Skip to main content
Category: Individual Rights

Individual Access Right Fees

Also known as: Access Fees, Right of Access Fees, Cost-Based Fee for Access
Simply put

Individual Access Right Fees are the limited charges a healthcare provider or health plan may pass on to a person who asks for a copy of their own health information under HIPAA. The fee generally must be reasonable and based only on actual costs, and it cannot be used to discourage people from getting their records. In many cases, such as when records are available through a patient portal, no fee should be charged at all.

Formal definition

Under the HIPAA Privacy Rule's individual right of access, a covered entity (or a business associate acting on its behalf) may impose only a reasonable, cost-based fee when providing an individual with a copy of their protected health information (PHI). Per the evidence, permissible cost components are generally limited to labor for copying the PHI, supplies for creating the paper copy or electronic media, postage when the copy is mailed, and preparation of an explanation or summary if the individual agrees in advance to that summary and its associated fee. Fees apply only where the individual is receiving a copy of their PHI, and no charge is generally warranted where the individual can obtain the information through means such as a patient portal. This entry addresses the fee limitation on the individual access right and does not cover fees for third-party disclosures, disclosures for treatment/payment/operations, or record fees permitted under other authorities. Note that the specific scope and any applicable dollar caps or fee-calculation methodologies have been subject to litigation and regulatory guidance, and state law may impose additional or more restrictive requirements; readers should verify against the current regulatory text and HHS OCR guidance.

Why it matters

The individual right of access is one of the cornerstone protections of the HIPAA Privacy Rule, and the fee limitation exists to ensure that cost is not used as a barrier to people obtaining copies of their own health information. When fees are inflated, calculated on impermissible cost components, or applied where no charge is warranted, they can effectively discourage individuals from exercising a right the regulation intends to be readily available. For compliance officers and privacy officers, getting fee practices right is therefore not merely an administrative detail but a matter of honoring a fundamental individual right.

Access-related failures, including overcharging and delays, have historically been an area of focus for HHS OCR enforcement of the Privacy Rule. Because the permissible fee is limited to actual, reasonable costs of copying labor, supplies, postage, and an agreed-upon summary, organizations that apply flat per-page schedules or bundle in overhead, retrieval, or search costs risk exceeding what the access right allows. Where records are available through a patient portal, the evidence indicates no charge is generally warranted, which further narrows the circumstances in which any fee is appropriate.

Beyond federal requirements, state law may impose additional or more restrictive limits on what may be charged for medical records, and the specific scope of permissible fees and any applicable calculation methodologies have been the subject of litigation and regulatory guidance. Readers should treat fee schedules as a live compliance area, verify their practices against the current regulatory text and HHS OCR guidance, and confirm applicable state-law requirements rather than relying on a single fixed formula.

Who it's relevant to

Privacy Officers and Compliance Officers
These professionals are responsible for setting and monitoring the organization's fee schedule for access requests. They should ensure fees are limited to the permissible cost components, that no charge is applied where records are available through a patient portal, and that practices are reconciled against current HHS OCR guidance and any more restrictive state-law requirements.
Health Information Management (HIM) and Medical Records Staff
Staff who fulfill copy requests apply fee schedules in day-to-day operations. They need clear guidance on what labor, supplies, and postage may be charged, when an agreed-upon summary fee applies, and when no fee should be assessed, so that access requests are handled consistently and within the access right's limits.
Covered Entities and Business Associates Handling Access Requests
A covered entity, or a business associate acting on its behalf, may impose the cost-based access fee. Both should understand that the fee limitation attaches specifically to the individual right of access and does not extend to third-party disclosures or fees permitted under other authorities, and that overcharging in this area has historically drawn enforcement attention.
Legal and Regulatory Counsel
Because the scope of permissible fees, any dollar caps, and calculation methodologies have been subject to litigation and evolving guidance, counsel play a key role in verifying current requirements and reconciling HIPAA's fee limitation with additional or more restrictive obligations under applicable state law.

Inside Individual Access Right Fees

Individual Access Right
The HIPAA Privacy Rule generally grants individuals the right to inspect and obtain a copy of protected health information about them held in a designated record set by a covered entity, subject to certain limited exceptions.
Reasonable, Cost-Based Fee
When an individual requests a copy of their PHI under the access right, a covered entity may generally charge only a reasonable, cost-based fee, rather than an unlimited or market-rate charge.
Permitted Fee Components
The allowable fee is typically limited to certain narrowly defined categories of cost associated with fulfilling the request. Practitioners should confirm the specific permitted components against the current regulatory text and HHS OCR guidance, as this area has been subject to interpretation and litigation.
Excluded Costs
Certain costs, such as those associated with searching for and retrieving the requested information, are generally not permitted to be passed on to the individual under the access right fee limitation. Readers should verify the current scope against applicable guidance.
Applicable Requesters and Scope
The fee limitation applies to requests made by the individual (or their personal representative) exercising the access right. Requests routed through other legal mechanisms or by third parties may be treated differently; the distinction is significant and should be evaluated against current guidance.
Enforcement Authority
HHS OCR enforces the individual access right, including the associated fee limitations, and has treated access-related issues, including overcharging, as an enforcement priority. Penalty tiers and figures are adjusted over time and should be confirmed against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about Individual Access Right Fees.

