Skip to main content
Category: De-identification and PHI Types

Designated Record Set

Also known as: DRS, Designated Record Sets
Simply put

A designated record set is the group of records a healthcare provider or health plan keeps that it uses to make decisions about individuals, such as medical records, billing records, and enrollment or claims records. Because this collection falls under HIPAA's privacy protections, it is generally the information individuals can request to access or ask to have amended. Not every piece of data an organization holds is part of the designated record set, so the specific boundaries matter for individual rights.

Formal definition

Under the HIPAA Privacy Rule, a designated record set is a group of records maintained by or for a covered entity that includes the medical records and billing records about individuals maintained by or for a covered health care provider; the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or other records used, in whole or in part, by or for the covered entity to make decisions about individuals. The 'records' comprising a designated record set consist of protected health information (PHI) that is collected, maintained, used, or disseminated by or for the covered entity. Identification of the designated record set is significant because it generally scopes an individual's rights of access and amendment under the Privacy Rule. This term is specific to the Privacy Rule and applies to PHI in any form; it should not be conflated with the Security Rule's narrower focus on ePHI. Note that some sources also discuss the designated record set in the context of the ONC Information Blocking Rule, which is a separate regulatory framework; readers should verify the exact regulatory definition and its precise scope against the current text of the applicable regulation, as related requirements under the HITECH Act, information blocking rules, or state law may impose additional obligations.

Why it matters

The designated record set is the practical boundary that determines the scope of an individual's HIPAA Privacy Rule rights to access and to request amendment of their protected health information. When a patient or health plan member asks to see or correct their records, the covered entity must be able to identify what falls within the designated record set, because that collection is generally the information subject to these rights. Getting this determination wrong in either direction creates compliance risk: defining it too narrowly can improperly deny individuals access to information they are entitled to, while defining it inconsistently can lead to incomplete or delayed responses to access requests.

Because the designated record set can span medical records, billing records, payment and claims records, health plan enrollment records, and other records used to make decisions about individuals, it often draws from multiple systems maintained by or for the covered entity. This makes identifying its precise boundaries an operational challenge, particularly in organizations where information is spread across electronic health records, billing platforms, and other repositories. The designated record set is not simply every piece of data an organization holds; the distinction matters for correctly fulfilling access and amendment requests.

Organizations should also be aware that the term appears in contexts beyond the HIPAA Privacy Rule. Some sources discuss the designated record set in relation to the ONC Information Blocking Rule, which is a separate regulatory framework with its own scope. Requirements under the HITECH Act, information blocking rules, or state law may impose additional obligations, so readers should verify the exact regulatory definition and its precise scope against the current text of the applicable regulation.

Who it's relevant to

Privacy Officers and HIPAA Compliance Staff
Privacy officers are typically responsible for defining and documenting what constitutes the organization's designated record set and for ensuring that access and amendment requests are fulfilled from the correct scope of records. Consistent identification of the designated record set supports reliable handling of individual rights requests under the Privacy Rule.
Health Information Management and Medical Records Teams
Staff who manage medical records and billing records need to know which records fall within the designated record set so they can locate and produce the appropriate information when individuals request access or amendment. Because these records may span multiple systems maintained by or for the covered entity, coordination across repositories is often necessary.
Health Plans
Health plans maintain enrollment, payment, claims adjudication, and case or medical management record systems that generally form part of their designated record set. Plan personnel handling member requests for access or amendment should understand which of these records are in scope.
Legal and Compliance Counsel
Counsel advising covered entities may need to interpret the boundaries of the designated record set, particularly where the term also arises under the ONC Information Blocking Rule or where state law or the HITECH Act may impose additional obligations. The precise scope should be verified against the current text of the applicable regulation.

Inside DRS

Medical Records
The medical and clinical records maintained by or for a covered entity, including provider notes, test results, and treatment documentation. This is a core component of the designated record set under the HIPAA Privacy Rule.
Billing Records
The billing and payment records maintained by or for a covered entity, such as claims, statements, and financial account information related to the individual's care.
Enrollment, Payment, Claims Adjudication, and Case or Medical Management Records
For a health plan, the records used to make decisions about individuals, including enrollment, payment, claims adjudication, and case or medical management systems.
Records Used to Make Decisions About Individuals
Any other group of records that is used, in whole or in part, by or for the covered entity to make decisions about individuals. This catch-all element means the designated record set is defined by use, not merely by record type.
Records Maintained By or For the Covered Entity
The set includes records the covered entity maintains itself as well as those maintained on its behalf, which can include records held by a business associate under a business associate agreement.

