Few administrative tasks carry as many ways to go wrong as releasing medical records. A request arrives by fax, email or in person. It might come from a resident, a family member, an attorney, an insurer or another provider. Each has different rights, each expects a response within a deadline, and sending the wrong thing to the wrong person is a privacy violation. Facilities that handle requests informally, through whoever happens to be at the desk, tend to struggle with both speed and accuracy.
A defined process and a few tools can fix that. This post outlines one, in general terms. Specific rules depend on federal and state law and on the type of request, so work with your compliance officer or counsel to confirm requirements.
Under the HIPAA Privacy Rule, individuals generally have a right to access their own health information, and covered entities must respond within a set period, with limited extensions allowed. Other requesters, such as attorneys or family members, may need a valid written authorization or may be covered by a specific legal exception. State law can add requirements for timing, fees and format. Confirm the current rules that apply to you and write them into your procedure.
Assign one person, with a backup, to manage requests, often the medical records or health information coordinator. Train that person and anyone who may receive a request at the front desk or on the unit to route it immediately.
Record the date received, the requester, what was asked for, the due date, and who is handling it. A spreadsheet works for small volumes, and a tracking tool works for larger ones. The log protects you if timeliness is ever questioned.
Before releasing anything, confirm who is asking and whether they are entitled to the information. Check authorization forms for completeness: the right resident, a clear description of what may be released, who may receive it, a signature and a date. For representatives, confirm their legal authority and keep a copy.
Release the minimum necessary when the request is not for the individual's own access, and the specific scope when the request is limited. Review the record before sending, with a clinician or privacy officer where needed.
Choose a method that protects the information:
Secure electronic delivery, such as an encrypted portal or encrypted email, where available
Encrypted media for large files, with the password sent separately
Mail or in-person pickup with identification checks
Fax only after verifying the number, and with a cover sheet
Never send records to an unverified email address, and double-check recipient details before sending.
Note what was sent, when, how, to whom and under what authority. Retain the request, authorization and log according to your retention policy.
Set internal due dates well ahead of the legal limit, and review the log each morning. Escalate stalled requests to the administrator. If an extension is allowed, send the notice required and record it.
Look at what your systems can do to reduce manual work:
Electronic export of record sections to a standard format
A patient or resident portal, where appropriate
Templates for authorization checks, cover letters and responses
Role-based access so only the records team can export complete charts
Audit logs showing who accessed or exported records
Avoid ad hoc copies saved to desktops and shared drives. Anything exported should be stored briefly and deleted when no longer needed.
Releasing records for the wrong resident, often from similar names
Including pages from other residents in a combined scan
Sending information to a fax number that was not verified
Releasing information beyond what the authorization allows
Missing a deadline because the request sat in an inbox
Spot checks of completed requests, done by a second person, catch many of these.
Short annual training on how requests are handled, who can approve them and how to report a mistake keeps the process alive. If something is sent wrongly, report it immediately so your privacy officer can assess whether it is a breach.
UnityCare IT helps healthcare and long-term care organizations in Oklahoma, Texas and Arkansas set up secure delivery, access controls and audit reporting that support records release.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172