Release of Information
HIPAA, Release of Information

Right of Access Compliance

A Contemporary Risk Management and Regulatory Imperative 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The HIPAA Right of Access (ROA) provision continues to stand as a vital patient-rights protection and a persistent enforcement focus for OCR. Since 2022, the OCR has escalated enforcement activity—issuing multiple monetary settlements ranging from small practices to large organizations, including significant penalties such as $200,000 against Oregon Health & Science University (OHSU) in 2025. This article updates the scholarly discussion with recent data, reviews enforcement activity, and underscores strategic imperatives for compliance through inclusive workforce education, robust policy frameworks, centralized oversight, and ongoing auditing.

Introduction

Since its introduction, HIPAA’s Right of Access—which empowers patients to access their protected health information (PHI)—has been elevated by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as a leading enforcement priority. OCR’s Right of Access Initiative, instituted in 2019, has remained dynamically active, with continued resolution of complaints and repeated emphasis across enforcement years 2022 through 2025.

Regulatory Framework of the Right of Access

Under HIPAA, individuals are entitled to access their PHI in “designated record sets” (45 C.F.R. § 164.524). Covered entities must provide this access within 30 days of receiving a request, with a single 30-day extension permitted if documented and communicated to the patient.

Key requirements include:

  • Timeliness: Records must be provided within the prescribed timeframes.
  • Reasonable fees: Covered entities may charge only cost-based fees for labor, supplies, and postage.
  • Format: Information must be provided in the form and format requested, if readily producible.
  • Exceptions: Access may be denied under limited circumstances, such as if disclosure is reasonably likely to endanger life or safety.

Failure to meet these requirements can result in HIPAA violations, OCR investigations, and reputational harm.

Recent Enforcement Activity (2022–2025)

OCR’s enforcement record demonstrates an ongoing pattern of provider noncompliance with the Right of Access. Key examples include:

2022:
- Multiple ROA settlements involving dental practices, including one finalized in December 2022.
- Memorial Hermann Health System settled for $240,000 over delayed access requests.

2023:
- OCR resolved 13 enforcement actions totaling $4.18 million, nearly doubling 2022’s penalties.
- Life Hope Labs was fined $16,500 for delayed records release.

2024:
- OCR imposed $170,000 in penalties against a dental practice and a Los Angeles County mental health program.

2025:
- Oregon Health & Science University (OHSU) was fined $200,000 for failing to provide timely access to a patient’s representative.
- OCR also continued settlements tied to ransomware incidents, such as the Comstar breach affecting over 585,000 individuals.

Enforcement Trend Analysis

Recent enforcement illustrates key trends:

  • Widespread focus: ROA cases involve providers of all sizes and types.
  • Significant financial liability: Penalties range from modest fines to $200,000+.
  • Business associate accountability: Covered entities are liable for their partners’ noncompliance.
  • Cybersecurity overlap: Breaches and ransomware are increasingly tied to ROA violations.

Compliance Challenges in Healthcare Organizations

Despite regulatory clarity, many organizations continue to struggle with operationalizing the Right of Access. Common barriers include:

  • Lack of workforce training: Staff may be unaware of timelines, fee structures, or documentation requirements.
  • Decentralized recordkeeping: PHI may be stored across multiple EHR platforms, making access requests cumbersome.
  • Inconsistent policies: Outdated or incomplete policies may lead to variable practices across departments.
  • Cultural barriers: Some providers remain reluctant to share full records, particularly behavioral health information, despite HIPAA requirements.

These challenges highlight the need for strong compliance frameworks that integrate policy, training, and oversight.

Risk Mitigation Through Compliance Programs

Right of Access compliance should be viewed not only as a legal requirement but as a risk management strategy. By embedding compliance into organizational culture, healthcare leaders can reduce the likelihood of OCR investigations and enhance patient satisfaction.

Effective strategies include:

1.  Policy development  

     Create and regularly update written policies aligned with HIPAA and state privacy rules.

2.  Workforce training  

     Ensure all staff—front desk, nursing, HIM, billing, IT—understand their responsibilities.

3.  Monitoring and auditing  

     Conduct regular internal audits of access requests, timeliness, and fees.

4.  Centralized oversight  

     Designate a privacy officer or compliance team to oversee all Right of Access processes.

