US Medical BillingRevenue cycle solutions
Compliance and Regulations

Responding to a Payer's Request for Medical Records

A request from a health plan for a patient's medical records lands on a billing desk constantly, and it tends to provoke one of two wrong reactions: send the entire chart without thinking, or treat the request as an accusation and stall. Both are mistakes. A payer is usually entitled to the records it needs to decide a claim, a practice is usually permitted to send them without asking the patient, and the claim will be denied if the records do not arrive complete and on time. The skill is in the middle: work out who is asking and why, send the right records — no more than the request needs — by the deadline that applies, and keep a record of exactly what was sent. This article explains the legal permission, its limit, where the deadline actually comes from, and how to answer a request well.

Updated 15 min read

On this page

Key takeaways

Why a payer asks for records

The first question is not whether to respond but why the payer is asking, because the reason is usually stated on the request and it sets everything that follows. A records request is rarely a random event; a payer wants records when a claim cannot be decided from the claim form alone. The common reasons fall into a short list:

  • Prepayment review — the payer is holding a claim and wants the records before it pays, often to validate coding or confirm the service was covered. Nothing has been paid yet, so the response is what releases payment.
  • Medical-necessity or coverage review — the payer is testing whether the service met its coverage criteria, i.e. its medical necessity standard, which the records either support or do not.
  • Coding or claim-edit validation — the payer is checking that what was billed matches what the record documents, for example validating the codes on a facility claim before payment.
  • A post-payment audit — the claim was already paid and the payer is revisiting it, which can end in a revised determination and a demand to return money.
  • An appeal or dispute — the practice is contesting a denial, and the records are the evidence that supports paying the claim.

The requester also matters. A commercial health plan requests records under the provider participation agreement; Medicare's contractors request them through an Additional Documentation Request, the subject covered in the article on the types of Medicare audits. Most requests are ordinary claim adjudication. The exception is a contact that reads as a fraud or benefit-integrity investigation rather than a coverage review — that is a different situation, and it belongs with the compliance program and counsel from the outset, not with a routine records response.

This sits in Compliance and Regulations for a reason

The two shapes: prepayment and post-payment requests

Underneath the specific reasons, a records request has one of two timings, and the timing changes what is at stake. A prepayment review happens before the claim is paid: the claim is held while the payer examines the records, and payment depends on the outcome. A post-payment review happens after the claim has already been paid: the payer revisits it and can leave the payment alone or issue a revised determination that finds an overpayment or an underpayment.

The difference is money and leverage. On a prepayment request the money has not moved, so a complete, timely response is what gets the claim paid. On a post-payment request the money is already in the practice's hands, so an inadequate response does not just cost a payment — it can turn into a demand to give money back. Knowing which one a request is tells a practice how urgent the downstream risk is.

How a prepayment records request and a post-payment records request differ — by timing, effect on the claim, and what a non-response causes
How a prepayment records request and a post-payment records request differ — by timing, effect on the claim, and what a non-response causes
DimensionPrepayment requestPost-payment request
When it happensBefore the claim is paid; the claim is held pending reviewAfter the claim has already been paid
What the payer is doingDeciding whether, and how much, to pay — an initial determinationRevisiting a paid claim — the result can be no change, or a revised determination
Effect of a complete, timely responseThe claim is adjudicated and payment is releasedThe paid claim is confirmed, or adjusted with an explanation
Effect of no responseThe claim is denied — a payment that was owed is lostA denial of the amount paid, creating an overpayment the payer will recover
Where the deadline comes fromThe request or the provider agreement; state prompt-pay rulesThe request or the provider agreement; the audit notice

The single most important line is the last effect row: on a post-payment request, the downside is not only a lost payment but a repayment obligation, which is why a post-payment audit deserves closer attention than its paid-already appearance suggests.

HIPAA lets a practice send the records

The most common worry — do we need the patient's permission first — has a clear answer for an ordinary payer request: no. The HIPAA Privacy Rule permits a covered entity to use and disclose protected health information for payment without patient authorization, and it specifically permits a provider to disclose that information to another covered entity — including a health plan — for the payment activities of the entity that receives it (45 CFR 164.506(c)(3)). A payer requesting records to adjudicate, review, or audit a claim is engaged in payment, so the disclosure is one the rule allows.

