Yes, medical records can be mailed. Under the HIPAA Privacy Rule, doctors, hospitals, clinics, pharmacies, and health plans must give you access to the health information they hold about you, and that includes sending a paper copy by mail to whatever address you provide.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information You submit a written request, the provider has 30 days to act, and the fee is limited to the actual cost of copying, supplies, and postage.
How to Ask a Provider to Mail Your Records
A provider is allowed to require your request in writing, but only if it has told you about that requirement in advance.2eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information Most offices keep a release form at the front desk or on their website. Whatever form you use, it needs to cover:
- Your full legal name, date of birth, and contact information.
- The dates of service and the types of records you want — for example, lab results, imaging, clinical notes, or billing records.
- The mailing address where the copy should go. If you’re sending records to a third party such as another doctor or an attorney, list that person’s name and address instead.
- Your signature and the date.
The request usually goes to the provider’s Health Information Management department. If the address isn’t listed on the website, the front desk can point you to it. Many providers will also accept the request through a patient portal, which tends to move faster than paper.
You can specify the format you want. If you ask for paper copies by mail, any provider should be able to accommodate that. If you want an electronic copy and the records are already stored electronically, the provider has to deliver them in the electronic format you asked for when that’s feasible, or in another electronic format you both agree on.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information
What Happens Between the Mailroom and Your Door
When a provider mails your records, HIPAA requires reasonable safeguards to protect the information in transit.3eCFR. 45 CFR 164.530 – Administrative Requirements In practice, only your name and address should appear on the outside of the envelope. No diagnosis codes, no department names that hint at the type of care, no clinical information showing through a window. Overstuffed envelopes that let pages shift into view are the kind of mistake that turns into a privacy violation.
If your file is thick — years of chart notes, imaging reports, hospital records from multiple stays — mailing is not always the best option. Certified mail with delivery tracking adds some security. Electronic delivery through a patient portal or encrypted email avoids the mailing risk entirely, and picking the records up in person is often quickest for a short file.
What a Provider Can Charge You
Providers can charge a fee, but only a reasonable, cost-based one. HIPAA limits what can go into the fee to three things: the labor to actually copy the records, the supplies (paper, a CD, a USB drive), and postage if you want them mailed.4U.S. Department of Health and Human Services. May a Covered Entity Charge Individuals a Fee for Providing the Individuals with a Copy of Their PHI What they cannot charge for is the time spent searching for or retrieving the records. Search-and-retrieval fees used to be routine, and some billing offices still slip them in.
For electronic copies of records that are already stored electronically, providers have a shortcut: a flat fee of up to $6.50 covering labor, supplies, and postage combined.5U.S. Department of Health and Human Services. Clarification of Permissible Fees for HIPAA Right of Access That $6.50 is not a cap on all requests. Paper copies of long files, calculated at per-page rates plus postage, will run higher. If a bill looks steep, ask for an itemized breakdown and check it against the three allowable categories.
How Long a Provider Has to Respond
The provider must act on your request within 30 calendar days of receiving it. Acting means either sending the records or sending you a written denial that explains why.2eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information If more time is needed, the provider can extend the deadline once by up to 30 additional days, and only if it sends you a written explanation and a new completion date before the first 30 days run out.
Simple requests often come back in a week or two. Complex ones, especially those spanning multiple departments or several years, tend to press against the deadline. If 30 days pass with no records and no extension notice, the provider is out of compliance.
When a Provider Can Refuse
Refusing to mail your records because it’s inconvenient, or because staff worry you’ll misunderstand or be upset by what you read, is not permitted. The valid grounds for denial are listed in federal regulation.6eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information They split into two groups.
Some denials are final. A provider can deny access without offering review when the material is a therapist’s psychotherapy notes kept separate from the main chart (routine mental health records don’t qualify), when the material was compiled for use in a legal proceeding, when the requester is an inmate and release would threaten institutional safety, when you agreed to suspend access while enrolled in a clinical trial, or when the information came from a confidential source and releasing it would likely identify that source.
Other denials come with an appeal built in. A licensed health professional can decide that releasing the records is reasonably likely to endanger your life or physical safety, or someone else’s, and that finding supports a denial. The same applies when a record references another person and disclosure could cause substantial harm to that person.1U.S. Department of Health and Human Services. Individuals’ Right under HIPAA to Access their Health Information Emotional discomfort is explicitly not enough. When you get a denial in this category, you can ask for a second opinion from a different licensed professional who wasn’t involved in the original decision, and that reviewer decides whether the denial stands.
If a Provider Won’t Cooperate
When a provider ignores your request, misses the deadline without notice, charges more than HIPAA allows, or denies access on grounds that don’t fit the regulation, you can file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights through its online complaint portal. Anyone can file, not just the patient.7U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint OCR has brought enforcement actions and imposed financial penalties in right-of-access cases.
For electronic records, a second law adds pressure. The 21st Century Cures Act prohibits “information blocking” — practices that interfere with the access, exchange, or use of electronic health information unless the practice is required by law or fits a specific regulatory exception.8HealthIT.gov. Information Blocking Since mid-2024, providers found to have committed information blocking face Medicare-related disincentives, including reduced Medicare payment updates for hospitals, a zero score in the MIPS Promoting Interoperability category for clinicians, and disqualification from Medicare Shared Savings Program participation for at least a year.9Federal Register. 21st Century Cures Act – Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking Naming the Cures Act in a follow-up conversation with a records office often changes the tone.
One Limit Worth Knowing
Your right to have records mailed only applies while the records still exist. There is no single federal rule setting a universal retention period for clinical records. Medicare requires participating hospitals to retain records for at least five years, and HIPAA requires covered entities to keep certain compliance documentation for six years, but state law does most of the work here, and requirements typically range from five to ten years depending on the state, the type of provider, and whether the patient was a minor. If you might need older records, request them sooner rather than later. Once the retention period expires, the provider may destroy them.