The HIPAA Right of Access in Medical Billing
Most of the HIPAA rules a billing operation lives under govern what a practice may do with a patient's information. The right of access runs the other way: it is the patient's right to get their own information back. Under 45 CFR 164.524, an individual may inspect and obtain a copy of the protected health information a practice holds about them — and because the records that right reaches expressly include billing records, this is not only a medical-records question. It is a billing-office obligation, on a defined clock, with a defined fee, and with one rule a billing team gets wrong more than any other: a patient's right to their records does not depend on whether they have paid for their care.
Updated 15 min read
On this page
Key takeaways
- The right of access (45 CFR 164.524) lets an individual inspect and obtain a copy of their own PHI in a designated record set, for as long as the information is maintained.
- The designated record set expressly includes a provider's billing records and a health plan's payment and claims-adjudication systems (45 CFR 164.501) — so billing records, claim data, and remittances a practice holds are within the right, not just the clinical chart.
- A covered entity must act on a request no later than 30 days after receiving it, with one permitted extension of no more than 30 days on written notice (45 CFR 164.524(b)(2)).
- Access must be provided in the form and format the individual requests if it is readily producible, including an electronic copy of information maintained electronically (45 CFR 164.524(c)(2)).
- An individual may direct the practice to transmit a copy to a third party they designate, if the request is in writing, signed, and clearly identifies the recipient (45 CFR 164.524(c)(3)).
- A practice may charge only a reasonable, cost-based fee limited to labor for copying, supplies for portable media, postage, and preparing an agreed summary (45 CFR 164.524(c)(4)) — not search, retrieval, or other overhead.
- Nonpayment is not a ground for denial. A practice may not withhold a patient's records because the bill for their care is unpaid; the grounds for denying access are the narrow, mostly reviewable ones the rule lists.
What the right of access is
The HIPAA Privacy Rule does more than permit a practice to use protected health information for payment; it also grants the individual an affirmative right to see and receive a copy of it. Under 45 CFR 164.524, a person has the right to inspect and obtain a copy of protected health information about themselves that a covered entity maintains in a designated record set, for as long as the information is kept in that set. It is the counterpart to the HIPAA Privacy Rule's permission side: the rule that lets a practice use the information to bill is the same rule that lets the patient get it back.
Two verbs sit inside the right, and they are not the same. To inspect is to view the information; to obtain a copy is to take it away in a usable form. An individual may ask for either or both, and a practice's process has to be able to deliver either — a patient who wants to read their file in the office is exercising the same right as one who wants an electronic copy emailed to them.
This is the individual's right, not a disclosure to someone else
Why a billing operation is in scope
It is tempting to treat the right of access as a medical-records-department problem. The definition of the records it reaches says otherwise. A designated record set is a group of records a covered entity uses to make decisions about individuals, and 45 CFR 164.501 names the parts of it outright: for a provider, the medical records and the billing records about individuals; for a health plan, the enrollment, payment, claims-adjudication, and case- or medical-management record systems. Billing is not adjacent to the right of access — it is written into the definition.
In practice that means an access request can reach into records a billing office owns and a medical-records clerk never sees: the itemized account of what was charged, the claim data the practice submitted, the explanations of benefits and remittances it holds, the notes on a patient's balance. If the practice used a record to make a decision about the patient — including a billing or payment decision — it is part of the set the patient may ask to see.
An itemized bill is not the whole right
The narrow grounds for withholding access
The right of access is broad, and the exceptions to it are narrow and specific. Two categories of information sit outside the right entirely: psychotherapy notes, and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative proceeding (45 CFR 164.524(a)(1)). Neither is something a billing operation ordinarily handles.
Beyond those, the rule allows a covered entity to deny access only on grounds it lists exhaustively, and it sorts them into two kinds:
- Unreviewable grounds (45 CFR 164.524(a)(2)) — a short, fixed list, such as records subject to the Clinical Laboratory Improvements or Privacy Act provisions, information obtained under a promise of confidentiality where access would reveal the source, or an inmate request that would jeopardize safety. A denial on one of these is not subject to review.
- Reviewable grounds (45 CFR 164.524(a)(3)) — chiefly where a licensed health care professional has determined that access is reasonably likely to endanger the life or physical safety of the individual or another person. A denial on a reviewable ground must be reviewed by a designated licensed professional if the individual asks.
An unpaid bill is not one of the grounds
For a billing operation the practical rule is simple: withholding access is not a billing decision. If a request appears to touch one of the narrow grounds, it is routed to the person responsible for the practice's access policy — usually the privacy officer — who applies the rule and, where a ground is reviewable, arranges the required professional review. A biller's job is to recognize the request and move it, not to decide it.
