HIPAA Right of Access Requirements: OCR Just Fined an Eye Clinic $50,000 for One Patient's Records
A patient at a California eye clinic asked for her own records in January 2023. She got them in January 2025. On August 27, 2026, the clinic paid HHS $50,000 and signed up for two years of federal monitoring. The rule it broke has not changed since 2017, and most practices could not tell you today how many open records requests they have.
The HIPAA right of access is 45 CFR 164.524. It gives an individual the right to inspect and obtain a copy of protected health information about them in a designated record set, for as long as the covered entity maintains it, with two narrow exceptions (psychotherapy notes and information compiled for litigation). Under 164.524(b)(2)(i), the covered entity must act on a request no later than 30 days after receipt, either by providing the access or by issuing a written denial. Under 164.524(b)(2)(ii), it may take one extension of no more than 30 days, but only if it sends the individual a written statement of the reasons for the delay and the date it will finish, and only if it sends that statement inside the first 30 days. Fees are limited under 164.524(c)(4) to a reasonable, cost-based amount covering labor for copying, supplies, postage, and any agreed summary. An unpaid balance is not a permitted ground for denial under 164.524(a)(2) or (a)(3).
- 30 days is the act-by date under § 164.524(b)(2)(i). It runs from receipt of the request, not from the day someone opens the fax or the portal message.
- There is exactly one extension, capped at 30 days, and it only exists if you send the written notice with reasons and a completion date before day 30 expires. A late notice is not an extension. It is a violation with a letter attached.
- Day 60 is an absolute outer limit. There is no second extension under § 164.524(b)(2)(ii)(B).
- The fee under § 164.524(c)(4) covers copying labor, supplies, postage, and an agreed summary. It does not cover search and retrieval, and it cannot be conditioned on the patient's account balance.
- On August 27, 2026 OCR settled with Azul Vision, Inc. for $50,000 and a two-year corrective action plan. It was the 55th enforcement action in the Right of Access Initiative, which began in 2019 with an $85,000 settlement against Bayfront Health St. Petersburg.
- The corrective action plan forces Azul Vision to report every access request to HHS with the date received and the date completed. That two-date log is the control the rule assumes you already have.
- The deadline is still 30 days. The Privacy Rule final rule targeted for August 2026 has not published, and HHS has separately listed a November 2026 proposed rule on the access timeframe. Until something appears in the Federal Register, nothing has changed.
- Eleven of the 55 actions were announced in a single batch in July 2022, and settlement amounts have ranged from $3,500 for a solo psychiatry practice to $240,000 for a 17-hospital system. The variable OCR keeps citing is delay, not size.
What does the HIPAA right of access actually require?
The rule is short and the obligations are concrete. Section 164.524 is part of the Privacy Rule, not the Security Rule, which is why it tends to get less attention from the IT side of a practice and more from the front desk, where it is usually handled badly.
The right attaches to protected health information in a designated record set. Under 164.501 that means the medical and billing records about the individual, plus anything else the practice uses to make decisions about them. It does not mean every scrap of data containing the patient’s name. Quality-improvement notes, peer review files, and the practice’s own compliance records are generally outside it. Psychotherapy notes kept separately from the rest of the chart are excluded by 164.524(a)(1)(i). Information compiled in anticipation of litigation is excluded by (a)(1)(ii).
Three things the rule requires that practices routinely get wrong:
- The form and format is the patient’s choice, if you can produce it. Under 164.524(c)(2)(ii), if the records are electronic and the patient asks for an electronic copy, you must provide it in the form and format requested if it is readily producible. “We only do paper” is not a compliant answer if your EHR can export a PDF.
- A written denial is a real document with required contents. Under 164.524(d)(2), a denial must be in plain language and state the basis, the patient’s review rights if any, and how to complain to both the practice and the HHS Secretary, including a contact name or title and phone number. A verbal “we can’t release that” is not a denial. It is silence.
- You must document who handles this. Under 164.524(e), the practice must document which designated record sets are subject to access and the titles of the persons or offices responsible for receiving and processing requests, and retain that documentation for six years under 164.530(j). If nobody in the practice can name the responsible title, that is a documented deficiency before a single request goes late.
