Under the HIPAA Right of Access Standard, What Fees May Covered Entities Charge Individuals for Copies of their PHI?

Modified on Mon, 14 Jul at 11:57 AM

DISCLAIMER: The information provided in this article, other knowledge base articles, and the Compliancy Group website do not, and are not intended to, constitute legal advice. All information, content, and materials in the Knowledge Base and on the Compliancy Group website are for general informational purposes only.


Introduction

This article discusses the fee amount that covered entities may charge individuals for copies of their medical records, and what costs can be included in that fee amount.

What is the HIPAA Right of Access Provision?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive, upon request, copies of the information in their medical and other health records maintained by their healthcare providers and health plans. This right is known as the HIPAA “right of access.”

What Fees May a Covered Entity Charge for Copies of PHI?


The Privacy Rule right of access provision permits a covered entity to impose a reasonable, cost-based fee if the individual requests a copy of their PHI (or agrees to receive a summary or explanation of the information).  The fee may include only the cost of: (1) labor for copying the PHI requested by the individual, whether in paper or electronic form; (2) supplies for creating the paper copy or electronic media (e.g., CD or USB drive) if the individual requests that the electronic copy be provided on portable media; (3) postage, when the individual requests that the copy, or the summary or explanation, be mailed; and (4) preparation of an explanation or summary of the PHI, if agreed to by the individual. 

The fee may not include costs associated with verification; documentation; searching for and retrieving the PHI; maintaining systems; recouping capital for data access, storage, or infrastructure; or other costs not listed above, even if such costs are authorized by State law.

Can a Covered Entity Change a Flat Fee for Electronic Copies of PHI Maintained Electronically?

Yes. A covered entity may charge individuals a flat fee for all requests for electronic copies of PHI maintained electronically, provided the fee does not exceed $6.50, inclusive of all labor, supplies, and any applicable postage. Charging a flat fee not to exceed $6.50 is therefore an option for entities that do not want to go through the process of calculating actual or average allowable costs for requests for electronic copies of PHI maintained electronically.

For additional information about allowable fees under the HIPAA right of access standard, please view this HHS guidance document: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html





Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article