an individual’s interest, intent, or prior experience with reproductive health care.

Example:

A pregnant individual in a state that bans abortion informs their health care provider that they intend to seek an abortion in another state where abortion is legal. The provider wants to report the statement to law enforcement to attempt to prevent the abortion from taking place. However, the Privacy Rule would not permit this disclosure of PHI to law enforcement under this permission for several reasons, including:

  • A statement indicating an individual’s intent to get a legal abortion, or any other care tied to pregnancy loss, ectopic pregnancy, or other complications related to or involving a pregnancy does not qualify as a “serious and imminent threat to the health or safety of a person or the public”. 
  • It generally would be inconsistent with professional ethical standards as it compromises the integrity of the patient–physician relationship and may increase the risk of harm to the individual.

Therefore, such a disclosure would be impermissible and constitute a breach of unsecured PHI requiring notification to HHS and the individual affected.

Consult with Legal Counsel & Malpractice Carrier
Due to the complexities of complying to the 2024 Final Rule, it is advised that regulated entities seek legal counsel and guidance regarding policies and procedures from your Risk Attorney through your malpractice insurance company.

About the Author, Joanne Byron

This article is sponsored by the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare compliance training organization.  Joanne serves as Board Chair for AIHC and oversees the Volunteer Education Committee.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking?  Part 2 of 2

Written by: A. Michi McClure, J.D., an AIHC member and Volunteer on the CEU Education Committee   

This article follows Part 1 on the topic of understanding potential HIPAA violations when releasing information.  Is it Right of Access or Information Blocking?  Both have penalties. If you haven’t yet, read Part 1. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

Right of Access Initiative 

An individuals’ right to access their Health Information is located at 45 CFR § 164.524 as part of the HIPAA rule. It provides individuals to exercise the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103.  The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.  On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS).

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are a continuation from the information provided in Part 1, demonstrating a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

To whom can the information be released?

In addition to the individual, the following individuals or entities may be allowed access to PHI under certain circumstances:

  1. Personal representatives: Individuals may designate a personal representative, such as a legal guardian, healthcare proxy, or other authorized person, to act on their behalf in obtaining access to their PHI.
  2. Parents and guardians: Parents or legal guardians may access the PHI of their minor children or children for whom they are legal guardians.
  3. Healthcare providers: Other healthcare providers may be granted access to an individual's PHI for the purpose of providing treatment or coordinating care.
  4. Business associates: Business associates that provide services to covered entities, such as billing or transcription services, may be allowed access to PHI to perform their services.

EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. Authorized parties may include:

  1. Other healthcare providers: Healthcare providers may be authorized to access an individual's EHI for the purpose of providing treatment or coordinating care.
  2. Health plans: Health plans may be authorized to access an individual's EHI for the purpose of administering benefits and coordinating care.
  3. Caregivers and family members: Caregivers and family members may be authorized to access an individual's EHI with the individual's consent or as authorized by law.
  4. Researchers: Researchers may be authorized to access de-identified EHI for research purposes, subject to certain privacy and security requirements.
  5. Public health authorities: Public health authorities may be authorized to access EHI for the purpose of monitoring and responding to public health threats.

May the request be denied?

A covered entity may deny a request for access to protected health information (PHI) under certain limited circumstances. The covered entity must provide a written denial and explanation of the denial to the individual, along with information on how to request a review of the denial. The limited circumstances under which a request for access may be denied include:

  1. Psychotherapy notes: Covered entities are not required to provide access to psychotherapy notes, which are notes recorded by a mental health professional documenting or analyzing the contents of a counseling session.
  2. Information compiled for legal proceedings: Covered entities may deny access to information that is created for the purpose of legal proceedings, such as attorney-client privileged communications.
  3. Information prohibited by law: Covered entities may deny access to PHI if providing access would be prohibited by another law.
  4. Information that may cause harm: Covered entities may deny access to PHI if they reasonably believe that providing access would endanger the life or physical safety of the individual or another person.

Under the information blocking rule, healthcare providers and other covered entities may only deny a request for access to EHI under certain limited circumstances. The exceptions under which a request for access may be denied include:

  1. Preventing harm: A healthcare provider may limit the access to EHI if they believe that providing access could reasonably result in harm to the individual or another person.
  2. Privacy: A healthcare provider may limit access to EHI if they reasonably believe that providing access would violate the privacy of another person.
  3. Security: A healthcare provider may limit access to EHI if they reasonably believe that providing access would pose a security risk to the EHI or to other systems that are part of the electronic health record ecosystem.
  4. Infeasibility: A healthcare provider may limit access to EHI if the request is not technically feasible or if providing access would require unreasonable effort or resources.

If access is denied, the healthcare provider must also provide information on how to file a complaint.

Fees allowed to be charged to the patient?