Can a covered entity charge whatever it costs to fulfill an individual's request for access to their PHI?
No. The HIPAA Privacy Rule permits only a reasonable, cost-based fee for individual access requests, and the categories of costs that may be included are limited. A covered entity generally cannot pass along the full range of its actual costs; for example, costs such as searching for and retrieving the records, or general overhead, typically fall outside what may be charged. The specific permissible cost components and any applicable flat-fee options should be confirmed against the current regulatory text and HHS OCR guidance, and note that state law may impose lower limits or additional restrictions.
Does the individual access right fee limit apply the same way when a patient directs their records to a third party as when they request records for themselves?
This distinction has a specific regulatory history and should be treated carefully. The fee limitations were developed in the context of an individual's right to access their own PHI, and the scope of when those limits apply to third-party directives has been subject to litigation and changing HHS OCR guidance. Because the applicability of the access-fee limits to third-party transmissions has shifted over time, readers should verify the current status against the applicable regulatory text and current HHS OCR guidance rather than assuming the limit applies uniformly.
What cost components may generally be included when calculating a permissible access fee?
The Privacy Rule allows a reasonable, cost-based fee limited to certain defined categories, which generally relate to the labor and supplies directly involved in producing the copy in the form and format requested, and, where applicable, postage. Costs such as record retrieval, searching, or general administrative overhead are typically not permissible. Because the precise permissible components carry specific regulatory meaning, covered entities should confirm the current list against the applicable regulatory text and current HHS OCR guidance before setting a fee schedule.
How can an organization calculate a compliant fee in practice?
Covered entities generally have more than one method available for calculating a cost-based fee, which may include actual costs, an average or reasonable estimate, or a flat fee for electronic copies of records maintained electronically. Whichever method is used, the organization should be able to demonstrate that the fee reflects only the permitted cost categories. Because the available methods and any flat-fee thresholds are defined by regulation and guidance that can change, verify the current options and any caps against the applicable regulatory text and current HHS OCR guidance.
Should the fee policy be documented, and what should that documentation address?
Documenting the fee methodology is generally advisable so the organization can support that any charge is reasonable and cost-based. Documentation typically addresses which calculation method is used, the cost components included, how those components map to the permitted categories, and how the policy accommodates requests in different forms and formats. Organizations should also account for the possibility that state law imposes stricter limits, and should periodically review the policy against current regulatory text and HHS OCR guidance.
How do state law and other requirements interact with the HIPAA access fee limits?
HIPAA's access fee limitations set a federal floor of individual protection, but state law may impose lower fee caps or additional restrictions, in which case the more protective requirement generally governs. Fee schedules established under other bodies of law, such as general medical-records copying statutes, do not necessarily satisfy the HIPAA access-fee limits. Organizations operating in multiple states should assess each applicable state's requirements alongside the federal standard and confirm details against current regulatory text and guidance.

Common misconceptions

A covered entity can charge whatever a state medical records statute permits, including per-page fees and retrieval charges.
When an individual is exercising the HIPAA access right, the fee is generally limited to a reasonable, cost-based amount under HIPAA. State law may set different or higher limits, but state law that permits fees exceeding what HIPAA allows for the access right does not override the HIPAA limitation for those requests. Where state law is more protective of the individual, it may impose additional constraints. Verify the interaction against current regulation and state law.
The fee limitation applies to every request for records, including those from attorneys, insurers, and other third parties.
The reasonable, cost-based fee limitation is tied specifically to the individual exercising their access right (or their personal representative acting on their behalf). Requests made by third parties under other authorities may be handled differently. The distinction between an individual-directed request and a third-party request is significant and should be evaluated carefully.
Covered entities may include the cost of searching for and retrieving the records in the access fee.
Search and retrieval costs are generally not permitted to be included in the fee charged to an individual exercising the access right. The permitted components are narrower, and practitioners should confirm which specific costs are allowable against the current regulatory text and HHS OCR guidance.

Best practices

Establish and document a written fee methodology for individual access requests that ties any charge to a reasonable, cost-based amount, and confirm the permitted components against the current regulatory text and HHS OCR guidance.
Distinguish operationally between requests made by the individual exercising their access right and requests submitted by third parties, since the applicable fee treatment generally differs.
Train records and release-of-information staff to avoid applying state per-page or retrieval-based fee schedules to individual access requests where those exceed what HIPAA permits.
Periodically review the fee schedule against current HHS OCR guidance and applicable state law, noting that state law may impose additional or more protective requirements and that penalty figures are adjusted over time.
Retain documentation supporting how any fee was calculated so it can be produced if HHS OCR reviews the practice, given that access issues have been an enforcement priority.
When uncertain whether a specific cost is chargeable, default to the more conservative interpretation and verify against current regulation rather than assuming a cost may be passed on to the individual.