
Designated Record Set Under HIPAA: What Healthcare Teams Need
TL;DR - HIPAA Designated Record Set
The designated record set is broader than the EHR and may include medical, billing, health-plan, and individual decision-making records.
An individual's HIPAA right of access generally extends to protected health information in designated record sets maintained by covered entities or business associates.
Provider records, payer records, and other decision records may sit across multiple systems, vendors, and formats.
Separately maintained psychotherapy notes and information prepared for legal proceedings are common exclusions.
A documented inventory helps teams identify record sources, owners, retrieval methods, exclusions, and escalation paths.
Strong governance improves request accuracy, turnaround visibility, quality review, and audit documentation.
A designated record set determines which protected health information an individual can generally inspect or obtain under the HIPAA Privacy Rule. The term sounds technical, but it affects everyday release of information decisions across hospitals, medical groups, health plans, and business associates.
The designated record set is broader than a single electronic health record. It may include medical records, billing records, health plan records, and other information used to make decisions about an individual. If healthcare teams define it too narrowly, they may overlook records that belong in a patient access response. If they define it too broadly, they may create unnecessary review work and inconsistent disclosures.
This guide explains the designated record set definition, examples of records that belong in it, common exclusions, and practical steps for governing the information across healthcare systems.
Need support with accurate, secure healthcare workflows? Explore AMI's healthcare services.
What Is a Designated Record Set Under HIPAA?
Under HIPAA, a designated record set is a group of records maintained by or for a covered entity that includes medical and billing records about individuals, certain health plan records, and other records used in whole or in part to make decisions about individuals. The official HHS designated record set guidance makes clear that the definition follows how information is used, not only where it is stored.
A record can qualify whether it is electronic, paper-based, scanned, archived, or maintained by a business associate. The important questions are whether the record is maintained by or for the covered entity and whether it falls within one of the defined record groups.
This makes the HIPAA designated record set an operational concept as much as a legal definition. Healthcare organizations need a repeatable way to identify systems, document types, data owners, and external partners that maintain information within scope.
What Records Are Included in a HIPAA Designated Record Set?
The exact contents vary by organization, but the designated record set generally includes three major groups of information.
1. Provider medical and billing records
For healthcare providers, the designated record set includes medical records and billing records about individuals. Examples may include histories and physicals, clinical notes, test results, imaging reports, medication information, treatment plans, discharge summaries, itemized bills, payment histories, and claim-related documentation.
The term is not limited to the legal health record or the primary EHR view. Relevant information may sit in specialty applications, billing platforms, document management systems, scanned files, or legacy repositories.
2. Health plan enrollment, payment, claims, and case-management records
For health plans, the designated record set includes enrollment, payment, claims-adjudication, and case-management record systems. These records may contain eligibility details, coverage decisions, claim histories, payment information, utilization activity, and case-management documentation.
Because payer information is distributed across operational platforms, teams should map the complete record lifecycle instead of relying on one application as the sole source.
3. Other records used to make decisions about individuals
A record may also belong in the designated record set when the organization uses it, in whole or in part, to make decisions about an individual. This functional test can bring additional operational records into scope even when they are not traditionally labeled medical or billing records.
Examples may include records supporting coverage decisions, care-management determinations, benefit decisions, or other individual-level actions. Organizations should evaluate actual use rather than depending only on document names.

How Does a Designated Record Set Affect the HIPAA Right of Access?
The designated record set defines much of the information available through an individual's HIPAA right of access. HHS explains that individuals generally have a right to inspect or obtain copies of protected health information in designated record sets maintained by a covered entity or its business associates, subject to limited exceptions. The HHS right of access guidance also explains the timing, form, and manner requirements that support access.
The current federal response period is generally 30 calendar days after receiving the request. One additional 30-day extension may be available when the organization provides a timely written explanation and expected completion date.
This is why designated record set governance directly affects PHI access requests. Teams must know which systems to search, who owns the records, how to retrieve them, and how to document completion. For a broader access overview, read What Is the Standard for Accessing Patient Information?
What Is Not Included in a Designated Record Set?
Two commonly cited exclusions are psychotherapy notes maintained separately from the medical record and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding.
The psychotherapy-note exclusion is narrow. It does not automatically exclude medication information, session start and stop times, treatment frequency, clinical test results, diagnosis summaries, treatment plans, symptoms, prognosis, or progress information that forms part of the medical record.
