HIPAA Right of Access Calculator
The most enforced right in HIPAA is also the cheapest one to get wrong.
A patient asks for their chart. Two questions follow, and both have precise answers in the regulation: by what date must you act, and what may you actually charge. Enter the facts of the request and this tool works out the deadline under 45 CFR 164.524(b)(2), builds the fee from only the four cost components the rule permits, applies the flat fee option where it fits, and tells you when the Ciox decision moves the request outside the patient rate. Free, private, no account.
The planner
Answer six questions, get the date and the number
Enter the date the request was received and the plan fills in. Everything runs in your browser. No dates, names, or fee figures are sent anywhere.
If you are considering a denial
A denial is still an action, so it is due by the same deadline, and it has to be in writing, in plain language, stating the basis, any review rights, and how to complain both to you and to the HHS Office for Civil Rights. These are the only grounds the rule allows.
Unreviewable grounds, 45 CFR 164.524(a)(2)
- The records are psychotherapy notes, or information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding.
- The request is from an inmate of a correctional institution for a copy, and the copy would jeopardize the health, safety, security, custody, or rehabilitation of the inmate or others.
- The information was created in the course of research that includes treatment, the individual agreed to the temporary suspension of access when consenting to the research, and the research is not yet complete.
- The records are subject to the Privacy Act and denial meets that statute's requirements.
- The information was obtained from someone other than a health care provider under a promise of confidentiality, and access would be reasonably likely to reveal the source.
Reviewable grounds, 45 CFR 164.524(a)(3)
- A licensed health care professional has determined, in the exercise of professional judgment, that access is reasonably likely to endanger the life or physical safety of the individual or another person.
- The PHI makes reference to another person who is not a health care provider, and a licensed health care professional has determined that access is reasonably likely to cause substantial harm to that other person.
- The request is made by a personal representative and a licensed health care professional has determined that access is reasonably likely to cause substantial harm to the individual or another person.
On these three the individual may request a review by a licensed health care professional who was not involved in the original decision, and the entity must abide by that reviewer's determination.
Not on either list: the individual owes you money, has not signed an authorization for their own records, will not explain why they want them, or has an open dispute with your practice. None of those is a lawful basis to withhold access.
The rule is short. The failures are operational: a front desk that routes patients into an authorization form, a records vendor applying a per page fee, a chart that sat for six weeks. Training the people who actually touch these requests is what changes the outcome.
This planner is an educational tool. It applies federal HIPAA rules and published HHS guidance to the facts you enter. It is not legal advice, it does not account for your state's medical records statute unless you supply those figures, and using it does not make an organization HIPAA compliant. Have counsel review your access policy and fee schedule.
What it covers
Six things this calculator gets right
The clock
Thirty calendar days, and the extension that most people get wrong
45 CFR 164.524(b)(2) gives you 30 days from receipt and exactly one 30 day extension, and the extension only exists if a written notice with the reason and the completion date reached the individual inside the first 30 days.
The fee
Four permitted cost components, and nothing else
Labor for copying, supplies, postage the individual asked for, and an agreed summary. The calculator has no field for search and retrieval time because that cost is not chargeable under the access right.
The $6.50 question
A flat fee option, not a universal cap
OCR offers a flat fee of no more than $6.50 for electronic copies of electronically maintained records. OCR has also said plainly that $6.50 is not a cap on all access fees. The tool tells you which of those two facts you are relying on.
After Ciox
Third-party directives are treated differently now
A 2020 federal decision vacated the expansion of the third-party directive and the guidance extending the patient rate to it. Change who the copy is going to and the fee analysis changes with it.
Denials
Five unreviewable grounds, three reviewable ones
The full list from 164.524(a)(2) and (a)(3), plus the reasons people actually give that are not on either list, like an unpaid balance.
State law aware
It asks rather than assumes
Many states set shorter deadlines or lower fee caps, and under 45 CFR 160.203 the more stringent rule wins. This tool does not invent a figure for your state. Enter yours and it recalculates.
The full picture
Why a six dollar fee dispute becomes a federal enforcement action
The right, and why it is unlike the rest of the Privacy Rule
Most of the Privacy Rule tells a covered entity what it may not do. 45 CFR 164.502(a) is a prohibition with exceptions cut into it. The individual right of access at 45 CFR 164.524 runs the other direction. It is an affirmative obligation with a date attached to it, and the obligation belongs to the individual rather than to a regulator, which is why it produces complaints at a rate nothing else in the rule matches.
