The HIPAA right of access, set out at 45 CFR 164.524, gives patients the right to inspect and obtain a copy of their protected health information held in a covered entity's designated record set, generally within 30 days of the request, for a fee limited to the entity's reasonable cost of fulfilling it. This right is one of the most actively enforced provisions in HIPAA, and it applies regardless of the format the records are kept in, paper or electronic.
What Patients Can Request
Under 45 CFR 164.524, a patient can request access to PHI maintained in a designated record set, which includes medical records, billing records, and other records used by or for the covered entity to make decisions about the individual. This covers most of what a typical patient thinks of as "my chart," including clinical notes, lab results, imaging reports, and billing history, with limited exceptions such as psychotherapy notes kept separately from the rest of the record, and information compiled for use in a civil, criminal, or administrative proceeding.
Patients can also direct that a copy of their records be sent to a third party of their choosing, such as another provider, in the same request. The covered entity must act on that direction within the same timeline. The fee limitation, however, no longer applies as broadly. In Ciox Health, LLC v. Azar (D.D.C. 2020), a federal court vacated the portion of the 2013 rule that extended the third party directive beyond electronic copies of PHI held in an electronic health record, and vacated the 2016 extension of the patient rate to third party directives. The cost-based fee limit at 45 CFR 164.524(c)(4) therefore applies to requests where the individual receives the copy, and to third party directives only for electronic copies of PHI maintained in an electronic health record.
The 30 Day Rule and Its Extension
A covered entity must act on an access request no later than 30 calendar days after receiving it. If the entity cannot meet that deadline, it is permitted a single 30 day extension, but only if it provides the individual with a written statement of the reasons for the delay and the date by which it will complete the request, within the original 30 day period. That means the maximum total time is 60 days, and only when the extension notice is issued on time. There is no provision for a second extension.
OCR has proposed shortening this window to 15 calendar days with one 15 day extension, in a notice of proposed rulemaking first announced in December 2020. That proposal has not been finalized, so the 30 day standard with one 30 day extension remains the operative requirement; confirm the current rule before relying on it. For records maintained off-site or requiring retrieval from an outside storage vendor, the timeline still runs from the date the request is received, not from when retrieval is complete. Covered entities need workflows that account for this rather than treating off-site storage as an automatic excuse for delay.
The Fee Limitation
HIPAA does not prohibit covered entities from charging for copies of records, but it limits what they can charge to a "reasonable, cost-based fee." That fee can include only the labor for copying, supplies for creating the copy, and postage if the patient requested mailing, plus the cost of preparing an explanation or summary if the patient agreed to that in advance. Covered entities cannot charge for the time spent searching for or retrieving the record, and, per OCR guidance, would not expect to incur or pass on copying labor costs when an individual accesses electronic PHI through a patient portal's view, download, and transmit functionality, because no copying labor is involved.
OCR guidance allows entities to use a calculated actual cost method, an average cost method, or a flat fee not to exceed $6.50 for requests for electronic copies of PHI maintained electronically, without calculating actual costs each time. OCR has since clarified that the $6.50 figure is an optional flat rate for that one method, not a cap on all permissible fees and not a default charge for every request.
Right of Access Requirements Summary
| Requirement | Standard |
|---|---|
| Response deadline | 30 calendar days from receipt of the request |
| Extension | One 30 day extension permitted, with written notice of reason and new date issued within the original 30 days |
| Format | Must be provided in the format requested by the individual if readily producible, including electronic form |
| Fee | Limited to a reasonable, cost-based fee for labor, supplies, and postage; no charge for search or retrieval time |
| Denial | Must be in writing, with the basis for denial and, where applicable, the patient's right to have the denial reviewed |
OCR's Right of Access Initiative
The HHS Office for Civil Rights has treated the right of access as an enforcement priority through its Right of Access Initiative, which focuses specifically on covered entities that fail to provide patients timely access to their own records at a permissible fee. The pattern OCR has described in its public guidance and resolution agreements centers on entities that either ignored access requests entirely, took significantly longer than the 30 or 60 day limits, or charged fees beyond what the cost-based fee limitation allows. OCR has announced a large number of resolution agreements under this initiative relative to other individual HIPAA provisions, reflecting how frequently covered entities mishandle this specific requirement. Organizations should treat access request handling as a defined, tracked workflow rather than an ad hoc task, given how consistently OCR has pursued this issue.
