On August 27, 2026, the Office for Civil Rights (“OCR”) at the U.S. Department of Health and Human Services (“HHS”) announced its resolution of an investigation into a California-based health care provider’s potential violation of the Health Insurance Portability and Accountability Act (“HIPAA”) Privacy Rule’s right of access provisions. This resolution brings the total to 55 enforcement actions under OCR’s Right of Access Initiative. We expect that number will continue to grow, given OCR’s continued focus on HIPAA’s access requirements and patient empowerment regarding their health information.
Summary of Enforcement Action
A health care provider offering optometry and ophthalmology services must pay $50,000 and enter into a corrective action plan with OCR after failing to provide an individual with timely access to her protected health information (“PHI”). The individual submitted her records request in January 2023 and filed a complaint with OCR in April 2023, but ultimately did not receive access to her health information until January 2025—almost two years after her initial request, and only after OCR initiated its investigation. OCR alleged that the provider failed to take timely action in response to the individual’s right of access request in accordance with the HIPAA Privacy Rule’s right of access standard.
Under the terms of the resolution agreement, the provider agreed to a corrective action plan with OCR that requires it to submit to monitoring for two years, requires it to review and revise, as necessary, its written policies and procedures to comply with the Privacy Rule and requires it to regularly report to OCR on its compliance efforts.
Timely Access to Records & Scoping Issues
The HIPAA Privacy Rule’s right of access provisions require that individuals, or their personal representatives, have timely access to PHI in the designated record set—generally within 30 days of the request, with the possibility of one 30-day extension for cause. See 45 CFR 164.524. OCR enforces the Privacy Rule, which establishes national standards to protect individuals’ health records, sets limits and conditions on the uses and disclosures of PHI and gives individuals the right to obtain a copy of their health records for a reasonable cost.
One of the most persistent sources of noncompliance under HIPAA’s right of access enforcement is an organization’s failure to timely produce the entirety of the designated record set, an error that frequently stems from difficulty in ascertaining the scope of information falling within the definition of “designated record set.” HIPAA defines designated record set at 45 CFR 164.501 as “a group of records maintained by or for a covered entity that is: (i) The medical records and billing records about individuals maintained by or for a covered health care provider; (ii) The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or (iii) Used, in whole or in part, by or for the covered entity to make decisions about individuals.” For purposes of this definition, the term record means any item, collection or grouping of information that includes PHI and is maintained, collected, used or disseminated by or for a covered entity. Notably, subsection (iii) of the definition is its own standalone category, is somewhat ambiguous, and could be interpreted quite broadly. Given that both the HIPAA Regulations and the Information Blocking Regulations define the parameters of their respective access rights based on the definition of designated record set in HIPAA, a health care provider’s ability to ascertain and define all information within its systems that comprise a designated record set has never been more necessary for ensuring compliance. Helpfully, guidance from the Office of the National Coordinator for Health Information Technology (“ONC”), which enforces the Information Blocking Regulations, issued a blog post that stated that what comprises the designated record set could be somewhat different from covered entity to covered entity based on a variety of factors – the services they are providing, the health information systems they are using, their documentation policies and procedures, etc.
Given the significant regulatory compliance obligations associated with the designated record set, and the increased enforcement focus by both OCR and ONC on timely access requirements that depend on proper designated record set identification, covered entities should consider reviewing their designated record set definitions, policies and inventories. Such a review can help confirm that these materials are accurate, complete and aligned with each of the three categories included within the HIPAA definition of a designated record set.
Covered entities should use caution when assessing policies that may use older terminology, such as “legal medical record” or “legal health record,” as such terms may be interpreted as only applying to a subset of the records that make up the designated record set. Any such policies should be drafted in a manner to draw appropriate distinctions if subcategories of the designated record set are being addressed. Because the scope of the designated record set now also carries interoperability implications, an organization must clearly understand the components of its designated record set that exist in electronic systems so that it can appropriately assess requests for electronic access and which implicate information blocking considerations.
As health care data regulation continues to evolve, organizations may want to consider whether prior organizational policies addressing data subsets, like the legal health or medical record, remain useful in context or introduce additional compliance risk.
Practical Takeaways
The HIPAA Right of Access Initiative is focused on improving compliance with 45 CFR 164.524, so all covered entities should ensure that they are able to provide timely access to PHI in the designated record set or, if an exception applies, a timely denial notice. This settlement illustrates that OCR continues to pursue enforcement where individuals experience lengthy delays in receiving access—here, a delay of nearly two years. Given that a number of the investigations under this OCR initiative continue to deal with inability to timely produce what OCR considers to be records within the designated record set, and given that access under the Information Blocking Regulations and enforcement by ONC also relies on understanding the content of the designated record set, having a written definition, policy or inventory of the contents of the covered entity’s designated record set is a key compliance document that should be regularly updated and revisited, particularly as health information systems change. Covered entities are encouraged to:
- Review and update policies and procedures governing the intake, tracking and fulfillment of right of access requests to confirm they align with the Privacy Rule’s timing requirements;
- Ensure the designated record set within the organization is clearly defined and scoped to ensure obligations can be met for a patient who exercises their access rights under HIPAA; and
- Train staff on how to identify, route and timely respond to records requests from patients and their personal representatives.
If you have any questions or would like additional information about this topic, please contact:
- Stephane Fabus at (414) 721-0904 or sfabus@hallrender.com;
- Emily Beukema at (248) 457-7882 or ebeukema@hallrender.com; or
- Your primary Hall Render contact.
Hall Render blog posts and articles are intended for informational purposes only. For ethical reasons, Hall Render attorneys cannot—outside of an attorney-client relationship—answer specific questions that would be legal advice.