5.  Patient engagement  

     Communicate clearly with patients regarding their rights, timelines, and any applicable fees.

6.  Cybersecurity integration  

     Align ROA procedures with breach and ransomware response protocols.

Conclusion

The HIPAA Right of Access reflects a core principle of modern healthcare: empowering patients with information to participate in their care. Recent enforcement actions from 2022–2025 highlight the continued priority OCR places on this right, with penalties applied to providers of all sizes.

Healthcare leaders must proactively address this risk by developing robust policies, ensuring comprehensive workforce training, monitoring compliance, and integrating cybersecurity protections. In doing so, organizations protect themselves from regulatory enforcement while upholding the trust and dignity of the patients they serve.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Burnout, Boundaries, and Compliance
Leadership

Burnout, Boundaries, and Compliance

Why Staff Wellness Is a Risk Management Issue 

Written By Dr. Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

This article, grounded in findings from the recent AIHC webinar presentation 'Burnout, Boundaries, and Compliance: Why Staff Wellness Is a Risk Management Issue,' explores how staff wellness programs can be embedded into organizational quality plans and compliance frameworks to proactively address workforce fatigue and prevent downstream risks.

In today’s healthcare environment, the intersection of staff wellness, regulatory compliance, and organizational quality has become impossible to ignore. As staff burnout reaches unprecedented levels, it is increasingly clear that wellness is not just a human resources concern, but a compliance and risk management imperative.

Understanding the Compliance Implications of Burnout

Burnout, defined by the World Health Organization as a syndrome resulting from chronic workplace stress that has not been successfully managed, presents real compliance risks. These risks include errors in clinical documentation, lapses in ethical judgment, and regulatory breaches. Healthcare organizations must recognize that failing to address burnout contributes to higher turnover, lower morale, increased patient safety incidents, and diminished organizational performance. These outcomes directly impact quality metrics and compliance reporting.

Embedding Staff Wellness into Quality Initiatives

A critical finding from Dr. Atkins presentation coupled with additional research identified the value of early detection—integrating wellness strategies at the onset of program design. Staff wellness plans must be embedded as part of quality improvement frameworks, not as optional extras. Organizations that build wellness into policy, practice, and compliance audits are more likely to see measurable improvements in documentation accuracy, patient satisfaction, and employee retention. Proactive wellness programs signal to staff that their well-being is prioritized and monitored, just like infection control or safety metrics.

Early Detection Is Essential

Early detection refers to the strategic implementation of burnout prevention strategies during the formative stages of a healthcare program or system process. Rather than responding to burnout reactively, early detection builds organizational resilience by identifying risk factors—such as understaffing, inadequate training, or high patient acuity—before they lead to harm. Embedding wellness at this early stage empowers staff and creates a feedback loop where staff input shapes policies, reducing the burden of moral distress and compassion fatigue.

Building a Compliance Culture That Prioritizes Wellness

Healthcare compliance leaders are in a unique position to advocate for systemic change. A culture of compliance that integrates wellness must address:

  1. clear policies on mental health support,
  2. confidential self-reporting pathways for burnout,
  3. regular staff wellness assessments, and
  4. accountability structures that enforce reasonable workloads and boundaries.

Wellness champions and wellness subcommittees can play a pivotal role in fostering peer support and resilience among teams.

Practical Steps for Implementation

To effectively embed wellness into compliance strategy, healthcare organizations should:

  • Incorporate staff wellness indicators into internal audits
  • Require burnout screening as part of risk assessments
  • Develop cross-functional wellness committees
  • Use anonymous staff feedback to refine wellness interventions
  • Align wellness initiatives with accreditation and CMS quality metrics

Conclusion

Burnout is a multifaceted risk that affects every level of a healthcare organization. By embedding wellness into compliance and quality frameworks from the start, organizations can create safer, more effective systems of care. Early detection, policy integration, and leadership advocacy are essential for ensuring that wellness is viewed not just as a benefit, but as a compliance requirement. The time for healthcare systems to act is now—staff wellness must be recognized as a foundational element of quality and risk management strategy.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • Agency for Healthcare Research and Quality. (2022). Patient Safety Primer: Burnout and Resilience. Retrieved from https://psnet.ahrq.gov
  • National Academy of Medicine. (2019). Taking Action Against Clinician Burnout: A Systems Approach to Professional Well-Being. The National Academies Press.
  • Shanafelt, T. D., & Noseworthy, J. H. (2017). Executive leadership and physician well-being: Nine organizational strategies to promote engagement and reduce burnout. Mayo Clinic Proceedings, 92(1), 129-146.
  • World Health Organization. (2019). Burn-out an “occupational phenomenon”: International Classification of Diseases. Retrieved from https://www.who.int

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Celebrating the Healthcare Compliance Officer

Celebrating the Healthcare Compliance Officer   

The American Institute of Healthcare Compliance is recognizing healthcare Compliance Officers – hats off to you!    

