FAQ & Compliance

The rules behind every release — in plain language.

Release of Information sits on top of federal and California law that most people only meet when they need a record urgently. Here is what governs it, and how Infomedic works within it.

This page is general information, not legal advice. Statutes and fee caps change. Confirm current requirements with your own counsel or Privacy Officer before relying on anything here.

Getting started

What exactly is "Release of Information"?

Release of Information (ROI) is the regulated process of disclosing a patient's protected health information to someone entitled to receive it — the patient themselves, another provider, an attorney, an insurer, or a court. It covers verifying that the requester has authority, pulling only the records within scope, redacting what must be withheld, delivering securely, and logging the disclosure.

Who can request medical records?

Typically: the patient; a personal representative such as a parent, guardian, conservator or executor; anyone holding a valid signed authorization from the patient; and parties acting under lawful process such as a subpoena or court order. Certain disclosures are permitted without authorization — treatment, payment and healthcare operations among them — but those are narrower than people often assume.

What makes an authorization valid?

A valid HIPAA authorization identifies the patient, describes specifically what information may be disclosed, names who may disclose it and who may receive it, states the purpose, carries an expiration date or event, explains the right to revoke, and is signed and dated by the patient or their personal representative. California adds its own content and formatting expectations under the CMIA.

We check every one of these elements before a record moves. Incomplete authorizations are returned with a note on exactly what is missing, rather than quietly rejected.

How do I submit a request to Infomedic?

Use the secure request form to tell us who you are and what you need. We reply within one business day with a secure channel for the signed authorization or subpoena, and a fee estimate before any work begins. Please don't email signed authorizations or clinical detail to us unprompted — wait for the secure link.

Timing & cost

How long does a request take?

Infomedic's standard service target is 24–72 hours from the point we hold a complete, valid request. Rush handling is available for same or next business day.

Those are our service standards, not the legal deadlines. Under HIPAA, a covered entity generally has 30 days to act on a patient's access request, with one 30-day extension available. California's Health & Safety Code §123110 is tighter: inspection within five working days of a written request, and copies within fifteen days.

What can I be charged for copies in California?

For patients requesting their own records, Health & Safety Code §123110 caps copying at $0.25 per page, or $0.50 per page for records copied from microfilm, plus reasonable clerical costs. Third-party requests from attorneys and insurers are not subject to that cap and are priced commercially.

Where a patient needs records to support an appeal of a denial of government benefits or program eligibility, the copy is provided at no charge.

Can a provider withhold records over an unpaid bill?

No. A patient's right of access does not depend on their account balance, and records cannot be held hostage to an outstanding bill. Copy fees themselves may still be charged within the statutory caps.

Who pays — the provider or the requester?

Either, and it is your choice. Many provider clients ask us to bill legal and insurance requesters directly, which brings their own net cost close to zero. Others prefer a flat retainer with all requester billing folded in. We set this before go-live so no invoice is ever a surprise.

Law & compliance

What is the difference between HIPAA and the CMIA?

HIPAA is the federal floor — the Privacy and Security Rules that govern protected health information nationwide. The Confidentiality of Medical Information Act is California's own statute, and in several respects it is stricter. Where they differ, the more protective rule applies. Working in California means satisfying both, which is why we build to the California standard by default.

Do you sign a Business Associate Agreement?

Always, before any provider engagement begins. As a Business Associate we are directly liable under HIPAA for safeguarding the PHI we handle. The BAA sets out permitted uses, our security obligations, breach notification timelines, subcontractor terms, and what happens to records when the relationship ends.

How do you handle subpoenas?

A subpoena is not automatically sufficient authority to release records. We check that the required patient notice and consumer notice have been served, that the timing is proper, and that the scope is defined. Where anything is defective, we raise it with your counsel before responding rather than after. Certified copies with a custodian of records affidavit and deposition-officer appearance are available where the matter requires them.

What about substance-use, mental-health and HIV records?

These categories carry additional protection — federal 42 CFR Part 2 for substance-use disorder treatment records, and specific California provisions for psychotherapy notes and HIV test results. A general authorization usually will not reach them. Our intake flags these categories so specific consent is obtained rather than assumed.

What happens if something goes wrong?

We contain, investigate and notify. Our BAA sets the notification window, and our incident procedure covers containment, root-cause analysis, your Privacy Officer's involvement in any risk assessment, and the corrective action that follows. Every disclosure being logged is what makes that investigation possible in the first place.

Security & records

How is my information protected?

PHI is encrypted in transit and at rest. Access is role-based and limited to the specialists working a given request. Intake and delivery run through secure channels — never consumer email or unencrypted attachments. Staff complete privacy training before touching a record, and access is logged.

How do you deliver records?

Encrypted download by default, with secure physical delivery where a certified paper set is required. Delivery method is agreed at intake, and receipt is recorded as part of the disclosure log.

What is an "accounting of disclosures"?

Patients have the right to ask who their records have been shared with. An accounting of disclosures answers that: date, recipient, what was disclosed and the basis for it. Because we log every release as it happens, we can produce this on request instead of reconstructing it from memory and email.

How long do you retain records you have processed?

Working copies are purged on the schedule set in your agreement once a request closes. Disclosure logs are retained for the period HIPAA requires. Optional long-term secure storage with re-retrieval is available where you want a set kept accessible.

Still have a question?

Ask us directly — a specialist will answer, and we'll tell you plainly if something needs your own counsel instead.