How fast the practice must respond
The rule puts the response on a clock. A covered entity must act on a request for access no later than 30 days after it receives the request (45 CFR 164.524(b)(2)(i)). Acting means either providing the access or, if a ground for denial applies, giving a written denial that explains it and how to seek review or complain.
One extension is allowed. If the practice cannot act within 30 days, it may take up to one additional 30-day period, but only if — within the original window — it gives the individual a written statement of the reason for the delay and the date it will complete the request (45 CFR 164.524(b)(2)(ii)). The rule permits only a single extension; a second one is not available.
Timely access is not a technicality the enforcer overlooks. HHS's Office for Civil Rights runs a HIPAA Right of Access Initiative — an enforcement effort aimed specifically at covered entities that fail to give individuals prompt access to their records at a reasonable cost — and it has been an active, ongoing priority producing a series of enforcement actions. A request left to drift toward the 30-day limit, or past it, is exactly the kind of lapse the initiative exists to catch.
The 30 days is a federal ceiling, not a target — and states can be stricter
The form, the format, and sending a copy elsewhere
The rule gives the individual, not the practice, the say over the form the copy takes. A covered entity must provide access in the form and format the individual requests, if the information is readily producible that way; if it is not, then in a readable hard copy or another form and format the parties agree to (45 CFR 164.524(c)(2)(i)). Where the information is maintained electronically and the individual asks for an electronic copy, the practice must provide it in the electronic form and format requested if readily producible, and otherwise in a readable electronic form the parties agree to (164.524(c)(2)(ii)).
A practice may offer a summary or explanation instead of the full copy, but only if the individual agrees to that in advance and agrees in advance to any fee for it (45 CFR 164.524(c)(2)(iii)). A summary is an option the patient can accept, not a substitute the practice can impose.
The right also runs to a person the individual chooses. If a request directs the practice to transmit a copy directly to a third party the individual designates, the practice must send it there — provided the request is in writing, signed by the individual, and clearly identifies the designated person and where to send the copy (45 CFR 164.524(c)(3)). This is what lets a patient have their records sent to a new provider, an attorney, or a family member, and the written-and-signed requirement is what protects against a copy being routed to the wrong hands.
A practice may require the request in writing
What a practice may charge
A practice may charge for a copy, but the rule caps both the size and the makeup of the fee. It must be a reasonable, cost-based fee, and 45 CFR 164.524(c)(4) enumerates the only costs it may include: the labor for copying the information, whether on paper or electronically; the supplies for a paper copy or the portable media the individual asked for; postage, when the individual asked for the copy to be mailed; and the cost of preparing a summary or explanation, if the individual agreed to one. Anything outside that list — the practice's overhead, the cost of searching for and retrieving the records, the time spent verifying identity — is not a permitted component of the fee.
Because the standard is cost-based, the honest way to set the fee is to build it from the actual or reasonable costs the rule allows, rather than to apply a flat charge chosen for convenience. HHS has published guidance on acceptable ways to calculate the fee; a practice should ground its charge in that guidance and in the current regulation rather than in a number carried over from a records vendor.
The fee cannot be used to collect the underlying bill
Building the right of access into the billing operation
For a billing office, complying with the right of access is less a legal project than a handful of defaults built into how records requests are handled.
Know that your billing records are in scope
The designated record set includes billing records and the payment and claims-adjudication systems (45 CFR 164.501). Treat a patient's request for their claim data, statements, or remittances as a right-of-access request, not a favor.Never condition access on a paid balance
Nonpayment for care is not a ground for denial. Separate the two ledgers: work the outstanding balance through the normal billing process, and release the records on the access timeline regardless of what the patient owes.Start the 30-day clock on receipt and track it
A covered entity must act within 30 days of receiving the request, with at most one 30-day extension on written notice (45 CFR 164.524(b)(2)). Log the receipt date, and treat the deadline as a ceiling to beat, not a target to reach.Honor the requested form, format, and destination
Provide the copy in the form and format requested where readily producible, including an electronic copy of electronic records, and transmit it to a third party when the individual's written, signed request directs it (45 CFR 164.524(c)(2)–(3)).Charge only a reasonable, cost-based fee
Limit any fee to the labor for copying, supplies, postage, and an agreed summary (45 CFR 164.524(c)(4)); leave out search, retrieval, and overhead, and never use the fee to recover the care bill.Route anything that looks like a denial
Withholding access is not a billing decision. Send any request that appears to touch a ground for denial to the privacy officer, who applies the rule and arranges the professional review a reviewable ground requires.
