> Individuals’ Right under HIPAA to Access their Health Information 45 CFR § 164.524
> Timeliness in Providing Access
> In providing access to the individual, a covered entity must provide access to the PHI requested, in whole, or in part (if certain access may be denied as explained below), no later than 30 calendar days from receiving the individual’s request. See 45 CFR 164.524(b)(2). The 30 calendar days is an outer limit and covered entities are encouraged to respond as soon as possible. Indeed, a covered entity may have the capacity to provide individuals with almost instantaneous or very prompt electronic access to the PHI requested through personal health records, web portals, or similar electronic means. Further, individuals may reasonably expect a covered entity to be able to respond in a much faster timeframe when the covered entity is using health information technology in its day to day operations.
> If a covered entity is unable to provide access within 30 calendar days -- for example, where the information is archived offsite and not readily accessible -- the covered entity may extend the time by no more than an additional 30 days. To extend the time, the covered entity must, within the initial 30 days, inform the individual in writing of the reasons for the delay and the date by which the covered entity will provide access. Only one extension is permitted per access request.
HIPAA has no private right to civil action in these scenarios, so we had to involve the state, and that process took about six months. It's definitely not fast; we were happily in the scenario where the records weren't time critical.
And as the parent comment said, you have to involve the state and it takes 6 months.
This is the part I had to go looking for. I've been in this space for just a bit now, and I can tell you that like most of American healthcare, it's a shitshow. Get ready to develop an app against your doctor's EHR API if they don't expose this via a patient portal.
I don't think the docs are too happy about giving you access to "their" work product, AKA your health data. And to some extent I sort of see where they're coming from - if they were photographers, they'd actually hold copyrights over images they take of you.
But the goals here are at least laudable and there is some rather glacial advancement.
The most interesting legal questions around this recently are regarding monkeys or other animals who take selfies, and whether they can own those works.
https://photocopyrightlaw.com/who-owns-the-copyright-to-a-wo...