US Healthcare · Records, Language & Access
HIPAA and Your Medical Records
Your right to access medical records under HIPAA — the 30-day rule, fees, patient portals, who HIPAA covers, and how to file a complaint with HHS.
Any patient who wants to obtain their own medical records, share records with a new provider, understand who can access their health information, or report a privacy violation.
The Health Insurance Portability and Accountability Act (HIPAA), passed in 1996 and significantly amended since, is the federal law that governs the privacy and security of health information in the United States. HIPAA gives patients important rights over their own health information: the right to see and obtain copies of their records, the right to request corrections, and the right to know who has accessed their information. Understanding HIPAA helps you access your own care more effectively and protect your health information.
Who HIPAA applies to
HIPAA applies to “covered entities” — organizations and individuals that handle protected health information (PHI) in specific contexts. Covered entities include:
- Healthcare providers (doctors, hospitals, clinics, pharmacies, nursing homes, and others) who transmit health information electronically
- Health plans (insurance companies, HMOs, Medicare, Medicaid)
- Healthcare clearinghouses (billing services, processing companies)
HIPAA also applies to “business associates” — vendors and service providers that handle PHI on behalf of covered entities, such as billing companies, IT vendors, and transcription services.
HIPAA does not apply to all entities that might hold health information. Employers, life insurance companies, and most wellness apps are generally not directly covered by HIPAA (though they may be subject to other laws).
Your right to access your own records
Under HIPAA’s Privacy Rule, you have the right to inspect and obtain a copy of your protected health information held by a covered entity. This is known as the Right of Access. Covered entities must:
- Provide access within 30 calendar days (extendable by 30 more with notice)
- Provide records in the format you request if they can readily produce it — including electronic format
- Charge only a reasonable, cost-based fee for copying and preparation
- Not deny access based on whether you have an outstanding bill
Electronic records through patient portals must generally be provided at no charge or at minimal cost. For paper copies or records that require manual preparation, fees vary by state and provider.
To request your records, submit a written request to the provider’s medical records department. Most providers have a standard records request form. You may need to present identification. If you are requesting records on behalf of someone else — a minor child, a parent, or someone who has designated you as a personal representative — you will need documentation of that authority.
What protected health information includes
Protected health information (PHI) under HIPAA includes any health information that identifies you or could reasonably be used to identify you, held or transmitted by a covered entity. This includes:
- Medical records: diagnoses, treatment notes, lab results, imaging
- Billing information: claims, payment records
- Insurance information: coverage details, eligibility records
- Appointment histories and scheduling records
There are 18 specific identifiers that, if linked to health information, make that information “protected” under HIPAA — including your name, date of birth, address, Social Security number, phone number, and more.
Disclosures that don’t require your authorization
HIPAA allows covered entities to share your health information without your explicit authorization for three primary purposes:
Treatment: Your provider can share relevant information with other providers involved in your care — the specialist you are referred to, the hospital where you are admitted, the pharmacy filling your prescription.
Payment: Your provider can share information with your insurer to process claims and verify coverage.
Healthcare operations: Covered entities can use your information for quality improvement, training, audits, and other internal operational purposes.
For most other disclosures — sharing with your employer, a family member not designated as your personal representative, law enforcement (with narrow exceptions), or researchers — a written HIPAA authorization is required.
Filing a complaint
If you believe a covered entity violated your HIPAA rights — by denying you access to your records, disclosing your information without authorization, or failing to safeguard your information — you can file a complaint with the HHS Office for Civil Rights (OCR). Complaints must be filed within 180 days of discovering the violation. OCR investigates complaints and has authority to impose civil money penalties.
You can also file a complaint with your state attorney general’s office, which may enforce additional state-level health privacy laws. Many states have privacy protections that go beyond HIPAA for specific categories of information such as mental health records, substance use treatment records, and reproductive health information.
Key terms
| Term | Plain meaning | Glossary |
|---|---|---|
| HIPAA | Federal law governing the privacy and security of your protected health information | → |
| Informed consent | Your agreement to a treatment or procedure after receiving clear information about it | → |
| Discharge | The formal process of leaving a hospital or inpatient setting | → |
| Inpatient | A patient formally admitted to a hospital, as opposed to an outpatient setting | → |
| Outpatient | Care provided without a formal hospital admission | → |
Common questions
- How long does a provider have to give me my medical records?
- Under HIPAA, covered entities must provide access to your medical records within 30 calendar days of your request. If they cannot meet this deadline, they may extend by 30 more days with written notice explaining the reason and the expected completion date. Requests must generally be fulfilled in the format you request if it is readily producible.
- Can a provider charge me a fee for my records?
- Yes, but only a reasonable, cost-based fee. HIPAA allows providers to charge for copying costs, postage, and labor to prepare the records. Fees vary by state and provider — some states limit what providers can charge, and many providers provide electronic records at no charge through patient portals.
- Who else can access my medical records?
- HIPAA allows providers to share your health information for treatment, payment, and healthcare operations without your specific authorization. They can share with other providers treating you, with your insurer for billing, and for defined operational purposes. For most other uses — including sharing with your employer, a family member, or a researcher — they generally need your written authorization.
- What is a HIPAA authorization form?
- A HIPAA authorization is a form you sign allowing a covered entity to use or share your health information for a specific purpose not covered by the standard treatment, payment, and operations exceptions. Examples include releasing records to your attorney, to a specific family member, or for use in research. The authorization must specify what information is shared, with whom, for what purpose, and for how long.
- What if I believe my privacy rights were violated?
- File a complaint with the HHS Office for Civil Rights (OCR), which enforces HIPAA. Complaints must be filed within 180 days of when you discovered the violation. OCR investigates complaints and can impose civil money penalties on covered entities that violate HIPAA. You can also contact your state attorney general's office for state-level privacy laws.
Sources
Last reviewed: September 2026