Organizations should also distinguish business records from information used to make decisions about individuals. Quality-assessment documents, peer-review materials, and operational reports do not automatically enter the designated record set simply because they mention a patient. However, the underlying protected health information used to make an individual decision may still be within scope.
For more context on permitted access, requester authority, and sensitive record handling, see PHI Records Explained: Who Can Access Medical Records and When?
How Should Healthcare Organizations Identify Their Designated Record Sets?
Healthcare organizations should use a documented inventory process rather than making scope decisions only after an access request arrives.
- Identify all systems that maintain medical, billing, enrollment, payment, claims-adjudication, and case-management records.
- List records used in whole or in part to make decisions about individuals.
- Map the covered entity, department, system owner, and business associate responsible for each record source.
- Document record formats, retention locations, retrieval methods, and known exclusions.
- Validate the inventory with privacy, legal, HIM, compliance, clinical, billing, payer, and IT stakeholders.
- Review the inventory after system migrations, acquisitions, vendor changes, and workflow redesigns.
The inventory should guide request intake, search instructions, escalation, quality review, and response tracking. It should not remain a policy document that operational teams cannot use.
Need stronger request intake, retrieval, review, and delivery controls? Explore AMI's Release of Information Support.
How Can Designated Record Set Governance Improve ROI Operations?
Clear governance reduces uncertainty during release of information workflows. When teams know which records fall within scope, they can route requests correctly, search the right systems, coordinate with business associates, and apply consistent quality checks.
A reliable workflow should connect the designated record set inventory to requester verification, request scope, record retrieval, exception review, secure delivery, and audit documentation. It should also show which requests are aging, which systems are causing delays, and which exceptions require privacy or legal review.
This structure is especially important when records are distributed across facilities, platforms, vendors, and acquired organizations. Learn how those dependencies affect fulfillment in Release of Information Process: From Request to Secure Delivery.
What Problems Can Weak Designated Record Set Controls Create?
An incomplete inventory can cause staff to miss billing information, archived files, specialty-system records, or documents maintained by a business associate. An overly broad inventory can create unnecessary searches, larger review volumes, and inconsistent responses.
Other common problems include unclear ownership, duplicate searches, manual follow-ups, inconsistent exclusion decisions, limited request status visibility, and weak audit documentation. These issues make it harder to meet access timelines and explain how a response was assembled.
Regular audits can reveal where the workflow breaks down. Useful measures include response time, requests requiring extensions, retrieval defects, missing-source incidents, business-associate turnaround, rework rates, and unresolved exceptions. Additional operational risks are covered in 7 ROI Medical Records Pain Points Healthcare Leaders Must Fix.
How Does AM Infoweb Support Designated Record Set and ROI Workflows?
AM Infoweb supports healthcare organizations with co-managed Release of Information operations designed around accuracy, secure handling, quality control, turnaround discipline, and request-level visibility.
AMI can support:
- Structured request intake and indexing
- Requester and patient verification
- Record-source identification and retrieval coordination
- Business-associate follow-up
- PHI-aware preparation and quality review
- Exception and escalation workflows
- Secure delivery support
- Turnaround, backlog, and quality reporting
- Audit-trail documentation
The objective is to strengthen execution while the healthcare organization retains policy authority, compliance oversight, and visibility into request outcomes.
What Should Healthcare Leaders Do Next?
A designated record set should not be treated as a static definition stored in a policy manual. It should be translated into a usable inventory that connects record sources, owners, business associates, retrieval instructions, exclusions, and quality controls.
Healthcare leaders should confirm that the inventory reflects current systems and actual decision-making practices. They should also test whether staff can use it to fulfill access requests consistently within required timelines.
Clear scope, disciplined workflows, and visible accountability help organizations support patient access while reducing avoidable rework and uncertainty across ROI operations.
Need clearer control over designated record set and ROI requests? AMI combines trained teams, secure workflows, QA, and request-level visibility to support accurate, timely record fulfillment.
Get in TouchFrequently Asked Questions
About the Author

Written by
Urza Dey
Urza Dey is a content and copywriter with over five years of experience across marketing, B2B SaaS, HealthTech, EdTech, and related industries. At AMI, they contribute to content strategy, blog development, and marketing communication focused on healthcare operations, business process management, and AI-enabled service delivery.