The scope is set by two defined terms. An individual has a right to inspect and obtain a copy of protected health information about them in a designated record set, for as long as that information is maintained. Designated record set is the phrase that does the work. It covers the medical records and billing records a provider maintains about individuals, the enrollment, payment, claims adjudication, and case management records a health plan maintains, and any other records used in whole or in part by or for the entity to make decisions about individuals. That last clause is broad, and it catches material that records departments often treat as internal. Two categories are carved out: psychotherapy notes as defined at 164.501, and information compiled in reasonable anticipation of or for use in a civil, criminal, or administrative action or proceeding.
Notice what is not a condition. There is no requirement that the individual explain why they want the records, no requirement that they be a current patient, no requirement that their account be settled, and no requirement that they sign an authorization. An authorization under 164.508 is the instrument a third party needs. An individual asking for their own chart needs nothing but a request.
The clock: thirty days, one extension, and a notice that has to actually go out
45 CFR 164.524(b)(2)(i) requires the covered entity to act on the request no later than 30 days after receipt. Acting means either providing the access or issuing a compliant written denial. Paragraph (b)(2)(ii) allows the entity to extend once, by no more than 30 days, and only if within the original period it provides the individual with a written statement of the reasons for the delay and the date by which it will complete its action on the request. One extension. Not one per request type, not one per department.
Three practical points follow from that text. The first is that these are calendar days running from receipt, and the rule contains no weekend or holiday adjustment. A request received on a Friday before a holiday week has the same 30 days as one received on a Monday. The second is that the extension is a conditional grant, not a default. Organizations frequently describe themselves as having 60 days. They do not. They have 30 days, plus a further 30 they can only claim by sending a specific written notice inside the first period, and an extension notice sent on day 34 is not an extension. It is documentation of a missed deadline.
The third is the one most likely to change behavior. The 30 days is an outer limit, not a target. HHS guidance is direct that covered entities are expected to respond as promptly as they are able, and in the modern case, where a patient asks for an electronic copy of records that already sit in an electronic health record with a patient portal attached, the gap between what the rule permits and what the technology allows is wide enough to be difficult to defend. A practice that takes 55 days to export a PDF is compliant on paper and looks obstructive on a complaint form.
The fee: four components, and the ones that are missing
45 CFR 164.524(c)(4) permits a reasonable, cost-based fee, and it enumerates what may go into it. There are four items. Labor for copying the protected health information requested, whether in paper or electronic form. Supplies for creating the paper copy or electronic media, if the individual requested the copy on portable media. Postage, when the individual has requested that the copy be mailed. And the cost of preparing an explanation or summary of the protected health information, if the individual agreed in advance to receive a summary instead of the records and agreed to the fee for it.
The list is closed, and what it leaves out is where the money usually is. Labor for searching for and retrieving the records is not chargeable. Neither is the cost of storing or maintaining the records or the system they live in, the licensing cost of the EHR, the time spent verifying identity, or the time a clinician spends reviewing the file to decide whether a denial ground applies. Those are costs of being a covered entity, not costs of making a copy. The mental model that helps here is narrow: you may charge for the act of copying and for the physical things the copy travels on, and for nothing that happens before or around it.
A second omission is worth stating separately. Inspection is free. The fee provision covers copies, so when an individual asks only to come in and review their record, there is no permitted charge, including for the staff member who sits with them.
HHS guidance describes three permitted ways to compute the fee. The first is actual cost, calculated for the specific request, which requires you to be able to show the copying labor and the supplies that went into it. The second is a schedule of average costs, developed for standard types of requests, which is administratively simpler and carries one important restriction: it may not be a per page fee where the records are maintained electronically. The third is a flat fee of no more than $6.50, available for electronic copies of protected health information maintained electronically, inclusive of all labor, supplies, and postage.
That third option generated a durable myth, and OCR published a clarification to kill it. The $6.50 figure is not a cap on what a covered entity may charge for copies of protected health information. It is a ceiling on one optional method, offered to entities that would rather not do the arithmetic. An entity using actual or average costs is governed by the reasonable, cost-based standard, which for a large paper chart may exceed $6.50 and for a portal export should be well under it.