When does the 30-day clock start, and what stops it?

The clock starts on receipt. Not on the day the request is logged, not on the day it reaches the right person, and not on the day the practice decides the request is valid. Under 164.524(b)(1) you may require requests in writing, provided you have told patients that in advance (typically in the Notice of Privacy Practices). You may not add requirements the rule does not contain. Requiring the patient to come in person, use a specific form, or explain why they want the records has no basis in 164.524 and OCR has treated each as an impermissible barrier.
Within 30 days, one of three things has to happen:
- The records are provided, in whole or in part, in the form requested.
- A written denial goes out that meets 164.524(d)(2).
- A written extension notice goes out that states the reasons for the delay and the date the practice will complete the request.
The extension is the piece practices misunderstand most. It is not automatic and it is not a second 30-day window you can invoke on day 35. Under 164.524(b)(2)(ii)(A) the notice has to be sent within the original 30 days. Under (b)(2)(ii)(B) there is only one. A practice that sends nothing by day 30 and delivers on day 45 has not used its extension. It has violated the rule and then complied late.
Sixty days is therefore the hard ceiling for any request, in any circumstance. The HIPAA breach notification rule has the same structure: a number that reads like a deadline but functions as the point past which OCR stops asking why.
What happened at Azul Vision?
Azul Vision, Inc. is an optometry and ophthalmology provider operating 31 clinics in California. According to the resolution agreement, a patient requested access to her records in January 2023. OCR received her complaint on April 27, 2023. The patient received her records in January 2025, roughly two years after she asked and well after OCR had opened its investigation.
OCR determined that Azul Vision potentially failed to take timely action in response to the request under the right of access standard. Azul Vision paid $50,000 and agreed to a corrective action plan that OCR will monitor for two years. Under the plan the practice must:
- Review and revise its written policies and procedures to comply with the Privacy Rule.
- Train all workforce members on the right of access and on the practice’s own procedures for it.
- Regularly submit to HHS a list of every access request received, including the date received and the date the response was completed.
OCR Director Paula M. Stannard’s statement made the enforcement posture explicit: it should not take an OCR investigation to get a covered entity to hand over records.
Three details matter for a smaller practice reading this. First, the trigger was one patient and one complaint. There was no breach, no ransomware, no thousands of affected individuals. Second, the settlement amount sits at the low-to-middle of the initiative’s range, which means $50,000 is what OCR considers proportionate for a two-year delay at a mid-sized group, not an outlier. Third, the corrective action plan does not ask for anything a competent practice would not already have. The log, the policy, and the training are the baseline. The plan simply makes HHS the auditor of that baseline for two years.
What can you charge, and what can you refuse?
The fee rules are where well-meaning practices create violations on purpose, usually by copying a state statute’s per-page schedule into the HIPAA context.
Under 164.524(c)(4), if the patient requests a copy, the fee may include only the cost of labor for copying (paper or electronic), supplies for paper or portable media, postage if the patient asked for mailing, and the cost of preparing a summary or explanation if the patient agreed to one in advance. HHS’s 2016 access guidance adds that a practice may instead charge a flat fee of up to $6.50 for electronic copies of electronically maintained records rather than calculating actual costs. What the fee cannot include is the labor of searching for and retrieving the records, the cost of the systems that store them, or any amount for verifying the request. A per-page state schedule that exceeds actual cost is not a defense.
One caveat on the fee rules: in Ciox Health v. Azar (D.D.C. January 23, 2020), a federal court vacated HHS’s application of the fee limits to requests that direct records to a third party, and limited the third-party-directive right to electronic PHI in an EHR. That ruling changed what applies when a patient’s lawyer asks for the file. It changed nothing about a patient asking for her own records, which is what the Azul Vision case was.
