What Is a Designated Record Set Under HIPAA?

A designated record set under HIPAA is the group of records a covered organization uses to make decisions about you: your medical charts, billing files, insurance enrollment and claims data, and any other records the organization actually relies on when deciding your care or coverage. It matters because your right to see, copy, and correct your health information is tied directly to what sits inside this set. If a record is in it, you generally have access. If a record is outside it, HIPAA’s access and amendment rights do not reach it.

What’s Inside a Designated Record Set

The federal regulation at 45 CFR 164.501 defines a designated record set across three categories, each keyed to the type of organization holding the information.1eCFR. 45 CFR 164.501 – Definitions

  • Medical records and billing records about you maintained by or for a healthcare provider. Medical records cover diagnoses, treatment plans, progress notes, lab results, and imaging. Billing records cover charges, payments, and insurance claims.
  • Enrollment, payment, claims processing, and case or medical management records maintained by or for a health plan such as a private insurer, Medicare, or Medicaid.
  • Any other group of records the covered entity uses, in whole or in part, to make decisions about individuals.

That third category is the reason the definition sweeps so widely. Wellness program files, disease management notes, clinical case records, and even records that came in from a different provider can qualify if your current covered entity uses them to make decisions about your care or coverage.2Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

Format does not matter. A “record” under the rule is any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity. Paper charts, electronic health records, scanned images, and archived files all count.1eCFR. 45 CFR 164.501 – Definitions

What Falls Outside

Some records held by a covered entity are not part of the designated record set, and two categories are expressly carved out of your right of access even where they otherwise would be.

  • Psychotherapy notes. Personal notes a mental health provider writes during or after a counseling session and keeps separate from the rest of your medical record are excluded from the right of access.
  • Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative proceeding is also excluded.3eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Beyond those exclusions, records that serve general business purposes rather than individual decision-making usually sit outside the designated record set. Quality assessment files, patient safety activity records, peer review documents, practitioner performance evaluations, and business planning materials are common examples. A peer review committee’s records may include your health information, but if the records exist to evaluate a provider’s performance rather than to make decisions about your treatment, they are not part of your designated record set.2Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

One point worth clearing up: lab results. You can request completed test reports directly from a CLIA-certified laboratory, not only from the ordering provider.4Department of Health and Human Services. HHS Strengthens Patients’ Right to Access Lab Test Reports

Who Holds Your Designated Record Set

HIPAA places the obligation on “covered entities”: healthcare providers who electronically transmit health information (hospitals, physician practices, clinics, pharmacies), health plans (private insurers, HMOs, Medicare, Medicaid), and healthcare clearinghouses that process claims data between providers and payers.

Business associates handle protected health information on behalf of covered entities, performing work like claims processing, billing, data analysis, or practice management.5eCFR. 45 CFR 160.103 – Definitions If a business associate maintains records that meet the definition, those records still count as part of the covered entity’s designated record set. You exercise your access rights through the covered entity, not by contacting the business associate.2Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

Requesting Your Records

You can inspect and obtain a copy of any protected health information about you that sits within a designated record set, for as long as the covered entity maintains it, regardless of when it was created, where it originated, or whether it’s stored on paper or electronically.2Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

How Long It Should Take

A covered entity must act on your access request within 30 days of receiving it, either by providing the records or by issuing a written denial. It may take a single 30-day extension only if it sends you a written explanation and a date by which it will finish, and that notice must arrive before the original 30 days run out.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

What You Can Be Charged

Covered entities can charge a reasonable, cost-based fee for copies, but the fee can only cover labor for copying, supplies (a CD or flash drive if you want portable electronic media), and postage if you asked for mailed copies. It cannot include costs for searching, retrieving, or maintaining the records.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

For electronic copies of records the entity already maintains electronically, HHS allows a flat fee of no more than $6.50 per request covering all labor, supplies, and postage, so the entity does not have to calculate actual costs.7Department of Health and Human Services. Is $6.50 the Maximum Amount That Can Be Charged

