A patient walks into your front office and asks for a list of everyone you've shared their medical records with over the past three years. Your office manager freezes. There's no log. No system. No idea where to start. That freeze can cost you six figures — or more.

Under HIPAA a disclosure accounting is required whenever a covered entity shares protected health information outside of a handful of exempt categories. It's one of the most overlooked patient rights in the Privacy Rule, and I've watched organizations of all sizes scramble when someone actually exercises it. This post breaks down exactly what triggers the requirement, what's exempt, what your accounting must contain, and how to build a system that keeps you compliant.

What the Privacy Rule Actually Says About Disclosure Accounting

Section 45 CFR § 164.528 gives every individual the right to receive an accounting of disclosures of their PHI made by a covered entity or its business associates. The accounting must cover the six years prior to the request — or, if shorter, the period since the compliance date of the Privacy Rule.

This isn't optional. It's not a courtesy. It's a legal obligation that applies to hospitals, physician practices, health plans, clearinghouses, and every business associate that touches PHI on their behalf.

When I consult with small practices, this is often the requirement they've never heard of. They know about Notice of Privacy Practices. They know about the minimum necessary standard. But disclosure accounting? It's a blind spot — and OCR knows it.

The Six-Figure Blind Spot Most Organizations Ignore

In 2011, Cignet Health of Prince George's County, Maryland, received a $4.3 million civil monetary penalty from HHS — the largest at that time. While the case centered on Cignet's refusal to provide patients access to their records, it put the entire industry on notice: OCR takes patient rights seriously, including the right to an accounting of disclosures.

More recently, OCR's enforcement actions have consistently targeted organizations that lack the internal systems to respond to patient rights requests. If your organization can't produce an accounting within 60 days of a request, you're exposed. Period.

Which Disclosures Must Be Tracked?

Here's where most organizations get confused. Not every disclosure triggers the accounting requirement. But the ones that do are more common than you'd think.

Disclosures You Must Account For

  • Public health reporting: Disclosures to public health authorities for disease surveillance, injury reporting, or vital statistics.
  • Disclosures to law enforcement: When you share PHI in response to a court order, subpoena, or law enforcement request.
  • Judicial and administrative proceedings: PHI disclosed in response to a legal proceeding.
  • Disclosures to HHS: When OCR investigates a complaint or conducts a compliance review.
  • Disclosures about decedents: PHI shared with coroners, medical examiners, or funeral directors.
  • Research purposes: When PHI is disclosed for research, even with IRB approval.
  • Disclosures to avert a serious threat: Sharing PHI to prevent or lessen a serious and imminent threat to health or safety.
  • Specialized government functions: Disclosures related to military, veterans' activities, national security, or intelligence.
  • Workers' compensation: PHI disclosed as authorized by workers' comp laws.

Disclosures Exempt from Accounting

  • Treatment, payment, and health care operations (TPO): The bread and butter of daily clinical work. These are exempt.
  • Disclosures to the individual: If you hand a patient their own records, that doesn't count.
  • Disclosures authorized by the patient: If the patient signed a valid authorization, no accounting entry is needed.
  • Disclosures for the facility directory: Patient name, location, and general condition shared for directory purposes.
  • Disclosures to persons involved in the individual's care: Family members, friends, or others the patient has identified.
  • Disclosures for national security or intelligence: Certain classified disclosures are exempt from accounting.
  • Disclosures to correctional institutions or law enforcement custodial situations: Under specific conditions outlined in the rule.
  • Disclosures that occurred before the compliance date: April 14, 2003, for most covered entities.

What Must the Accounting Include?

When a patient requests their disclosure accounting, you can't hand them a vague summary. The Privacy Rule specifies exactly what each entry must contain.

For each disclosure, your accounting must include:

  • The date of the disclosure
  • The name and address (if known) of the entity or person who received the PHI
  • A brief description of the PHI disclosed
  • A brief statement of the purpose of the disclosure, or a copy of the request that triggered it

For multiple disclosures to the same entity for the same purpose — like recurring public health reports — you can provide the information for the first disclosure, the frequency or number of disclosures, and the date of the last disclosure during the accounting period.

