Designated Record Set
A designated record set is the group of records a healthcare provider or health plan keeps that it uses to make decisions about individuals, such as medical records, billing records, and enrollment or claims records. Because this collection falls under HIPAA's privacy protections, it is generally the information individuals can request to access or ask to have amended. Not every piece of data an organization holds is part of the designated record set, so the specific boundaries matter for individual rights.
Under the HIPAA Privacy Rule, a designated record set is a group of records maintained by or for a covered entity that includes the medical records and billing records about individuals maintained by or for a covered health care provider; the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or other records used, in whole or in part, by or for the covered entity to make decisions about individuals. The 'records' comprising a designated record set consist of protected health information (PHI) that is collected, maintained, used, or disseminated by or for the covered entity. Identification of the designated record set is significant because it generally scopes an individual's rights of access and amendment under the Privacy Rule. This term is specific to the Privacy Rule and applies to PHI in any form; it should not be conflated with the Security Rule's narrower focus on ePHI. Note that some sources also discuss the designated record set in the context of the ONC Information Blocking Rule, which is a separate regulatory framework; readers should verify the exact regulatory definition and its precise scope against the current text of the applicable regulation, as related requirements under the HITECH Act, information blocking rules, or state law may impose additional obligations.
Why it matters
The designated record set is the practical boundary that determines the scope of an individual's HIPAA Privacy Rule rights to access and to request amendment of their protected health information. When a patient or health plan member asks to see or correct their records, the covered entity must be able to identify what falls within the designated record set, because that collection is generally the information subject to these rights. Getting this determination wrong in either direction creates compliance risk: defining it too narrowly can improperly deny individuals access to information they are entitled to, while defining it inconsistently can lead to incomplete or delayed responses to access requests.
Because the designated record set can span medical records, billing records, payment and claims records, health plan enrollment records, and other records used to make decisions about individuals, it often draws from multiple systems maintained by or for the covered entity. This makes identifying its precise boundaries an operational challenge, particularly in organizations where information is spread across electronic health records, billing platforms, and other repositories. The designated record set is not simply every piece of data an organization holds; the distinction matters for correctly fulfilling access and amendment requests.
Organizations should also be aware that the term appears in contexts beyond the HIPAA Privacy Rule. Some sources discuss the designated record set in relation to the ONC Information Blocking Rule, which is a separate regulatory framework with its own scope. Requirements under the HITECH Act, information blocking rules, or state law may impose additional obligations, so readers should verify the exact regulatory definition and its precise scope against the current text of the applicable regulation.
Who it's relevant to
Inside DRS
Common questions
Answers to the questions practitioners most commonly ask about DRS.