Stethoscope resting on a sheet of medical insurance records

This is a question that sounds simple but has quite a complicated answer that raises a whole host of questions. Who is responsible for maintaining the records? How long do they need to be retained? Who owns the records? And, perhaps most importantly, who has access to them?

Illinois law draws an important distinction between ownership of medical records and the right to access the information contained within those records. Understanding that distinction can help patients, providers and families avoid confusion. The issue arises more often than many people realize. People change physicians and want copies of years of treatment records. Children seek records for aging parents. Attorneys request records in connection with litigation. 

The short answer is that medical records are not treated like a car title, a bank account or a deed to real estate. Generally speaking, healthcare providers own the records they create and maintain. However, patients possess strong rights to inspect and obtain copies of information contained within those records. Federal law — most notably the Health Insurance Portability and Accountability Act, commonly known as HIPAA — grants patients important access rights. Illinois law provides similar protections.

For most patients, the practical result is that ownership matters far less than access. Years ago, requests for medical records often involved a trip to a physician’s office and a wait while office staff photocopied portions of a chart. Not surprisingly, it’s a different world these days given that electronic health records have transformed the way information is stored, shared and accessed. (Certainly, you’ve noticed your doctor no longer takes notes but rather enters info into the computer.) Patients now expect to view laboratory results, reports, medication lists, appointment histories, medical histories and physician notes through online patient portals.

Doctors, on the other hand, remain responsible for protecting confidential medical information and ensuring records are released only to those legally entitled to receive them. The provider who releases records to the wrong person can face ramifications that range from regulatory consequences to civil liability.

A common situation involves family relationships. Many spouses assume they are automatically entitled to obtain the other’s medical records. Parents often assume they can access records for adult children. And children frequently seek records for elderly parents whose health is declining.

But it’s not the familial relationship that matters; it’s whether there is authority. Powers of attorney for healthcare, statutes regarding parental rights, guardianship orders, written authorizations and similar documents generally determine who has access. While it may not be hard to determine if someone is acting in good faith, the real challenge is confirming the requester possesses the necessary legal authority. This is just one reason the well-advised reader and their loved ones should have powers of attorney.

Another challenge involves record retention. Most people assume doctors’ records must be kept forever. Federal and state requirements, however, govern how long certain records must be maintained. Different rules may apply depending on the type of provider, the nature of the treatment and the age of the patient. As such, patients are sometimes surprised to discover that records from treatment received decades earlier may no longer exist.

The issue becomes even more complicated when physicians retire, relocate, merge practices or sell their practice. Central Illinois has seen substantial healthcare consolidation since I moved to town in 1999. Independent physician practices increasingly have become affiliated with larger healthcare systems. Those transactions often involve the transfer, management and storage of vast quantities of medical records. When handled properly, patients may never notice the transition. When handled poorly, confusion can arise regarding where records are located and how they may be obtained. The lesson for patients is that it’s best to be proactive now.

Not surprisingly, cybersecurity has emerged as one of the most significant issues facing healthcare providers today. Historically, the main concern was unauthorized access to filing cabinets and paper charts. Today, doctors maintain huge quantities of electronic health information. Medical records contain some of our most sensitive data — social security numbers, insurance information, dates of birth, financial information and detailed health histories. For hackers, that information has real world value.

For that reason, ransomware attacks and data breaches have become major concerns throughout the healthcare industry. Such an event happened to one major local healthcare entity a few years ago and ended in litigation. Breaches involving medical records can trigger notification obligations, regulatory investigations, reputational harm and litigation. Within the healthcare industry, safeguarding patient information has become as important as maintaining the records themselves.

What does all this mean for you? First, understand your rights and maintain copies of important medical information, both for yourself and for those you love. Second, families should ensure that powers of attorney and other authorization documents are in place before an emergency arises. Third, remember that medical records are far more than information stored on a computer server. They are often essential to ongoing treatment, insurance claims, legal matters and critical healthcare decisions. Understanding who can access those records and under what circumstances can spare considerable frustration when it matters most.

Leave a comment

Your email address will not be published. Required fields are marked *