13.2 Filing, HIPAA Storage & Record Release

Key Takeaways

  • CMAC tasks 4.02.5–4.02.7 cover alphabetical and numerical filing methods, storing records under HIPAA privacy and security rules, and responding to release or transfer requests with proper authorization.
  • Alphabetical filing uses the patient’s last name (with unit or other indexing rules); numerical filing uses MRN or other assigned numbers and often needs a master patient index to locate charts.
  • HIPAA Privacy Rule governs uses/disclosures of PHI; Security Rule protects electronic PHI (access control, encryption, audit logs, workstation security); both apply to storage and transmission.
  • Record release and transfer require valid authorization (or another permitted pathway such as TPO treatment disclosure per policy), identity verification, minimum necessary judgment when applicable, and documentation of what was sent.
  • Never release records based on a phone caller’s word alone without verification; fax and portal releases need correct destinations and cover-sheet protections.
Last updated: August 2026

Filing, Secure Storage, and Lawful Release

After information enters the chart (Section 13.1), medical assistants must file it correctly, store it securely, and release it only through proper channels. Blueprint tasks 4.02.5–4.02.7 sit inside Medical Record Management’s 6% (~10 scored items) and frequently appear as scenario stems: misfiled chart, unlocked records room, or release without authorization.

4.02.5 — File Documents Using Various Filing Methods

Even in EHR-first clinics, staff still file paper, scan batches, and understand how master indexes and chart numbers work. The blueprint highlights alphabetical and numerical methods.

Alphabetical Filing

Rule (typical unit method concepts)Application
File by last name, then first name, then middleSmith, Anna before Smith, Brian
Nothing comes before something“Brown” before “Browne” in many systems—follow office rules
Prefixes and hyphenated namesFollow facility indexing manual (Mac/Mc, Hispanic compound surnames)
Identical namesUse DOB or middle name as a tiebreaker per policy
Business/organization namesMay file as written unit—less common for patient charts

Color coding on paper charts (first letters of last name) speeds retrieval and reduces misfiles—know that it supports alphabetical systems rather than replacing indexing rules.

Numerical Filing

MethodHow it worksStrength
Straight numericCharts in ascending MRN order (12345, 12346…)Simple sequence
Terminal digitPrimary sort on last digits of number (common in large paper systems)Distributes filing activity; fewer crowded “new number” shelves
Middle digitVariant primary mid-section sortLess common; know it exists as a numeric variant

Numerical systems usually require a master patient index (MPI) or EHR search because staff cannot guess a number from a name alone. Advantage: better privacy at a glance (hallway chart shows number, not full name) and fewer “same last name” collisions. Disadvantage: misfiled numbers can be hard to find without audit tools.

Practical Filing Workflow (Paper or Scan Queues)

  1. Confirm patient identity on every page (name, DOB, MRN).
  2. Remove paperclips that jam scanners; repair torn pages.
  3. File to the correct section (labs, consents, progress notes, insurance).
  4. For EHRs, use the correct document type and encounter link when scanning.
  5. Do not leave loose PHI on counters or in unlocked “to be filed” boxes overnight.
  6. Double-check similar names (Jennifer Lee vs Jennifer Li) before final file.
Filing errorConsequencePrevention
Chart filed under maiden vs married name inconsistentlyLost recordConsistent legal-name + alias fields
Lab report in wrong numeric chartWrong-patient decisionsTwo identifiers on every page
Unscanned ROI sitting in a drawerMissed authorization trailDaily scan/file deadlines

4.02.6 — Store Patient’s Medical Records Using HIPAA Privacy and Security Rules

HIPAA (Health Insurance Portability and Accountability Act) privacy and security requirements are tested across Domain 2 and again here as storage practice. Task 4.02.6 focuses on how records are kept, not only abstract definitions.

Privacy Rule vs Security Rule (Storage Angle)

RuleFocusStorage examples
Privacy RuleWhen PHI may be used/disclosed; patient rightsLimit who can browse charts; no hallway gossip; patient right to access
Security RuleSafeguards for electronic PHI (ePHI)Unique logins, auto logoff, encryption, audit logs, secure transmission
Breach Notification (HITECH-related)Notify after impermissible compromise of unsecured PHILost unencrypted USB with charts triggers assessment/notification workflow

PHI includes demographic and clinical data that can identify a patient (name + diagnosis, MRN, full-face photo, etc.). Minimum necessary means workforce members access only what their role requires.

