How a HIPAA Business Associate Supports a Patient Access Request
A HIPAA business associate can help fulfill a patient access request, but the covered entity remains responsible for the individual’s right of access. The current rule gives the covered entity no later than 30 calendar days after receipt to act on a request. Retrieving records from a business associate does not create a second clock.
The business associate agreement should say who receives requests, what records the associate must make available, whether it may send an electronic copy directly, and how it returns the request to the covered entity for decisions outside its assigned role. Software should support that allocation without inventing the designated record set or a reason to deny access.
Who is responsible for the access request?
Section 164.524 places the access duty on the covered entity. Subject to stated exceptions and denial provisions, an individual has a right to inspect and obtain a copy of protected health information about that individual in a designated record set for as long as the information is maintained there. The rule also tells the covered entity how to receive a request, act on it, provide access, handle denials, and retain required documentation.
HHS’s business associate FAQ uses the same allocation. It says covered entities are responsible for Privacy Rule rights, including access, amendment, and accounting. It also says the right includes information in a designated record set held by a business associate unless that information merely duplicates what the covered entity already maintains.
The business associate still has duties. Legal responsibility, contract allocation, and operational work must remain distinct. A covered entity cannot treat the vendor’s queue as a pause button for the request.
What records can the business associate hold?
The question is whether protected health information sits in a designated record set covered by section 164.524. The covered entity must identify those record sets and document who receives and processes access requests.
A health software vendor may hold records that the covered entity uses to make decisions about individuals. The result depends on the system, contract, and record use. A generic product rule should not decide whether logs, derived fields, support notes, duplicates, or metadata belong. The covered entity needs a documented determination that the associate can implement.
Do not confuse this determination with permission to reuse the records for another purpose. A BAA defines permitted and required uses and disclosures; it is not a general data license. The review of cross-tenant clinic benchmarking under a BAA explains why contract scope and a separate use remain different questions.
How does the 30-day clock work?
The current text of 45 CFR 164.524 requires the covered entity to act on an access request no later than 30 days after receipt. If the covered entity grants the request, it must inform the individual and provide the requested access under the rule. If it denies the request in whole or in part, it must issue the required written denial.
The rule allows one extension of no more than 30 days when the covered entity cannot act within the initial period. Within the first 30 days, it must give the individual a written statement explaining the delay and the date by which it will complete its action. The extension is not automatic, and only one is available.
A vendor handoff should preserve the original receipt time. An operational record can contain the request ID, received timestamp, due date, assigned action, status, and escalation owner. This editorial workflow does not authorize the associate to grant itself an extension.
What must the business associate agreement cover?
Section 164.504 requires a business associate contract to establish permitted and required uses and disclosures. Among its listed terms, the contract must provide that the associate will make protected health information available in accordance with section 164.524. If the associate carries out a covered entity’s obligation under the Privacy Rule, it must comply with the requirements that apply to the covered entity in performing that obligation.
The HHS FAQ says the parties may agree that the associate will provide access directly to individuals. This can fit a situation where the associate is the only holder of all or part of the designated record set. Direct delivery should not be inferred from technical capability. The agreement and procedure need to say whether the associate sends to the covered entity, the individual, or the individual’s designee.
HHS’s direct-liability fact sheet adds another boundary. It identifies a business associate’s failure to provide a copy of electronic protected health information to the covered entity or to the individual or designee, whichever the BAA specifies, as a matter for which OCR may have direct enforcement authority under the cited provisions. That agency explanation should be presented as guidance about enforcement, alongside the regulation and contract.
What should the software workflow do?
If a request reaches the associate, the system should connect it to the covered entity’s contract-defined process. It should preserve receipt time, requested scope, possible record set, and response owner. Identity checks and communication should follow the approved procedure without creating unreasonable barriers.
The export step should use the requested form and format when readily producible. For electronic records and an electronic-copy request, section 164.524 describes the requested electronic form and format when readily producible, or a readable electronic form and format agreed with the individual when it is not. The associate should not silently substitute a summary. The rule permits a summary or explanation only under its stated agreement and fee conditions.