Yes, covered entities under HIPAA Privacy Rule may charge a reasonable, cost-based fee for providing individuals with access to their protected health information (PHI).

  • The fee may only include the cost of labor for copying the PHI, supplies for creating the paper or electronic copy, and postage if the individual has requested that the PHI be mailed to them.
  • The fee may not include the cost of searching for and retrieving the PHI or any other associated administrative costs.

Covered entities are required to inform individuals of the fee in advance.

  • The fee may not be a barrier to individuals accessing their PHI. Covered entities must also provide access to the PHI in the format requested by the individual if it is readily producible in that format.

It's important to note that there are some situations where fees cannot be charged, such as when an individual requests access to their PHI for the purposes of filing a complaint with the HHS or if the covered entity fails to provide the individual with access to their PHI in a timely manner. Some state laws may limit or prohibit the fees that can be charged for providing access to PHI.

No, under the information blocking rule, healthcare providers and other covered entities may not charge fees that are not reasonably necessary for accessing, exchanging, or using EHI.

  • This means that if an individual requests access to their EHI or for their EHI to be transmitted to another entity, covered entities are generally not allowed to charge fees that are higher than the cost of labor and resources required to fulfill the request.

Additionally, if a covered entity charges fees for any other services or products related to EHI, such as an EHR system, the fee must be reasonably related to the actual cost of providing the service or product. The covered entity must also provide a detailed explanation of the fees and how they were calculated and must make the fees publicly available.

It's important to note that there are some circumstances where a covered entity may be able to charge fees that are higher than the cost of labor and resources, such as when the request is complex or involves large amounts of EHI. However, these fees must be reasonable, and the covered entity must provide an itemized bill explaining the fees.

Please review Part 1 for more information. 

We also encourage consulting with your malpractice Risk Attorney.  Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs.  If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking? Part 1 of 2

Written by: A. Michi McClure, J.D. an AIHC member and Volunteer on the CEU Education Committee   

The right of access and information blocking are both related to the access and exchange of health information, but they are different in several key ways. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

 

Right of Access Initiative 

Individuals’ Right under HIPAA to Access their Health Information 45 CFR § 164.524

This initiative helps to empower individuals to take control of their own health information, allowing them to better manage their healthcare and make informed decisions about their health. By ensuring that individuals have access to their own health information, this initiative also helps to improve the quality and continuity of care, while also protecting the privacy and security of that information.

The right of access is a requirement under HIPAA that individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

ePHI is defined in HIPAA regulation as any protected health information (PHI) that is created, stored, transmitted, or received in any electronic format or media. The right of access also includes the right to request that their PHI be transmitted to another entity, such as another healthcare provider or a personal health record (PHR). Covered entities must provide individuals with timely access to their PHI and may only deny access under certain limited circumstances.

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103

Information blocking is a practice in which a healthcare provider, health plan, or other covered entity intentionally interferes with the access, exchange, or use of electronic health information. The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.

The ultimate goal of the Information Blocking Act is to promote greater collaboration and coordination among healthcare providers and other stakeholders, which can lead to improved quality of care, better patient outcomes, and more efficient use of healthcare resources. By breaking down barriers to the exchange of health information, this legislation aims to facilitate the development and implementation of innovative healthcare solutions that can improve the overall health of the population.

On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS). Prior to this date the definition of EHI was limited to the data elements represented in the United States Core Data for Interoperability (USCDI) v1.

Covered entities may not use information blocking practices to prevent or interfere with access, exchange, or use of EHI, except in certain limited circumstances.

Confused?

While both the right of access and information blocking are designed to promote the access and exchange of health information, the right of access focuses on individuals' access to their own PHI, while information blocking focuses on the sharing of EHI between covered entities.

Additionally, the right of access is a long-standing requirement under HIPAA, while information blocking is a more recent requirement under the 21st Century Cures Act.

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are provided as a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

Enforcement date:

The HIPAA Privacy Rule was first enforced in the United States on April 14, 2003. The Office for Civil Rights (OCR) began an enforcement initiative in 2019.

First enforced in the United States on September 1, 2023.

Goal:

To give individuals greater control over their own health information. This initiative:

  • Ensures individuals the right to access their own medical records and to receive copies of those records in a timely manner, without undue delay or cost.
  • Provides individuals the right to request access to their health information held by covered entities, such as healthcare providers, health plans, and healthcare clearinghouses.
    • These entities must provide individuals with their requested information in the format and manner requested by the individual if it is readily producible in that format. This information can include medical and billing records, as well as other health information such as test results and imaging reports.

