HIPAA Medical Records Request Template
Four documents and three sheets that route every request by legal basis, because the deadline, the fee cap and the logging duty come apart.
Free download · No account needed
Request Register, routing table
Four duties, and each one changes at a different row
Six months at a fictional practice, Bellhaven Family Medicine. 246 requests, one intake queue, one fee schedule, no log.
| Pathway | Reqs | 30 days | Fee cap | Min nec | Logged |
|---|---|---|---|---|---|
| Access, copy to the individual | 121 | Yes | Yes | No | No |
| Access by directive, electronic copy | 19 | Yes | No | No | No |
| Authorization | 77 | No | No | No | No |
| Required by law | 8 | No | No | No | Yes |
| Permitted without authorization | 21 | No | No | Yes | Yes |
| Total | 246 | Five profiles, no two alike | |||
136 of 246carried at least one obligation the single queue got wrong
19 on a 30-day clock nobody was counting. 88 invoiced with a retrieval line the cap does not permit. 29 accountable disclosures never logged. The queue was not broken. It had one column too few.
Remaining columns: Received, Capacity, Copy Goes To, Format, Attached, Act By, Extension Letter By, Deadline Source, Verified, Scope Set, Owner.
Every guide to the HIPAA medical records request process teaches the same two rules: act within 30 days, and cap the fee. Both are real. Both belong to one pathway out of five, and a records office runs one queue across all of them. Four separate obligations attach to a request, the legal basis it arrives under decides which apply, and no two pathways carry the same four. Read them down and they invert against how urgent each request feels.
The routine one a receptionist handles is on a hard clock with a fee capped to four permitted costs, and nothing about it ever needs logging. The subpoena that feels urgent has no HIPAA deadline and no HIPAA fee cap, is limited to the minimum necessary, and is the one that has to be written down for six years. One field decides all four, and almost nobody records it.
Bellhaven Family Medicine took 246 requests in six months through a single queue. Re-triaged by pathway, 19 were on a 30-day clock nobody was counting, 88 were invoiced with a retrieval line the cap does not permit, and 29 accountable disclosures were never logged at all. That is 136 of 246, 55 percent, carrying at least one obligation the queue got wrong. The queue was not broken. It had one column too few. Records arriving from elsewhere run the other direction, and an outside records chronology handles those.
What's in the pack
Request Register
One row per request carrying the pathway and all four consequences that fall out of it. Two date columns on every access row: the day action is due, and the last day a written extension can still go out.
Request Procedure
The written procedure, built around the routing table rather than around a workflow. It names the designated record sets and the office responsible, both of which the rule requires documented, and sits alongside the wider HIPAA policy set. What lands in that set starts at the front desk, and every unjustified field on the patient intake form is one more thing that has to be produced. Care plans are the part of the record with their own review and signature deadlines, tracked in the care plan documentation pack.
Fee Schedule Note
Your own schedule mapped line by line to labor for copying, supplies, postage or an agreed summary. The lines that map to nothing are the exposure, and the rows the cap never reached are the discount nobody had to give.
Authorization Verification Checklist
Worked element by element rather than signed off as a whole, because a form missing a required element is not an authorization. Includes the two routing traps that send a 30-day request into a queue with no clock.
Response Letter
Four letters, because a records office sends four kinds and three of them carry required content. The extension letter has its own deadline, inside the first 30 days, and a letter sent after that is a late notice.
Release Log
Written in the shape of an accounting: date, recipient with address if known, what was disclosed, and the purpose. The artifact a patient can demand becomes a filter over the log rather than a reconstruction from memory.
Denial and Redaction Log
The ground for each withholding, whether review rights attach, and where a judgement-based ground was used, the named licensed professional who made the determination. A reviewable denial without one is not a valid denial.
Records Request Deadline and Accounting Watch
A weekly pass that leads with the extension windows closing this week rather than the 30-day dates, then directives sitting in the wrong queue, unmapped fee lines, and accountable disclosures missing an element.
How to use it
- 1
Open in River, or download it
Open the pack in River and let the agent route your live queue, or download the blank Word and CSV files instantly and work through them yourself.
- 2
Route before anything else
Four fields decide the row: who asked in their own capacity, what was attached, who receives the copy, and what format is going from where the content lives.
- 3
Set two dates on every access row
The day action is due, and the last day an extension can go out. The second one is inside the first 30 days and it is the date worth watching.
- 4
Log the release, not the request
Four elements on every row as it goes out. That is what turns an accounting request from a week of archaeology into a filter over a sheet you already keep.
Frequently asked questions
Is this template free?
Yes. Download the whole pack as Word documents and CSV sheets with no credit card. "Edit with AI" is a separate, optional path for practices that want the agent to route their live queue and compute both dates on every row. Other packs are in the template library.
What format are the downloaded files?
Word documents (.docx) for the procedure, the fee note, the verification checklist and the letters, and CSV (.csv) for the three sheets, zipped into one file. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets.
Why does the fee cap not apply to a third-party directive?
Because a court said so. In 2020 the fee limitation was held to apply only to an individual's request for their own records and not to a request to transmit records to a third party. The 30-day clock still runs, so the two rules come apart on that row.
How can a subpoena have no HIPAA deadline?
Because the Privacy Rule sets a deadline only on the access pathway. A subpoena's date comes from the court or the requester. What the rule does impose is a precondition: without a court order behind it, disclosure needs satisfactory assurance of notice or a protective order first.
Do we have to log every disclosure we make?
No, and that is the point. Treatment, payment and operations are out. Disclosures to the individual are out. Disclosures under an authorization are out. What is left is mostly the permitted-without-authorization pathway, which is also where minimum necessary applies and the whole chart usually goes anyway.
Does this pack decide whether a disclosure is permitted?
No. It routes, tracks, prices, scopes and logs. Whether a disclosure is permitted, whether a denial ground applies and how to read a subpoena are for your privacy officer and, where compulsion is involved, counsel. The security risk analysis those roles also own is a separate pack.
What if our state law is stricter?
Then it governs, on whichever of the four columns it reaches. Several states cap copying fees below the federal permitted costs or shorten the response window. The register records which source each date and cap came from, so a later reviewer can see the reasoning rather than infer it.
Route it first, and three of the four duties decide themselves
Download the blank pack as Word and CSV files, or open this exact pack in River and let the agent route your live queue and find the rows on a clock nobody was counting.
Edit with AI