Common questions

Answers to the questions practitioners most commonly ask about DRS.

Does a designated record set include every record a covered entity holds about an individual?
No. A designated record set is generally limited to records used, in whole or in part, to make decisions about individuals, typically medical and billing records maintained by or for a covered entity, and enrollment, payment, claims adjudication, and case or medical management records for health plans. Not every document that mentions an individual falls within the designated record set. Records used solely for other purposes, and certain information such as psychotherapy notes or information compiled for use in legal proceedings, are commonly treated differently. Because the precise boundaries depend on how records are actually used, you should confirm scope against the current Privacy Rule text.
Is the designated record set the same thing as the medical record?
Not exactly. The medical record is often a component of a designated record set, but the concept is broader. A designated record set can also include billing records and, for health plans, enrollment, payment, claims, and case management records. It may span multiple systems and formats, paper, electronic, and other media, rather than a single clinical chart. Treating the two as identical can cause an organization to overlook records that an individual has a right to access. Verify how the term applies to your specific record systems under the current regulation.
How should an organization identify what falls within its designated record set?
A common approach is to inventory the record systems maintained by or for the organization and evaluate which records are used, in whole or in part, to make decisions about individuals. This generally includes medical and billing systems and, for health plans, enrollment, payment, claims, and case management systems. Because designated record sets can cross multiple applications, departments, and formats, documenting the systems and their uses helps support consistent responses to access and amendment requests. Definitions should be confirmed against the current Privacy Rule, and note that state law may impose additional recordkeeping or access requirements.
How does the designated record set relate to an individual's right of access under the Privacy Rule?
The individual's right to inspect and obtain a copy of their protected health information generally applies to information maintained in a designated record set. Identifying the designated record set is therefore a practical prerequisite to fulfilling access requests, because it establishes which records are within scope. Certain categories may be excluded or handled under specific provisions. Organizations should apply the current Privacy Rule requirements regarding scope, timing, form, format, and any permitted grounds for denial, and confirm details against current HHS OCR guidance.
Do business associates need to consider the designated record set?
In many cases, yes, when a business associate maintains records on behalf of a covered entity that form part of that covered entity's designated record set. The business associate agreement typically addresses how the business associate supports the covered entity's obligations, including making relevant information available for access and amendment. The specific responsibilities depend on the terms of the agreement and how records are maintained, so those documents and the current regulatory requirements should be reviewed to confirm each party's role.
Does maintaining records across paper and electronic systems affect the designated record set?
It can, because a designated record set is defined by how records are used to make decisions about individuals, not by their format. Relevant records may exist in paper, electronic, and other forms across different systems. This is a Privacy Rule concept covering protected health information in all forms, which is broader than the Security Rule's focus on electronic protected health information. Organizations generally need processes to locate and compile responsive records regardless of medium, and should verify scope and handling against the current regulation.

Common misconceptions

The designated record set only includes the formal medical chart.
The designated record set is generally broader than the medical chart. It also encompasses billing records, and for health plans, enrollment, payment, claims adjudication, and case management records, as well as any other records used to make decisions about the individual. Scope is driven by how records are used, not by a single document.
The right of access under the Privacy Rule extends to everything in the designated record set without limitation.
While individuals generally have a right to access PHI in a designated record set, the Privacy Rule includes certain exceptions and limitations, such as psychotherapy notes and information compiled for legal proceedings. Practitioners should verify specific exclusions against the current regulatory text, as some categories fall outside the accessible set.
The designated record set is a Security Rule concept limited to electronic records.
The designated record set is a Privacy Rule concept and applies to PHI in all forms, including paper and oral records where applicable, not just ePHI. The Security Rule, by contrast, governs only electronic PHI, so the two should not be conflated.

Best practices

Inventory and document all record groups that qualify as designated record sets, including medical, billing, and any records used to make decisions about individuals, so access requests can be fulfilled completely and consistently.
Clarify in business associate agreements how PHI maintained by or for the covered entity within the designated record set will be produced when an individual exercises the right of access.
Establish clear procedures for identifying which portions of a record are subject to access and which fall under Privacy Rule exceptions, and train staff to apply those distinctions correctly.
Verify the specific scope, exceptions, and any timing requirements for access requests against the current text of the HIPAA Privacy Rule, since regulatory details are subject to change.
Confirm whether applicable state law or the HITECH Act imposes additional access or record-handling obligations beyond the federal HIPAA baseline.
Periodically review and update the designated record set inventory as systems, vendors, and record uses change, to ensure decision-making records remain accounted for.