Responding to a Payer's Request for Medical Records
A request from a health plan for a patient's medical records lands on a billing desk constantly, and it tends to provoke one of two wrong reactions: send the entire chart without thinking, or treat the request as an accusation and stall. Both are mistakes. A payer is usually entitled to the records it needs to decide a claim, a practice is usually permitted to send them without asking the patient, and the claim will be denied if the records do not arrive complete and on time. The skill is in the middle: work out who is asking and why, send the right records — no more than the request needs — by the deadline that applies, and keep a record of exactly what was sent. This article explains the legal permission, its limit, where the deadline actually comes from, and how to answer a request well.
Updated 15 min read
On this page
Key takeaways
- A payer requesting a patient's records is routine and lawful. HIPAA permits a provider to disclose protected health information to a health plan for the plan's payment activities without patient authorization (45 CFR 164.506), and "payment" is defined broadly enough to cover claims adjudication, medical-necessity and coverage review, and utilization review.
- The permission is not a blank check. The minimum necessary standard still applies to a disclosure to a payer, and there is no exception because the payer asked. Send what the stated purpose needs, not the entire chart by reflex, and screen for material — psychotherapy notes, substance-use-disorder records — that needs separate authorization.
- Read the reason on the request. Payers ask for records for a handful of purposes — prepayment review before a claim is paid, a medical-necessity or coding review, a post-payment audit, and to process an appeal — and which one it is tells a practice what is at stake.
- The response deadline is almost never a universal number. It comes from the request itself, the provider agreement, or (for Medicare) the contractor's notice, and it varies by plan, contract, and state. Treat the deadline on the request as the one that governs.
- No records means denial. A claim the payer cannot substantiate is denied — pended-then-denied on prepayment review, or a post-payment technical denial that creates an overpayment — for a reason unrelated to the care that was given.
- Records requests are a compliance function. Complete, legible, timely, well-logged responses are what an audit-ready billing operation produces, because the record a practice sends is the record that decides the claim.
Why a payer asks for records
The first question is not whether to respond but why the payer is asking, because the reason is usually stated on the request and it sets everything that follows. A records request is rarely a random event; a payer wants records when a claim cannot be decided from the claim form alone. The common reasons fall into a short list:
- Prepayment review — the payer is holding a claim and wants the records before it pays, often to validate coding or confirm the service was covered. Nothing has been paid yet, so the response is what releases payment.
- Medical-necessity or coverage review — the payer is testing whether the service met its coverage criteria, i.e. its medical necessity standard, which the records either support or do not.
- Coding or claim-edit validation — the payer is checking that what was billed matches what the record documents, for example validating the codes on a facility claim before payment.
- A post-payment audit — the claim was already paid and the payer is revisiting it, which can end in a revised determination and a demand to return money.
- An appeal or dispute — the practice is contesting a denial, and the records are the evidence that supports paying the claim.
The requester also matters. A commercial health plan requests records under the provider participation agreement; Medicare's contractors request them through an Additional Documentation Request, the subject covered in the article on the types of Medicare audits. Most requests are ordinary claim adjudication. The exception is a contact that reads as a fraud or benefit-integrity investigation rather than a coverage review — that is a different situation, and it belongs with the compliance program and counsel from the outset, not with a routine records response.
This sits in Compliance and Regulations for a reason
The two shapes: prepayment and post-payment requests
Underneath the specific reasons, a records request has one of two timings, and the timing changes what is at stake. A prepayment review happens before the claim is paid: the claim is held while the payer examines the records, and payment depends on the outcome. A post-payment review happens after the claim has already been paid: the payer revisits it and can leave the payment alone or issue a revised determination that finds an overpayment or an underpayment.
