
HIPAA Right of Access: Requirements, Timelines, Fees, and Exceptions
TL;DR: HIPAA Right of Access
HIPAA generally gives individuals access to protected health information in designated record sets.
Covered entities generally must act within 30 calendar days, with one documented 30-day extension when permitted.
Requested electronic formats should be provided when readily producible.
Fees must be reasonable, cost based, and limited to permitted labor, supplies, postage, and agreed summary preparation.
Only limited grounds support denial, and some denials require review rights.
Standardized intake, identity verification, tracking, QA, and escalation improve compliant fulfillment.
The HIPAA right of access generally allows individuals to inspect or obtain copies of protected health information about themselves in designated record sets maintained by covered healthcare providers and health plans. The right applies to much more than information displayed in a patient portal.
Healthcare organizations need a reliable process for receiving requests, verifying identity or authority, locating responsive information, applying limited exclusions, producing records in an appropriate format, calculating permitted fees, and documenting completion.
This guide explains the federal requirements at a practical level. It is general educational information and not legal advice. Organizations should evaluate applicable federal and state requirements with qualified counsel.
Need structured support across healthcare information workflows? Explore AMI's healthcare services.
What Is the HIPAA Right of Access?
Under the HIPAA Privacy Rule, individuals generally have a broad right to inspect and obtain copies of protected health information about themselves in one or more designated record sets. The right applies whether information is stored electronically, on paper, onsite, offsite, or in an archive.
HHS explains the requirements in its official HIPAA right of access guidance. Covered entities should treat the federal timeframe as an outer limit and respond sooner when information is readily available.
The right belongs to the individual or an authorized personal representative. A request is different from a routine treatment, payment, or healthcare-operations disclosure and may require different documentation and fee handling.
What Information Is Included in a Designated Record Set?
A designated record set generally includes medical and billing records maintained by or for a healthcare provider, enrollment, payment, claims, and case-management records maintained by or for a health plan, and other records used to make decisions about individuals.
The scope can include clinical notes, laboratory reports, imaging reports, billing information, claims data, insurance information, and other decision-making records. It is not limited to the legal medical record or information in the EHR.
Organizations should maintain a documented inventory of systems, repositories, departments, vendors, and business associates that hold designated-record-set information. See the related guide to the designated record set under HIPAA.
Who Can Submit a HIPAA Access Request?
An individual may request access directly. A personal representative may also exercise the right when authorized under applicable law. Depending on the circumstances, this may include a parent, guardian, healthcare power of attorney, executor, administrator, or another person with legal authority.
Covered entities may verify identity and authority, but verification measures should be reasonable and should not create unnecessary barriers. Requirements that make access difficult without a legitimate need can undermine compliance.
Requests directing records to another person should clearly identify the designated recipient and where the information should be sent. Organizations should distinguish an individual access request from a HIPAA authorization or other disclosure pathway.
How Should Healthcare Organizations Receive Access Requests?
The Privacy Rule permits covered entities to require access requests in writing, provided they inform individuals of that requirement. Request forms should be clear, accessible, and limited to information needed to fulfill the request.
A practical intake process should capture:
- Requester identity and contact information
- Patient or member identifiers
- Description and date range of requested information
- Requested form and format
- Delivery method and destination
- Personal-representative authority, when applicable
- Date received and responsible owner
Requests received through different channels should enter one tracking system. The regulatory clock should not restart because a request moves between departments or a business associate.
How Long Does a Covered Entity Have to Respond?
A covered entity generally must act on an access request no later than 30 calendar days after receipt. If it cannot act within that period, it may take one additional 30-day extension if it gives the individual written notice within the first 30 days explaining the reason for delay and the expected completion date.
Only one extension is permitted under the federal rule. The 30-day period is an outer limit, not a default production target. State law or another applicable requirement may require a faster response.
HHS enforcement continues to focus on timely access. A 2025 OCR settlement described a provider that failed to provide records within the required period and identified it as the agency's 54th Right of Access Initiative enforcement action. See the HHS right-of-access settlement announcement.

What Fees Can Be Charged for Records?
When an individual requests a copy, HIPAA permits only a reasonable, cost-based fee for specified activities. Permitted components may include labor for copying, supplies for creating the requested copy or electronic media, postage when mailing is requested, and preparation of an agreed summary or explanation.
The fee may not include costs for verification, searching, retrieving information, maintaining systems, or recouping infrastructure costs. Individuals should receive advance notice of an approximate fee when a charge may affect their choice of format or delivery.
If state law allows a higher fee, the HIPAA limitations still apply to an individual's HIPAA access request. A state law that requires a lower fee or prohibits a fee may also affect the amount charged.