This is not a narrow reading. The Privacy Rule defines “payment” expansively (45 CFR 164.501), and the definition reaches nearly every reason a payer asks for records: determinations of eligibility and coverage and the adjudication of claims; billing, claims management, and collection; review of health care services for medical necessity, coverage, appropriateness of care, or justification of charges; and utilization review, including precertification, concurrent review, and retrospective review. A records request tied to any of those is a payment activity, and the records themselves are part of the designated record set — which the rule defines to include a provider's medical and billing records — that a covered entity maintains.

The permission is the payment purpose, not the payer's status

The limit: send the minimum necessary, not the whole chart

Permission to disclose is not permission to over-disclose. The minimum necessary standard applies to a disclosure to a payer, and — this is the part practices get wrong — there is no exception because the payer requested the records (45 CFR 164.502(b)). The Privacy Rule's minimum-necessary exceptions cover things like a disclosure to the individual or a request by a treating provider for treatment; a payer's request for payment is not among them. So the practice must make reasonable efforts to limit what it sends to the minimum necessary for the payer's stated purpose.

In practice that cuts both ways, and it usually favors sending less, not more. If the request is about one date of service or one procedure, the response is the records for that encounter — not the patient's entire history. Sending the whole chart when a page was asked for is itself a minimum-necessary problem, and it buries the record that actually decides the claim. The discipline of matching the disclosure to the request is the subject of applying the minimum necessary standard, and it is exactly the discipline a records request calls for.

Screen for records that need more than the payment permission

Where the deadline actually comes from

The most-searched question about a records request — how many days do we have — has no universal answer, and any source that gives you one number is wrong for most requests. There is no single federal deadline for responding to every payer's records request. Instead, the deadline comes from whichever of these applies:

The request itself
A records request states the date by which the payer expects the documentation. For a Medicare Additional Documentation Request, CMS's rule is that the contractor sets and states an “expected timeframe,” and the contractor denies the claim if the records are not received by it — so the operative deadline is the one printed on the request, not a number a practice can look up in advance.
The provider agreement
A commercial payer's records-request timeframe usually comes from the participation contract. A plan may publish a default in its provider manual, but that default is typically expressed as applying unless the agreement says otherwise — so the contract governs, and two payers, or two contracts with the same payer, can differ.
State prompt-pay law
For fully insured commercial claims, a state's prompt-pay rules often provide that a payer's request for additional information suspends the clock the payer is on to pay or deny the claim, and that the clock restarts when the information is received. Those rules — and the windows in them — vary by state, so the applicable one depends on where the plan is regulated.

Treat the date on the request as the deadline

What a non-response costs

The reason the deadline matters is that not responding is not neutral — it decides the claim against the practice. When a payer asks for the records behind a claim and does not get them, it denies the claim. In Medicare, this is explicit: no payment is made unless the information needed to determine the amount due is furnished (section 1833(e) of the Social Security Act), and the CMS rule is that a contractor denies the claim, in whole or in part, when the requested documentation is not received in the expected timeframe. Commercial payers reach the same result through their provider agreements — a prepayment claim is denied, or a post-payment claim becomes a “technical denial” of the amount paid — when the records are not produced.

The sting is that the denial has nothing to do with the quality of the care. A claim that was clean, for a service that was necessary and correctly coded, is lost because the record was not sent — or was sent late, or was the wrong record. And on a post-payment request the denial does not just erase a payment: it creates an overpayment the payer will recover, which is where the practice's own 60-day overpayment rule and the payer's recoupment mechanics take over. A missed records request is one of the most avoidable ways to lose money that was rightfully earned.

How to respond well

Answering a records request well is mostly ordinary discipline done reliably. The steps are the same whether the requester is a commercial plan or a Medicare contractor.