Physical Storage Controls

ControlCorrect practice
Records room / file cabinetsLocked when unattended; badge or key control
Chart racksNot facing public hallways with open PHI
Fax/printer areasPrompt pickup; secure release locations
ShreddingCross-cut or approved destruction for discards—not open trash
Off-site storageBusiness associate agreements when a vendor stores PHI
Workstation screensPrivacy screens; position away from waiting areas

Electronic Storage Controls

  1. Unique user IDs—never share passwords or leave a session open for “the next person.”
  2. Role-based access—front desk vs clinical vs billing see different modules.
  3. Automatic logoff / manual lock when stepping away (links to 4.02.8).
  4. Encryption for laptops, portable media, and email when policy requires.
  5. Backup and disaster recovery managed by IT—but staff must still follow downtime charting procedures.
  6. Audit logs—inappropriate access (snooping a celebrity or neighbor) is discoverable and reportable.
  7. Remote work—home printers, family-shared computers, and public Wi-Fi are high-risk; follow telework policy or do not take ePHI home.
Storage failureWhy it fails HIPAA-minded policy
Leaving signed progress notes on the reception counter overnightImpermissible access risk
Posting a photo of the schedule board with full names + procedures on social mediaUnauthorized disclosure
Storing patient lists on a personal phone photo rollUnsecured ePHI / device control failure
Discussing a lab result in a crowded elevatorIncidental disclosure minimized poorly

Retention: Facilities keep records for periods set by state law, payer rules, and policy (often years beyond last visit; longer for minors in many states). On the exam, do not invent a single national retention number—know that records are retained per legal/facility retention schedules, not discarded when the drawer is full.

4.02.7 — Respond to Requests for Release or Transfer of Patient’s Medical Records

Release of information (ROI) and transfer requests come from patients, other providers, attorneys, insurers, and schools. Task 4.02.7 tests process discipline: verify authority, verify identity, release the right content, document the disclosure.

Common Pathways (Conceptual)

Request typeTypical requirement
Patient requests own recordsVerify identity; follow access timelines/policy; may charge reasonable cost-based fees where allowed
Another treating provider (continuity)Often treatment-related disclosure under Privacy Rule + facility policy; still verify request legitimacy
Patient transfer to new PCPAuthorization + complete relevant chart elements
Attorney / third partyValid authorization or other legal process (subpoena handling per policy/risk management)
Insurance / payerLimited to what is needed for payment/operations when applicable; authorizations when required
Family member inquiryNo release without authorization (or personal representative status) except narrow emergency situations per policy

Step-by-Step ROI Response

  1. Receive the request in writing when policy requires (portal, signed form, secure message).
  2. Authenticate the requester (photo ID for in-person patient pickup; verify provider office callback numbers from a trusted directory).
  3. Validate authorization: patient name, who may receive records, what may be released, purpose, expiration or event, signature/date, and special categories if needed.
  4. Clarify scope if the request is vague (“send everything forever”).
  5. Retrieve only authorized content; apply minimum necessary when the request is not a full patient-directed copy requiring complete designated record set access.
  6. Prepare copies or secure electronic transmit; use cover sheets on faxes with confidentiality notices.
  7. Confirm destination before send (wrong fax number = breach risk).
  8. Document date, what was released, to whom, method, and staff initials; log in ROI disclosure log if used.
  9. Refuse or escalate improper requests (unsigned forms, fishing expeditions, identity fails) and explain how to submit a valid request.

Transfer vs Copy

  • Transfer often means the patient’s care is moving and another facility needs a working set of records—still requires proper process.
  • Copy for patient is a patient right of access pathway; do not create barriers that violate policy timelines.
  • Original charts generally stay with the creating facility unless policy/legal process says otherwise—send copies, not the only original paper chart, in routine transfers.

High-Yield Refusal / Caution Scenarios

ScenarioCorrect instinct
Spouse demands full chart without authorizationDo not release; explain authorization needed
Employer calls for diagnosis detailsNo—unless valid authorization or other legal basis
Urgent ED requests records for active treatmentFollow emergency treatment disclosure policy; verify facility; document
Patient wants records altered to remove an accurate diagnosisCannot falsify; explain amendment request process instead
Staff faxes HIV results to a number the patient “thinks is right”Verify number; use secure methods; special protections per policy

Integrated Storage + Release Scenario

A patient asks reception to “email my whole chart to my sister for her research project.” You do not email PHI to a third party without a valid authorization naming the sister and scope. You offer the proper ROI form, verify identity, and, if authorized, send through approved secure channels—while the paper request form itself is filed/scanned under HIPAA storage rules (locked EHR document section, not a sticky note on a public board).

End-to-End Checklist (4.02.5–4.02.7)

  1. File by the clinic’s alphabetical or numerical system with two-identifier checks.
  2. Store paper under lock and ePHI under access control, encryption, and workstation security.
  3. Release or transfer only with validated authority, correct content, secure method, and disclosure documentation.

If you can index a chart, explain privacy vs security storage controls, and run a clean ROI, you own tasks 4.02.5–4.02.7.

Test Your Knowledge

Why do numerical filing systems usually require a master patient index (MPI) or electronic name search?

A
B
C
D
Test Your Knowledge

Which practice best stores patient records in line with HIPAA privacy and security expectations (task 4.02.6)?

A
B
C
D
Test Your Knowledge

A man calls claiming to be a patient’s brother and demands last week’s STD results over the phone. What is the best response?

A
B
C
D
Test Your Knowledge

In alphabetical filing of patient charts, which ordering is correct assuming standard last-name-first indexing?

A
B
C
D