Skip to main content
Category: Individual Rights

Fee Limitations

Also known as: Right of Access Fee Limitations, PHI Copy Fee Limits, Reasonable Cost-Based Fee
Simply put

Fee Limitations refers to the rules under the HIPAA Privacy Rule that cap what a covered entity or business associate may charge an individual to receive a copy of their protected health information (PHI). Generally, any fee must be reasonable and cost-based, meaning it can only reflect certain limited, actual costs of producing the copy. These limits exist so that cost does not become a barrier to individuals exercising their right to access their own health records.

Formal definition

Under the HIPAA Privacy Rule's right of access provisions (generally at 45 CFR 164.524(c)(4)), a covered entity may charge an individual only a reasonable, cost-based fee for a copy of PHI or for acting on an access request. As reflected in HHS OCR guidance, permitted cost components are typically limited to labor for copying the PHI (whether in paper or electronic form), supplies for creating the paper copy or portable electronic media, postage where the individual requests mailing, and, if requested, the cost of preparing a requested explanation or summary. Costs such as record retrieval, searching, and general maintenance of systems are generally excluded from the permissible fee. HHS OCR has also described a flat-fee option (commonly cited as up to $6.50) as one method covered entities may use for electronic copies of PHI maintained electronically; practitioners should verify the current figure and methodology against current OCR guidance. Note that the 2020 Ciox Health v. Azar decision affected the application of these fee limitations to third-party directives (requests to send PHI to a third party), and the scope of fee limits in that context should be confirmed against current guidance. The HITECH Act expanded individual access rights (including access to electronic copies) and interacts with these fee provisions. Business associates that maintain PHI may have obligations relating to access and, following the Omnibus Rule and OCR's guidance on direct liability of business associates, can bear direct regulatory liability for failing to make ePHI available as required; obligations are not solely derivative of the business associate agreement. State law and other frameworks may impose additional or stricter fee constraints. This entry concerns HIPAA and is distinct from HITRUST, which is a private certification framework and does not itself establish these fee rules; readers should verify all specific figures, dates, and citations against the current regulatory text and current OCR guidance.

Why it matters

The HIPAA right of access is one of the most fundamental protections the Privacy Rule grants individuals, and cost can quickly become the practical barrier that defeats it. Fee Limitations exist so that patients are not effectively priced out of obtaining copies of their own health records. When a covered entity or business associate imposes fees that exceed the reasonable, cost-based standard, it is not merely a billing dispute; it can constitute a violation of an individual's right of access under the HIPAA Privacy Rule and expose the organization to enforcement by HHS OCR.

Right of access, including fee practices, has been a sustained enforcement priority for HHS OCR through its Right of Access Initiative, which has produced numerous settlements addressing failures to provide timely access to records. Because the permissible fee components are narrow, and commonly misunderstood costs such as record retrieval, searching, and general system maintenance are excluded, organizations that build fee schedules around traditional record-copying charges risk overcharging individuals in ways that draw regulatory scrutiny.

The area is also legally dynamic. The 2020 Ciox Health v. Azar decision affected how these fee limitations apply to third-party directives (requests to send PHI to a third party rather than to the individual). As a result, an organization's fee methodology that was compliant for one type of request may not translate cleanly to another. Compliance officers should treat fee schedules as living documents that must be reconciled against current OCR guidance rather than set once and forgotten.

Who it's relevant to

Privacy Officers and HIM/Release-of-Information Staff
Those who administer access requests and set copy-fee schedules must ensure fees are reasonable and cost-based, drawing only on permitted cost components and excluding retrieval, searching, and system-maintenance costs. They should periodically reconcile fee schedules against current OCR guidance, including the flat-fee option, and account for how third-party directives may be treated differently following Ciox Health v. Azar.
Compliance and Legal Teams
Given sustained OCR enforcement attention on the right of access, compliance and legal professionals should treat fee practices as a monitored risk area. They should verify current figures, citations, and the post-Ciox scope of fee limits, and confirm whether applicable state law imposes stricter fee constraints than HIPAA.
Business Associates Handling PHI
Business associates that maintain PHI may have obligations relating to access and can face direct regulatory liability for failing to make ePHI available as required, independent of the terms of the business associate agreement. They should coordinate with covered entities on how access requests and any associated fees are handled.
Health IT and Systems Vendors
Vendors supporting electronic records and portable-media production affect the labor and supply costs that legitimately factor into a permissible fee, as well as an organization's ability to use the electronic flat-fee option. Their configuration and support choices can influence whether an organization's fee methodology stays within the cost-based standard.

