OCR's HIPAA Right of Access Initiative: The 5-Point Checklist Senior Living Operators Need

Every HIPAA compliance conversation in senior living defaults to breach prevention — encryption, ransomware, stolen laptops. There's a second, much quieter enforcement lane that has nothing to do with hacking, and it has been running at a steady clip since 2019: the Office for Civil Rights' Right of Access Initiative, which polices how fast a covered entity or business associate hands a patient or resident their own records after they ask for them. On December 16, 2025, OCR announced a $112,500 settlement with Concentra, Inc., an Addison, Texas occupational health provider, after a patient made six separate requests for his own records beginning in February 2018 and didn't receive the complete file until March 2019 — marking the initiative's 54th enforcement action since launch. Nine months earlier, a $200,000 civil monetary penalty against Oregon Health & Science University had been the 53rd. Fifty-four settlements in roughly six years, none of them tied to a hacker, a ransomware gang, or a stolen device — every one of them tied to a records request that didn't get answered fast enough.

The rule at the center of all fifty-four cases is 45 CFR 164.524. A covered entity — or a business associate acting on its behalf — must act on an individual's request for access to their protected health information within 30 calendar days of receiving it. One extension is available, but only if the entity notifies the requester in writing, within that original 30-day window, of the reason for the delay and the specific date the records will be produced; the extension itself is capped at another 30 days. The scope of what has to be produced is broad: the "designated record set" covers medical and billing records, care plans, and anything else used to make decisions about the individual, with two narrow carve-outs — psychotherapy notes and information compiled for use in a civil, criminal, or administrative proceeding. There is no small-facility exception and no staffing-shortage exception; the clock runs the same whether the requester is a 40-unit assisted living community or a 400-bed hospital system.

For senior living and multifamily healthcare-adjacent operators specifically, the highest-risk failure point isn't the records themselves — it's figuring out who is legally entitled to ask for them. Under 45 CFR 164.502(g), a personal representative must be treated exactly as the individual would be, with full access rights, but only if that person actually holds legal authority under state law — a documented healthcare power of attorney, a court-appointed conservator or guardian, or, for a deceased resident, an executor or administrator. A concerned adult child calling the front desk without documentation is not automatically a personal representative, and neither is a general financial power of attorney that doesn't extend to healthcare decisions. OHSU's $200,000 penalty is a case study in what happens when this goes wrong procedurally rather than maliciously: a personal representative's request, faxed to OHSU on April 24, 2019, got a partial response from OHSU's records vendor five days later, but the complete file wasn't produced until August 26, 2021 — more than two years and two separate OCR complaints after the original fax. Nobody at OHSU refused the request outright; it simply never got tracked to completion.

Fees are a second common trap, and the rules changed under a court ruling that many facilities still haven't caught up with. HIPAA permits only a "reasonable, cost-based fee" for an individual's own copy of their records, and OCR's long-standing guidance actively encourages providing that first copy free. A 2020 federal court decision, Ciox Health, LLC v. Azar, vacated the broader fee cap HHS had tried to apply to records a patient directs to a third party — meaning a flat per-page charge is fair game when a resident asks that records be sent to a new physician or an attorney, but the stricter cost-based limitation still applies in full when the resident or their personal representative is requesting a copy for themselves. Charging the same flat per-page rate to every requester, regardless of whether the records are going to the individual or somewhere else, is exactly the kind of fee-schedule confusion OCR's initiative has repeatedly cited as a violation.

New patient medical record form with stethoscope representing HIPAA designated record set documentation

California operators have a materially tighter clock than the federal 30-day standard, and it's easy to miss because most national compliance checklists only cite HIPAA. Health and Safety Code Section 123110 requires a health care provider to permit inspection of a patient's record within five working days of a request and to transmit copies within 15 days — less than half of HIPAA's baseline. Because HHS's preemption standard favors whichever law gives the individual the greater right of access, California's faster deadline, not HIPAA's 30-day window, is the one that actually governs day-to-day operations for providers in this state. The statute also caps copying fees at $0.25 per page (or $0.50 for microfilm) plus reasonable clerical cost — a specific, checkable number that's considerably more restrictive than the general "reasonable, cost-based fee" language in the federal rule.