Getting an Electronic Copy

If you ask for an electronic copy in a specific format and the covered entity maintains the records electronically, it must provide the copy in that format if it can readily do so. If not, it should offer another readable electronic format. Paper is the fallback only when an electronic copy is not readily producible at all.8Department of Health and Human Services. If an Individual Requests an Electronic Copy

Sending Copies to Someone Else

You can direct a covered entity to send your records to a third party, such as another provider, an attorney, or a family member. The request must be in writing, signed by you, and must clearly identify who should receive the records and where to send them. A scanned or electronically signed request is acceptable.2Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information

Proving Who You Are

Before releasing records, a covered entity must verify your identity through reasonable policies if you are not already known to it. HIPAA does not prescribe a specific method.9U.S. Department of Health and Human Services. The HIPAA Privacy Rule’s Right Of Access and Health Information Technology

When Access Can Be Denied

A covered entity cannot refuse a request just because it’s inconvenient. Denials must fit specific grounds in the regulation, and some come with your right to an independent review.

Denials With No Right to Review

  • Requests for psychotherapy notes or legal-proceeding materials, which are excluded from the right of access.
  • Inmate requests, where a correctional institution or its healthcare provider concludes that providing a copy would jeopardize the health, safety, or security of the inmate, other inmates, or staff.
  • Records created during a research study you agreed to enroll in on the condition that access would be temporarily suspended; the provider can hold back that information until the research concludes.
  • Information obtained from a non-provider source under a promise of confidentiality, where release would likely reveal the source.3eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Denials You Can Have Reviewed

Three grounds carry a right to review by a different licensed health professional not involved in the original decision:

  • A licensed professional determined that giving you access is reasonably likely to endanger your life or physical safety, or someone else’s.
  • The records reference another person (not a healthcare provider), and a professional determined access would likely cause substantial harm to that person.
  • The request came from your personal representative, and a professional determined that access would likely cause substantial harm to you or someone else.3eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Reviewable denials are rare in practice. Most access requests involve routine medical and billing records where none of these safety concerns apply.

Asking for Corrections

If information in your designated record set is wrong or incomplete, you can ask the covered entity to amend it. The entity may require the request in writing with a reason, as long as it tells you those requirements in advance.10eCFR. 45 CFR 164.526 – Amendment of Protected Health Information

It has 60 days to act, with one possible 30-day extension if it sends written reasons for the delay before the initial deadline.11eCFR. 45 CFR 164.526 – Amendment of Protected Health Information

Denial is allowed on four grounds: the entity did not create the record and the originator is still available to handle the request; the record is not part of a designated record set; the record would not be available for inspection under the access rules; or the record is already accurate and complete. That last ground is the one most people run into. If you disagree, you can submit a written statement of disagreement, which must then be linked to the disputed record for future disclosures.11eCFR. 45 CFR 164.526 – Amendment of Protected Health Information

If a Covered Entity Won’t Comply

The Office for Civil Rights at HHS enforces HIPAA’s access and amendment rules. Penalties follow a four-tier structure based on the level of fault, with an annual cap of $1.5 million for identical violations in a single calendar year:

  • Did not know and could not reasonably have known: $100 to $50,000 per violation.
  • Reasonable cause, not willful neglect: $1,000 to $50,000 per violation.
  • Willful neglect, corrected within 30 days: $10,000 to $50,000 per violation.
  • Willful neglect, not corrected within 30 days: minimum $50,000 per violation.12eCFR. 45 CFR 160.404 – Amount of a Civil Money Penalty

OCR launched a Right of Access Initiative in 2019 and has since produced dozens of enforcement actions targeting providers and health plans that fail to hand over records on time. Settlements have ranged from $15,000 for smaller practices to $200,000 for larger organizations, with penalties imposed as recently as 2025.13Department of Health and Human Services. Resolution Agreements

If a covered entity ignores or unreasonably delays your request, you can file a complaint with OCR online at no cost. That complaint is what triggers an investigation and the potential penalties above.