Ciox, and the piece of the rule that is no longer there
The HITECH Act gave individuals a statutory right to direct a covered entity to transmit a copy of their records to a designated third party. Congress wrote that right narrowly: it reached a copy of an electronic health record with respect to protected health information of the individual in electronic format. The 2013 Omnibus Rule extended the directive to all protected health information in a designated record set, in any format. A 2016 OCR guidance document then extended the patient rate fee limit to those third-party directives.
In Ciox Health, LLC v. Azar, 435 F. Supp. 3d 30 (D.D.C. 2020), the court vacated both. It held that HHS could not use general rulemaking authority to enlarge the limited third-party directive Congress had enacted, and that the 2016 change to the patient rate was in substance a legislative rule adopted without notice and comment. OCR issued a notice at the end of January 2020 stating that the fee limitation set out at 45 CFR 164.524(c)(4) applies only to an individual's request for access to their own records, and does not apply to an individual's request to transmit records to a third party.
Sorting requests into three buckets keeps this manageable. When the individual asks for a copy for themselves, in any format, the full access right and the full fee limit apply. When the individual directs an electronic copy of EHR data to a third party, the statutory directive survives and you must transmit it, while OCR's post-Ciox position is that the fee limitation does not extend there. When the individual directs paper copies to an attorney, or a law firm sends its own request on a signed authorization, you are outside 164.524 for fee purposes and your state's medical records fee schedule is usually what governs.
A caution about bucket two and three. Many organizations continue to apply the patient rate to individual-directed transmissions as a matter of policy, and there are good reasons for that beyond the regulation. State law may cap the fee independently, and charging a patient a materially higher price because they asked you to send their records to their lawyer rather than to their kitchen table is a position that reads badly in a complaint, a deposition, or a review. The tool flags the distinction so you can decide deliberately rather than by default.
Denial: a closed list, and the reasons that are not on it
45 CFR 164.524(a)(2) lists five grounds for denial that carry no right of review, and they are all narrow. The information falls in the psychotherapy notes or legal proceedings carve-outs. An inmate of a correctional institution requests a copy and the copy would jeopardize the health, safety, security, custody, or rehabilitation of the inmate or of others. The information was created in the course of research that includes treatment, the individual agreed to a temporary suspension of access when consenting, and the research is not complete. Certain Privacy Act situations. Or the information came from someone other than a health care provider under a promise of confidentiality and access would be reasonably likely to reveal the source.
Paragraph (a)(3) adds three reviewable grounds, and each requires an individualized professional judgment rather than a policy: a licensed health care professional determines that access is reasonably likely to endanger the life or physical safety of the individual or another person; the information references another person who is not a provider and access is reasonably likely to cause that person substantial harm; or the request comes from a personal representative and access is reasonably likely to cause substantial harm to the individual or another person. Where one of these is used, the individual may demand review by a licensed health care professional designated by the entity who was not directly involved in the denial, and the entity is bound by that reviewer's determination.
Everything else is not a denial ground. An unpaid balance is not. A refusal to state a purpose is not. An unsigned authorization is not, because no authorization is required. A worry that the individual will use the records in litigation is not, and the legal proceedings carve-out is narrower than it sounds: it covers material compiled in anticipation of a proceeding, not the underlying clinical record that would exist regardless.
When you do deny, 164.524(d) sets the form. Timely, written, in plain language, stating the basis. A description of review rights where they exist and how to exercise them. A description of how to complain to the covered entity, including the name or title and telephone number of the contact person or office, and how to complain to the Secretary. Partial denials still require you to release everything else after excluding the denied portion. And under (d)(3), if you do not hold the information but know who does, you have to tell the individual where to direct the request.
The format right, which is the one that gets skipped
45 CFR 164.524(c)(2) requires access in the form and format requested by the individual, if it is readily producible in that form and format. Only when it is not readily producible does the rule fall back to a readable hard copy or such other form and format as agreed to by the covered entity and the individual. For electronic records where the individual asks for an electronic copy, the same structure applies at (c)(2)(ii) with electronic formats.