Skilled nursing facilities face a third, faster clock still, and it doesn't come from HIPAA at all. Federally certified nursing facilities are separately bound by 42 CFR 483.10 under the Nursing Home Reform Act, which entitles a resident or their legal representative to access their clinical record within 24 hours of an oral or written request — weekends and holidays excluded — and to receive photocopies with only 2 working days' advance notice, at a fee limited to labor, supplies, and postage. That requirement is enforced through the CMS survey and certification process, not an OCR complaint, which means a certified SNF can be cited for an access failure well before HIPAA's 30-day clock, or California's 15-day clock, would even come into play. Assisted living and memory care communities that aren't Medicare/Medicaid-certified don't fall under this rule, but they're still bound by Health and Safety Code 123110 the moment they meet the statute's definition of a health care provider — so knowing which of these three clocks actually applies to a given property is the first, and most commonly skipped, compliance step.

None of this is a paperwork technicality with no teeth behind it. Civil monetary penalties for HIPAA violations, including Right of Access failures, are assessed on the same four-tier structure as every other Privacy and Security Rule violation: for violations assessed on or after January 28, 2026, per-violation exposure runs from $145 at the low end up to an annual aggregate cap of $2,190,294 for uncorrected willful neglect. In practice, OCR's Right of Access settlements have historically landed well below that ceiling — Concentra's $112,500 and OHSU's $200,000 are both squarely representative of the range the initiative has produced since 2019 — but a corrective action plan typically rides alongside the payment, adding a year or more of OCR monitoring, mandatory policy revisions, and staff retraining on top of the settlement figure itself.

OCR has also shown, as recently as December 2025, that it's actively widening what counts as an access violation rather than narrowing its focus. On December 3, 2025, OCR Director Paula M. Stannard issued a "Dear Colleague" letter putting regulated entities on notice that parents must be able to access the non-confidential portions of a minor child's record through a patient portal — flagging that some health systems have applied adolescent-privacy age restrictions too broadly, inadvertently locking parents out — and stating that OCR "will use all civil remedies available, including civil monetary penalties," where noncompliance is found. The legal mechanism is the same Right of Access authority discussed throughout this article, just pointed at a portal-configuration failure instead of a paper-request failure — a signal that the initiative isn't limited to how a front desk handles a fax; it now reaches how an organization's own patient-facing technology is configured by default.

Whoever holds the designated record set doesn't change who's on the hook. OHSU's records lived, in part, with a third-party vendor — Diversified Business Services, Inc. — and OHSU was still the party that paid the $200,000 penalty, because a covered entity cannot contract its way out of the 45 CFR 164.524 deadline. The same principle applies to any senior living property that relies on a third-party EHR platform, a billing system, or an IT provider with administrative access to resident records: if that vendor is slow to pull a file, the clock doesn't pause, and the fine doesn't land on the vendor. A business associate agreement should specify, in writing, how quickly the vendor will produce designated-record-set data back to the covered entity — with enough buffer built in to still meet California's 15-day copy deadline or OBRA's 2-working-day deadline, not just HIPAA's 30-day outer limit.

A workable Right of Access program for a senior living or multifamily healthcare-adjacent operator comes down to five concrete pieces, each one directly traceable to a documented OCR failure pattern: a single designated intake point and a written log that timestamps every request against the correct clock (24 hours/2 days for a certified SNF, 5/15 days under California Health and Safety Code 123110, 30 days as the outer HIPAA floor for anyone else); a written policy — not tribal knowledge — defining exactly what documentation qualifies someone as a personal representative, so front-desk and care staff have an escalation path instead of a judgment call; a posted, capped fee schedule that separates the individual's own reasonable-cost-based rate from any higher third-party-directive rate; a documented turnaround commitment from every vendor or IT provider holding any part of the designated record set; and an annual review confirming the log, the policy, and the fee schedule still match current staff and current regulations. Every one of OCR's 54 settlements traces back to a gap in one of those five pieces.

This is precisely the operational gap Mytek Pros' compliance audit practice is built to close before OCR — or a resident's family — finds it first. As a licensed California low-voltage contractor and managed service provider (License #1116987) with DIR public-works registration (PW-LR-1001158430), BICSI-certified staff, and DBE/DVBE/MBE certification, based in Carlsbad and serving San Diego County and businesses across California, Mytek Pros conducts HIPAA, SOC 2, and NIST-aligned compliance audits that map exactly where a property's designated record set actually lives — across EHR platforms, billing systems, and the IT infrastructure vendors touch — and pair that mapping with a documented, defensible Right of Access policy: intake logging, personal-representative verification, a compliant fee schedule, and vendor turnaround commitments built to beat California's 15-day clock, not just HIPAA's 30-day one. Our managed IT and managed security services, typically $125-$250 per user per month, keep that documentation current year-round instead of rebuilt from scratch after a complaint. If your community or business has never stress-tested how it would actually handle a records request today, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com before OCR settlement number 55 has your organization's name on it.

Questions about audits? Get in touch or explore our Audits services.