A patient calls Tuesday morning and asks that her visit notes reach a specialist before an appointment the next day. The front-desk employee who takes the call is careful and conscientious, and she cannot answer any of the three questions the request raises: whether the notes can be emailed, whether a signed release is needed first, and whether the patient's husband can collect a printed copy if the electronic route stalls.
Down the hall, a billing supervisor is asking why a claim went out to an insurer for a visit the patient paid for in full and specifically asked to keep private.
In the storage closet behind the break room, an office manager has just found four retired laptops and eleven boxes of paper charts nobody can account for.
Each situation may require a privacy, security or compliance review. All three also expose the same governance problem: no function was clearly assigned to an owner.
Answer ownership questions first
Information governance gets described as a policy exercise, which makes it sound like something that lives in a binder. In working terms it is a set of answers to recurring questions. Who may access information? Who approves a release? Who handles a privacy complaint? Who owns the retention schedule? Who decides whether a new workflow creates new risk? Who fixes the process after information is mishandled?
The HIPAA Privacy Rule requires a covered entity to designate a privacy official responsible for developing and implementing its privacy policies, and to name a contact person or office for complaints.1 That designation is only the starting point. A four-provider group may assign privacy and security duties to one administrator. A 40-provider group may split them across privacy, security, compliance, IT and operations. What matters in either case is that each function has a name attached, that the name is known to staff, and that a backup exists when the owner is unavailable.
Build the map on one page. A workable ownership map has three columns — function, primary owner, backup — and about 10 rows: privacy complaints, patient access requests, amendments, accounting of disclosures, self-pay restrictions, confidential communication preferences, business associate inventory, retention schedule, secure destruction, audit-log review.
A first pass might take an hour or two, most of it spent confirming who owns each function rather than who is assumed to. That time is among the highest-yield the administrator may spend on health information all year: it converts unstated assumptions into a document the practice can train against, hand to a new hire, and produce when an auditor, regulator, or patient asks who is responsible.
Review the map annually and after any leadership change. Access roles deserve the same treatment when staff change jobs, not only when they leave — an employee who moves from the front desk to billing may retain permissions from both roles unless someone reviews them.
What counts as “the record”
Release of information is where privacy, customer service, legal exposure and ordinary workflow all meet, and a common error is a narrow reading of what the patient is entitled to.
The governing concept is the designated record set. It includes medical records, billing records, payment and claims records, case-management records, and other records used in whole or in part to make decisions about individuals.2 The last clause is the test. The access right reaches beyond the visit note.

The questions in the opening have different answers. HIPAA generally permits a provider to send records to another provider for treatment without obtaining the patient's authorization. Email is not prohibited, but the practice must apply reasonable privacy safeguards and its Security Rule controls. A spouse does not receive full access simply by being a spouse; pickup depends on the patient's direction, the spouse's status as a personal representative under applicable law, or another permitted basis, together with appropriate identity verification.3
Requester type changes everything downstream. A specialist receiving records for treatment is a different transaction from an attorney requesting records for litigation. A patient directing a copy to a third party requires separate review from a third party requesting records on its own behalf. Requester authority, the applicable access or authorization pathway, permitted fees, format and state law can differ.4 Staff who cannot tell the categories apart will often default to whichever answer feels safest — usually a delay.
Log every request and release handled through the practice’s formal release-of-information workflow: requester, patient, authority relied on, what was sent, date received, date completed, delivery method, fee if any, and who handled it. The log helps the practice demonstrate that it treats similar requests consistently. It is an operating record, not the same thing as HIPAA’s accounting of disclosures.
The rule that fails without a flag
Self-pay restrictions are an example of a legal requirement that collapses without an operational hook.
A practice must agree to restrict disclosure to a health plan when the disclosure would be for payment or healthcare operations and is not otherwise required by law, and the information pertains solely to an item or service paid in full by the patient or another person other than the health plan.5 Execution means the related claim must be suppressed, held or otherwise stopped before transmission. That requires a registration script that captures the request, a billing flag that survives to the encounter, a documentation convention so the clinical team knows, and a final check before submission.
Miss any one of those controls and the practice's standard billing workflow may override the restriction.
Confidential communication requests behave the same way. A patient may ask to be reached at an alternate number or address. That preference has to live somewhere scheduling, billing, clinical and records staff can all see it — not in a free-text note that only the person who wrote it will ever find.
