Skip to main content
Category: Individual Rights

Access to Designated Record Set

Also known as: DRS, Right of Access to Designated Record Set, Individual Access to DRS, Patient Access to Designated Record Set
Simply put

Under the HIPAA Privacy Rule, individuals generally have the right to see and get copies of their own health information that a covered entity keeps in what is called a designated record set. This typically includes records such as medical records, billing and payment records, claims records, and health plan enrollment and case management records. Covered entities are generally expected to have a process in place so that individuals, or their personal representatives, can request access to this information.

Formal definition

Access to the designated record set refers to an individual's right under the HIPAA Privacy Rule to inspect and obtain a copy of protected health information (PHI) about them that is maintained by or for a covered entity within a designated record set (DRS). A DRS generally comprises records used, in whole or in part, to make decisions about individuals, and typically includes medical records, billing and payment records, claims records, health plan enrollment records, and case management records, as reflected in the evidence. The right of access attaches to information within the DRS rather than to all PHI a covered entity may hold, so certain records may fall outside its scope. Covered entities are generally expected to maintain a process for individuals and their personal representatives to request access, and, where applicable, to request amendment of PHI in the DRS. This entry addresses the Privacy Rule right of access only; it does not cover the specific response timeframes, permissible fees, grounds for denial, or the separate right to amendment in detail, and it is distinct from the Security Rule's technical concept of access control to electronic PHI. State law, the HITECH Act, and current HHS OCR guidance may impose additional or more specific requirements, and practitioners should verify particulars against the current regulatory text.

Why it matters

The right of access to the designated record set is one of the most fundamental individual rights under the HIPAA Privacy Rule, and it is also one of the areas where covered entities most frequently encounter compliance difficulty. When individuals cannot readily obtain copies of their own health information, they may be unable to participate meaningfully in their own care, coordinate treatment across providers, verify the accuracy of billing and claims records, or exercise related rights such as requesting an amendment. Because the right attaches specifically to information within the designated record set, which generally includes medical records, billing and payment records, claims records, health plan enrollment records, and case management records, understanding what falls inside and outside that set is essential to responding to requests correctly.

Access-related failures have historically drawn regulatory attention from HHS OCR, which enforces the Privacy Rule. Denying or unreasonably delaying an individual's access to their designated record set, or imposing improper obstacles to it, can expose a covered entity to enforcement scrutiny. Because penalty tiers and specific figures are adjusted over time, organizations should confirm current enforcement guidance rather than relying on fixed numbers.

It is important to recognize the limits of this right. The right of access covers PHI within the designated record set rather than every piece of PHI a covered entity may hold, so certain records may fall outside its scope. Response timeframes, permissible fees, and grounds for denial are governed by separate provisions of the Privacy Rule and are not addressed in detail here. State law, the HITECH Act, and current HHS OCR guidance may impose additional or more specific requirements, so practitioners should verify particulars against the current regulatory text.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are typically responsible for establishing and maintaining the process by which individuals and their personal representatives request access to the designated record set. They generally need to define which records constitute the designated record set within their organization and ensure staff can distinguish PHI subject to the right of access from records that may fall outside its scope.
Covered Entities (Providers and Health Plans)
Healthcare providers and health plans that maintain designated record sets, including medical, billing, claims, enrollment, and case management records, must be able to respond to individual access requests. Facilities are generally expected to have a documented process in place for patients and their personal representatives to access, and where applicable request amendment of, information in their designated record set.
Health Information Management (HIM) and Records Staff
Staff who manage medical and administrative records are often the operational point of contact for access requests. They generally need to understand what records make up the designated record set so they can produce responsive information accurately, while recognizing that certain records may fall outside the right of access.
Legal and Regulatory Advisors
Attorneys and compliance advisors help interpret the scope of the designated record set and the limits of the right of access, including how state law, the HITECH Act, and current HHS OCR guidance may impose additional or more specific requirements beyond the baseline Privacy Rule right. They should verify response timeframes, permissible fees, and grounds for denial against the current regulatory text.

Inside DRS

Designated Record Set (DRS)
Under the HIPAA Privacy Rule, a group of records maintained by or for a covered entity that generally includes medical and billing records about individuals maintained by or for a health care provider, enrollment, payment, claims adjudication, and case or medical management records maintained by or for a health plan, or records used in whole or in part to make decisions about individuals. The term has a specific regulatory meaning that is narrower than every document an entity holds about a person.
Right of Access
The Privacy Rule right that generally permits an individual (or their personal representative) to inspect and obtain a copy of PHI about themselves that is held within a designated record set. This right attaches to PHI in all forms covered by the Privacy Rule, including paper, electronic, and other media, not solely ePHI.
Scope of Accessible Information
Access generally applies to PHI maintained in the designated record set for as long as the information is retained. Certain categories, such as psychotherapy notes and information compiled in reasonable anticipation of litigation, are typically excluded from the right of access. Practitioners should confirm current exclusions against the applicable regulatory text.
Form, Format, and Delivery
Individuals may generally request access in a particular form or format, and the covered entity is expected to provide it if the information is readily producible in that form; otherwise a readable hard copy or another agreed format is provided. Requests may include directing a copy to a designated third party, subject to applicable requirements.
Timeliness and Fees
Covered entities are generally expected to act on access requests within the timeframe established by the Privacy Rule and may charge only a reasonable, cost-based fee limited to specified components. Specific timeframes and permitted fee elements should be verified against current HHS OCR guidance, as details are subject to change and litigation.
Role of Business Associates
Business associates that maintain a designated record set on behalf of a covered entity may be obligated, through the business associate agreement, to support the covered entity's fulfillment of access requests. The individual's right of access runs to the covered entity; obligations reach business associates through the defined contractual relationship rather than directly in all cases.