Denials and the Right to Have Them Reviewed
Not every denial of an access request has to be treated the same way. HIPAA distinguishes between denials that are not subject to any review and denials that must offer the patient a path to appeal. Denials without a review right include situations such as PHI created or obtained during research that includes treatment, where access is temporarily suspended for the duration of the research with the patient's agreement, and PHI held by certain correctional institutions about inmates. Reviewable denials include cases where a licensed health care professional has determined, in the exercise of professional judgment, that access is reasonably likely to endanger the life or physical safety of the individual or another person.
When a denial is reviewable, the covered entity must provide the individual with the right to have a licensed health care professional, who was not directly involved in the original denial decision, review that determination. The reviewing professional's decision is binding, and the covered entity must provide or deny access consistent with that outcome. This review process is separate from filing a complaint with OCR, and patients can generally pursue both if they believe an improper denial has occurred.
Right of Access Versus Accounting of Disclosures
Patients sometimes conflate the right of access under 164.524 with a separate right, the accounting of disclosures under 45 CFR 164.528. The right of access is about obtaining a copy of the record itself. The accounting of disclosures is about obtaining a list of certain disclosures the covered entity has made of the patient's PHI to outside parties, such as for public health reporting, over a specified look-back period. The two rights have different scopes, different exceptions, and in the case of accounting requests, no fee limitation in the same form as access requests. Practices handling patient requests should be able to distinguish which right a patient is actually invoking, since the response process differs for each.
How This Applies to Digital and Text-Based Record Requests
Patients increasingly expect to request and receive records through digital channels, including patient portals and, in some workflows, secure forms sent by text. When a practice uses text messaging to direct patients toward a records request form or portal link, the underlying access rules under 164.524 still govern the response, regardless of the channel used to initiate the request. Guidance on building compliant intake forms accessible by text is covered in HIPAA compliant forms by text.
The broader question of whether texting itself is an appropriate channel for PHI, separate from the access request process, is addressed in is texting HIPAA compliant. Practices building out patient communication workflows that touch on record requests should review both the access timeline requirements here and the channel-level safeguards described there; see healthcare texting solutions for how a compliant messaging setup supports both.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
How long does a provider have to respond to a records request?
Under 45 CFR 164.524, a covered entity must act on a request within 30 calendar days of receiving it. If more time is needed, the entity can take one additional 30 day extension, but only if it notifies the patient in writing, within the original 30 days, of the reason for the delay and the new expected completion date.
Can a doctor charge for medical records?
Yes, but the fee is limited to a reasonable, cost-based amount covering labor for copying, supplies, and postage if mailed. Providers cannot charge for the time spent searching for or retrieving the record, and cannot charge at all for electronic copies delivered through a patient portal or similar no-cost electronic method.
What records can a patient request under HIPAA?
Patients can request PHI in the designated record set, which generally includes medical records, treatment notes, lab and imaging results, and billing records used to make decisions about their care. Psychotherapy notes kept separately from the rest of the record and information compiled for legal proceedings are excluded.
Can a patient have records sent directly to another provider?
Yes. Under 45 CFR 164.524, a patient can direct that their records be sent to a third party, such as another treating provider, and the same 30 day timeline applies. The fee limitation is narrower after Ciox Health, LLC v. Azar (D.D.C. 2020), which vacated the extension of the patient rate to third party directives except for electronic copies of PHI held in an electronic health record.
What is OCR's Right of Access Initiative?
It is an enforcement priority area within the HHS Office for Civil Rights focused on covered entities that fail to provide patients timely access to their own PHI at a permissible fee, as required under 45 CFR 164.524. It reflects that access failures are among the most commonly enforced HIPAA violations.
Can a provider deny a patient's request for their records?
In limited circumstances. Some denials are not subject to review, such as those involving psychotherapy notes. Other denials must be reviewable, meaning the patient can request that a licensed health professional not involved in the original decision review it. Any denial must be provided in writing with the basis stated.
Does the 30 day rule apply to electronic health records?
Yes. The 30 day deadline, and the possible single 30 day extension, apply regardless of whether records are paper or electronic. For electronic health information, patients also have the right to request the format they prefer, such as a downloadable file, if the covered entity can readily produce it in that form.
What should a patient do if a provider ignores their records request?
A patient can file a complaint with the HHS Office for Civil Rights, which investigates right of access complaints as part of its enforcement priorities. Complaints can be filed directly with OCR and do not require going through the provider first, though contacting the provider's privacy officer is often a faster first step.
Support timely, compliant patient access
Meeting the 30 day rule depends on tracking requests and getting patients accurate information fast. FRANSiS supports compliance for healthcare texting, with a signed BAA included for covered entities and business associates. Contact us to discuss how text-based workflows can help route and confirm access requests.


