Release of Information (ROI) Requests in a Therapy Practice: The 30-Day Rule, What a Valid Authorization Must Contain, and the 5 Requests You Should Never Fulfill As-Is
To handle a release of information request correctly, a therapy practice must verify the requester's identity, confirm that the authorisation is HIPAA-compliant, release only the specified records, and respond within 30 days under the HIPAA right of access.
Psychotherapy notes, substance use disorder records, and subpoenas each follow separate, stricter rules.
What it doesn't tell you is that the risk in records requests almost never comes from missing the deadline.
It comes from releasing the wrong thing to the wrong party on a form that was never valid in the first place - and across the behavioral health practices HireGaynell supports, roughly 4 in 10 incoming ROI requests arrive with an authorization that is incomplete, expired, or legally insufficient.
This guide covers what a valid ROI actually requires, the timelines that apply, and the five request types you should never fulfill as-is.
What counts as a release of information in a therapy practice?
A release of information (ROI) is any disclosure of protected health information (PHI) outside your practice that requires the client's written authorization. In behavioral health, the most common ROIs are requests from attorneys, other providers, insurance companies, schools, disability examiners, family members, and clients themselves.
Not every disclosure needs an ROI. Under HIPAA, you may disclose PHI without authorization for treatment, payment, and healthcare operations (TPO) - sending records to a client's psychiatrist for care coordination, or submitting documentation a payer requires to process a claim, generally falls under TPO.
Everything outside TPO and a short list of legal exceptions requires a signed, valid authorization under 45 CFR 164.508.
The operational mistake I see most often in solo practices is treating these as the same workflow. They aren't.
A TPO disclosure is routine. An authorization-based disclosure is a compliance event that needs verification, logging, and a scope check every single time.
What makes a release of information form HIPAA-valid?
A HIPAA-valid authorization must contain six core elements and three required statements.
If any one is missing, the authorization is defective, and you cannot release records on it.
The core elements, per HHS guidance on authorizations, are:
A specific description of the information to be disclosed (not "any and all records" without context)
The name of the person or class of persons authorized to make the disclosure (your practice)
The name of the person or organization the records go to
A description of the purpose of the disclosure ("at the request of the individual" is acceptable when the client initiates)
An expiration date or expiration event
The client's signature and date
The three required statements: the client's right to revoke the authorization in writing, whether treatment or payment is conditioned on signing (for therapy, it almost never can be), and the fact that records may be redisclosed by the recipient and lose HIPAA protection.
When a defective form arrives, don't fix it yourself and don't release "just the summary" as a compromise.
Send it back with a note identifying what's missing, and log the date you did.
That log entry is your protection if the requester later claims you obstructed them.
How long do you have to respond to a records request under HIPAA?
When the client (or their personal representative) requests their own records, the HIPAA right of access under 45 CFR 164.524 gives you 30 calendar days to provide them, with one 30-day extension allowed if you notify the client in writing of the reason and new date.
Many states impose shorter windows - some as short as 5 to 15 days - and the shorter rule always wins.
Do not treat 30 days as a target.
The HHS Office for Civil Rights has run a dedicated Right of Access enforcement initiative since 2019 and has settled dozens of cases against providers - including small practices - for slow or ignored access requests, with penalties reaching into six figures.
Across the practices HireGaynell supports, our internal standard is 5 business days from a complete, valid request to delivered records, and the average practice we manage receives 6 to 9 records requests per month. At that volume, "I'll get to it Friday" is how requests age past the deadline.
You may charge a reasonable, cost-based fee for copies provided to the client - labor for copying, supplies, and postage - but not for retrieval, and not inflated per-page rates that state law might allow for third parties.
Client access fees follow the federal cost-based standard.
Are psychotherapy notes included in a release of information?
No - not unless the authorization specifically and separately says so.
HIPAA gives psychotherapy notes special protection: they are excluded from the client's right of access, and disclosing them requires a standalone authorization that covers psychotherapy notes explicitly.
A general "any and all records" ROI does not reach them.
The catch is definitional.
Psychotherapy notes are only your private process notes kept separate from the medical record. Your progress notes - diagnosis, treatment plan, session start/stop times, modalities, symptoms, prognosis - are the medical record, and they are fully releasable and fully accessible to the client.
If you keep everything in one note in your EHR, you have no psychotherapy notes as HIPAA defines them, and everything you wrote is discoverable.
SimplePractice, TherapyNotes, and most behavioral health EHRs support a separate, locked psychotherapy-notes field for exactly this reason; if you're already running your documentation through SimplePractice billing workflows, turning that field on is a ten-minute fix with major legal consequences.
Substance use disorder records add another layer: if any part of your practice meets the definition of a Part 2 program, those records fall under 42 CFR Part 2, which historically required consent even for many TPO disclosures.
The 2024 Part 2 final rule aligned much of this with HIPAA - including a single consent for future TPO uses - with a compliance date of February 16, 2026, so 2026 is the first full year the new framework applies.
Note: verify applicability to your practice; most private-pay therapy practices are not Part 2 programs.
How should a therapist respond to a subpoena for records?
A subpoena is not an automatic green light, and this is where practices get hurt. Here is the sequence I run:
Identify what you received. A subpoena signed only by an attorney is not the same as a court order signed by a judge. A court order compels disclosure; an attorney-issued subpoena alone generally does not override the client's confidentiality in therapy records.
Do not confirm the person is your client. Even acknowledging the treatment relationship is a disclosure.
Contact the client (or their attorney). The cleanest resolution is a signed, valid authorization from the client covering exactly what the subpoena demands - or the client's attorney moving to quash.
Demand satisfactory assurances if no authorization comes. HIPAA permits disclosure in response to a subpoena only with a court order, a qualified protective order, or documented assurances that the client was notified and given the chance to object.
Release the minimum necessary, log it, and keep the paperwork permanently. The subpoena, the assurances, the cover letter, and the exact page range you sent all go in the file.
If any step feels ambiguous, a 20-minute call with a healthcare attorney is cheaper than a board complaint. This is also one of the workflows a trained mental health virtual assistant can triage for you - flagging what arrived, pulling the client file, and drafting the response packet — while the legal judgment stays with you.
The 5 ROI requests you should never fulfill as-is
These are the five request patterns that, in my experience, cause the most damage when a practice processes them on autopilot:
"Any and all records" requests from attorneys. Overbroad by design. Push back for a specific date range and record type, and remember psychotherapy notes need their own authorization.
A parent requesting a minor's therapy records. State law governs whether the minor consented to their own treatment and therefore controls the record. Several states give minors independent confidentiality rights for outpatient mental health care (verify your state's minor consent statute). Check before you send anything to either parent, especially in custody disputes.
An insurance company requesting the full chart for a routine claim. Payers are usually entitled to what's necessary to adjudicate the claim - not your entire record. Minimum necessary applies. If the request is tied to an audit or a denial, handle it inside your claim denial and appeal workflow so the disclosure and the appeal stay consistent.
A family member "helping" an adult client. No authorization, no records - full stop. Grief, concern, and even a durable power of attorney form you haven't verified do not substitute for a valid ROI or documented personal-representative status.
A request for records you no longer hold - or should no longer hold. How you answer depends on your retention schedule and destruction log. If you can't say with certainty what you still have and when the rest was destroyed, fix that first; my breakdown of therapy records retention requirements covers the state-by-state timelines and the destruction documentation that protects you here.
How to build a repeatable ROI workflow (so this stops eating your week)
Records requests are a volume problem disguised as a legal problem. Individually, each one takes 20 to 45 minutes done correctly. At 6 to 9 per month, that's a real block of clinical time - and it's exactly the kind of protocol-driven work that shouldn't sit on the clinician.
The workflow I install in the practices we manage: a single intake point for all requests (one fax line, one email), a validity checklist taped to the process (six elements, three statements), a 5-business-day internal deadline, a disclosure log with date, requester, scope, and what was sent, and a standing rule that anything involving a subpoena, a minor, or Part 2 records gets escalated before release.
Across the practices HireGaynell supports, that structure cuts average ROI turnaround from about two weeks to under five business days and has eliminated invalid-authorization releases entirely.
If you want the broader picture of where records requests sit among everything else on your plate, the mental health practice admin FAQ maps the full workload.
Conclusion
In my experience running behavioral health operations, the practices that get burned on records requests are never the ones that answered slowly - they're the ones that answered fast on a bad authorization.
Validate the form before you touch the chart, keep psychotherapy notes structurally separate in your EHR, treat every subpoena as a question rather than an order, and log every disclosure the day it goes out.
Do those four things consistently, and ROI requests become a 15-minute task instead of a license risk.
If records requests, intake paperwork, and payer documentation are eating hours you should be spending in session, this is exactly the work HireGaynell's practice administration support takes off your desk - book a free consultation, and we'll map your current ROI workflow in the first call.