Grounds for denial are listed exhaustively in 164.524(a)(2) and (a)(3). The unreviewable grounds cover psychotherapy notes, litigation materials, certain correctional and research contexts, Privacy Act records, and information obtained under a promise of confidentiality. The reviewable grounds require a licensed professional’s judgment that access is reasonably likely to endanger someone. That is the complete list. An unpaid balance is not on it. OCR imposed a $100,000 civil money penalty on ACPM Podiatry in 2022 after the practice withheld records over an unpaid bill and then ignored OCR’s letters. The penalty exposure for a small practice tends to track that second factor as much as the first.
What has OCR actually penalized?

OCR announced the Right of Access Initiative as an enforcement priority in 2019. The first settlement, announced September 9, 2019, was $85,000 against Bayfront Health St. Petersburg, a 480-bed hospital that took more than nine months to give a mother the fetal heart monitor records of her unborn child. Azul Vision is the 55th action. In between, the pattern has been stable:
- Eleven actions were announced in one batch on July 15, 2022, totaling $626,000.
- The smallest settlement was $3,500, against a solo psychiatry practice. The largest was $240,000, against Memorial Hermann Health System, where one patient made five requests over 564 days before receiving complete records.
- Dental practices, podiatrists, otolaryngologists, behavioral health providers, a lab, and a county mental health program are all on the list. The initiative is not aimed at hospitals.
The amount tracks three things OCR states in nearly every press release: how long the patient waited, whether the practice responded to OCR’s technical assistance and data requests, and whether the records eventually provided were complete. It does not track the size of the provider. A two-provider practice that ignores an OCR letter is in more danger than a hospital system that answers it the same week.
Is the 30-day deadline changing to 15 days?
Not yet, and the answer has gotten more complicated over the summer.
HHS proposed shortening the response window from 30 days to 15 days in a January 21, 2021 notice of proposed rulemaking that also covered care coordination and in-person inspection rights. That proposal sat for four years. In early 2026 OCR held a Tribal consultation on it, and the Office of Management and Budget’s 2026 Unified Agenda listed a final rule for August 2026.
Two things happened next. August 2026 came and went without publication in the Federal Register. And the same Unified Agenda listed a separate proposed rule, targeted for November 2026, titled “HIPAA Privacy Rule to Promote Individuals’ Timely Access to their Protected Health Information,” which would solicit comment specifically on the response timeframe. Several health-law firms have read that as a signal HHS will not finalize the 15-day provision from the 2021 proposal and intends to re-propose the timing question on its own.
For a practice, the operational conclusion is simple. The eCFR text of 164.524 is current to August 27, 2026 and shows no changes since January 3, 2017. Thirty days is the rule you are measured against today. If your process cannot reliably hit 30, a 15-day rule would only make the failure visible faster. The pending Security Rule overhaul, now targeted for 2027, does not touch 164.524 at all.
Why records requests fail in a small practice
The Azul Vision facts are unusual only in duration. The mechanism is ordinary and shows up in practices of every size.
A request arrives by fax, portal message, phone, or in person. It lands with whoever answered. That person either forwards it to a records clerk, a practice manager, or a release-of-information vendor, or sets it aside to deal with after the patient in front of them. Nobody writes down the date it arrived. Two weeks later the request is a sticky note. If the practice uses an outside release-of-information company, the request goes into that vendor’s queue, and the practice assumes the vendor owns the deadline. It does not. Under 164.524 the covered entity owes the access. A business associate that misses it has breached its agreement, but the OCR complaint names the practice.
Then one of three things stalls it: the practice wants an unpaid balance settled first, the request needs “verification” that nobody has defined, or the chart is split between a legacy system and the current EHR and pulling both is a project nobody has been assigned. The patient calls twice, then files a complaint. OCR sends a data request. Now the practice needs to produce a list of access requests with dates received and dates completed, and discovers it has never kept one.
The fix is not a policy. Most practices already have a policy. The fix is a log.
What a practice should do this week

- Start the log today. Five columns: date received, act-by date (received plus 30), extension sent and new date, date completed, days open. Every request from every channel gets a row the day it arrives. This is the exact list Azul Vision now has to send to HHS, and building it voluntarily costs a spreadsheet.