The word that matters in both fallbacks is agreed. When you cannot meet the request, the rule directs you into a conversation with the individual, not into a unilateral substitution. Handing over a paper packet to someone who asked for a PDF is a failure of the format right even though the underlying records were released, and it is a failure that shows up in complaints because the individual usually asked for the electronic version for a reason.
This is also the seam where the access right meets the information blocking regulations at 45 CFR part 171. Those rules ask whether a practice is likely to interfere with the access, exchange, or use of electronic health information, with defined exceptions that must be met in full. A response that lands inside the HIPAA deadline can still be an interference if the delay or the format substitution was not reasonable and necessary. Two regimes, one records desk, and the more demanding one sets your operating standard.
Why OCR keeps enforcing this specific right
OCR launched its Right of Access Initiative in 2019, and it has produced more enforcement actions than any other announced initiative in HIPAA's history, passing 50 settlements and civil monetary penalties. A March 2025 action imposed a $200,000 civil monetary penalty involving a failure to provide timely access to a personal representative, and a subsequent settlement resolved for $112,500.
The pattern in these cases is remarkably consistent, and it is not about sophisticated privacy failures. Someone asks for records. Nothing happens. They ask again. They file a complaint with OCR. OCR contacts the entity, the records are produced, and the enforcement action follows anyway because the records arrived only after the federal government got involved. The underlying failure is almost always operational: a request that reached the wrong inbox, a staff member who assumed an authorization was needed, a vendor relationship where nobody owned the clock, a personal representative whose documented authority was not recognized.
That is also why the fix is unglamorous. Log every access request the day it arrives, with the received date, because that date is the only input to the deadline and reconstructing it later is guesswork. Give one named person the queue. Write the fee method down and apply it consistently, or waive fees for individual requests entirely, which many organizations have concluded is cheaper than the staff time spent administering six dollar charges. Tell people the approximate fee up front, which OCR's guidance directs. Train the front desk to recognize an access request when it does not arrive on your form, because that is where the misrouting begins. And when a personal representative appears, decide their authority under state law rather than under office habit.
What is coming, and what to do about it now
HHS proposed a substantial set of Privacy Rule changes in a notice of proposed rulemaking published January 21, 2021, including shortening the access response period from 30 days with a 30 day extension to 15 days with a 15 day extension, along with changes to identity verification standards, the right to take notes or photographs of records during an inspection, and the scope of the electronic third-party directive. That proposal has not been finalized. Public reporting indicates the final rule went to the Office of Management and Budget on April 4, 2026 and is awaiting review.
Nothing about that changes today's obligation, and you should not build a program on a proposed rule. What it does change is how much slack a slow process has. An organization that currently fills routine requests in three to five days will not notice if the deadline halves. One that habitually runs to day 55 will be non-compliant on the day a final rule takes effect, without having changed anything. The cheapest preparation available is to stop treating the outer limit as the target, which is also the change most likely to keep you out of a complaint file in the meantime.
Primary sources
- 45 CFR 164.524, Access of individuals to protected health information
- HHS Office for Civil Rights, Individuals' Right under HIPAA to Access their Health Information
- Ciox Health, LLC v. Azar, 435 F. Supp. 3d 30 (D.D.C. 2020)
- Proposed Modifications to the HIPAA Privacy Rule, 86 Fed. Reg. 6446 (Jan. 21, 2021)
- HHS Office for Civil Rights, Resolution Agreements and Civil Money Penalties
Keep going
The pages that sit either side of this one
Policy
HIPAA release of information policy
The written procedure behind the desk: identity verification, disclosure logging, and who decides what leaves the building.
Write the policyGuide
The information blocking rule
A separate regulation that reaches the same conduct from another direction. Meeting the 30 day HIPAA clock does not settle whether a delay was information blocking.
Read the guideFree tool
Free HIPAA authorization form generator
For the requests that genuinely are third-party disclosures. Six core elements and three required statements under 45 CFR 164.508.
Build a formFree tool
HIPAA breach notification deadline calculator
The other clock that runs in a records office, for when a release went further than it should have.
Calculate the datesFree tool
HIPAA violation penalty calculator
The four culpability tiers and the annual limits, which is the arithmetic behind every Right of Access settlement.
See the tiersGuide
HIPAA training requirements
What the Privacy and Security Rules actually require you to teach, and how to document that you taught it.
