A designated record set under HIPAA is the group of records a covered entity keeps and uses to make decisions about you: your medical records, your billing records, and, if you have coverage, your health plan’s enrollment, claims, and care management records. The definition sits at 45 CFR § 164.501, and it matters because your rights to see and correct your health information reach exactly this set of records and no further.1eCFR. 45 CFR 164.501 – Definitions
How HIPAA Defines It
The Privacy Rule describes a designated record set as a group of records maintained by or for a covered entity that falls into one of two named categories (provider medical and billing records, or health plan enrollment, payment, claims, and case management records) plus a catch-all: any other record used, in whole or in part, to make decisions about individuals.1eCFR. 45 CFR 164.501 – Definitions
That decision-making test is the whole point. If a record is used to decide what care you get, whether a service is covered, or what you owe, it’s in. Internal documents that never touch decisions about a specific patient generally aren’t.
Location doesn’t change the answer. Records a business associate holds for a covered entity (a records storage vendor, a claims processor) are still part of the designated record set, and the covered entity remains responsible for giving you access.2U.S. Department of Health and Human Services. Do Business Associates Have Obligations
What Providers Keep in It
For a doctor, hospital, clinic, or other provider, the designated record set is built around two things: medical records and billing records about individuals.1eCFR. 45 CFR 164.501 – Definitions
The medical side is broad. Diagnoses, treatment plans, physician notes, lab results, pathology reports, imaging studies, medication lists, discharge summaries, and signed consent forms all belong. Anything that documents the care you received or informs future care is in scope.
The billing side is equally in. Itemized charges, payments from you or your insurer, adjustments, and explanations of benefits all qualify, because providers rely on that information when deciding what you owe and how care is coordinated with your coverage.
What Health Plans Keep in It
A health plan’s designated record set covers enrollment records (participation dates, eligibility, demographic details), payment records (premium history), claims adjudication records showing how each claim was processed and the reasoning behind approvals and denials, and case or medical management records used to coordinate your care.1eCFR. 45 CFR 164.501 – Definitions
If your plan denied a claim or limited coverage for a procedure, the records behind that decision belong to you under this rule. So does the documentation of any prior authorization, medical necessity review, or appeals decision.
What’s Not in the Designated Record Set
Some records containing your health information sit outside your access rights, either because they aren’t part of the set or because HIPAA specifically carves them out.
Psychotherapy notes are the most misunderstood exclusion. These are notes a mental health professional records to document or analyze a counseling session and keeps separate from the rest of the medical record. The category is narrow. Medication prescriptions and monitoring, session start and stop times, treatment frequency, clinical test results, and summaries of diagnosis, treatment plan, symptoms, prognosis, and progress are specifically not psychotherapy notes, and those items stay accessible.3GovInfo. 45 CFR 164.501 – Definitions Only the therapist’s private session-by-session analysis is off limits.
Information compiled in reasonable anticipation of a legal proceeding is also excluded from access.4eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
Peer review files, quality assessment data, and business planning documents typically fall outside the set entirely because they aren’t used to make decisions about a specific individual.
Your Right to See and Copy the Records
You can inspect and obtain a copy of any protected health information in your designated record set, for as long as the covered entity maintains it, regardless of when it was created or whether it’s on paper or electronic.5U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information You can also direct the covered entity to send a copy to a third party you choose.
How Long the Response Takes
A covered entity must act on your request within 30 days. If it can’t meet that deadline, it may take one 30-day extension, but only if it notifies you in writing before the original 30 days run out, explains the reason, and gives you a date certain.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information There is no second extension.
What You Can Be Charged
Fees have to be reasonable and cost-based, and HIPAA limits what “cost” can include: the labor of copying, supplies like paper or a USB drive, postage if you asked for mailing, and the cost of preparing a summary if you requested one and agreed to the fee in advance.7U.S. Department of Health and Human Services. May a Covered Entity Charge Individuals a Fee for Providing Copies You cannot be charged for searching for or retrieving the records, verifying your identity, or reviewing the request.
For electronic copies of records that are maintained electronically, covered entities have the option of charging a flat fee of no more than $6.50, inclusive of all labor, supplies, and postage.5U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information State law can set additional limits, but it cannot be used to justify charges beyond what HIPAA allows for a direct patient request.
Your Right to Correct the Records
You can also ask a covered entity to amend information in your designated record set that you believe is inaccurate or incomplete.8eCFR. 45 CFR 164.526 – Amendment of Protected Health Information The response window is 60 days, with a single 30-day extension available if the entity notifies you in writing. The entity can require that you submit the request in writing and give a reason for the change.
An amendment request can be denied in limited situations: the entity didn’t create the record (and the original creator is available), the record isn’t part of the designated record set, the record wouldn’t be available for inspection under the access rules, or the record is already accurate and complete. If your request is denied, you have the right to file a written statement of disagreement, and the covered entity must include it with your records going forward.8eCFR. 45 CFR 164.526 – Amendment of Protected Health Information
When Access Can Be Denied
Even for records that sit squarely in the designated record set, HIPAA allows denial in specific situations, split into two groups.
Denials You Can’t Appeal Internally
These denials are unreviewable and apply on their face, without a case-by-case evaluation:
- The information is psychotherapy notes or material compiled for litigation.
- You are an inmate and providing a copy would jeopardize the safety or security of the facility, staff, or other inmates.
- You agreed to suspend access as a condition of participating in a clinical research study still in progress.
- The information is subject to the federal Privacy Act and denial meets that law’s requirements.
- The information came from someone other than a healthcare provider under a promise of confidentiality, and access would likely identify the source.
These grounds are set out in 45 CFR § 164.524.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
Denials You Can Have Reviewed
A licensed health care professional can also deny access based on professional judgment that the release would likely endanger the life or safety of you or another person, cause substantial harm to someone referenced in the records, or (when the request comes from a personal representative rather than you directly) cause substantial harm. These denials are reviewable: you can request a second review by a different licensed professional who wasn’t involved in the original decision.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
If You Get Denied or Ignored
Failure to provide access is one of the most common HIPAA complaints filed with the HHS Office for Civil Rights, and OCR has pursued a series of enforcement actions specifically over delayed and denied records requests.9U.S. Department of Health and Human Services. Enforcement Highlights10U.S. Department of Health and Human Services. Five Enforcement Actions Hold Healthcare Providers Accountable
If a covered entity denies your request or lets the deadline pass, you can file a complaint with OCR through its online portal or in writing.11U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint OCR investigates and can require corrective action, negotiate a settlement, or impose civil money penalties. In practice, filing the complaint is often enough to get the records released.