The difference is money and leverage. On a prepayment request the money has not moved, so a complete, timely response is what gets the claim paid. On a post-payment request the money is already in the practice's hands, so an inadequate response does not just cost a payment — it can turn into a demand to give money back. Knowing which one a request is tells a practice how urgent the downstream risk is.
| Dimension | Prepayment request | Post-payment request |
|---|---|---|
| When it happens | Before the claim is paid; the claim is held pending review | After the claim has already been paid |
| What the payer is doing | Deciding whether, and how much, to pay — an initial determination | Revisiting a paid claim — the result can be no change, or a revised determination |
| Effect of a complete, timely response | The claim is adjudicated and payment is released | The paid claim is confirmed, or adjusted with an explanation |
| Effect of no response | The claim is denied — a payment that was owed is lost | A denial of the amount paid, creating an overpayment the payer will recover |
| Where the deadline comes from | The request or the provider agreement; state prompt-pay rules | The request or the provider agreement; the audit notice |
The single most important line is the last effect row: on a post-payment request, the downside is not only a lost payment but a repayment obligation, which is why a post-payment audit deserves closer attention than its paid-already appearance suggests.
HIPAA lets a practice send the records
The most common worry — do we need the patient's permission first — has a clear answer for an ordinary payer request: no. The HIPAA Privacy Rule permits a covered entity to use and disclose protected health information for payment without patient authorization, and it specifically permits a provider to disclose that information to another covered entity — including a health plan — for the payment activities of the entity that receives it (45 CFR 164.506(c)(3)). A payer requesting records to adjudicate, review, or audit a claim is engaged in payment, so the disclosure is one the rule allows.
This is not a narrow reading. The Privacy Rule defines “payment” expansively (45 CFR 164.501), and the definition reaches nearly every reason a payer asks for records: determinations of eligibility and coverage and the adjudication of claims; billing, claims management, and collection; review of health care services for medical necessity, coverage, appropriateness of care, or justification of charges; and utilization review, including precertification, concurrent review, and retrospective review. A records request tied to any of those is a payment activity, and the records themselves are part of the designated record set — which the rule defines to include a provider's medical and billing records — that a covered entity maintains.
The permission is the payment purpose, not the payer's status
The limit: send the minimum necessary, not the whole chart
Permission to disclose is not permission to over-disclose. The minimum necessary standard applies to a disclosure to a payer, and — this is the part practices get wrong — there is no exception because the payer requested the records (45 CFR 164.502(b)). The Privacy Rule's minimum-necessary exceptions cover things like a disclosure to the individual or a request by a treating provider for treatment; a payer's request for payment is not among them. So the practice must make reasonable efforts to limit what it sends to the minimum necessary for the payer's stated purpose.
In practice that cuts both ways, and it usually favors sending less, not more. If the request is about one date of service or one procedure, the response is the records for that encounter — not the patient's entire history. Sending the whole chart when a page was asked for is itself a minimum-necessary problem, and it buries the record that actually decides the claim. The discipline of matching the disclosure to the request is the subject of applying the minimum necessary standard, and it is exactly the discipline a records request calls for.
Screen for records that need more than the payment permission
Where the deadline actually comes from
The most-searched question about a records request — how many days do we have — has no universal answer, and any source that gives you one number is wrong for most requests. There is no single federal deadline for responding to every payer's records request. Instead, the deadline comes from whichever of these applies:
- The request itself
- A records request states the date by which the payer expects the documentation. For a Medicare Additional Documentation Request, CMS's rule is that the contractor sets and states an “expected timeframe,” and the contractor denies the claim if the records are not received by it — so the operative deadline is the one printed on the request, not a number a practice can look up in advance.
- The provider agreement
- A commercial payer's records-request timeframe usually comes from the participation contract. A plan may publish a default in its provider manual, but that default is typically expressed as applying unless the agreement says otherwise — so the contract governs, and two payers, or two contracts with the same payer, can differ.
- State prompt-pay law
- For fully insured commercial claims, a state's prompt-pay rules often provide that a payer's request for additional information suspends the clock the payer is on to pay or deny the claim, and that the clock restarts when the information is received. Those rules — and the windows in them — vary by state, so the applicable one depends on where the plan is regulated.
