In a small or mid-sized medical practice, the to-do list never exactly gets shorter. Phones ring, schedules shift, prior auths pile up, and someone always seems to need something “right away.” In that kind of environment, a patient records request can feel like one more administrative task to squeeze in later.
That is a mistake.
Under HIPAA, giving patients timely access to their records is not optional customer service. It is a legal right. HHS says patients generally have a right to inspect or obtain a copy of the protected health information in their designated record set, and covered entities must act on a request no later than 30 calendar days after receiving it. A practice can take one additional 30-day extension only if it sends the patient a written explanation for the delay within the original 30 days. HHS also makes clear that 30 days is the outside limit, not the target.
That means “we’re busy,” “the manager is out,” “records is backed up,” or “the chart is archived somewhere” are not magic phrases that make the deadline disappear. In fact, HHS specifically says the clock still runs even when records are old, archived, or handled by a business associate.
Why does this matter so much? Because access to records is part of how patients manage their care. They may need records for a second opinion, ongoing treatment, an insurance dispute, disability paperwork, or just to understand what happened during a visit. When a practice delays or mishandles that request, the patient is not just inconvenienced. They are being blocked from information that federal law says they are entitled to receive.
And HHS has shown repeatedly that it is willing to enforce this.
One recent example involved Concentra. HHS OCR said the company failed to provide timely access within 30 days. According to OCR, the patient made six requests starting in February 2018 and did not receive the records until March 2019, more than a year later. The case ended with a $112,500 settlement. That is a very expensive way to learn that “we’ll circle back” is not a HIPAA workflow.
Another example was Life Hope Labs. OCR said the lab failed to provide timely access to requested records, and the matter was resolved with a $16,500 settlement under the Right of Access Initiative.
OCR has also pursued smaller providers. In 2021, the Diabetes, Endocrinology & Lipidology Center agreed to pay $5,000 to settle a potential violation of the HIPAA right-of-access standard. That amount is smaller, but the lesson is the same: size does not protect a practice from enforcement. OCR’s enforcement pages make clear that these cases include providers of many different sizes, including small offices.
So what does a good response look like in real life?
It looks like having a simple process. Someone receives the request. Someone logs the date. Someone confirms what is being requested and in what format. Someone owns the task until it is done. If there is a legitimate delay, the patient gets the required written notice before day 30. None of this is glamorous, but it is how practices stay compliant.
What does a bad response look like? Letting the request sit in a fax tray. Sending the patient in circles. Waiting for a supervisor who never replies. Treating the request like a favor instead of a right. Charging improper fees. Assuming the deadline starts when the “right person” finally sees it. Those are the habits that turn ordinary administrative sloppiness into regulatory trouble.
For medical practices, timely records responses are not just about avoiding fines. They are part of patient trust. When patients ask for their records, they should not feel like they are trying to break into a vault from a heist movie. They should feel like the practice understands the rules, respects their rights, and has its act together.
That is the standard. And under HIPAA, it is not an especially optional one.