Patient Records Requests in Behavioral Health: Meeting the HIPAA 30-Day Access Clock


Most behavioral health programs treat a patient’s request for their own records as a front-desk task. Surveyors, payers and the HHS Office for Civil Rights (OCR) treat it as a compliance obligation with a hard clock, and a late or improperly narrowed response is one of the easiest privacy complaints for a former patient to file and for an investigator to prove. The paper trail either shows the date the request arrived and the date it was fulfilled, or it does not.

This is operational guidance for owners, clinical directors and compliance officers, not legal advice. State law, accreditors and payer contracts may add requirements.

The 30-Day Clock Behavioral Health Programs Keep Missing

Under the HIPAA Privacy Rule, a behavioral health program that is a covered entity must act on a patient’s request to access or get a copy of their own records no later than 30 calendar days after the request is received. The program may take one extension of up to 30 additional days, but only if, within the original 30 days, it gives the patient a written notice explaining the reason for the delay and the date it will respond. There is no second extension. OCR explains these timing rules in its guidance on the individual right of access.

Thirty days sounds generous. In practice it disappears, because the clock starts when the program receives the request, not when the person who processes records finally sees it. A request faxed to a residential house on a Friday, left in a therapist’s inbox, or handed to a tech on the night shift has already started running.

Why Access Requests Go Late: The Five Failure Points

When we review access logs during mock surveys, late requests almost always trace to the same process gaps.

Unlogged intake points: Requests arrive by fax, email, patient portal, phone and in person at sites that have no instruction to date-stamp and forward them the same day.

Clinical review as a hidden hold: A clinician is asked to “look over the chart first,” the chart sits in their queue, and nobody owns the deadline while it waits.

The wrong form: Staff tell the patient to complete a HIPAA authorization or come in person, which the right of access does not require, and the request stalls while the patient goes back and forth.

Archived records: Alumni ask for records from a prior EHR or a closed location, and no one knows who holds the login or the storage vendor contract.

No extension letter: The program realizes on day 35 that it needed more time, which is five days too late to send the one extension notice the rule allows.

What Patients Are Entitled To, and What You May Withhold

The right of access covers the patient’s designated record set: the clinical record, billing records and other records used to make decisions about them. In behavioral health that includes assessments, treatment plans, progress notes, medication records and discharge summaries. A program may not require the patient to explain why they want the records, and it may not withhold records because the patient has an unpaid balance.

Programs may require requests in writing if they tell patients so, typically in the Notice of Privacy Practices, but may not add obstacles such as notarization or an in-person visit.

There are a limited number of grounds for denial. Some are not reviewable. The best-known in this field is that psychotherapy notes are excluded from the right of access entirely. Others are reviewable: for example, when a licensed health care professional determines, in the exercise of professional judgment, that access is reasonably likely to endanger the life or physical safety of the patient or another person. A reviewable denial must be in writing, must explain the basis and the patient’s review rights, and, if the patient asks, must be reviewed by a licensed professional the program designates who did not participate in the original decision. Even when part of a record is withheld, the rest must be provided.

The Psychotherapy Notes Trap

This is where behavioral health programs most often get the rule backwards. HIPAA defines psychotherapy notes narrowly: notes a mental health professional records to document or analyze the contents of a counseling session and that are kept separate from the rest of the medical record. Medication records, session start and stop times, treatment modalities, test results, diagnosis, functional status, treatment plan, symptoms, prognosis and progress summaries are excluded from that definition.

The operational truth we see repeatedly: many EHRs have a note template labeled “psychotherapy note” that is stored in the same chart, printed in the same record and visible to billing and utilization review staff. Those notes are not psychotherapy notes for HIPAA purposes, because they are not kept separate, and they are part of what the patient is entitled to receive. A program that withholds them on that basis has made an improper denial. If your clinicians rely on the exclusion, confirm with your EHR vendor that the notes live in a genuinely segregated location with restricted access, and document that configuration.

Fees, Format and Third-Party Requests

Programs may charge patients a reasonable, cost-based fee for copies, limited to certain labor for copying, supplies, postage, and preparing a summary if the patient agrees to one. Fees for searching for or retrieving records are not permitted. OCR’s guidance also describes an optional flat fee of up to $6.50 for electronic copies of records maintained electronically. Many programs simply charge nothing for patient requests, which removes an entire category of complaint.

If the patient asks for a particular form and format, such as a PDF or paper, the program must provide it if readily producible, and records maintained electronically must be available as an electronic copy.

Substance use disorder records add a layer. SAMHSA’s 42 CFR Part 2 guidance is the place to confirm the details, but in general terms Part 2 does not stop a program from giving patients their own records. Sending Part 2 records to a third party at the patient’s direction, however, is a disclosure, and it needs a written consent that meets Part 2’s requirements. Run third-party requests for SUD records through your consent workflow, not just your HIPAA access workflow.

What OCR Enforcement Tells Operators

OCR launched its Right of Access Initiative in 2019 and has since announced dozens of resolution agreements and civil money penalties against providers of every size. The resolution agreements are published on OCR’s enforcement page, and they read like a checklist of the failures above: requests that sat for months, partial records sent without explanation, and repeated follow-ups from the patient that went unanswered. The underlying problem is rarely the first missed deadline; it is the lack of any log showing the program knew about the request at all.

Build the Access Log This Week

You can close most of this gap in a few days. Pull the last ten records requests your program received, from every location, and for each one write down the date received, the date fulfilled, who handled it, and whether anything was withheld and why. If you cannot find ten, or cannot find the received dates, that is your finding.

Then set up a single access log with these fields, and make it the only place requests are tracked:

  • Date and channel received, and the site that received it
  • Day-25 checkpoint, so an extension letter can go out before day 30 if needed
  • Records provided, form and format, and delivery method
  • Any portion withheld, the denial ground, and the date the written denial was sent
  • Whether Part 2 records were involved and, for third-party requests, the consent on file
  • Fee charged, if any

Finally, give every intake point one written instruction: date-stamp any records request the day it arrives and route it to the privacy officer that day. Add it to orientation and annual privacy training.

If you want an outside review of your access process, your psychotherapy notes configuration or your broader privacy program, our behavioral health compliance services team can assess it against HIPAA and Part 2. Programs without a dedicated privacy lead often assign this work to a fractional compliance officer. You can also start with our HIPAA compliance checklist. Call (888) 458-6619 to talk with our compliance team.

Frequently Missed Details

Does the clock pause while a clinician reviews the chart? No. Any clinical review happens inside the 30 days, and only a written extension notice sent within that window buys more time.

What about requests from parents of adolescent patients? Whether a parent is a personal representative depends heavily on state law, particularly for minors who can consent to their own mental health or SUD treatment. Settle this in policy with counsel before the request arrives.

Questions about a specific request that is already running late? Call us at (888) 458-6619.

We will be happy to hear your thoughts

Leave a reply

Som2ny Network
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart