How to get medical records for a lawsuit: the complete field guide
For attorneys, paralegals and legal nurse consultants who request records for litigation. You walk away with the right route for each provider, a request letter, a tracking log and a completeness check.
To get medical records for a lawsuit, use 1 of 4 routes: the patient's HIPAA right of access (30 days, plus 1 extension of up to 30 more), a signed HIPAA authorization, a subpoena backed by satisfactory assurances under 45 CFR 164.512(e), or a court order. Psychotherapy notes and federally protected substance use records need separate permission. Then check what arrived against bills and pharmacy fills.
Most record problems in a lawsuit start on the day the request goes out. The wrong route gets rejected, a vague scope brings back the discharge summary and little else, and nobody notices the missing therapy notes until the defense expert points at them.
Getting records in 8 numbers
The 4 routes to medical records, and how to pick one
Every medical record you get in litigation arrives by 1 of 4 legal routes: the patient's own access request, a signed authorization, a subpoena that meets HIPAA's conditions, or a court order. Each has its own deadline (or none), fee rules and ways to fail.
Most firms default to the authorization for everything. That hides a fact worth knowing: under HIPAA, an authorization only permits a provider to disclose. The patient's right of access is the only route that requires the provider to act by a federal deadline. When a records department stalls, the route you chose decides how hard you can push.
Patient access
- Legal basis
- 45 CFR 164.524
- Deadline
- 30 days from receipt, 1 extension of up to 30 more
- Fee rule
- Reasonable, cost-based: labor, supplies, postage only
- Best for
- Your own client's full chart, in electronic form
- Weak spot
- Excludes psychotherapy notes and material compiled for litigation
HIPAA authorization
- Legal basis
- 45 CFR 164.508
- Deadline
- None in HIPAA; state law and provider policy
- Fee rule
- State copy statute or the provider's schedule
- Best for
- Pre-suit requests to many providers at once
- Weak spot
- 1 missing element makes the form defective
Subpoena
- Legal basis
- 45 CFR 164.512(e)(1)(ii) plus the court's subpoena rule
- Deadline
- The compliance date on the subpoena, subject to objections
- Fee rule
- State law or court rule
- Best for
- An opposing party's records, or a nonparty's
- Weak spot
- Rejected without satisfactory assurances
Court order
- Legal basis
- 45 CFR 164.512(e)(1)(i)
- Deadline
- Whatever the order sets
- Fee rule
- Varies
- Best for
- Disputed scope, system data, Part 2 records
- Weak spot
- Covers only what the order expressly authorizes
The decision path below is how we would sort a new provider. It is a starting map, not a rule of law: state statutes add layers.
The route follows from 2 facts: who the patient is to you, and what kind of record you need.
Route 1: the patient's right of access under HIPAA
Under 45 CFR 164.524, an individual has a right to inspect and get a copy of their protected health information in a designated record set, for as long as the provider keeps it. The designated record set is broader than most people think: the medical records and billing records a provider keeps about the patient, plus any other records used, in whole or in part, to make decisions about them.
2 things are carved out: psychotherapy notes, and "information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding." Expect incident reports and risk management files to land in that second bucket, often shielded in discovery too by state peer review privileges.
"the covered entity must act on a request for access no later than 30 days after receipt of the request"
The clock runs from receipt, so send access requests by a method that proves delivery. The provider may extend once, by no more than 30 days, and only with a written statement of reasons and a completion date sent inside the original 30. A provider that goes silent at day 30 without that letter has missed the deadline.
Form, format and fees
If the records are electronic and the patient asks for an electronic copy, the provider must produce it in the form and format requested if readily producible, or another agreed readable format (164.524(c)(2)(ii)). Ask for a searchable PDF in chart order, with imaging by disc or link.
The fee must be reasonable and cost-based, covering only 4 things: copying labor, supplies, postage, and a summary the patient agreed to in advance. No search and retrieval fee. HHS guidance adds a shortcut: a provider that does not want to calculate actual or average costs may charge a flat fee of up to $6.50, inclusive of labor, supplies and postage, for electronic copies of records maintained electronically. HHS has also clarified that $6.50 is an option, not a cap on every access fee.
What changed after Ciox Health v. Azar
Until January 2020, HHS guidance applied the patient-rate fee limits to a patient's written direction to send records to a third party, such as a law firm. In Ciox Health v. Azar, the U.S. District Court for the District of Columbia vacated that extension. In its notice on the ruling, HHS said the fee limitation in 164.524(c)(4) applies only to an individual's request for access to their own records, not to a request to transmit records to a third party, and that the third-party directive now reaches only electronic copies of records held in an electronic health record.
The practical result: a letter on firm letterhead that says "my client directs you to send the records to us" does not get the patient rate. Some firms have clients request their own electronic copy and share it. That can be cheaper for a clean chart, but it puts the client in the middle of the logistics. We would use it for the core hospital and clinic chart and authorizations for the rest.
The deadline has teeth. The HHS Office for Civil Rights has imposed a $200,000 civil money penalty on a health system for failing to provide timely access. A letter citing 164.524(b)(2) and the receipt date moves a stalled request faster than a third phone call.
Routes 3 and 4: subpoenas, court orders and satisfactory assurances
Once a case is filed, you need records from people who will not sign for you. 45 CFR 164.512(e) sets 2 paths for a covered entity to disclose in a judicial or administrative proceeding.
"In response to an order of a court or administrative tribunal, provided that the covered entity discloses only the protected health information expressly authorized by such order"
A court order is the clean path, and its scope is its limit. Draft it like a request letter: date range, record categories, format, images and itemized billing.
A subpoena without a court order is the common path, and where requests fail. The provider may respond only on satisfactory assurance from the requesting party, in 1 of 2 forms.
Either way, the provider needs a written statement with documentation. Your word is not enough. A qualified protective order is an order or a stipulation that bars the parties from using the records for anything other than the proceeding and requires return or destruction of the records, including copies, at the end of it (164.512(e)(1)(v)).
How to package a subpoena so it gets answered
- Serve notice on the parties first. In federal court, a subpoena for documents must be served with notice on each party before it goes to the record holder (FRCP 45(a)(4)). State rules have their own notice periods.
- Attach the assurance. Send the cover letter with either the patient notice, proof of mailing and a statement that the objection period ran with no objection, or a copy of the QPO or the motion for it.
- Name the categories. A subpoena "for all records" gets the same abstract an authorization does. List the categories from chapter 6.
- Ask for a certification. Request a custodian declaration that supports admission under your jurisdiction's business records rule (chapter 10).
- Diary the objection window. In federal court a nonparty's written objection is due before the earlier of the compliance date or 14 days after service (FRCP 45(d)(2)(B)). An objection shifts the fight to a motion to compel.
Our view: in any case with more than a handful of nonparty providers, stipulate to a qualified protective order early. 1 stipulated QPO covers every later subpoena and saves a notice cycle per provider.
Records with extra locks: psychotherapy notes, SUD records, deceased patients
3 categories break the default rules.
Psychotherapy notes
45 CFR 164.501, 164.508(a)(2)
- Notes by a mental health professional documenting or analyzing the contents of a counseling session, kept separate from the rest of the medical record.
- The definition excludes medication monitoring, session start and stop times, treatment modalities and frequency, test results, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis and progress.
- So the regular mental health chart is reachable with a normal authorization.
- Not reachable through patient access at all.
Substance use disorder records under Part 2
42 CFR 2.12, 2.31, 2.32, 2.61, 2.64
- Applies to records from a federally assisted SUD program that would identify the patient as having an SUD.
- Written consent has its own required elements (2.31), separate from HIPAA's list.
- A subpoena alone is not enough: the holder may not disclose in response unless a court enters an authorizing order under Part 2 (2.61).
- Anyone who receives the records is barred from using them in proceedings against the patient without consent or an order (2.12(d)).
Part 2 in practice
The rule was amended by a final rule published on February 16, 2024 (89 FR 12472), with a compliance date of February 16, 2026. It kept the litigation restrictions. The required redisclosure notice says it plainly:
"A general authorization for the release of medical or other information is NOT sufficient to meet the required elements of written consent to further use or redisclose the record"
For a Part 2 order in a civil case, 42 CFR 2.64 requires the application to use a fictitious name for the patient, notice to the patient and the record holder with a chance to respond, and a finding of good cause: other ways of getting the information are not available or would not be effective, and the public interest and need outweigh the potential injury to the patient, the physician-patient relationship and the treatment services. The order must limit disclosure to the parts of the record essential to its objective. Representing the patient, get a Part 2 consent. On the other side, plan for a motion.
Deceased patients and wrongful death
HIPAA keeps protecting a deceased patient's records for 50 years after death (164.502(f)). The person who signs is the personal representative: an executor, administrator or other person with authority under applicable law to act for the deceased or the estate (164.502(g)(4)). State law decides who that is. A statutory wrongful death beneficiary may not be the personal representative for HIPAA purposes. Get the appointment early and attach the letters to every request. Some states widen the list: California's 1158 lets an heir sign an attorney's pre-suit authorization.
What to ask for, by provider type
Scope is where "complete" productions go wrong. The provider's legal health record, what it certifies as its business record, is usually narrower than HIPAA's designated record set, and a release clerk defaults to it. System metadata such as the EHR audit trail needs its own request: EHR audit trails in malpractice cases. Name what you want.
| Provider | Ask for by name | Commonly missed | Why it bites later |
|---|---|---|---|
| Hospital | ED record (triage, physician and nursing notes), H&P, orders, progress notes, nursing flowsheets, MAR, OR and anesthesia records, pathology, consults, consents, discharge summary | Flowsheets and MAR; outside records scanned in; a return ED visit on another account | Vitals, pain scores and medication times live in flowsheets and the MAR, not in the narrative notes |
| Hospital imaging | Radiology reports and the images (DICOM) on disc or by link | The images themselves; prior comparison studies | Your expert reads images, not reports. See reading DICOM imaging |
| Hospital billing | UB-04 claim form and an itemized statement with revenue codes and charges | The itemized statement (the UB-04 is a summary); adjustments and payer payments | Specials and liens are built from line items, not claim totals |
| Physician office or clinic | Progress notes, problem and medication lists, referrals, lab and test results, portal messages, phone notes | Portal messages and nurse-line notes; records received from other providers; pre-incident visits | Pre-incident complaints and gaps in treatment come out of the clinic chart first |
| Physician billing | CMS-1500 claims and an itemized ledger with CPT codes | Write-offs, payer adjustments, balance transfers | The paid amount, not the billed amount, drives many damages and lien fights. See medical billing review |
| Pharmacy | Dispensing history: drug, strength, quantity, fill dates, prescriber | A second pharmacy; cash fills | A prescriber you have never heard of is a provider you have not requested |
| Physical therapy or chiropractic | Initial evaluation, daily notes, re-evaluations, discharge summary, attendance and cancellation log | Daily notes for every billed date; the no-show log | Missed visits get argued as failure to mitigate; missing notes get argued as unproven treatment |
| Ambulance or EMS | Patient care report with times | Dispatch timestamps; monitor data | Scene findings are often recorded here first |
- Designated record set
- HIPAA's term for medical and billing records and any other records used to make decisions about the patient. Sets the scope of patient access.
- Legal health record
- The provider's own definition of what it certifies and releases as its business record. Often narrower than the designated record set.
- Flowsheet
- Structured nursing data such as vitals, intake and output, neuro checks and pain scores, often printed as a separate report.
- UB-04 and CMS-1500
- The standard claim forms for institutional (hospital) and professional (physician) billing.
- DICOM
- The file format for medical images. A report describes an image; a DICOM file is the image.
The request clock, from letter to complete file
Here is how 1 hospital request runs on a patient access clock, with the follow-ups we would schedule. The dates are hypothetical; the rules behind each step are not.
- Mar 2Request sent
Patient's signed access request for an electronic copy, sent by certified mail and to the HIM department's fax. Categories listed by name.
Tracking log, row 7 - Mar 4Received: day 0
Certified mail receipt signed. The 30-day clock starts here, not on Mar 2. Due date: Apr 3.
USPS receipt - Mar 16Day 12 follow-up
Call confirms the request is logged and assigned. Note the name and the request number.
Tracking log, note - Mar 31Day 27: extension letter
Hospital writes that older encounters sit in an archived system and gives a completion date of May 3. Sent inside the first 30 days, so the extension is valid. It is the only one allowed.
Hospital letter, 1 page - Apr 3Day 30: original deadline
Nothing due, because the extension was noticed in time. Diary May 3.
Calendar - Apr 20Day 47: partial production
212 pages: ED and inpatient notes. No nursing flowsheets, no MAR, no images, no itemized bill.
Production 1, pages 1 to 212 - Apr 21Deficiency letter
Lists the 4 missing categories, cites the original request and the May 3 date.
Template 3, chapter 8 - May 1Day 58: second production
96 pages of flowsheets and MAR, an imaging link, and the itemized statement.
Production 2, pages 213 to 308 - May 5Completeness check
The itemized bill shows a return ED visit on Jan 20. No Jan 20 notes in either production. New request for that encounter, which sat on a separate account number.
Itemized bill, line 41
The provider met the rule and the file was still incomplete. Only a check against the bill found the missing visit.
A follow-up cadence that works
Diary 4 dates on every request: a receipt check around day 10 to 14, a status call around day 25, the deadline, and a completeness check within a week of each production. For authorizations, use your state's deadline or 30 days as a house rule. A request silent for 60 days goes to a subpoena or a fresh access request.
Count pages on arrival and log them; page counts are the fastest way to tell a second production from a duplicate. If you Bates stamp on arrival, log the range too. The Bates numbering guide covers the numbering side.
Templates: request letter, tracking log, completeness checklist
Working drafts, not legal forms. Adapt them to your state; a state statutory form takes priority where one exists.
1. Medical records request letter
Send with a signed HIPAA authorization, or adapt the first paragraph for a patient access request signed by the patient.
[DATE]
[PROVIDER NAME]
Attn: Health Information Management / Release of Information
[ADDRESS] | Fax: [FAX] | Email: [EMAIL]
Re: Request for medical and billing records
Patient: [FULL NAME] | DOB: [MM/DD/YYYY] | MRN or account: [IF KNOWN]
Dates of service: [START DATE] to [END DATE or "present"]
Enclosed is a HIPAA-compliant authorization signed by [the patient /
the personal representative, with letters of administration attached].
Please produce the following records for the dates above:
1. Emergency department records: triage, physician and nursing notes
2. History and physical, orders, progress notes, consult notes
3. Nursing flowsheets (vitals, pain scores, neuro checks, I&O)
4. Medication administration record (MAR)
5. Operative, anesthesia and pathology records
6. Discharge summary and discharge instructions
7. Radiology reports AND the images in DICOM format (disc or link)
8. Outside records received and scanned into the chart
9. Patient portal messages and telephone encounter notes
10. Billing: UB-04 or CMS-1500 claim forms AND an itemized statement
showing each charge, adjustment and payment
Format: searchable PDF in chart order, delivered by [secure link / email].
Please include a custodian of records certification stating the page
count and that the production is complete for the categories and dates
above. If any category does not exist, please say so in writing.
If you need to extend your response time or deny any part of this
request, please tell us in writing and give the reason.
Contact: [NAME], [PHONE], [EMAIL]. Reference: [FILE NUMBER]
[SIGNATURE BLOCK]
2. Records tracking log
1 row per request, not per provider. Most providers get asked more than once. Paste into a spreadsheet; the header row is tab-free so it splits on commas.
Row,Provider,Department,Route (access/auth/subpoena/order),Categories requested,Date range,Date sent,Date received by provider,Due date,Extension noticed (Y/N + new date),Follow-up 1,Follow-up 2,Date produced,Pages,Bates range,Certification (Y/N),Complete (Y/N),Gaps found,Next action,Authorization expires 1,[Hospital],[HIM],[auth],[ED;flowsheets;MAR;images;itemized bill],[01/12/2026-present],[MM/DD],[MM/DD],[MM/DD],[N],[MM/DD],[MM/DD],[MM/DD],[0],[PLTF 000001-000000],[N],[N],[none yet],[call HIM],[MM/DD/YYYY]
3. Deficiency follow-up letter
Send the day after a partial production. Specific beats polite: list what is missing and tie it to the original request.
[DATE] [PROVIDER NAME], Release of Information Re: [PATIENT NAME], DOB [MM/DD/YYYY], your reference [NUMBER] Thank you for the production received [DATE] ([PAGE COUNT] pages). Our request dated [DATE] asked for the categories below, which were not included: - [Nursing flowsheets, MM/DD/YYYY to MM/DD/YYYY] - [Medication administration record] - [Imaging in DICOM format for studies on MM/DD/YYYY] - [Itemized statement of charges] - [Records of the encounter on MM/DD/YYYY, shown on your bill at line [N]] Please produce these categories or confirm in writing that they do not exist. [For a patient access request: Your response is due by [DATE] under 45 CFR 164.524(b)(2).] [SIGNATURE BLOCK]
Completeness checklist
Run this against every production before anyone summarizes it.
0 of 12 checked
Worked example: a rear-end collision file, request by request
| Provider | Route | Pages | What came back | Gap found |
|---|---|---|---|---|
| County EMS | Authorization | 4 | Patient care report, Jan 12 | None |
| Hospital ED | Access + authorization | 308 | 2 productions (chapter 7) | Return ED visit Jan 20 on another account |
| Primary care | Authorization | 19 | Visits Jan 15 and Feb 2, referral to PT and MRI | Note from 2024 mentions neck stiffness and chiropractic care |
| Imaging center | Authorization | 2 | Cervical MRI report, Feb 20 | No images |
| PT clinic | Authorization | 61 | Evaluation, daily notes, billing ledger | 18 billed visits, 14 notes |
| Pharmacy | Authorization | 3 | Fill history Jan 12 to Apr 30 | Jan 13 prescription from an urgent care clinic not on intake |
The PT gap is the one a defense expert would find. The clinic's ledger bills 18 visits between February 24 and April 28. The produced notes cover 14. Laying the billed dates against the produced notes shows where:
4 billed visits have no note. That is a records request, not a finding, until the clinic answers in writing.
What the firm requests next
- PT clinic. A deficiency letter for the 4 dates, plus the attendance log. If the clinic confirms no notes exist, it becomes a billing question.
- Hospital. The January 20 return ED visit, with its own itemized bill.
- Imaging center. The MRI images in DICOM, because the defense will retain a radiologist.
- Urgent care clinic. A new authorization and request. The client forgot a visit the day after the crash.
- Prior chiropractor. The 2024 records. The defense will get them anyway; seeing them first prepares the attorney for a pre-existing condition argument.
All 5 requests came from checking the file against itself. None came from reading the notes in order.
Custodian certifications and the no-records letter
In federal court, medical records usually come in as business records under FRE 803(6): made at or near the time by someone with knowledge, kept in the course of a regularly conducted activity, with making the record a regular practice, and shown by the custodian's testimony or a certification, unless the opponent shows the source or method indicates a lack of trustworthiness.
The certification route runs through FRE 902(11), which lets a domestic business record self-authenticate on a custodian's certification. It comes with a condition people forget: before trial or hearing, the proponent must give the adverse party reasonable written notice of the intent to offer the record and make the record and certification available for inspection. Most states have their own versions.
Read what the custodian actually certified
A custodian who certifies "the records produced" are true copies has not certified the whole chart. That is why the letter in chapter 8 asks for a page count and a completeness statement. A refusal to sign it tells you something too.
The no-records letter
When a provider says it has no records for a date or a category, get it in writing from the custodian. The absence of an entry in a regularly kept record can itself be evidence under FRE 803(7), offered to prove that the matter did not occur or exist, if a record was regularly kept for that kind of matter. A clerk's "we don't have anything" on the phone proves nothing later. A signed statement that the clinic has no daily note for March 10 is something both sides can work with.
Where AI helps once the records arrive, and where it fails
Getting records is a legal and clerical process, and AI does not change the law of it. Some tools market agentic AI that drafts and sends requests; a person still gets the right signature and decides whether the reply is complete. AI earns its keep on the step after: reading thousands of produced pages fast enough to find what is missing while there is time to ask.
What a large language model does well on produced records
An LLM is good at the tedious middle of record review: sorting productions into encounters, pulling dates, providers and medications into a table, and drafting an AI medical records summary. Tools built on retrieval-augmented generation (RAG) answer from your uploaded pages, and page-level citations let you verify in seconds.
Where it fails
- OCR on faxes and old scans. A fax of a fax loses margins, times and initials. A page read at low confidence should be flagged, not guessed.
- Handwriting. Handwritten notes, medication orders and signatures still defeat general tools often enough that a person should check every handwritten entry that carries weight. See whether AI can read handwritten records.
- Copy-forward text. EHR notes carry text forward from earlier visits, including old dates and old findings. A model that takes the first date it sees will put findings on the wrong day.
- Ambient AI scribes. Notes drafted from recorded visits read smoothly and can carry errors the clinician signed without catching. Test them like any record.
- Hallucination. A general generative AI tool asked to "summarize the chart" can state a fact that appears on no page. In court filings, fabricated AI citations have already led to sanctions under Rule 11, most famously in Mata v. Avianca (S.D.N.Y. 2023). The same discipline applies to a chronology: if a line has no source page, it does not go in the demand or the expert packet.
A vendor checklist for legal AI tools that touch medical records
A signed BAA before any upload
HIPAA compliant AI means the vendor signs a business associate agreement. No BAA, no protected health information.
A citation on every line
Every fact in the output links to its source page. Spot-check 10 before you trust the rest.
No training on your data
In the contract, where it binds, and not in marketing copy alone. Your clients' records should not improve someone else's model.
Low-confidence flags
Pages read with low confidence go to a person instead of into the summary.
An audit trail of AI use
A log of who uploaded, viewed, edited and exported, so you can answer questions about how a work product was made.
Human in the loop by design
The tool drafts, a person reviews and signs. SOC 2 and HIPAA security controls, plus an easy way to correct a line and keep the correction.
More on the security side in HIPAA-compliant AI medical record review, and on accuracy in whether AI is accurate enough for court.
Where Medrecords AI fits, and an offer
Medrecords AI does not request or retrieve records, send authorizations or serve subpoenas. You get the records by the routes in this guide. Once you upload them, Medrecords AI does the cross-checking from chapter 9, with a citation on every line.
- Missing records identification flags visits, providers and date ranges that the file implies should exist but were not produced: a billed date with no note, a referral with no specialist record, a prescriber with no chart. Each flag is cited to the page that implies it. Flags are signals, not verdicts; you decide what to request next.
- Provider list extraction pulls every provider named anywhere in the file, which is how an urgent care visit the client forgot turns up.
- Supplemental record review compares a new production to the existing file and marks what agrees, what conflicts and what is new, so the second and third productions do not get read from scratch.
- Deduplication and Bates numbering keep overlapping productions clean, with Bates numbers stable through dedupe, sort and export.
- The cited medical chronology links every entry to its source page.
Medrecords AI works under SOC 2 and HIPAA controls and signs a BAA; details are on the security and HIPAA pages. It organizes, cites and flags. It does not decide what a record means for your case. You review, you revise, you sign.
See what your file is missing before the defense does.
Book a demo with a production you already have, then run your first case free on us. Every line comes back cited to its source page. You review, you revise, you sign.
Scheduling only. No records move from a public page.
Questions people ask about getting medical records
- Can an attorney subpoena medical records without the patient's consent?
- Often yes, once a case is pending. Without a court order, the provider needs satisfactory assurance under 45 CFR 164.512(e): proof the patient got notice and the objection time passed, or a qualified protective order. Part 2 substance use records also need a Part 2 court order.
- How long does a provider have to respond to a medical records request?
- For a patient's own access request under HIPAA, 30 days from receipt, with 1 extension of up to 30 days if the provider sends a written reason before day 30. HIPAA sets no deadline for authorizations; state law and the subpoena's terms do. California gives providers 5 days for an attorney's pre-suit request.
- How much can a provider charge for medical records for a lawsuit?
- For a patient's own copy, HIPAA allows a cost-based fee limited to labor, supplies and postage, or an optional flat fee of up to $6.50 for electronic copies of electronic records. After Ciox Health v. Azar (2020), those limits do not apply to records sent to a law firm. Attorney requests usually fall under state copy-fee statutes.
- What is the difference between a HIPAA authorization and a patient access request?
- An access request is the patient exercising a right, with a 30-day deadline and limited fees. An authorization is permission for the provider to release records to someone else, such as a law firm. It must contain the 164.508(c) elements, and HIPAA sets no deadline for acting on it.
- Can I get a deceased person's medical records for a wrongful death case?
- Yes, through the personal representative: the executor, administrator or other person with authority under state law. HIPAA protects the records for 50 years after death. Attach proof of authority to each request.
- Does a standard release cover psychotherapy notes and substance use treatment records?
- No. Psychotherapy notes, a therapist's separately kept session notes, need a standalone authorization. Federally assisted substance use disorder program records need a Part 2 consent or a Part 2 court order. The regular mental health chart is reachable with a normal authorization.
- Can AI request medical records for my firm?
- Some software drafts and sends request letters, but the legal requirements do not change: the right person must sign the right form, and someone must check what comes back. Medrecords AI does not request or retrieve records. It reads the records you upload and flags what the file implies is missing, with a citation for each flag.
- Is it HIPAA compliant to upload medical records to AI?
- It can be, if the vendor signs a business associate agreement, safeguards the data and does not use it outside the agreement. A consumer AI tool with no BAA has made no HIPAA commitments. Check the BAA, security controls and data-use terms before the first upload.
- Can ChatGPT summarize medical records for a lawsuit?
- A general chatbot can produce a fluent summary, but without a BAA it is the wrong place for client records, and without page-level citations you cannot verify it. Fabricated AI content has already drawn Rule 11 sanctions. Use a HIPAA compliant AI tool that cites every line, and verify before you file.
- Can AI tell me which medical records are missing?
- It can flag likely gaps: billed dates with no note, referrals with no specialist record, prescribers with no chart. Those are signals to check, not findings. The note may sit under another account, so the next step is a deficiency request and a written custodian answer.
Sources and method
The rules in this guide were checked against primary sources in September 2026: the current text of the HIPAA Privacy Rule on eCFR, 42 CFR Part 2 on eCFR and its 2024 final rule on govinfo, HHS Office for Civil Rights guidance on access fees and on the Ciox Health v. Azar ruling, the Federal Rules of Evidence and Civil Procedure as published by the Legal Information Institute, and the California Legislature's text of Evidence Code 1158. The worked example, mock authorization, timeline dates and PT billing comparison are hypothetical and labeled. The follow-up cadence and route opinions are ours. No statistic here is invented or presented as a study.
What each source carries
- 45 CFR 164.524Right of access, deadline, extension, format, fees
- 45 CFR 164.508Authorization elements, statements, defects
- 45 CFR 164.512(e)Court orders, subpoenas, satisfactory assurances, qualified protective orders
- 45 CFR 164.501, 164.502Definitions, deceased patients, personal representatives
- 42 CFR Part 2SUD consent, notice, subpoenas and court orders
- 89 FR 124722024 Part 2 final rule and its February 16, 2026 compliance date
- HHS OCRThe $6.50 flat fee option and that it is not a cap; the Ciox notice; the access enforcement penalty
- Legal Information InstituteFRCP 45 notice and objection timing; FRE 803(6), 803(7) and 902(11)
- California LegislatureEvidence Code 1158: 5 days, fees, statutory form