A provider can lawfully refuse to hand over your medical records only for reasons listed in 45 CFR ยง 164.524, and a HIPAA denial of medical records access must arrive in writing with a specific explanation. Some grounds are final; others entitle you to have a different licensed professional review the decision. If the denial was improper, or the provider ignores the rules for issuing one, you can file a complaint with the HHS Office for Civil Rights, which has assessed penalties as high as $2,190,294 per year for access violations.
What a Valid Denial Letter Must Say
Every denial must be in plain language and contain three things: the basis for the denial, a statement of your review rights and how to exercise them (when review is available), and instructions for filing a complaint either internally with the provider or with the Secretary of HHS.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information The letter must also identify the provider’s designated privacy contact by name or title and give a phone number.
A vague denial that fails to explain the legal basis or omits the complaint instructions is itself a regulatory violation. Keep the letter. It anchors everything that follows.
Grounds That Cannot Be Appealed Internally
Five categories of records fall outside your access right with no built-in review. If the denial cites one of these, there is no second-opinion process inside the provider’s walls; your only recourse is a complaint to federal authorities if you believe the ground was misapplied.
- Psychotherapy notes kept separately from the rest of the chart. Your treatment summaries and diagnoses are still accessible; the therapist’s private session notes are not.2eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
- Information compiled in anticipation of, or for use in, a civil, criminal, or administrative proceeding. This prevents access requests from bypassing normal discovery.2eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
- Records held by a correctional institution, where release would jeopardize the health, safety, or security of the inmate, other inmates, or staff.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
- Information obtained from someone other than a healthcare provider under a promise of confidentiality, when release would likely reveal that source.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
- Research records created during a clinical trial you are still enrolled in, but only if you agreed to suspend access when you consented. The provider must restore access when the study ends.3U.S. Department of Health & Human Services. What Does the HIPAA Privacy Rule Say About a Research Participant’s Right of Access to Research Records or Results
Grounds That Give You a Right to Review
Two denial grounds come with a built-in right to a second opinion from a different licensed healthcare professional. Both involve clinical judgment calls where reasonable professionals might disagree.
The first is a safety-based denial: a licensed professional determines that granting access is reasonably likely to endanger your life or physical safety, or that of another person.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information This is a high bar. A worry that a diagnosis might upset you emotionally does not qualify. The regulation requires a genuine risk of physical harm.
The second applies when the records reference another person and a licensed professional concludes that release is reasonably likely to cause that person substantial harm.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information This surfaces most often in family and domestic-dispute situations where disclosure could invite retaliation. The third party protected here cannot be another healthcare provider; the exception covers non-provider individuals mentioned in the record.
How to Ask for the Review
If your denial fits one of the two reviewable grounds, you have the right to ask the provider to assign a different licensed professional (someone not involved in the original denial) to look at the same clinical question again.1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
Contact the privacy officer or HIPAA compliance department listed in the denial letter. Put the request in writing. Identify the specific records you’re seeking and attach the original denial. Many providers have an internal form. Use a submission method that creates a paper trail: certified mail with return receipt, a secure patient portal that timestamps messages, or hand delivery against a signed acknowledgment.
The regulation does not fix a specific number of days for the reviewer’s decision. It requires the determination to happen “within a reasonable period of time.”1eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information If several weeks pass with no response, follow up in writing. The provider must treat the reviewer’s decision as final and grant access promptly if the reviewer overturns the original denial. Unreasonable delay can itself support a federal complaint.
When Silence Counts as a Denial
Deadlines matter as much as reasons. A provider must act on your access request within 30 calendar days of receiving it, either producing the records or issuing a written denial. The clock starts on receipt, whether the records sit on-site, with a business associate, or in off-site storage.4U.S. Department of Health & Human Services. How Timely Must a Covered Entity Be in Responding to Individuals’ Requests for Access to Their PHI
The provider can take one 30-day extension, but only by sending you a written explanation of the delay and a specific completion date before the first 30 days run out.4U.S. Department of Health & Human Services. How Timely Must a Covered Entity Be in Responding to Individuals’ Requests for Access to Their PHI Only one extension per request. A provider that lets 60 days pass without acting is in violation. OCR has treated timeliness as a priority: its Right of Access Initiative has produced at least 25 enforcement actions against providers who failed to produce records on time.5U.S. Department of Health and Human Services. Five Enforcement Actions Hold Healthcare Providers Accountable
Filing a Complaint With the Office for Civil Rights
When a denial cites an unreviewable ground you think was wrongly applied, when internal review fails, or when the provider ignores deadlines or issues a defective denial letter, you can complain to the HHS Office for Civil Rights. OCR accepts complaints through its online portal and investigates alleged Privacy Rule violations.6U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint
You have 180 days from when you knew or should have known about the violation. OCR can extend this deadline for good cause.7U.S. Department of Health and Human Services. How to File a Health Information Privacy or Security Complaint Include the provider’s name, a description of what happened, and supporting documents: the original request, the denial letter, any review request and response, and a dated log of your communications.
OCR investigates by reviewing the provider’s internal policies and the records at issue. Depending on complexity and regional caseload, the process can take months. Most cases resolve through voluntary corrective action or a formal resolution agreement in which the provider commits to compliance steps and monitoring, typically for three years.8U.S. Department of Health and Human Services. Resolution Agreements
One boundary worth naming: HIPAA applies to “covered entities,” meaning healthcare providers that transmit information electronically, health plans, and healthcare clearinghouses.9U.S. Department of Health and Human Services. Covered Entities and Business Associates A provider that never submits electronic claims or transactions falls outside HIPAA entirely, though that scenario is increasingly rare.
Penalties Providers Face
OCR can impose civil money penalties when a provider refuses to cooperate or the violation is severe. The amounts sit in four fault-based tiers, adjusted yearly for inflation. As of 2026:10Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
- Didn’t know and couldn’t reasonably have known: $145 to $73,011 per violation, with an annual cap of $49,848 for identical violations.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, capped at $2,190,294 per year.
- Willful neglect, corrected within 30 days of discovery: $14,602 to $73,011 per violation, same annual cap.
- Willful neglect, not corrected: $71,011 to $2,190,294 per violation, same annual cap.
Most Right of Access resolutions have settled well below the statutory maximums, but the tier structure means a provider that stonewalls after being put on notice faces sharply higher exposure than one that made an honest error. That gap is the reason a documented complaint often moves a stuck request faster than another letter to the privacy officer.