US Healthcare · Records, Language & Access
HIPAA and Your Medical Records
Your right to access medical records under HIPAA — the 30-day rule, fees, patient portals, who HIPAA covers, and how to file a complaint with HHS.
Any patient who wants to obtain their own medical records, share records with a new provider, understand who can access their health information, or report a privacy violation.
The Health Insurance Portability and Accountability Act (HIPAA), passed in 1996 and significantly amended since, is the federal law that governs the privacy and security of health information in the United States. HIPAA gives patients important rights over their own health information: the right to see and obtain copies of their records, the right to request corrections, and the right to know who has accessed their information. Understanding HIPAA helps you access your own care more effectively and protect your health information.
Who HIPAA applies to
HIPAA applies to “covered entities” — organizations and individuals that handle protected health information (PHI) in specific contexts. Covered entities include:
- Healthcare providers (doctors, hospitals, clinics, pharmacies, nursing homes, and others) who transmit health information electronically
- Health plans (insurance companies, HMOs, Medicare, Medicaid)
- Healthcare clearinghouses (billing services, processing companies)
HIPAA also applies to “business associates” — vendors and service providers that handle PHI on behalf of covered entities, such as billing companies, IT vendors, and transcription services.
HIPAA does not apply to all entities that might hold health information. Employers, life insurance companies, and most wellness apps are generally not directly covered by HIPAA (though they may be subject to other laws).
Your right to access your own records
Under HIPAA’s Privacy Rule, you have the right to inspect and obtain a copy of your protected health information held by a covered entity. This is known as the Right of Access. Covered entities must:
- Provide access within 30 calendar days (extendable by 30 more with notice)
- Provide records in the format you request if they can readily produce it — including electronic format
- Charge only a reasonable, cost-based fee for copying and preparation
- Not deny access based on whether you have an outstanding bill
Electronic records through patient portals must generally be provided at no charge or at minimal cost. For paper copies or records that require manual preparation, fees vary by state and provider.
To request your records, submit a written request to the provider’s medical records department. Most providers have a standard records request form. You may need to present identification. If you are requesting records on behalf of someone else — a minor child, a parent, or someone who has designated you as a personal representative — you will need documentation of that authority.
What protected health information includes
Protected health information (PHI) under HIPAA includes any health information that identifies you or could reasonably be used to identify you, held or transmitted by a covered entity. This includes:
- Medical records: diagnoses, treatment notes, lab results, imaging
- Billing information: claims, payment records
- Insurance information: coverage details, eligibility records
- Appointment histories and scheduling records
There are 18 specific identifiers that, if linked to health information, make that information “protected” under HIPAA — including your name, date of birth, address, Social Security number, phone number, and more.
Disclosures that don’t require your authorization
HIPAA allows covered entities to share your health information without your explicit authorization for three primary purposes:
Treatment: Your provider can share relevant information with other providers involved in your care — the specialist you are referred to, the hospital where you are admitted, the pharmacy filling your prescription.
Payment: Your provider can share information with your insurer to process claims and verify coverage.
Healthcare operations: Covered entities can use your information for quality improvement, training, audits, and other internal operational purposes.
For most other disclosures — sharing with your employer, a family member not designated as your personal representative, law enforcement (with narrow exceptions), or researchers — a written HIPAA authorization is required.
Filing a complaint
If you believe a covered entity violated your HIPAA rights — by denying you access to your records, disclosing your information without authorization, or failing to safeguard your information — you can file a complaint with the HHS Office for Civil Rights (OCR). Complaints must be filed within 180 days of discovering the violation. OCR investigates complaints and has authority to impose civil money penalties.
You can also file a complaint with your state attorney general’s office, which may enforce additional state-level health privacy laws. Many states have privacy protections that go beyond HIPAA for specific categories of information such as mental health records, substance use treatment records, and reproductive health information.