Treat the date on the request as the deadline
What a non-response costs
The reason the deadline matters is that not responding is not neutral — it decides the claim against the practice. When a payer asks for the records behind a claim and does not get them, it denies the claim. In Medicare, this is explicit: no payment is made unless the information needed to determine the amount due is furnished (section 1833(e) of the Social Security Act), and the CMS rule is that a contractor denies the claim, in whole or in part, when the requested documentation is not received in the expected timeframe. Commercial payers reach the same result through their provider agreements — a prepayment claim is denied, or a post-payment claim becomes a “technical denial” of the amount paid — when the records are not produced.
The sting is that the denial has nothing to do with the quality of the care. A claim that was clean, for a service that was necessary and correctly coded, is lost because the record was not sent — or was sent late, or was the wrong record. And on a post-payment request the denial does not just erase a payment: it creates an overpayment the payer will recover, which is where the practice's own 60-day overpayment rule and the payer's recoupment mechanics take over. A missed records request is one of the most avoidable ways to lose money that was rightfully earned.
How to respond well
Answering a records request well is mostly ordinary discipline done reliably. The steps are the same whether the requester is a commercial plan or a Medicare contractor.
Identify the requester and the reason
Read who is asking and why: a prepayment review, a medical-necessity or coding review, a post-payment audit, or an appeal. A benefit-integrity or fraud contact is not a routine request and goes to the compliance program and counsel, not to the records queue.Find the deadline that applies
Take the date from the request, and check it against the provider agreement and any state prompt-pay rule. Calendar it, and treat the earliest governing date as the deadline.Pull the complete, correct record
Assemble the records for the right patient, the right date of service, and the right encounter — the ones the request actually asks for. Confirm they are legible and complete: missing signatures, an unsigned order, or an illegible note can turn a supported claim into a denial as surely as sending nothing.Limit it to the minimum necessary
Send what the stated purpose needs, and no more, and screen out anything specially protected — psychotherapy notes or 42 CFR Part 2 records — that requires separate consent before it goes to a payer.Send it securely and confirm it arrived
Use the channel and format the payer specifies, protect the transmission, and get confirmation of receipt where the payer offers it. A records package that never arrived is a non-response, no matter that it was sent.Log exactly what was sent
Keep a copy of the precise records package and a note of the request date, the deadline, the send date, and the method. The log is what proves a timely, complete response if the claim is later denied for “no records,” and it is the record an internal audit will look for.
Records requests are a compliance function
A practice cannot choose whether payers will ask for records, but it can decide how ready it is to answer. Being audit-ready is not a special project; it is the everyday state of a billing operation whose documentation is complete, whose records are retrievable by patient and date of service, and whose responses go out on time and are logged. That readiness is one of the things a functioning compliance program produces, and it is what turns a records request from a fire drill into a routine task.
Two habits carry most of the weight. The first is retention: a practice can only produce a record it still has and can find, so keeping medical records for the period its payers, contracts, and applicable law require — and being able to retrieve them quickly — is the precondition for answering any request. The second is the loop back to documentation: every denial for insufficient records is a signal about a gap in what the practice captures at the point of care, and closing that gap is worth more than winning the appeal.
Educational, not legal advice
Common questions
Can a health plan get a patient's medical records without the patient's authorization?
For an ordinary claim, yes. The HIPAA Privacy Rule permits a provider to disclose protected health information to a health plan for the plan's payment activities without patient authorization (45 CFR 164.506), and "payment" is defined to include claims adjudication, medical-necessity and coverage review, and utilization review. The permission has limits — the minimum necessary standard still applies, and some material such as psychotherapy notes needs separate authorization — but a payer asking for the records behind a claim it is paying or reviewing generally does not need the patient to sign off.
Do we have to send the entire chart?
No, and usually you should not. The minimum necessary standard applies to a disclosure to a payer, and there is no exception because the payer asked (45 CFR 164.502(b)). Send the records the request actually needs — the encounter, date of service, or procedure at issue — rather than the patient's whole history. Sending more than was asked for is itself a minimum-necessary problem, and it buries the record that decides the claim.