  1. Identify the requester and the reason

    Read who is asking and why: a prepayment review, a medical-necessity or coding review, a post-payment audit, or an appeal. A benefit-integrity or fraud contact is not a routine request and goes to the compliance program and counsel, not to the records queue.
  2. Find the deadline that applies

    Take the date from the request, and check it against the provider agreement and any state prompt-pay rule. Calendar it, and treat the earliest governing date as the deadline.
  3. Pull the complete, correct record

    Assemble the records for the right patient, the right date of service, and the right encounter — the ones the request actually asks for. Confirm they are legible and complete: missing signatures, an unsigned order, or an illegible note can turn a supported claim into a denial as surely as sending nothing.
  4. Limit it to the minimum necessary

    Send what the stated purpose needs, and no more, and screen out anything specially protected — psychotherapy notes or 42 CFR Part 2 records — that requires separate consent before it goes to a payer.
  5. Send it securely and confirm it arrived

    Use the channel and format the payer specifies, protect the transmission, and get confirmation of receipt where the payer offers it. A records package that never arrived is a non-response, no matter that it was sent.
  6. Log exactly what was sent

    Keep a copy of the precise records package and a note of the request date, the deadline, the send date, and the method. The log is what proves a timely, complete response if the claim is later denied for “no records,” and it is the record an internal audit will look for.

Records requests are a compliance function

A practice cannot choose whether payers will ask for records, but it can decide how ready it is to answer. Being audit-ready is not a special project; it is the everyday state of a billing operation whose documentation is complete, whose records are retrievable by patient and date of service, and whose responses go out on time and are logged. That readiness is one of the things a functioning compliance program produces, and it is what turns a records request from a fire drill into a routine task.

Two habits carry most of the weight. The first is retention: a practice can only produce a record it still has and can find, so keeping medical records for the period its payers, contracts, and applicable law require — and being able to retrieve them quickly — is the precondition for answering any request. The second is the loop back to documentation: every denial for insufficient records is a signal about a gap in what the practice captures at the point of care, and closing that gap is worth more than winning the appeal.

Educational, not legal advice

Common questions

Can a health plan get a patient's medical records without the patient's authorization?

For an ordinary claim, yes. The HIPAA Privacy Rule permits a provider to disclose protected health information to a health plan for the plan's payment activities without patient authorization (45 CFR 164.506), and "payment" is defined to include claims adjudication, medical-necessity and coverage review, and utilization review. The permission has limits — the minimum necessary standard still applies, and some material such as psychotherapy notes needs separate authorization — but a payer asking for the records behind a claim it is paying or reviewing generally does not need the patient to sign off.

Do we have to send the entire chart?

No, and usually you should not. The minimum necessary standard applies to a disclosure to a payer, and there is no exception because the payer asked (45 CFR 164.502(b)). Send the records the request actually needs — the encounter, date of service, or procedure at issue — rather than the patient's whole history. Sending more than was asked for is itself a minimum-necessary problem, and it buries the record that decides the claim.

How many days do we have to respond to a payer's records request?

There is no universal number. The deadline comes from the request itself, the provider participation agreement, or a state's prompt-pay rules, and it varies by payer, contract, and state. A Medicare Additional Documentation Request states an "expected timeframe" the contractor sets; a commercial payer's default is usually overridable by the contract. Treat the date the payer states on the request as the governing deadline, and ask for an extension before it passes if you need one.

What happens if we don't send the requested records?

The claim is denied. On a prepayment request, the claim is held and then denied when the records are not received. On a post-payment request, the amount already paid is denied as a technical denial, which creates an overpayment the payer will recover. In Medicare, a contractor denies the claim in whole or in part when the documentation is not received in the expected timeframe. The denial is for a reason unrelated to the care — a payable claim lost because the record was not produced on time.

Is a records request an audit or an accusation?

Usually neither. Most records requests are ordinary claim adjudication — a prepayment review, a medical-necessity or coding check, or an appeal — and the right response is a complete, timely records package. The exception is a contact from a benefit-integrity or program-integrity contractor, or anything that reads as a fraud investigation rather than a coverage review; that is a different situation covered in the article on the types of Medicare audits, and it belongs with the practice's compliance program and counsel from the outset.

Authoritative sources

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.