Skip to main content
medRxiv
  • Home
  • About
  • Submit
  • ALERTS / RSS
Advanced Search

Health Care Provider Compliance with the HIPAA Right of Individual Access: a Scorecard and Survey

Deven McGraw, Nasha Fitter, Lisa Belliveau Taylor
doi: https://doi.org/10.1101/19004291
Deven McGraw
Ciitizen Corporation
  • Find this author on Google Scholar
  • Find this author on PubMed
  • Search for this author on this site
  • For correspondence: deven{at}ciitizen.com
Nasha Fitter
Ciitizen Corporation
  • Find this author on Google Scholar
  • Find this author on PubMed
  • Search for this author on this site
Lisa Belliveau Taylor
Ciitizen Corporation
  • Find this author on Google Scholar
  • Find this author on PubMed
  • Search for this author on this site
  • Abstract
  • Full Text
  • Info/History
  • Metrics
  • Data/Code
  • Preview PDF
Loading

Abstract

Background Historically, patients have had difficulty obtaining copies of their medical records, notwithstanding the legal right to do so. In 2018, a study of 83 top hospitals found discrepancies between those hospitals’ published information and telephone survey responses regarding their processes for release of records to patients, indicating noncompliance with the HIPAA right of individual access.

Objective Assess state of compliance with the HIPAA right of access across a broader range of health care providers and in the context of real records requests from patients.

Methods Evaluate the degree of compliance with the HIPAA right of access 1) by scoring the responses of 51 health care providers to actual patient record requests against the HIPAA right of access requirements and 2) through additional telephone surveys of health care institutions regarding release of records to patients.

Results Based on the scores of responses of 51 health care providers to record requests and the responses of 3003 healthcare institutions to telephone surveys, more than 50% of health care providers are out of compliance with the HIPAA right of access. The most common failures were refusal to send records to patient or patient’s designee by e-mail; health care institutions’ responses to telephone survey also indicate 24% are potentially noncompliant with HIPAA’s fee limitations. With respect to actual patient record requests, for 71% of providers the records were provided in compliance with HIPAA only after supervisors and privacy officials were educated on HIPAA’s requirements.

Conclusions Recent federal proposals prioritize patient access to medical records through certified electronic health record (EHR) technology, but access by patients to their complete clinical records via EHRs is years away. In the meantime, health care providers need to focus more attention on compliance with the HIPAA right of access, including better training of staff on HIPAA requirements. Greater enforcement of the law will help motivate providers to prioritize this issue.

Competing Interest Statement

All authors receive compensation (either salaries or payments to independent contractors) from Ciitizen Corporation, which is a platform to enable patients (beginning with cancer patients) to collect, organize and share their medical records. There are no other competing interests to declare.

Clinical Trial

study is not a clinical trial - it is a study of compliance with law, so it is not human subjects research.

Funding Statement

As noted above, all three authors are either employed by, or are independent contractors to, Ciitizen Corporation, which provided the sole funding support for this research. No external funding was received.

Author Declarations

All relevant ethical guidelines have been followed and any necessary IRB and/or ethics committee approvals have been obtained.

Yes

All necessary patient/participant consent has been obtained and the appropriate institutional forms have been archived.

Yes

Any clinical trials involved have been registered with an ICMJE-approved registry such as ClinicalTrials.gov and the trial ID is included in the manuscript.

Not Applicable

I have followed all appropriate research reporting guidelines and uploaded the relevant Equator, ICMJE or other checklist(s) as supplementary files, if applicable.

Not Applicable

Data Availability

The url with supplemental data referred to in the manuscript will be available August 14, 2019.

https://www.patientrecordscorecard.com

Data Availability

The url with supplemental data referred to in the manuscript will be available August 14, 2019.

https://www.patientrecordscorecard.com

Copyright 
The copyright holder for this preprint is the author/funder, who has granted medRxiv a license to display the preprint in perpetuity. All rights reserved. No reuse allowed without permission.
Back to top
PreviousNext
Posted August 13, 2019.
Download PDF
Data/Code
Email

Thank you for your interest in spreading the word about medRxiv.

NOTE: Your email address is requested solely to identify you as the sender of this article.

Enter multiple addresses on separate lines or separate them with commas.
Health Care Provider Compliance with the HIPAA Right of Individual Access: a Scorecard and Survey
(Your Name) has forwarded a page to you from medRxiv
(Your Name) thought you would like to see this page from the medRxiv website.
CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
Share
Health Care Provider Compliance with the HIPAA Right of Individual Access: a Scorecard and Survey
Deven McGraw, Nasha Fitter, Lisa Belliveau Taylor
medRxiv 19004291; doi: https://doi.org/10.1101/19004291
Twitter logo Facebook logo LinkedIn logo Mendeley logo
Citation Tools
Health Care Provider Compliance with the HIPAA Right of Individual Access: a Scorecard and Survey
Deven McGraw, Nasha Fitter, Lisa Belliveau Taylor
medRxiv 19004291; doi: https://doi.org/10.1101/19004291

Citation Manager Formats

  • BibTeX
  • Bookends
  • EasyBib
  • EndNote (tagged)
  • EndNote 8 (xml)
  • Medlars
  • Mendeley
  • Papers
  • RefWorks Tagged
  • Ref Manager
  • RIS
  • Zotero
  • Tweet Widget
  • Facebook Like
  • Google Plus One

Subject Area

  • Health Policy
Subject Areas
All Articles
  • Addiction Medicine (349)
  • Allergy and Immunology (668)
  • Allergy and Immunology (668)
  • Anesthesia (181)
  • Cardiovascular Medicine (2648)
  • Dentistry and Oral Medicine (316)
  • Dermatology (223)
  • Emergency Medicine (399)
  • Endocrinology (including Diabetes Mellitus and Metabolic Disease) (942)
  • Epidemiology (12228)
  • Forensic Medicine (10)
  • Gastroenterology (759)
  • Genetic and Genomic Medicine (4103)
  • Geriatric Medicine (387)
  • Health Economics (680)
  • Health Informatics (2657)
  • Health Policy (1005)
  • Health Systems and Quality Improvement (985)
  • Hematology (363)
  • HIV/AIDS (851)
  • Infectious Diseases (except HIV/AIDS) (13695)
  • Intensive Care and Critical Care Medicine (797)
  • Medical Education (399)
  • Medical Ethics (109)
  • Nephrology (436)
  • Neurology (3882)
  • Nursing (209)
  • Nutrition (577)
  • Obstetrics and Gynecology (739)
  • Occupational and Environmental Health (695)
  • Oncology (2030)
  • Ophthalmology (585)
  • Orthopedics (240)
  • Otolaryngology (306)
  • Pain Medicine (250)
  • Palliative Medicine (75)
  • Pathology (473)
  • Pediatrics (1115)
  • Pharmacology and Therapeutics (466)
  • Primary Care Research (452)
  • Psychiatry and Clinical Psychology (3432)
  • Public and Global Health (6527)
  • Radiology and Imaging (1403)
  • Rehabilitation Medicine and Physical Therapy (814)
  • Respiratory Medicine (871)
  • Rheumatology (409)
  • Sexual and Reproductive Health (410)
  • Sports Medicine (342)
  • Surgery (448)
  • Toxicology (53)
  • Transplantation (185)
  • Urology (165)