Six years (and what it does not cover)
Retention is where confident wrong answers cluster. HIPAA requires covered entities to retain required Privacy Rule documentation for six years from the date of creation or the date it was last in effect, whichever is later.1 That obligation covers policies, procedures, notices, complaints and related actions.
It is not a clinical record retention rule. How long the practice must keep patient charts depends on state law, payer requirements, litigation exposure, organizational policy and patient-care need — and the answer differs for adult records, minors' records, behavioral health and substance use disorder records, imaging, and billing files. Practices that hear “six years” and apply it to charts have adopted a number that came from somewhere else entirely.
Keep a written retention schedule with four columns: record category, retention trigger, minimum period, disposition method. Cite the source of each requirement in the schedule itself, so the next administrator inherits the reasoning rather than the conclusion.
Two schedule entries that catch practices out: scanned originals — verify the image is complete, legible and correctly indexed before destroying paper, because that sequence cannot be reversed — and retired systems, where records must remain retrievable through the full retention period even after the software that created them is gone. Legacy access planning belongs in the EHR replacement decision, not in the panic six months after go-live.
The devices nobody thinks about
HIPAA requires reasonable disposal safeguards but does not prescribe one disposal method. Paper may be shredded or otherwise rendered unreadable and unreconstructable. Electronic media should be sanitized using a method appropriate to the medium, the information and the risk. NIST defines media sanitization as rendering access to target data infeasible for a given level of effort and provides current guidance in SP 800-88 Rev. 2.6 The practical test is whether the practice could defend the conclusion that the data cannot reasonably be recovered once the device leaves its hands.
The equipment that gets missed is predictable. Laptops and servers are usually remembered. Scanners, multifunction copiers, retired firewalls, backup drives and the tablet in the procedure room may not be. Many multifunction copiers contain internal storage that can retain images or job data, including devices returned at the end of a lease.
Document destruction the way you document release: what was destroyed, date range, authority, method, vendor, date, person responsible, and the certificate of destruction if one was supplied.
Keep it alive
ARMA’s current recordkeeping principles organize the work around record lifecycle management, accountability, availability, compliance, protection, transparency and trustworthiness.7 The vocabulary is heavier than a medical group needs. The practical translation is simpler: named ownership, documented rules and retrievable evidence make the process easier to operate and defend.
Start with the 10-row map. Fill in the rows you can. The rows you cannot fill in are the value you get from this article.
Notes
- 45 C.F.R. § 164.530, “Administrative requirements,” including designation of a privacy official and complaint contact and retention of required Privacy Rule documentation. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- 45 C.F.R. § 164.524, “Access of individuals to protected health information.” https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- U.S. Department of Health and Human Services, Office for Civil Rights, guidance on treatment disclosures, email and personal representatives: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/disclosures-treatment-payment-health-care-operations/index.html and https://www.hhs.gov/hipaa/for-professionals/faq/570/does-hipaa-permit-health-care-providers-to-use-email-to-discuss-health-issues-with-patients/index.html and https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/personal-representatives/index.html
- U.S. Department of Health and Human Services, Office for Civil Rights, "Court Order on Right of Access." https://www.hhs.gov/hipaa/court-order-right-of-access/index.html
- U.S. Department of Health and Human Services, Office for Civil Rights, "Under HIPAA, may an individual request that a covered entity restrict how it uses or discloses that individual's protected health information?" https://www.hhs.gov/hipaa/for-professionals/faq/3026/under-hipaa-may-an-individual-request-that-a-covered-entity-restrict-how-it-uses-or-discloses-that-individuals-protect-health-information/index.html
- U.S. Department of Health and Human Services, Office for Civil Rights, "What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health information?"; National Institute of Standards and Technology, SP 800-88 Rev. 2, Guidelines for Media Sanitization. https://www.hhs.gov/hipaa/for-professionals/faq/575/what-does-hipaa-require-of-covered-entities-when-they-dispose-information/index.html and https://csrc.nist.gov/pubs/sp/800/88/r2/final
- ARMA International, "The Principles," 2025 framework. https://arma.org/hubfs/46943926/Principles Graphic %288.5 x 11 in%29.pdf?hsLang=en








