Read the requirementsQuestions
HIPAA right of access, answered with citations
How long do we have to respond to a HIPAA records request?
Thirty calendar days from receipt of the request. 45 CFR 164.524(b)(2)(i) requires the covered entity to act on the request no later than 30 days after it arrives, and paragraph (b)(2)(ii) permits one extension of no more than 30 days. The extension is conditional, not automatic: within that first 30 day period you must give the individual a written statement of the reason for the delay and the date by which you will complete your action, and you may take only one such extension. Two details trip people up. First, these are calendar days. There is no tolling for weekends, holidays, or a records office that is closed for a week. Second, 30 days is an outer limit rather than a service target. OCR's access guidance is explicit that entities are expected to respond as promptly as they are able, and a practice that routinely uses all 60 days for a request its system could fill in an afternoon is inviting a complaint.
How much can we charge a patient for a copy of their own records?
A reasonable, cost-based fee, and only one built from the four components listed at 45 CFR 164.524(c)(4): labor for copying the protected health information requested, supplies for creating the paper copy or electronic media, postage when the individual has requested that the copy be mailed, and preparing an explanation or summary of the information if the individual agreed in advance to receive one and to the fee. That list is exhaustive. Labor for searching for and retrieving the records is not on it and may not be charged, which is the single most common overcharge OCR finds. Neither are data storage or system maintenance costs, the price of the EHR, or staff time spent verifying identity or reviewing the file for denial grounds. OCR's guidance describes three ways to calculate the permitted fee: actual costs computed per request, a schedule of average costs for standard request types, or a flat fee of no more than $6.50 for electronic copies of records maintained electronically.
Is the HIPAA records fee capped at $6.50?
No, and this is one of the most persistent misreadings in health information management. The $6.50 figure is a ceiling on one optional method. OCR published a clarification saying directly that $6.50 is not a cap on fees for copies of PHI. A covered entity that uses the actual cost method or a published schedule of average costs is bound by the reasonable, cost-based standard at 164.524(c)(4), which may come out above or below $6.50 depending on the request. What the flat fee option buys you is simplicity and safety: charge it and you never have to defend an arithmetic exercise, because the fee is inclusive of all labor, supplies, and postage. Note also what the flat fee does not cover. It is available only for electronic copies of protected health information maintained electronically. A paper chart being photocopied is not eligible for it.
What changed after Ciox Health v. Azar?
In January 2020 the United States District Court for the District of Columbia decided Ciox Health, LLC v. Azar, 435 F. Supp. 3d 30, and two holdings matter operationally. First, the court vacated the 2013 Omnibus Rule's expansion of the HITECH third-party directive insofar as it went beyond a request for a copy of an electronic health record with respect to protected health information of an individual in an electronic format. Second, it vacated the 2016 guidance that had extended the patient rate fee limitation to third-party directives, on the ground that the change functioned as a legislative rule adopted without notice and comment. OCR issued a notice at the end of January 2020 confirming that the fee limitation at 164.524(c)(4) applies to an individual's request for access to their own records and does not apply to an individual's request to transmit records to a third party. What survives is narrower than what many policies still say. When a patient asks you to send an electronic copy of their EHR data to an app or a new physician, the right to have it transmitted still stands. When a patient asks you to mail paper copies to their attorney, you are outside the vacated portion and typically in the territory of your state's records fee schedule.
Can we require a patient to sign a HIPAA authorization to get their own records?
No, and doing so is one of the fact patterns OCR's Right of Access Initiative was built to catch. The access right at 45 CFR 164.524 belongs to the individual and does not depend on an authorization. 164.524(b)(1) lets you require that the request be in writing, and you may use your own request form as long as it does not create a barrier or unreasonably delay the individual. What you may not do is convert a right into a transaction: route the patient onto a 164.508 authorization, hand the paperwork to a records vendor, and return a per page invoice. The individual then pays a third-party disclosure price for their own chart and loses the 30 day clock. If the individual is the one asking, it is an access request no matter which piece of paper it arrives on, and the timing and fee protections travel with it.
Can we withhold records because the patient owes us money?