Must Records Be Provided in the Requested Format?
If protected health information is maintained electronically and the individual requests an electronic copy, the covered entity must provide it in the requested electronic form and format when readily producible. If it is not readily producible, the parties should agree on another readable electronic format.
For paper or other records, access should be provided in the requested form and format when readily producible or in another format agreed with the requester. Organizations should not force portal delivery when the individual requests another available method.
Reasonable safeguards apply to transmission. HHS guidance also addresses situations in which an individual requests an unsecure delivery method after being warned of the risks.
When Can Access Be Denied?
The right of access has limited exceptions. Certain information is excluded from the right, including psychotherapy notes maintained separately from the medical record and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative proceeding.
Other denial grounds may be reviewable or non-reviewable depending on the rule. Reviewable denials can involve a licensed healthcare professional's determination that access is reasonably likely to endanger life or physical safety or cause substantial harm in specified circumstances.
A denial must be provided in writing and explain the basis, any available review right, and how the individual may complain to the covered entity or HHS. When only part of the requested information is denied, the organization should provide access to the remaining information when possible.
How Should Business Associates Support Access Requests?
Covered entities remain responsible for fulfilling individual-rights obligations. A business associate agreement may specify whether the business associate provides access directly or sends the information to the covered entity for production.
Vendor involvement does not extend the federal response period. Organizations should define request routing, retrieval time, format conversion, secure delivery, fee controls, escalation, and evidence requirements in their operating procedures and agreements.
Track vendor-held designated-record-set locations and test whether records can be retrieved promptly. A record that exists but cannot be located reliably creates operational and compliance risk.
Need disciplined request intake, retrieval, and secure delivery? Explore AMI's Release of Information Support.
Which Operational Controls Support Timely Access?
Strong controls make every request visible from intake through closure. A request log should include receipt date, scope, requester, identity verification, assigned owner, systems searched, exclusions, fee notice, delivery method, completion date, and escalation history.
Use alerts before deadlines rather than on the due date. Age requests by calendar days and identify those waiting on vendors, archived systems, legal review, or requester clarification.
Quality assurance should confirm that the correct person's information was produced, the scope was complete, exclusions were applied appropriately, and delivery evidence was retained.
What HIPAA Right of Access Mistakes Should Teams Avoid?
Common mistakes include:
- Limiting production to information visible in the patient portal
- Treating the 30-day outer limit as the standard turnaround target
- Restarting the clock when another department or vendor receives the request
- Charging search, retrieval, verification, or infrastructure costs
- Denying access because an individual has an unpaid medical bill
- Requiring unnecessary forms, notarization, or in-person visits
- Failing to provide a written denial or available review rights
- Producing incomplete records from only one designated-record-set system
Organizations should review complaints and repeat contacts as signals of process friction. The release of information process should make responsibilities and evidence clear at every handoff.
How AM Infoweb Supports HIPAA Access Workflows
AM Infoweb supports healthcare organizations with structured release-of-information workflows, trained teams, request tracking, quality controls, and secure delivery processes.
With two decades of experience in the U.S. healthcare industry, AM Infoweb uses a co-managed model that brings AI agents and skilled human agents together to eliminate process bottlenecks and execute secure healthcare workflows.
AMI can support:
- Request intake and indexing
- Identity and authority verification workflows
- Designated-record-set retrieval coordination
- Request tracking and deadline monitoring
- Format and delivery preparation
- Fee and exception workflow support
- Quality assurance and escalation
- Operational reporting and backlog visibility
The co-managed model helps organizations add capacity while retaining privacy oversight, policy authority, and control of reviewable decisions. For related guidance, see who can access PHI records and when.
What Should Healthcare Organizations Do Next?
Map every channel through which an access request can arrive and every location that may hold designated-record-set information. Assign ownership at intake, retrieval, review, delivery, and escalation stages.
Then test real requests against the process. Measure completion time, aging, retrieval delays, fee accuracy, incomplete productions, complaints, and repeat contacts.
The HIPAA right of access is both a legal requirement and an operational workflow. Clear intake, complete retrieval, appropriate review, timely delivery, and traceable evidence help protect individual rights and organizational accountability.
Need more reliable HIPAA access-request execution? AMI combines trained teams, PHI-aware workflows, quality assurance, escalation controls, and clear operational visibility across the request lifecycle.
Get in TouchFrequently Asked Questions
About the Author

Written by
Urza Dey
Urza Dey is a content and copywriter with over five years of experience across marketing, B2B SaaS, HealthTech, EdTech, and related industries. At AMI, they contribute to content strategy, blog development, and marketing communication focused on healthcare operations, business process management, and AI-enabled service delivery.