The goal of the Information Blocking Act, also known as the 21st Century Cures Act, is:

  • To improve the interoperability of electronic health records (EHRs) and other health information technology (HIT) systems in the United States.
  • Aims to promote the secure and efficient sharing of health information among healthcare providers, patients, and other stakeholders in the healthcare system.
  • Prohibits healthcare providers, health IT developers, and health information exchanges from engaging in practices that prevent or discourage the access, exchange, or use of electronic health information. This includes actions such as charging excessive fees for access to health information, creating technical barriers to the sharing of health information, and imposing unreasonable delays on the release of health information.

When must records be provided:

Covered entities, such as healthcare providers and health plans, are generally required to provide patients with access to their protected health information (PHI) upon request, unless an exception applies.

Specifically, a covered entity must provide access to PHI within 30 days of receiving a request from the individual, unless the covered entity provides a written explanation of the delay and the reason for the delay and extends the time-period by an additional 30 days.

Under the information blocking rule, EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. These circumstances are listed below in the following chart.

It's important to note that a healthcare provider must provide a clear explanation for any limitations on access to EHI and must make a good faith effort to provide access to as much EHI as possible.

Healthcare providers are also required to make available any information blocking policies or procedures that they have in place, and to provide patients with information on how to file a complaint if they believe that their access to EHI has been improperly limited or blocked.

What information is subject to?

Under HIPAA, individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. PHI is broadly defined as any information, including demographic information, that:

  1. Relates to the individual's past, present, or future physical or mental health or condition;
  2. Relates to the provision of healthcare to the individual; or
  3. Identifies the individual or could reasonably be used to identify the individual.

Some examples of PHI that are subject to the right of access include:

  • Medical and clinical records, including diagnoses, test results, and treatment plans;
  • Billing and insurance information;
  • Prescription and medication records;
  • Immunization records;
  • Lab reports;
  • Radiology images;
  • Health insurance enrollment and coverage information; and
  • Personal demographic information, such as name, address, and social security number, if it is included in the individual's health record.

Under the information blocking rule, electronic health information (EHI) is subject to the right of access and exchange. EHI is defined as:

  • Electronic protected health information (ePHI) that is created, stored, transmitted, or received by a covered entity or business associate that is subject to HIPAA.

Some examples of EHI that are subject to the information blocking rule include:

  1. Clinical notes, including progress notes and operative notes;
  2. Diagnostic imaging, including X-rays, MRIs, and CT scans;
  3. Laboratory test results;
  4. Pathology reports;
  5. Medication lists and prescription histories;
  6. Immunization records;
  7. Vital signs and other clinical measurements;
  8. Patient demographic information, such as name, address, and social security number, if it is included in the EHI.

Penalties?

YES

The right of access initiative is enforced by the Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS). OCR can investigate complaints of noncompliance and may take enforcement actions against covered entities that violate the right of access requirements.

  • If OCR determines that a covered entity has violated the right of access requirements, the covered entity may be subject to civil monetary penalties, which can range from $100 to $50,000 per violation, depending on the severity of the violation.
  • The maximum annual penalty for all violations of an identical requirement or prohibition is $1.5 million.

In addition to civil monetary penalties, OCR may require the covered entity to develop a corrective action plan and to monitor the covered entity's compliance.

It's important to note that individuals also have the right to file a complaint with OCR if they believe that a covered entity has violated their right of access. OCR may investigate complaints and take enforcement actions as appropriate.

YES

There are penalties for violating the information blocking rule which is enforced by the Office of the National Coordinator for Health Information Technology (ONC) and the Department of Health and Human Services (HHS). Covered entities that engage in information blocking practices may be subject to enforcement actions, which can include:

  1. Civil monetary penalties: The HHS may impose civil monetary penalties of up to $1 million per violation for each instance of information blocking.
  2. The maximum annual penalty for all violations of an identical requirement or prohibition is $5 million.
  3. Disincentives for health information exchange: The HHS may also take steps to limit or restrict a covered entity's participation in certain health information exchange programs or to exclude the entity from certain government healthcare programs.
  4. Publication of violators: The ONC may publish the names of covered entities that have engaged in information blocking practices, which can harm the entity's reputation and public image.

In Summary 


It is important to respect patient access to information while protecting confidential information. This can be a daunting task for any size organization. After reviewing the information above and you still have questions, consider additional training in HIPAA and release of information.

Additional and important aspects of this topic not covered in this article is information excluded from both Right of Access and Information Blocking rules, when the request may be denied, to whom the information can be released and allowable (and unallowable) fees a patient can be charged. These topics will be covered in Part 2.

We also encourage consulting with your malpractice Risk Attorney. Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs. If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.



What Is HIPAA Right of Access?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.


HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.


HIPAA Enforcement


HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.


In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.


Complying With the HIPAA Privacy Right of Access Rule


If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.


A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html


The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:


“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?


This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.


If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.


o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.

  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.


Resources to Comply With ROI and Right of Access


Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:


Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More