Skip to main content
Category: Individual Rights

Access to Electronic Copy

Also known as: Right to Electronic Copy of PHI, Electronic Access to PHI
Simply put

Under the HIPAA Privacy Rule, if a covered entity keeps your protected health information electronically, you generally have the right to get an electronic copy of it. In most cases you can request the copy in the electronic format you prefer, and if the records can be readily produced that way, the covered entity should provide it in that format or in an agreed-upon alternative. This right applies to the individual whose information it is and is separate from the broader rules governing how such information may be used or disclosed.

Formal definition

The individual right of access under the HIPAA Privacy Rule generally entitles an individual to obtain an electronic copy of protected health information (PHI) that a covered entity maintains electronically in a designated record set. Where the PHI is readily producible in the electronic form and format requested by the individual, the covered entity is generally expected to provide it in that form and format; if it is not readily producible in the requested form, the copy may be provided in a readable electronic form as agreed to by the covered entity and the individual. This entry addresses the individual's access right to electronic copies only and does not cover the full scope of access-request procedures, timeliness requirements, permissible grounds for denial, or fee limitations, all of which readers should verify against the current Privacy Rule text and current HHS OCR guidance. Note that this right arises under the Privacy Rule (governing PHI in all forms) rather than the Security Rule, and that the HITECH Act and applicable state laws may impose additional or more stringent requirements.

Why it matters

The right to obtain an electronic copy of protected health information is a cornerstone of individual empowerment under the HIPAA Privacy Rule. When a covered entity maintains PHI electronically, individuals generally have the ability to receive that information in electronic form, which supports patients in managing their own care, seeking second opinions, transferring records between providers, and engaging more actively with their health data. Because so much health information is now stored in electronic health record systems, the electronic access right has become one of the most frequently exercised individual rights, and one of the most common sources of friction between patients and organizations.

For covered entities, mishandling access requests carries real compliance exposure. Denying an individual a copy in the electronic form they requested when the records are readily producible in that form, or defaulting to paper when electronic copies are feasible, can put an organization out of step with the Privacy Rule's access provisions. HHS OCR has treated the individual right of access as an enforcement priority, and access-related complaints are a recurring category of concern. Organizations should treat electronic access as an operational obligation to build into their workflows rather than an ad hoc exception.

It is important to keep this right in its proper scope. The electronic copy right arises under the Privacy Rule, which governs PHI in all forms, and is distinct from the Security Rule's requirements for protecting ePHI. This entry addresses only the individual's right to an electronic copy; the broader mechanics of access requests, permissible grounds for denial, timeliness requirements, and fee limitations should be verified against the current Privacy Rule text and current HHS OCR guidance. The HITECH Act and applicable state laws may also impose additional or more stringent requirements.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are typically responsible for designing and overseeing the procedures that fulfill access requests. They should ensure that intake, verification, format negotiation, and delivery processes account for the individual's right to an electronic copy in a requested or agreed-upon format, and that staff understand this right flows from the Privacy Rule rather than the Security Rule. Detailed procedures, timeliness, and fee handling should be confirmed against current Privacy Rule text and HHS OCR guidance.
Health Information Management and Records Teams
Records and HIM staff are often the ones who determine whether PHI is readily producible in a requested electronic form and who execute the actual production. They need practical familiarity with the organization's electronic health record and export capabilities so they can distinguish between formats that are readily producible and those that require an agreed-upon alternative.
IT and EHR System Administrators
Technical teams that manage electronic record systems shape what electronic formats an organization can readily produce. Their configuration and export capabilities directly affect whether the covered entity can honor a requested format, making their input important when evaluating what is reasonably feasible.
Covered Entities Generally
Any covered entity that maintains PHI electronically should recognize the individual's electronic access right as an operational obligation to build into standard workflows. Because state law and the HITECH Act may impose additional requirements, organizations operating across jurisdictions should verify their obligations beyond the baseline federal Privacy Rule.

Inside Access to Electronic Copy

Individual Right of Access
Under the HIPAA Privacy Rule, individuals generally have the right to inspect and obtain a copy of protected health information (PHI) about themselves that is maintained in a designated record set by a covered entity or by a business associate acting on its behalf.
Electronic Copy of ePHI
When the requested PHI is maintained electronically in one or more designated record sets, the individual generally has the right to obtain a copy in the electronic form and format they request, if it is readily producible in that form and format.
Readily Producible Standard
If the requested electronic form and format is not readily producible, the covered entity is generally expected to provide the copy in a readable electronic form and format as agreed upon with the individual. This is a Privacy Rule access concept and should be distinguished from Security Rule transmission safeguards.
Designated Record Set
Access rights apply to information within the designated record set, which has a specific regulatory meaning under the Privacy Rule and typically includes medical and billing records used to make decisions about individuals. Not all data a covered entity holds falls within this set.
Transmission to a Third Party
An individual may direct a covered entity to transmit an electronic copy of PHI to a designated person or entity, subject to the requirements and any limitations reflected in current HHS OCR guidance, which readers should verify against the applicable regulatory text.
Fees for Copies
A covered entity may generally impose a reasonable, cost-based fee for providing copies, within the parameters permitted under the Privacy Rule and current HHS OCR guidance. Specific fee limitations and permissible cost components should be confirmed against current guidance.
Timeliness of Response
Covered entities are generally required to act on access requests within the timeframe established by the Privacy Rule. The specific number of days and any permitted extension should be verified against the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Access to Electronic Copy.