No. The permitted grounds for denial are a closed list. 45 CFR 164.524(a)(2) sets out five unreviewable grounds, all narrow: psychotherapy notes or information compiled for a legal proceeding, an inmate copy request where the copy would jeopardize safety or security, research access temporarily suspended with the individual's prior agreement, certain Privacy Act situations, and information obtained from a non-provider under a promise of confidentiality where access would reveal the source. 164.524(a)(3) adds three reviewable grounds, each requiring a licensed health care professional's judgment that access is reasonably likely to endanger life or physical safety or cause substantial harm. An unpaid balance appears nowhere in either list. Neither does an open billing dispute, a malpractice concern, a refusal to explain the purpose of the request, or the individual having left the practice on bad terms.
What has to be in a written denial?
45 CFR 164.524(d) requires that a denial be timely, meaning within the same deadline that would have applied to providing access, and in writing and in plain language. It must state the basis for the denial. If a reviewable ground was used it must describe how the individual may exercise their review rights, and if a review is requested, a licensed health care professional designated by the entity who was not directly involved in the original denial must decide within a reasonable period, with the entity bound by that determination. The denial must also describe how the individual may complain to the covered entity, naming the contact person or office and telephone number, and how to complain to the Secretary of HHS. One more requirement is often missed: if you deny access in part, you must still give access to any other protected health information requested, after excluding the part you denied. And under 164.524(d)(3), if you do not maintain the information but know where it is, you have to tell the individual where to direct the request.
Do we have to provide the records in the format the patient asked for?
If you can readily produce it, yes. 45 CFR 164.524(c)(2)(i) requires access in the form and format requested by the individual if it is readily producible in that form and format, and if not, in a readable hard copy form or such other form and format as agreed to by the covered entity and the individual. For electronic records where the individual requests an electronic copy, (c)(2)(ii) requires the electronic form and format requested if readily producible, and otherwise a readable electronic form and format as agreed to. The operative word in both is agreed. When you cannot meet the request, the fallback is a negotiation with the individual, not a unilateral choice by the records office. Quietly substituting a paper packet for the PDF someone asked for is a denial of the format right even though the records themselves were handed over.
How does the information blocking rule interact with this?
They overlap and they are not the same test. HIPAA gives you an outer deadline and a fee ceiling. The information blocking regulations at 45 CFR part 171 ask a different question: whether a practice is likely to interfere with the access, exchange, or use of electronic health information, with a set of exceptions that must be satisfied in full to be relied on. A response delivered on day 29 satisfies HIPAA and may still be a problem under part 171 if the delay was not reasonable and necessary and no exception applies. Health IT developers and certain networks face civil monetary penalties for information blocking, while providers are subject to appropriate disincentives established by CMS. If your records office is fielding electronic requests for electronic data, both regimes are live at once.
Are the access rules about to change?
A change has been proposed but is not in effect, and you should be running today's program on today's rule. HHS published a notice of proposed rulemaking on January 21, 2021 titled Proposed Modifications to the HIPAA Privacy Rule To Support, and Remove Barriers to, Coordinated Care and Individual Engagement, which would among other things shorten the access response period from 30 days with a 30 day extension to 15 days with a 15 day extension. That proposal has never been finalized. Public reporting indicates the final rule was sent to the Office of Management and Budget on April 4, 2026 and remains pending review. Until a final rule is published in the Federal Register with a compliance date, 30 days plus one 30 day extension is the requirement. The practical planning point is that an organization currently filling requests on day 55 has no margin if the deadline halves, and one already answering in a week will not notice the change at all.
Does answering access requests correctly make our organization HIPAA compliant?
No. Handling access requests well satisfies one right in one rule. Organizational compliance is a program: a documented risk analysis under the Security Rule, administrative, physical, and technical safeguards, a notice of privacy practices, business associate agreements, breach response, sanctions, and workforce training with records to prove it happened. No training provider and no tool can certify an organization as HIPAA compliant, and the federal government does not accredit or endorse HIPAA training providers. What training gives you is evidence that the people who answer these requests were taught the rules, which is a different and more defensible claim than compliance.
Training that reaches the records desk
The people who answer these requests decide whether you get complained about
This page is educational and is not legal advice. USA HIPAA is a private training provider. Completing training is not the same as organizational HIPAA compliance, and no federal agency accredits or endorses HIPAA training providers. Verify every regulatory statement here against the primary sources linked above, and consult counsel about your state's medical records statute before setting a fee schedule. Browse the compliance library.