Summer May Be Winding Down, But the HIPAA Right of Access Initiative Is Still Here

Newsletter
Overview

Summer may be winding down, but the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) Right of Access Initiative is not. OCR launched its Right of Access Initiative in 2019 to address the widespread failure of covered entities to provide timely access to records. With the August 27, 2026, announcement of a settlement with Azul Vision, Inc. (“Azul Vision”), the initiative has now resulted in 55 enforcement actions, signaling that patient access remains a year-round compliance priority. Against that enforcement backdrop, covered entities should revisit the deadlines that apply to access requests—and ensure those deadlines are not lost in the end-of-summer shuffle.

The HIPAA Right of Access: What HIPAA Requires

Under the HIPAA Privacy Rule, individuals have a right to access and obtain a copy of their protected health information (“PHI”) maintained in a designated record set. Covered Entities must act on a request for access no later than 30 calendar days after receipt. If the entity cannot meet the 30-day deadline, it may take a single 30-day extension, provided it gives the individual a written statement of the reasons for the delay and the date by which it will fulfill the records request.

The Azul Vision settlement illustrates the consequences of allowing an access request to linger well beyond its regulatory deadline.

The Azul Vision Investigation and Settlement

In January 2023, a patient submitted a request for access to PHI maintained by Azul Vision. When the records were not provided, the patient filed a complaint with OCR in April 2023. OCR opened an investigation, but Azul Vision did not provide the requested records to the patient until January 2025—nearly two years after the initial request and well beyond the 30-day (or, with extension, 60-day) regulatory timeframe. The settlement requires Azul Vision, a California-based optometry and ophthalmology provider, to pay $50,000 and implement a two-year corrective action plan monitored by HHS. Azul Vision is also required to:

  • Review and revise its policies and procedures for processing access requests;
  • Report to HHS on all PHI access requests received and their completion dates during the monitoring period; and
  • Train all workforce members on its policies and procedures, including the right-of-access requirements.
Key Takeaways and Compliance Steps for Covered Entities

Regarding the settlement, OCR Director Paula M. Stannard stated, “The right of access is key to empowering individuals to take control of their own health. It should not be necessary for OCR to initiate a right of access investigation before a covered entity will provide an individual with access to their requested records.”

The statement and the settlement underscore that a delay in providing the records is, itself, a violation of an individual’s right; providing the records after the deadline does not cure a covered entity’s failure to meet the required timeframe.

As organizations return from summer schedules and prepare for the fall, this is an opportune time to ensure that access requests are properly received, tracked, escalated, and completed. Covered entities should evaluate their right-of-access processes and consider the following measures:

  • Centralized Intake and Tracking. Establish a centralized system for receiving and logging all access requests. A single point of intake reduces the risk that requests are lost or overlooked.
  • Deadline Escalation Protocols. Build automated reminders and escalation procedures tied to the 30-day deadline. Designate a responsible individual or compliance officer to receive escalation alerts when a request approaches its due date.
  • Extension Documentation. If a 30-day extension is needed, document the reason in writing and notify the requesting individual of the expected completion date before the initial 30-day window expires. Remember that only one extension is permitted.
  • Workforce Training. Provide regular, documented training to all workforce members on right-of-access policies, timelines, and procedures. Training should be repeated at least annually and upon any policy revision.
  • Business Associate Coordination. Where PHI is maintained by a business associate (e.g., an electronic health records vendor or cloud storage provider), ensure that business associate agreements address cooperation with access requests and that contractual response timelines allow the covered entity to meet its 30-day obligation.
  • Periodic Audits. Conduct periodic internal audits of access-request processing to measure average response times, identify bottlenecks, and confirm that requests are being fulfilled within regulatory timelines. Document audit findings and any corrective measures taken.
Conclusion

The Azul Vision settlement is another reminder that OCR’s Right of Access Initiative is not riding off into the sunset. Providing records eventually does not erase an untimely response, and OCR may pursue enforcement even when the requested records are ultimately produced. As summer draws to a close, covered entities should take the opportunity to review their access-request workflows, address bottlenecks, and ensure that requests are fulfilled within HIPAA’s required timeframes.

Quarles will continue to monitor these updates and their implications for health care organizations. If you have questions about HIPAA compliance, generally, please contact your Quarles attorney or:

Follow Quarles

Subscribe Media Contact
Back to Main Content

We use cookies to provide you with the best user experience on our website and to analyze statistics related to our website. To understand more about how we use cookies, or for instructions to change your preference and browser settings, please see our Privacy Notice. Please note that if you choose to reject cookies, doing so may impair some of our website's functionality.