Does the right of access apply only to electronic records, or does an individual's request for an electronic copy mean the covered entity must always produce one?
The right of access under the Privacy Rule generally applies to protected health information maintained in a designated record set regardless of form, not only electronic records. Where PHI is maintained electronically, an individual generally has the right to request an electronic copy, and a covered entity is generally required to provide it in the electronic form and format requested if it is readily producible in that form and format. If it is not readily producible in the requested form, the covered entity and individual generally work to agree on an alternative readable electronic form. This is a Privacy Rule right of access and should not be confused with Security Rule obligations governing ePHI. Verify specifics against the current regulatory text.
Is the right to an electronic copy the same as a HIPAA Security Rule requirement, and does providing electronic access satisfy the Security Rule?
No. The right to an electronic copy arises from the Privacy Rule's right of access, which covers PHI in all forms. The Security Rule is a separate rule that governs the confidentiality, integrity, and availability of ePHI through administrative, physical, and technical safeguards. Fulfilling an access request does not by itself satisfy Security Rule obligations, and having Security Rule safeguards in place does not by itself satisfy the access right. The two rules impose distinct obligations that a covered entity generally must meet independently. Confirm details against current guidance.
In what electronic format must a covered entity provide the copy?
A covered entity generally must provide the copy in the electronic form and format requested by the individual if the information is readily producible in that form and format. If it is not readily producible as requested, the covered entity and individual generally arrive at an agreed-upon alternative readable electronic format. There is no single universally mandated file type in the regulatory text; the standard centers on what is readily producible and readable. Because format expectations and any related guidance can change, confirm current requirements against the applicable regulation.
Can a covered entity charge a fee for providing an electronic copy?
The Privacy Rule generally permits a reasonable, cost-based fee for providing copies, and the components that may be included in such a fee are addressed in the regulatory text and OCR guidance. Fee limitations and the treatment of labor, supplies, and postage have been the subject of specific guidance and legal developments over time. Because permissible fee methodologies and figures are adjusted and subject to interpretation, a covered entity should verify current fee rules and any applicable state-law limits before setting charges.
How quickly must a covered entity respond to a request for an electronic copy?
The Privacy Rule generally establishes an outer time limit for acting on an access request, with a possibility of a limited extension when the covered entity provides the individual with a written statement of the reasons for delay and the expected completion date. Because the specific number of days and extension conditions are set in the regulatory text and may be updated, confirm the current timeframes against the applicable regulation rather than relying on a fixed figure here. Note that state law may impose shorter deadlines.
What should a covered entity do if an individual asks that the electronic copy be sent to a third party?
The right of access generally includes the ability for an individual to direct the covered entity to transmit a copy to a designated third party, subject to conditions in the regulatory text, such as the request being in writing, signed, and clearly identifying the recipient and where to send the copy. The scope of directed-transmission obligations has been affected by legal developments over time, so a covered entity should verify the current requirements and any distinctions between the individual's own access and third-party directives before implementing a workflow. Transmission should also be handled consistent with applicable Security Rule safeguards for ePHI.

Common misconceptions

Providing an electronic copy is governed by the HIPAA Security Rule.
The individual right of access, including the right to an electronic copy, arises under the HIPAA Privacy Rule and applies to PHI in a designated record set. The Security Rule governs safeguards for ePHI and applies to how the electronic copy is protected in transit and at rest, but it does not create the access right itself. The two rules are complementary but distinct in scope.
An individual can demand any electronic format and the covered entity must always produce it.
The right is to the requested electronic form and format only when it is readily producible in that form. If it is not readily producible, the covered entity generally provides the copy in a readable electronic form and format agreed upon with the individual, rather than being obligated to build or purchase capabilities to meet any arbitrary format request.
The right of access covers everything a covered entity or its vendors hold about a person.
Access generally applies to PHI within a designated record set, a term with a specific regulatory meaning. Certain information may fall outside that set. Business associates typically fulfill access requests only as provided in the business associate agreement and on behalf of the covered entity, rather than as an independent obligation.

Best practices

Establish a documented process for identifying which requested information falls within the designated record set, distinguishing it from information that may be outside the scope of the access right.
Offer individuals their requested electronic form and format when readily producible, and document any agreement reached on an alternative readable electronic format when it is not.
Apply Security Rule safeguards to the electronic copy during production and transmission, recognizing that the access right derives from the Privacy Rule while protection of the ePHI is a Security Rule concern.
Confirm response timeframes and any permitted extensions against the current Privacy Rule text, and track requests to ensure timely action.
Verify permissible fee structures against current HHS OCR guidance before charging, and keep fees reasonable and cost-based where fees are applied.
Address business associate responsibilities for access requests explicitly in business associate agreements, and check whether state law or the HITECH Act imposes additional requirements beyond the baseline HIPAA obligations.