The right of access is one of several individual rights the Privacy Rule creates — the right to amend a record (45 CFR 164.526) and the right to an accounting of certain disclosures (45 CFR 164.528) are separate rights with their own procedures. It sits alongside the other regulatory duties in the Compliance and Regulations category, and where a practice's records are held by a vendor, the business associate agreement must require that vendor to make the information available so the practice can meet a request. Because the rules are revised and enforcement guidance evolves, a practice's access policy should point to the current regulation and be reviewed when it changes.
Educational, not legal advice
Common questions
Does a patient have a right to their billing records, or only their clinical chart?
Billing records are squarely within the right. The designated record set that the right of access reaches expressly includes a provider's billing records and a health plan's payment and claims-adjudication systems (45 CFR 164.501). So a patient may request the protected health information in their billing file — the itemized account, the claim data the practice holds, the remittances and explanations of benefits — not only the medical record. Providing an itemized statement is good practice but is not, by itself, the same as responding to a right-of-access request.
Can we refuse to release records until the patient pays their outstanding balance?
No. Nonpayment for care is not a ground for denying access, and a covered entity may not withhold a patient's records because the bill for their care is unpaid. The grounds for denial are the narrow ones the rule lists at 45 CFR 164.524(a). The outstanding balance is collected through the ordinary billing process; it is not a condition on the patient's right to their own information. The only charge the rule allows on an access request is the reasonable, cost-based fee for producing the copy.
How long do we have to respond to a request for access?
A covered entity must act on a request no later than 30 days after receiving it (45 CFR 164.524(b)(2)(i)). If it cannot, it may take one additional period of up to 30 days, but only if it gives the individual, within the original window, a written statement of the reason for the delay and the date it will finish. Only one extension is allowed. The 30 days is a federal outer limit, not a target, and a state law that requires faster access or grants a broader right is not preempted — so the real deadline is the tighter of the two.
What can we charge for a copy of the records?
Only a reasonable, cost-based fee. Under 45 CFR 164.524(c)(4) the fee may include just the labor for copying the information, the supplies for a paper copy or the portable media requested, postage if the copy is mailed, and the cost of preparing a summary the individual agreed to. It may not include search and retrieval, general overhead, or the cost of verifying identity — and it can never be used to recover the unpaid bill for the patient's care. HHS has published guidance on how to calculate an acceptable fee.
A patient asked us to send their records to another provider. Do we have to?
Yes, when the request meets the rule's form. If an individual directs the practice to transmit a copy of their protected health information to a third party they designate, the practice must send it, provided the request is in writing, signed by the individual, and clearly identifies the designated person and where to send the copy (45 CFR 164.524(c)(3)). The written-and-signed requirement is the safeguard that keeps a copy from being routed to the wrong recipient.
Can we require patients to submit access requests in writing?
Yes, if the practice informs individuals of that requirement (45 CFR 164.524(b)(1)). A written request is a reasonable way to document what was asked for and when the 30-day clock started. What a practice cannot do is turn the requirement into an obstacle — an overly burdensome form or process that discourages requests is inconsistent with the right, and the clock still runs from when the request is received.
Key terms in this article
Defined once, on their own pages.
Continue learning
Where to go next.
The HIPAA Privacy Rule in Medical Billing
The permission side of the same rule — how billing counts as a payment activity, and the standard that bounds a disclosure to anyone other than the patient.
Applying the Minimum Necessary Standard in Medical Billing
The discipline of sending only what a purpose requires — and why it does not apply to a disclosure to the patient who is the subject of the record.
Business Associate Agreements in Medical Billing
The contract that must require a records vendor to make PHI available so the practice can meet a patient's right of access.
Authoritative sources
- HHS Office for Civil Rights — Individuals' Right under HIPAA to Access their Health Information (opens in a new tab)
The HHS office that administers and enforces the HIPAA rules. Explains the scope of the right of access, the designated record set, the 30-day timeframe, the form and format requirements, the third-party directive, and the reasonable cost-based fee — including that access may not be conditioned on payment for health care services.
- 45 CFR 164.524 — Access of individuals to protected health information (opens in a new tab)
eCFR. Sets the right to inspect and obtain a copy of PHI in a designated record set, the grounds for denial (reviewable and unreviewable), the 30-day timeframe and single extension, the form and format requirements and third-party directive, and the reasonable cost-based fee.
- 45 CFR 164.501 — Definitions (designated record set) (opens in a new tab)
eCFR. Defines the designated record set the right of access reaches — expressly including a provider's medical and billing records and a health plan's enrollment, payment, and claims-adjudication systems.