Comparing HIPAA access and disclosure scenarios
Different situations trigger different HIPAA rules. Understanding which scenario applies helps you know whether to submit a records request, sign an authorization form, or file a complaint.
| Scenario | Authorization required? | Who initiates? | Your options |
|---|---|---|---|
| You request your own records | No — it is your legal right | You | Written request; fulfilled within 30 days |
| Provider shares with a treating physician | No — treatment exception | Provider | Routine; you can request an accounting of disclosures |
| Provider bills your insurer | No — payment exception | Provider | Routine; covered by HIPAA’s permissive disclosure rules |
| Records shared with a specific third party you choose | Yes — written authorization required | You | Complete and sign a HIPAA authorization form |
| Covered entity experiences a data breach | No — breach notification required | Covered entity | Must notify you within 60 days; large breaches reported to HHS |
| You believe your rights were violated | No — complaint mechanism | You | File with HHS OCR within 180 days of discovery |
Requests for your own records are the most common scenario and require no authorization — only identity verification. Authorizations come into play when you want records sent to parties outside your direct care team, such as attorneys, researchers, or non-treating family members.
What this looks like in practice
Imagine Diane, a 52-year-old recently diagnosed with a thyroid condition, who is transferring care to a new endocrinologist across town. She logs into her previous internist’s patient portal and submits a records request for the last five years of visit notes, lab results, and referral letters. She selects electronic delivery and adds the new specialist’s secure email. The practice acknowledges the request within three business days and delivers the records electronically within ten days — well inside the 30-day HIPAA deadline — at no charge, because the records are already in digital format.
Her new endocrinologist also needs the thyroid ultrasound images from a hospital radiology department where Diane had a scan. That hospital is a separate covered entity, so Diane completes a HIPAA authorization form there, specifying the scan date, the receiving provider, the purpose (continuing care), and an expiration of 90 days. The radiology department transmits the images directly.
Weeks later, Diane notices a line in her Explanation of Benefits that suggests her records were shared with an entity she does not recognize. She contacts HHS OCR online, submitting a brief description of the discrepancy and requesting an investigation. The process — from initial records transfer to complaint — all flows through HIPAA’s structured rights and mechanisms, none of which required her to hire a lawyer or pay extra fees.
Step by step: requesting your medical records
- Identify which covered entity holds the records you need. Each provider or facility maintains its own records — your primary care practice, the hospital where you were admitted, and the imaging center that did your MRI are each separate custodians.
- Obtain the records request form. Contact the medical records department by phone, in person, or through the patient portal. Most practices have a standardized form; some accept a written letter if no form is provided.
- Specify what you want. Describe the date range, record types (visit notes, lab results, imaging reports, billing records), and the format you prefer — electronic is usually faster and often free.
- Indicate where to send the records. If you want them sent directly to another provider, include that provider’s name, address, and fax or secure email. If you want them sent to yourself, provide your mailing address or email.
- Present identification when submitting. Government-issued photo ID is typically required to confirm you are the patient or an authorized representative. If requesting on behalf of another person, bring documentation of your authority (power of attorney, guardian documents, or parental consent forms for a minor).
- Note the date of submission. The 30-day compliance clock starts when the covered entity receives your request. Keep a copy of the request and any confirmation number or receipt.
- Follow up if the deadline passes. If you have not received the records or a written extension notice within 30 calendar days, contact the medical records department in writing and reference your original request date.