How many days do we have to respond to a payer's records request?
There is no universal number. The deadline comes from the request itself, the provider participation agreement, or a state's prompt-pay rules, and it varies by payer, contract, and state. A Medicare Additional Documentation Request states an "expected timeframe" the contractor sets; a commercial payer's default is usually overridable by the contract. Treat the date the payer states on the request as the governing deadline, and ask for an extension before it passes if you need one.
What happens if we don't send the requested records?
The claim is denied. On a prepayment request, the claim is held and then denied when the records are not received. On a post-payment request, the amount already paid is denied as a technical denial, which creates an overpayment the payer will recover. In Medicare, a contractor denies the claim in whole or in part when the documentation is not received in the expected timeframe. The denial is for a reason unrelated to the care — a payable claim lost because the record was not produced on time.
Is a records request an audit or an accusation?
Usually neither. Most records requests are ordinary claim adjudication — a prepayment review, a medical-necessity or coding check, or an appeal — and the right response is a complete, timely records package. The exception is a contact from a benefit-integrity or program-integrity contractor, or anything that reads as a fraud investigation rather than a coverage review; that is a different situation covered in the article on the types of Medicare audits, and it belongs with the practice's compliance program and counsel from the outset.
Key terms in this article
Defined once, on their own pages.
Continue learning
The Medicare form of a records request, how much to disclose, the permission behind it, and the duty a post-payment finding can trigger.
The Types of Medicare Audits
The Medicare contractors that request records — MAC review, RAC, CERT, UPIC, and SMRC — and the Additional Documentation Request they use to ask for them.
Applying the Minimum Necessary Standard
How to limit a disclosure to what the request needs — the discipline that decides how much of a chart goes to a payer.
The HIPAA Privacy Rule for Billing
The payment permission that lets a practice disclose records to a payer without patient authorization, and what else the Privacy Rule requires of a billing operation.
The 60-Day Overpayment Rule
When a post-payment records review turns up an overpayment, the practice's own duty to report and return it — separate from the payer's recoupment.
Authoritative sources
- 45 CFR § 164.506 — Uses and disclosures to carry out treatment, payment, or health care operations (opens in a new tab)
U.S. Department of Health and Human Services (via the Cornell Legal Information Institute). A covered entity may disclose protected health information for its own payment activities and to another covered entity or health care provider for the payment activities of the entity that receives the information; payment disclosures do not require patient authorization.
- 45 CFR § 164.501 — Definitions (“payment” and “designated record set”) (opens in a new tab)
U.S. Department of Health and Human Services (via the Cornell Legal Information Institute). "Payment" is defined to include, among other activities, determinations of eligibility and coverage, claims adjudication, billing, claims management and collection, review of health care services for medical necessity, coverage, appropriateness, or justification of charges, and utilization review; the "designated record set" includes a provider's medical and billing records.
- 45 CFR § 164.502(b) — Minimum necessary (opens in a new tab)
U.S. Department of Health and Human Services (via the Cornell Legal Information Institute). A covered entity must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose; a disclosure to a payer for payment is not among the standard's listed exceptions.
- 42 U.S.C. § 1395l(e) — No Medicare payment absent information needed to determine amounts due (section 1833(e) of the Social Security Act) (opens in a new tab)
Office of the Law Revision Counsel (via the Cornell Legal Information Institute). No payment is made to a provider or other person under Medicare Part B unless the information necessary to determine the amounts due has been furnished — the statutory basis for a contractor's records request and for denial when it is not answered.
- CMS Medicare Program Integrity Manual (Pub. 100-08), Chapter 3 (opens in a new tab)
Centers for Medicare & Medicaid Services. The Additional Documentation Request, defined as all documentation requests associated with prepayment and post-payment review; the requirement that a contractor states the expected timeframe for a response; and the rule that MACs, RACs, the SMRC, and UPICs deny a claim, in whole or in part, when the requested documentation is not received.