Inside Fee Limitations

Reasonable, Cost-Based Fee Standard
Under the HIPAA Privacy Rule's right of access provisions (generally located at 45 CFR 164.524(c)(4)), when a covered entity charges an individual for a copy of their PHI, any fee must be reasonable and cost-based. This is a substantive limitation on what may be charged, not a prohibition on all fees. Readers should verify the current regulatory text, as OCR guidance and case law have shaped its application.
Permitted Cost Components
The fee generally may include only certain limited costs, such as labor for copying the PHI (whether in paper or electronic form), supplies for creating the copy (e.g., paper or portable electronic media if requested), postage when the individual requests mailing, and preparation of an explanation or summary if the individual agrees in advance to such a summary and any associated fee. These categories should be confirmed against current OCR guidance.
Excluded Costs
Costs generally not permitted to be passed to the individual include costs associated with verification, documentation, searching for and retrieving the PHI, maintaining systems, and recouping capital or infrastructure costs. Retrieval/search fees are a commonly cited example of costs OCR has indicated may not be charged to the requesting individual.
Optional Flat-Fee Method
OCR guidance has described an optional flat-rate approach (commonly referenced as up to $6.50) that a covered entity may elect to use for providing electronic copies of PHI maintained electronically, in lieu of calculating actual or average costs. This is an option, not a cap or a required ceiling on all fees; the specific figure and its applicability should be confirmed against current HHS guidance.
HITECH Act Interplay
The HITECH Act expanded certain access rights, including the right to receive PHI in electronic form when maintained electronically, which affects how fee limitations apply to electronic copies. The fee-limitation framework should therefore be read together with HITECH-driven access provisions.
Impact of Ciox Health v. Azar (2020)
In Ciox Health, LLC v. Azar, a federal court vacated the extension of the individual fee limitation to third-party directives (i.e., when an individual directs that a copy be sent to a third party). As a result, the statutory fee limitations most clearly apply to copies requested by and provided to the individual, while fees for third-party directives may be treated differently. Practitioners should verify current OCR guidance, as this remains an evolving area.
Application to Business Associates
Business associates that maintain PHI may be obligated to make it available to satisfy access requests. Under the Omnibus Rule and OCR's guidance on direct liability of business associates, business associates can have direct regulatory liability for failing to provide required electronic PHI to the covered entity or the individual as needed to meet 45 CFR 164.524(c)(2)(ii)/(c)(3)(ii). Specific obligations are also allocated through the business associate agreement, but this does not eliminate a business associate's independent liability under HIPAA.

Common questions

Answers to the questions practitioners most commonly ask about Fee Limitations.