Documents and terms you’ll see
When navigating HIPAA and your medical records, you will encounter documents and terms including:
- HIPAA — The federal law governing the privacy and security of protected health information held by covered entities
- Protected Health Information — Any individually identifiable health information held or transmitted by a covered entity or its business associates
- Covered Entity — A healthcare provider, health plan, or clearinghouse required to comply with HIPAA’s Privacy and Security Rules
- Business Associate — A vendor or contractor that handles protected health information on behalf of a covered entity, bound by HIPAA through a formal Business Associate Agreement
- Right of Access — Your legal entitlement under HIPAA to inspect and obtain copies of your own health information from a covered entity’s Designated Record Set
- Designated Record Set — The specific set of records a covered entity uses to make decisions about you, and the scope of your right-of-access request
- Authorization — A signed document permitting a covered entity to use or disclose your protected health information for a purpose not covered by the treatment, payment, or operations exceptions
Key terms
| Term | Plain meaning | Glossary |
|---|---|---|
| HIPAA | Federal law governing the privacy and security of your protected health information | → |
| Informed consent | Your agreement to a treatment or procedure after receiving clear information about it | → |
| Discharge | The formal process of leaving a hospital or inpatient setting | → |
| Inpatient | A patient formally admitted to a hospital, as opposed to an outpatient setting | → |
| Outpatient | Care provided without a formal hospital admission | → |
Common questions
- How long does a provider have to give me my medical records?
- Under HIPAA, covered entities must provide access to your medical records within 30 calendar days of your request. If they cannot meet this deadline, they may extend by 30 more days with written notice explaining the reason and the expected completion date. Requests must generally be fulfilled in the format you request if it is readily producible.
- Can a provider charge me a fee for my records?
- Yes, but only a reasonable, cost-based fee. HIPAA allows providers to charge for copying costs, postage, and labor to prepare the records. Fees vary by state and provider — some states limit what providers can charge, and many providers provide electronic records at no charge through patient portals.
- Who else can access my medical records?
- HIPAA allows providers to share your health information for treatment, payment, and healthcare operations without your specific authorization. They can share with other providers treating you, with your insurer for billing, and for defined operational purposes. For most other uses — including sharing with your employer, a family member, or a researcher — they generally need your written authorization.
- What is a HIPAA authorization form?
- A HIPAA authorization is a form you sign allowing a covered entity to use or share your health information for a specific purpose not covered by the standard treatment, payment, and operations exceptions. Examples include releasing records to your attorney, to a specific family member, or for use in research. The authorization must specify what information is shared, with whom, for what purpose, and for how long.
- What if I believe my privacy rights were violated?
- File a complaint with the HHS Office for Civil Rights (OCR), which enforces HIPAA. Complaints must be filed within 180 days of when you discovered the violation. OCR investigates complaints and can impose civil money penalties on covered entities that violate HIPAA. You can also contact your state attorney general's office for state-level privacy laws.
- What is a Designated Record Set?
- A Designated Record Set (DRS) is the set of records maintained by or for a covered entity that is used to make decisions about individuals. For providers, it includes medical and billing records. For health plans, it includes enrollment, payment, and claims adjudication records. Your HIPAA right of access applies specifically to information in the Designated Record Set, not to every document a provider may hold about you.
- Can a covered entity ever deny my records request?
- Yes, but only in narrow circumstances. Permitted grounds include: the requested information consists of psychotherapy notes; it was compiled in reasonable anticipation of litigation; or access could endanger your life or another person's safety. If denied, the entity must provide a written explanation. Some denials are reviewable — you may request that a licensed healthcare professional not involved in the original decision review the denial.
- How do I request a correction to my medical records?
- HIPAA gives you the right to request an amendment if you believe your protected health information is inaccurate or incomplete. Submit the request in writing to the covered entity's medical records department. The entity has 60 days to respond (extendable by 30 days with notice). If denied, the entity must explain why, and you may submit a statement of disagreement that becomes part of your permanent record and is attached to any future disclosures.
- What is a Notice of Privacy Practices?
- A Notice of Privacy Practices (NPP) is a document that every covered entity must provide to patients explaining how it uses and discloses protected health information, what your HIPAA rights are, and how you can exercise them. Providers must offer the NPP at your first visit; you are not required to sign an acknowledgment, but many offices ask you to sign confirming you received it. The NPP is also available on the provider's website under most circumstances.
Sources
Last reviewed: September 2026