How Long Do You Have to Respond?

Under HIPAA a Disclosure Accounting Is Required Within 60 Days

Once a patient submits a request, you have 60 days to provide the accounting. You can get a single 30-day extension if you notify the patient in writing, explain the reason for the delay, and state the date you'll provide the accounting.

The first accounting in any 12-month period must be provided at no charge. For additional requests within the same 12-month window, you may charge a reasonable, cost-based fee — but only if you inform the patient of the fee in advance and give them a chance to withdraw the request.

Building a System That Actually Works

I've seen organizations try to track disclosures on sticky notes, in spreadsheets buried on someone's desktop, or not at all. None of those approaches survive an OCR investigation.

Here's what works:

1. Centralize Your Disclosure Log

Use a single, organization-wide system — whether it's a module in your EHR, a dedicated database, or a compliance platform. Every department that makes disclosures needs to feed into the same log. Decentralized tracking creates gaps, and gaps create liability.

2. Train Every Person Who Touches PHI

Your workforce needs to know which disclosures require tracking and how to log them. This isn't a one-time orientation topic. It's an annual training requirement, and it should include real scenarios your staff actually encounters. Our HIPAA training catalog covers disclosure accounting in the context of day-to-day operations — not abstract theory.

3. Assign Accountability

Someone — your Privacy Officer, compliance lead, or office manager — must own this process. They review the log monthly, audit for completeness, and handle incoming patient requests. Without a named owner, the system decays within months.

4. Include Business Associates

Your business associates make disclosures on your behalf. Under the Privacy Rule, you're responsible for including those disclosures in your accounting. Your BAAs should require associates to provide you with the information needed for accounting, and you should verify they're actually doing it.

What Happens When You Can't Produce an Accounting

OCR doesn't need a data breach to investigate you. A single patient complaint about an unfulfilled accounting request can trigger a review. And once OCR starts looking, they rarely stop at one issue.

The investigation will expose whether you have policies, whether your workforce is trained, and whether your systems actually function. If the answer to any of those is no, you're looking at a corrective action plan at minimum — and potentially a civil monetary penalty under the HHS enforcement framework.

I've consulted with a mid-size specialty practice that received a patient complaint specifically about a denied accounting request. The practice had no disclosure log, no written policy, and no evidence of workforce training on the topic. The corrective action plan took 18 months to complete and consumed staff time they couldn't afford to lose.

The Business Associate Wrinkle

The 2013 Omnibus Rule extended direct liability to business associates. If your BA makes a disclosure of PHI that should have been tracked and they fail to log it, both of you have a problem. Your business associate agreements need explicit language requiring your BA to maintain disclosure records and provide them to you within a defined timeframe.

Most template BAAs I review gloss over this requirement with vague language. That's not good enough. Specify the data elements, the timeframe for reporting, and the format. Make it auditable.

Frequently Asked Question: Do I Need to Track Disclosures for Treatment, Payment, or Operations?

No. Under the current Privacy Rule, disclosures made for treatment, payment, and health care operations (TPO) are explicitly exempt from the accounting requirement. This exemption covers the vast majority of day-to-day PHI sharing in clinical settings — sending records to a referring physician, submitting claims to a payer, or conducting quality improvement activities. However, disclosures outside TPO — like those to public health authorities, law enforcement, or for research — must be tracked and accounted for upon patient request.

Stop Treating Disclosure Accounting as an Afterthought

This requirement has been in the Privacy Rule since 2003. It's not new. But in my experience, it's still one of the most poorly implemented provisions across covered entities of all sizes. The fix isn't complicated — it requires a centralized log, trained staff, a responsible owner, and business associate cooperation.

If your organization hasn't tested its ability to produce a disclosure accounting on demand, do it this week. Have someone submit an internal test request. See what happens. If the answer is silence and confusion, you know exactly where you stand.

Building a compliant workforce starts with targeted education. Explore our HIPAA compliance training programs to make sure your team knows what disclosures to track, how to log them, and how to respond when a patient exercises their rights.