The primary goal of a compliance officer is to mitigate risk.  Compliance officers must keep up with new and evolving regulations to ensure their organization is compliant.  This involves investigating complaints and conducting internal auditing and monitoring for compliance. Larger health organizations have compliance teams and utilize internal auditors to delegate the auditing and monitoring functions within the organization.  Compliance is a complex and difficult job!

Healthcare compliance began as a response to concerns about the quality of healthcare provided by medical practitioners. The compliance profession itself emerged in the 20th Century and has progressed to become a critical part of a healthcare organization’s infrastructure. 

Since then, compliance officers have become indispensable to the successful and safe running of a business. Compliance officers are responsible for ensuring that companies and businesses obey regulations and requirements imposed on them. The field has since diversified to fit all kinds of firms and businesses. Compliance officers are expected to have high ethical standards, to be reliable, honest, and effective to promote not only a culture of compliance, but to ensure quality of care and patient safety.

The Office of Inspector General (OIG) began publishing Compliance Program Guidances (CPGs) in the late 1990s.  These guides were to be used as voluntary, nonbinding documents to support health care industry stakeholders with the intent that they be used for self-monitoring purposes.  Access has been available on the Internet at www.oig.hhs.gov to the public. These include CPGs directed at:

  1. hospitals;
  2. home health agencies;
  3. clinical laboratories;
  4. third-party medical billing companies;
  5. the durable medical equipment, prosthetics, orthotics, and supply industry;
  6. hospices;
  7. Medicare Advantage (formerly known as Medicare+Choice) organizations;
  8. nursing facilities;
  9. physicians;
  10. ambulance suppliers; and
  11. pharmaceutical manufacturers.

More recently, on November 6, 2023, the OIG has published a general compliance program guidance (GCPG) with promise to publish industry-sector specific guidances in the near future.  On February 21, 2024 the OIG stated that the first two industry segment-specific CPGs (ICPGs) will address Medicare Advantage and nursing facilities. OIG intends to publish these guidance documents in 2024, but as of September 2024, we are still waiting for more ICPG information. According to an OIG statement on their website, for the next two ICPGs, OIG anticipates addressing hospitals and clinical laboratories.

About the GCPG vs ICPGs

The General Compliance Program Guidance (GCPG) is a reference guide for the health care compliance community and other health care stakeholders. The GCPG provides information about relevant Federal laws, compliance program infrastructure, OIG resources, and other information useful to understanding health care compliance. This voluntary guide is a document to be updated over time by the OIG.

The GCPG covers the following topics:

  • Health Care Fraud Enforcement and Other Standards: Overview of Certain Federal Laws
  • Compliance Program Infrastructure: The Seven Elements
    • Written Policies and Procedures
    • Compliance Policies and Procedures
    • Compliance Leadership and Oversight
      • Board Compliance Oversight
    • Effective Lines of Communication with the Compliance Officer and Disclosure Programs
    • Enforcing Standards: Consequences and Incentives
    • Risk Assessment, Auditing, and Monitoring
    • Responding to Detected Offenses and Developing Corrective Action Initiatives
  • Compliance Program Adaptations for Small and Large Entities
  • Other Compliance Considerations
  • OIG Resources and Processes

The ICPGs will address the following:

  • Standards for different types of providers, suppliers and other participants in the health care industry subsector or ancillary industry sectors
  • These guidances will be tailored to fraud and abuse risk areas for each industry subsector
  • Outlines compliance measures that participants are expected to take to reduce risk

Free Compliance Resources Offered by AIHC

This Article is Written by the AIHC Education Department.  AIHC offers online training w/certification in the field of Corporate Compliance, Internal Forensic Auditing on How to Conduct Internal Investigations and Auditing for Compliance for those requiring more than on-the-job training.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More