Is "Fee Limitations" a real HIPAA concept, or just an informal term?
It is a real regulatory concept. The HIPAA Privacy Rule expressly limits the fees a covered entity (and, in applicable circumstances, a business associate) may charge an individual for a copy of their protected health information under 45 CFR 164.524(c)(4). In general, any fee charged must be reasonable and cost-based. Readers should verify the specific provisions against the current regulatory text, as OCR guidance in this area has evolved.
Do fee-limitation obligations only apply to covered entities, with business associates insulated through the business associate agreement?
No. While business associate agreements allocate responsibilities, business associates also have direct regulatory liability in this area. Following the 2013 Omnibus Rule and OCR's guidance on the direct liability of business associates, a business associate can be held directly liable for failing to provide ePHI to a covered entity or an individual as needed to satisfy the individual's right of access under 45 CFR 164.524(c)(2)(ii) and (c)(3)(ii). Obligations do not attach solely through the agreement. Confirm the current scope against OCR guidance.
What cost components may generally be included in the fee, and what must be excluded?
As reflected in 45 CFR 164.524(c)(4) and OCR guidance, a reasonable, cost-based fee may generally include labor for copying the PHI (whether paper or electronic), supplies for creating the copy (such as paper or portable media), postage when the individual requests mail delivery, and, if agreed to in advance, the cost of preparing an explanation or summary. Costs such as those associated with verification, documentation, searching for and retrieving the PHI, and general overhead are generally excluded. Because OCR's treatment of permissible cost elements has been the subject of guidance and litigation, readers should verify against current OCR materials and the regulatory text.
Is there a simplified way to calculate the fee instead of itemizing actual costs?
OCR guidance has described more than one permissible approach, including calculating actual costs, using a schedule of average costs, and, for electronic copies of PHI maintained electronically, a flat fee option identified by OCR as up to $6.50 (inclusive of labor, supplies, and postage). This flat fee is an optional method, not a cap on all fees or a required charge. Because these figures and methods appear in OCR guidance that has been subject to change and litigation, confirm the current amount and its availability against current OCR guidance before relying on it.
How did the Ciox Health v. Azar decision affect fee limitations for records sent to third parties?
In the 2020 Ciox Health v. Azar decision, a federal court vacated the portion of OCR guidance that extended the individual right-of-access fee limitations to an individual's directive to send PHI to a third party. As a result, the fee limitations under 45 CFR 164.524(c)(4) apply to requests where the individual is obtaining their own copy, but the third-party directive fee limitation described in prior guidance was set aside. State law and other requirements may still affect third-party requests. Verify the current status of OCR guidance, as the agency has posted notices reflecting the court's ruling.
Does complying with the fee limitations also satisfy any HITECH Act or state-law requirements?
Not necessarily. The fee limitations sit within the HIPAA Privacy Rule right of access, which HITECH strengthened, so the two are interrelated, but compliance with 45 CFR 164.524(c)(4) addresses the HIPAA fee standard specifically. State laws frequently impose their own limits or record-copy fee schedules, and where state law is more protective of the individual it may apply. Organizations should evaluate applicable state law alongside HIPAA and confirm current requirements before setting a fee schedule. HITRUST CSF certification, being a private control framework, does not by itself establish compliance with these fee requirements.

Common misconceptions

Fee limitations mean a covered entity cannot charge anything for copies of PHI.
The Privacy Rule permits a reasonable, cost-based fee. Fee limitations restrict which cost components may be included and require reasonableness; they do not bar charging altogether. The optional flat-fee method is one permitted approach for electronic copies.
The same fee limitations apply identically whether the individual receives the copy or directs it to a third party.
Following Ciox Health v. Azar (2020), the fee limitation was vacated as applied to third-party directives. The clearest application of the individual fee limitation is to copies provided to the individual. Third-party directive fees may be handled differently, and practitioners should confirm current OCR guidance.
Because obligations are allocated through a business associate agreement, business associates have no independent HIPAA liability for access-related requirements.
Under the Omnibus Rule and OCR's direct-liability guidance, business associates can be directly liable for failing to provide electronic PHI to the covered entity or individual as required to satisfy the access provisions. The BAA allocates responsibilities but does not remove independent statutory liability.

Best practices

Document your methodology for calculating access fees, choosing among actual cost, average cost, or the optional flat-fee approach, and confirm the current permissible figure and method against current OCR guidance and 45 CFR 164.524(c)(4).
Exclude non-permitted costs such as search, retrieval, verification, and infrastructure/capital costs from any fee charged to the individual.
Maintain a clear distinction in your policies and workflows between copies requested by the individual and third-party directives, accounting for the Ciox Health v. Azar decision, and verify current guidance before applying fee limits to third-party directives.
Address electronic access explicitly, ensuring that when PHI is maintained electronically the individual can receive it in the requested electronic form consistent with HITECH-driven access rights, and apply the appropriate fee approach for electronic copies.
Update business associate agreements and internal procedures to reflect both the allocation of access obligations and the fact that business associates may bear direct HIPAA liability for failing to make electronic PHI available.
Periodically review fee schedules, policies, and OCR guidance because permitted amounts, methods, and enforcement interpretations are adjusted over time; confirm any specific dollar figures or citations against the current regulation and current HHS guidance, and check whether applicable state law imposes additional or stricter requirements.