Keep access records inside the approved health-data boundary. Do not copy request contents into advertising or unrelated analytics systems. The article on health conversion tracking outside HIPAA explains why another product boundary can add risk.
Where should decisions and denials remain?
Section 164.524 contains specific unreviewable and reviewable grounds for denial. It also requires access to other requested protected health information, where possible, after excluding material for which a denial ground exists. A written denial must use plain language and include the basis, applicable review rights, and complaint information.
A software vendor should not translate those provisions into a universal “sensitive record” switch. Some reviewable grounds depend on professional judgment by a licensed healthcare professional. The covered entity must designate the reviewer required by the rule when a review is requested. The associate can present status, collect the approved determination, produce the permitted portion, and preserve an audit record.
When the request is broader than the associate’s holdings, route it back instead of marking it complete. When the covered entity knows another location maintains the requested information, section 164.524 addresses informing the individual where to direct the request. Product behavior should reflect the approved process, not generate legal conclusions from incomplete inventory.
An evidence checklist for covered entities and vendors
- List the covered entity, business associate, applicable agreement, and current access procedure.
- Identify designated record sets and the systems that maintain them.
- Record the original receipt timestamp and current 30-day due date.
- Assign intake, identity verification, record search, export, delivery, denial, review, and complaint responsibilities.
- State whether the associate sends records to the covered entity or directly to the individual or designee.
- Test requested electronic formats with synthetic records and document any format agreement.
- Prove that duplicate copies are not produced unnecessarily and that partial access remains possible when approved.
- Escalate missing records, uncertain scope, delivery failure, or a possible denial before the deadline expires.
This checklist is editorial advice, not text from HHS. It makes the contract executable and the request traceable. A signed BAA alone does not prove that the workflow can find, export, and deliver the right records on time. The broader product-boundary review for BAAs applies the same evidence discipline to another vendor context.
Frequently asked questions
Does a business associate have to answer every patient directly?
No universal rule in these sources assigns every request directly to the associate. The covered entity remains responsible. The BAA and procedure may require the associate to provide records to the covered entity or to deliver an electronic copy directly to the individual or designee.
Does asking the vendor for records restart the 30-day clock?
No. The rule gives the covered entity no later than 30 days after receipt to act. Internal retrieval from a business associate should preserve that original deadline.
Can the business associate decide that a record is outside the designated record set?
It should not invent that decision. The covered entity should document its designated record sets and give the associate rules it can implement. Uncertain cases need escalation to the responsible privacy or legal reviewer.
Can the associate send a summary instead of the records?
Not by default. Section 164.524 permits a summary or explanation in place of access only when the individual agrees in advance to it and to any associated fee allowed by the rule.
References
- Electronic Code of Federal Regulations, “45 CFR 164.524, Access of individuals to protected health information,” retrieved August 16, 2026, https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- Electronic Code of Federal Regulations, “45 CFR 164.504, Uses and disclosures: Organizational requirements,” retrieved August 16, 2026, https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
- U.S. Department of Health and Human Services, “Does the HIPAA Privacy Rule require a business associate to provide individuals with access to their protected health information or an accounting of disclosures, or an opportunity to amend protected health information?” retrieved August 16, 2026, https://www.hhs.gov/hipaa/for-professionals/faq/246/do-business-associates-have-obligations/index.html
- U.S. Department of Health and Human Services, “Direct Liability of Business Associates,” retrieved August 16, 2026, https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/factsheet/index.html
Related articles
Do AWS CloudTrail Multi-Region Trails Move Healthcare Audit Data Into One Region?
Yes. An AWS CloudTrail multi-Region trail can centralize events from enabled AWS Regions into one selected Amazon S3 bucket. The bucket may…
Why a Zocdoc Timeslot Update Must Send the Complete Provider Day
A Zocdoc timeslot update is a full replacement for one provider and date. The documented PUT /v1/providers/{provider_id}/calendar/timeslots…
How DrChrono Chooses the Time Zone for Appointment Reminders
DrChrono appointment reminders use a defined time-zone precedence. The practice group supplies the default reminder source, but an…