- Name the owner by title and write it down. Section 164.524(e)(2) requires it. Pick the title, not the person, so the obligation survives turnover.
- Give the front desk one instruction. Any request for records, in any form, gets logged the same day and forwarded to the owner. No triage, no judgment, no “let me check your balance.”
- Write the extension letter template now. Reasons for delay, expected completion date, sent before day 30. If the template does not exist, the extension does not get used, and the practice goes straight from compliant to violating on day 31.
- Pull the fee schedule and compare it to 164.524(c)(4). Delete anything for search, retrieval, or verification. Either calculate actual copying cost or use the $6.50 flat fee for electronic copies of electronic records.
- Rewrite the denial letter. Plain language, basis for denial, review rights, complaint route to the practice and to HHS with a name or title and phone number. That is 164.524(d)(2), and a denial that omits any element is itself a violation.
- Check the release-of-information vendor contract. Confirm the turnaround it promises is inside 30 days from the date the practice receives the request, not from the date the vendor receives it. The gap between those two dates is yours.
- Review the log every Monday. Anything past day 20 with no records out gets the extension letter that week. Anything past day 30 with nothing sent is already reportable to OCR by the patient.
OCR runs two initiatives that reach small practices: this one, and the Risk Analysis Initiative under the Security Rule. Both start from a document the practice was supposed to have already. If the security risk analysis under 164.308(a)(1)(ii)(A) is the other one you cannot produce on request, the HIPAA Security Risk Assessment Tool: Excel + Guide is $57 and covers that side: asset inventory, threat and vulnerability pairing, risk scoring, and a dated revision log. It does not cover the access log above, because that one is five columns and you can build it before lunch.
The bottom line
The right of access is the HIPAA obligation most likely to generate a complaint from a patient who is not angry about a breach, just waiting. Thirty days is the act-by date, sixty is the wall, and the only way to prove you hit either is a log with two dates in it. Azul Vision is now keeping that log for HHS. Keeping it for yourself is cheaper.
Sources
- 45 CFR 164.524, Access of individuals to protected health information (eCFR, current as of August 27, 2026; last amended 79 FR 7316, February 6, 2014; no changes after January 3, 2017).
- 45 CFR 164.501, Definitions (designated record set).
- 45 CFR 164.530(j), Documentation retention.
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles HIPAA Right of Access Investigation with Azul Vision, Inc.,” press release, August 27, 2026 ($50,000, two-year corrective action plan, 55th action).
- HHS Office for Civil Rights, Azul Vision, Inc. Resolution Agreement and Corrective Action Plan, OCR Transaction Number 23-526909 (complaint received April 27, 2023; 31 clinics in California).
- HHS Office for Civil Rights, “Individuals’ Right under HIPAA to Access their Health Information, 45 CFR 164.524,” guidance (fees, $6.50 flat fee option, form and format).
- HHS Office for Civil Rights, “OCR Settles First Case in HIPAA Right of Access Initiative,” Bayfront Health St. Petersburg, September 9, 2019 ($85,000).
- HHS Office for Civil Rights, “OCR Settles Eleventh Investigation in HIPAA Right of Access Initiative,” Dr. Rajendra Bhayani, November 12, 2020 ($15,000).
- HHS Office for Civil Rights, eleven Right of Access resolutions announced July 15, 2022 (Memorial Hermann Health System $240,000; ACPM Podiatry $100,000 civil money penalty; total $626,000).
- Ciox Health, LLC v. Azar, No. 18-cv-0040 (D.D.C. January 23, 2020) (fee limitation and third-party directive holdings).
- HHS, Modifications to the HIPAA Privacy Rule to Support, and Remove Barriers to, Coordinated Care and Individual Engagement, Notice of Proposed Rulemaking, 86 FR 6446, January 21, 2021 (proposed 15-day response period).
- Office of Management and Budget, 2026 Unified Agenda of Regulatory and Deregulatory Actions, HHS/OCR entries (Privacy Rule final rule targeted August 2026; “HIPAA Privacy Rule to Promote Individuals’ Timely Access to their Protected Health Information,” proposed rule targeted November 2026).