Access to Designated Record Set
Under the HIPAA Privacy Rule, individuals generally have the right to see and get copies of their own health information that a covered entity keeps in what is called a designated record set. This typically includes records such as medical records, billing and payment records, claims records, and health plan enrollment and case management records. Covered entities are generally expected to have a process in place so that individuals, or their personal representatives, can request access to this information.
Access to the designated record set refers to an individual's right under the HIPAA Privacy Rule to inspect and obtain a copy of protected health information (PHI) about them that is maintained by or for a covered entity within a designated record set (DRS). A DRS generally comprises records used, in whole or in part, to make decisions about individuals, and typically includes medical records, billing and payment records, claims records, health plan enrollment records, and case management records, as reflected in the evidence. The right of access attaches to information within the DRS rather than to all PHI a covered entity may hold, so certain records may fall outside its scope. Covered entities are generally expected to maintain a process for individuals and their personal representatives to request access, and, where applicable, to request amendment of PHI in the DRS. This entry addresses the Privacy Rule right of access only; it does not cover the specific response timeframes, permissible fees, grounds for denial, or the separate right to amendment in detail, and it is distinct from the Security Rule's technical concept of access control to electronic PHI. State law, the HITECH Act, and current HHS OCR guidance may impose additional or more specific requirements, and practitioners should verify particulars against the current regulatory text.
Why it matters
The right of access to the designated record set is one of the most fundamental individual rights under the HIPAA Privacy Rule, and it is also one of the areas where covered entities most frequently encounter compliance difficulty. When individuals cannot readily obtain copies of their own health information, they may be unable to participate meaningfully in their own care, coordinate treatment across providers, verify the accuracy of billing and claims records, or exercise related rights such as requesting an amendment. Because the right attaches specifically to information within the designated record set, which generally includes medical records, billing and payment records, claims records, health plan enrollment records, and case management records, understanding what falls inside and outside that set is essential to responding to requests correctly.
Access-related failures have historically drawn regulatory attention from HHS OCR, which enforces the Privacy Rule. Denying or unreasonably delaying an individual's access to their designated record set, or imposing improper obstacles to it, can expose a covered entity to enforcement scrutiny. Because penalty tiers and specific figures are adjusted over time, organizations should confirm current enforcement guidance rather than relying on fixed numbers.
It is important to recognize the limits of this right. The right of access covers PHI within the designated record set rather than every piece of PHI a covered entity may hold, so certain records may fall outside its scope. Response timeframes, permissible fees, and grounds for denial are governed by separate provisions of the Privacy Rule and are not addressed in detail here. State law, the HITECH Act, and current HHS OCR guidance may impose additional or more specific requirements, so practitioners should verify particulars against the current regulatory text.
Who it's relevant to
Inside DRS
Common questions
Answers to the questions practitioners most commonly ask about DRS.