Common questions

Answers to the questions practitioners most commonly ask about DRS.

Does the right of access under the Privacy Rule apply only to electronic records?
No. This is a common misconception. The individual right of access is a HIPAA Privacy Rule provision, and the Privacy Rule covers protected health information in all forms, including paper and, in certain contexts, oral information. The right applies to PHI maintained in a designated record set regardless of medium. The focus on electronic records often stems from confusion with the Security Rule, which governs only electronic PHI. Readers should verify specific requirements against the current regulatory text.
Does an individual have a right to access every record or piece of information a covered entity holds about them?
Not necessarily. The right of access generally extends to PHI within a designated record set, not to all information a covered entity may hold. A designated record set is a defined term with a specific regulatory meaning that typically includes records used to make decisions about individuals. Certain categories of information may fall outside the designated record set, and there are also limited grounds on which access may be denied. The precise scope should be confirmed against the current Privacy Rule text.
How should a covered entity determine what falls within its designated record set for an access request?
Covered entities generally benefit from defining and documenting, in advance, which record systems constitute their designated record set. Because the designated record set typically includes records used to make decisions about individuals, this analysis should consider medical and billing records as well as other decision-making records. Documenting these determinations helps ensure consistent responses to access requests. Specific categories should be evaluated against the current regulatory definition.
In what form must a covered entity provide records in response to an access request?
Under the Privacy Rule, covered entities are generally expected to provide access in the form and format requested by the individual if the PHI is readily producible in that form and format. If it is not readily producible as requested, a readable alternative form is typically provided by agreement with the individual. Because format and access requirements are detailed in the regulation, readers should confirm the current requirements against the applicable regulatory text.
Are there limits on what a covered entity may charge for providing access?
Generally, any fee associated with providing access is subject to limitations under the Privacy Rule and is intended to be reasonable and cost-based rather than a source of revenue. Fee rules have been the subject of ongoing regulatory attention and guidance, and specific permissible cost components should not be assumed. Readers should verify current fee limitations and any applicable guidance against the current regulation, and note that state law may impose additional or more restrictive requirements.
How does a covered entity handle situations where it wants to deny an access request?
The Privacy Rule recognizes only limited grounds for denying access, and some denials may be subject to review while others generally are not. Covered entities typically should treat denial as an exception, apply only the recognized grounds, and document the basis for any denial along with any applicable review process afforded to the individual. Because the specific grounds and procedures are set out in the regulation, they should be confirmed against the current Privacy Rule text, and state law may provide additional access rights.

Common misconceptions

The right of access covers every document a covered entity holds about a patient.
Access generally applies to PHI within the designated record set, a defined subset of records. Materials outside the DRS, and certain excluded categories such as psychotherapy notes or information compiled for litigation, are typically not subject to the access right. Practitioners should confirm exclusions against the current regulatory text.
The designated record set only involves electronic health information.
The right of access arises under the Privacy Rule, which covers PHI in all forms, including paper and other media. This differs from the Security Rule, which governs only ePHI. A DRS may contain records in multiple formats.
Achieving HITRUST CSF certification or another framework alone demonstrates compliance with access obligations.
The right of access is a legal requirement under the HIPAA Privacy Rule enforced by HHS OCR. HITRUST is a private organization and its CSF is a certifiable control framework; certification does not by itself establish HIPAA compliance and does not substitute for meeting the Privacy Rule's access requirements. State law or the HITECH Act may impose additional obligations.

Best practices

Define and document what constitutes your organization's designated record set, including where records are maintained across systems, formats, and business associates, so access requests can be fulfilled completely and consistently.
Establish a documented process for receiving, verifying, and responding to access requests within the timeframes set by the Privacy Rule, and verify current timeframes against HHS OCR guidance because details are subject to change.
Adopt a fee schedule limited to the reasonable, cost-based components permitted by the rule, and periodically review it against current OCR guidance and relevant litigation developments.
Include obligations in business associate agreements that require business associates maintaining a DRS to support the covered entity's fulfillment of access requests, recognizing that these obligations flow through the contractual relationship.
Train workforce members to distinguish PHI within the designated record set from excluded categories such as psychotherapy notes and litigation-related materials, so access is neither wrongly denied nor over-disclosed.
Check whether state law or the HITECH Act imposes additional access, format, or timing requirements beyond HIPAA, and apply the more protective standard where applicable.