HIPAA's Privacy Rule, at 45 CFR § 164.501, defines a designated record set as, "(1) A group of records maintained by or for a covered entity that is: (i) The medical records and billing records about individuals maintained by or for a covered health care provider; (ii) The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or (iii) Used, in whole or in part, by or for the covered entity to make decisions about individuals. (2) For purposes of this paragraph, the term record means any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity."
That third category, records "used, in whole or in part... to make decisions about individuals", is broad. It doesn't just mean "the official chart." It means any record, regardless of format or where it physically lives, that gets used to make decisions about a specific patient or member.
Learn more: Why are designated record sets important to PHI?
The record, not the PHI
Healthcare attorney Kim Stanger's analysis points out that the regulatory test doesn't ask whether the PHI itself was used to make a decision about the patient, it asks whether the record containing that PHI was used for that purpose. That distinction matters because covered entities routinely copy the same health information into multiple systems, and not all of those systems function as decision-making tools. A data set built for quality control or peer review, for instance, might contain identical PHI to what's in the medical chart, yet fall outside the DRS because that particular system isn't used to make decisions about individuals
Stanger also notes, drawing on the Privacy Rule's original 2000 commentary, that the "decisions" triggering DRS status aren't limited to clinical or treatment decisions. Financial and administrative determinations, such as whether a patient's deductible has been met, count too, because they can affect a patient's interests just as a treatment decision would.
What's normally included
Given that definition, a designated record set generally includes:
- Medical records: physician notes, lab results, imaging reports, nursing notes, discharge summaries, and treatment plans.
- Billing and claims records: invoices, insurance claims, payment histories, and explanation of benefits documents.
- Case management and care coordination records: care plans, referral documentation, and utilization review notes.
- Enrollment and eligibility records (for health plans): membership applications, coverage determinations, and eligibility files.
- Any other records used to make decisions about the individual, such as records used to evaluate a complaint, an appeal, or a request for services.
Importantly, this applies regardless of the medium. Paper charts, EHR entries, PDFs, scanned documents, emails that were used to make a clinical or coverage decision, and even certain database fields can all fall within the DRS if they meet the functional test above.
However, oral communications generally don't count. As Stanger notes, citing OCR's own FAQ guidance, the Privacy Rule's definition of "record" contemplates information that has been recorded in some manner, so a covered entity generally isn't required to give a patient access to, say, a recorded customer-service call, unless that recording is actually retained and used to make decisions about the patient rather than kept for internal quality review.
What's normally excluded
Not every document a covered entity creates or stores counts as part of the designated record set. The text of 45 CFR § 164.524, has identified certain categories that fall outside the DRS, most notably:
- Psychotherapy notes: As defined at 45 CFR § 164.501. The regulation defines these as notes recorded by a mental health professional documenting or analyzing a private counseling session, kept separate from the rest of the individual's medical record. The definition excludes medication prescription and monitoring, session start/stop times, treatment modalities and frequency, clinical test results, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress.
- Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding: For instance, materials prepared specifically for litigation. This exclusion is set out at 45 CFR § 164.524(a)(1)(ii).
- Quality assurance, peer review, and business planning records that are not used to make decisions about the specific individual: These include aggregate quality metrics, internal audits, or accreditation records that don't bear directly on one patient's care or claims. Stanger's discussion of the regulatory history reinforces HHS's own 2000 commentary that gave the example of a hospital's peer review files that include PHI about many patients but are used only to improve care generally, not to decide anything about a particular individual and are therefore outside that hospital's DRS.
- Internal administrative or "convenience" copies: These include duplicates of information already in the primary record and are not used for decision-making, for instance, a temporary working copy a nurse writes notes on before transcribing into the official chart.
Stanger also flags that HHS deliberately built flexibility into this standard rather than carving out categorical, always-excluded buckets. Commenters on the original rule asked HHS to permanently exclude things like peer review, credentialing, and compliance-committee materials from the DRS definition. HHS declined, explaining that it couldn't guarantee those categories would never be used to make decisions about individuals in every organization, so the rule stays fact-specific to each covered entity's actual practices rather than offering a blanket exemption.
Why this distinction matters
- Right of access - Patients have the right to inspect and obtain a copy of their PHI in a designated record set, with very limited exceptions. If a document isn't part of the DRS, the covered entity generally isn't obligated to provide it under this right.
- Right to amend - Patients can request amendments to inaccurate or incomplete information in a designated record set. Records outside the DRS aren't subject to this amendment right.
- Accounting of disclosures - When evaluating breaches or preparing an accounting of disclosures, organizations often look to what's in the DRS to understand the scope of PHI involved.
- Compliance risk - Misclassifying something as outside the DRS to avoid disclosure obligations is a common mistake. OCR has pursued enforcement actions against covered entities for improperly denying access requests. OCR has made the right of access a sustained enforcement priority through its dedicated "Right of Access Initiative," launched in 2019. For instance, in a January 2021 resolution agreement, OCR required Banner Health to pay $200,000 and adopt a two-year corrective action plan after finding that two patients had not received timely access to their medical records, in one case, records requested in December 2017 weren't provided until May 2018, a delay of several months beyond HIPAA's required turnaround time.
Read also: How Paubox can help with HIPAA Right of Access
FAQs
Does the DRS include records held by a business associate?
Yes, if a business associate maintains records used to make decisions about an individual on the covered entity's behalf, those records are part of the covered entity's DRS even though the covered entity doesn't physically hold them.
How long must a covered entity retain designated record set information?
HIPAA itself doesn't set a retention period for DRS content, retention is instead governed by state law and other applicable regulations.
Can a covered entity charge a fee for providing DRS records?
Yes, but the fee must be reasonable and cost-based, limited to labor, supplies, and postage, and a flat per-page fee often isn't compliant unless it falls within a state-specific exception HHS has recognized.
Does the DRS distinction apply the same way to HIPAA covered health plans as it does to providers?
The same functional test applies, but the record types differ.
