4.1 Defining the HIPAA Designated Record Set (DRS) Across Clinical and Billing Systems
Key Takeaways
- Under 45 CFR § 164.501, the Designated Record Set (DRS) is a legal grouping of records maintained by or for a covered entity that encompasses medical records, billing records, health plan enrollment/payment/claims systems, and any records used in whole or in part to make healthcare decisions about individuals.
- The legal DRS is substantially broader than an Electronic Health Record (EHR); it spans disparate enterprise clinical and financial repositories, Picture Archiving and Communication Systems (PACS), Laboratory Information Systems (LIS), patient portal communications, and records maintained by Business Associates.
- Statutory and regulatory exclusions from the DRS include psychotherapy notes (§ 164.501), legal defense work product compiled in reasonable anticipation of litigation (§ 164.524(a)(1)(ii)), administrative raw data/audit logs/worksheets not used to make clinical decisions, and source data (e.g., raw EKG strips or pathology slides) when summarized in formal interpretive reports.
- Under 45 CFR § 164.103 and § 164.105, hybrid entities must formally document and maintain administrative, physical, and technical firewalls around their designated healthcare components; only records within those covered components and associated Business Associate systems fall within the DRS.
- Covered entities bear legal responsibility under Business Associate Agreements (BAAs) to ensure third-party vendors holding DRS components produce them within HIPAA individual right of access (§ 164.524) and amendment (§ 164.526) compliance timelines.
Defining the HIPAA Designated Record Set (DRS) Across Clinical and Billing Systems
AHIMA CHPS Blueprint Focus: Health Information Management (HIM) and healthcare compliance executives frequently conflate a facility's commercial Electronic Health Record (EHR) with the legal Designated Record Set (DRS). For the CHPS examination, candidates must master the precise statutory definition under 45 CFR § 164.501, navigate complex boundaries between included clinical/financial systems and excluded administrative data, manage distributed repositories across Business Associates, and enforce compliance across hybrid organizational structures.
1. Statutory Architecture of the Designated Record Set
The Designated Record Set is the jurisdictional cornerstone of an individual's rights under the HIPAA Privacy Rule. Specifically, the individual's legal right to inspect and obtain a copy of their health data under 45 CFR § 164.524 and the right to request an amendment under 45 CFR § 164.526 apply exclusively to information maintained within a DRS.
The Three Functional Prongs of 45 CFR § 164.501
Under federal regulation, a Designated Record Set is defined as a group of records maintained by or for a covered entity that comprises:
- Healthcare Provider Medical and Billing Records: The medical records and billing records about individuals maintained by or for a covered healthcare provider;
- Health Plan Core Records: The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or
- The Decision-Making Standard: Any records used, in whole or in part, by or for the covered entity to make decisions about individuals.
Defining a "Record"
Under § 164.501, a record is broadly defined as "any item, collection, or grouping of information that includes protected health information (PHI) and is maintained, collected, used, or disseminated by or for a covered entity." It is not restricted to any single technical medium; it encompasses structured relational databases, unstructured narrative text, digital imaging files, physical paper charts, microfiche archives, audio recordings, and electronic communications.
The "Used to Make Decisions" Rule
The third prong of § 164.501 is the most expansive and frequently tested concept on the CHPS exam. Even if a particular document, spreadsheet, or communication resides outside the primary clinical chart or patient accounting system, if a healthcare provider or health plan utilizes that information—in whole or in part—to make a clinical, financial, or administrative determination affecting an individual's care, coverage, or benefits, that information legally becomes part of the Designated Record Set.
2. Clinical and Financial Data Elements Included in the DRS
To ensure complete compliance during Release of Information (ROI) processing and legal discovery, HIM leaders must inventory all enterprise systems housing DRS components:
A. Inpatient and Outpatient Clinical Records
- Physician and Nursing Documentation: History and physical (H&P) examinations, progress notes, nursing assessments, flowsheets, vital sign logs, multidisciplinary care plans, clinical pathways, and discharge summaries.
- Surgical and Procedural Documentation: Operative reports, anesthesia records, recovery room (PACU) monitoring sheets, and informed consent documentation.
- Orders and Medication Administration: Physician order entry (CPOE) records, medication administration records (MAR), e-prescribing logs, and pharmacy dispensing records.
B. Billing, Financial, and Revenue Cycle Systems
- Encounter Billing Data: Itemized hospital bills, patient account ledgers, charge capture records, and superbills.
- Claims Adjudication Files: Electronic claims submissions (e.g., ANSI ASC X12 837I/837P institutional and professional claims), CMS-1500 and UB-04 claim forms, and Remittance Advices (ANSI ASC X12 835).
- Payment and Denial Records: Explanation of Benefits (EOBs), prior authorization approvals/denials, insurance verification records, and financial hardship/charity care applications used to determine patient financial responsibility.
C. Diagnostic Imaging and Laboratory Systems
- Picture Archiving and Communication Systems (PACS): Digital Imaging and Communications in Medicine (DICOM) files, raw MRI/CT/ultrasound image slices, formal signed radiologist interpretive reports, nuclear medicine scans, and digital fluoroscopy recordings.
- Laboratory Information Systems (LIS): Clinical chemistry panels, hematology counts, microbiology cultures, urinalysis data, blood bank compatibility records, and surgical pathology/cytology diagnostic reports.
D. Clinical Communications and Digital Engagement Platforms
- Patient Portal Communications: Secure asynchronous messages, clinical inquiries, and provider advice transmitted through patient portals (e.g., Epic MyChart, Cerner HealtheLife).
- Clinician Secure Communications: Electronic mail messages, secure text messages, and telehealth consultation chat transcripts between treating clinicians when used to make clinical decisions or formulate treatment plans.
- Telemedicine Recordings: Audio or audiovisual recordings of remote clinical encounters if stored and utilized for diagnosis, treatment, or clinical monitoring.
E. Device Telemetry and Remote Patient Monitoring (RPM)
- Data streams transmitted from implantable cardioverter-defibrillators (ICDs), pacemakers, continuous glucose monitors (CGMs), home blood pressure cuffs, or pulse oximeters that are uploaded to or referenced by clinicians within the patient's record.
3. Explicit Statutory and Regulatory Carve-Outs from the DRS
Equally vital for the CHPS exam is identifying data elements that fall outside the legal definition of the Designated Record Set. Disclosing these excluded items under a general patient right-of-access request violates organizational policy and may breach federal confidentiality standards.
[Enterprise Healthcare Data Universe]
|
+--------------------------------+--------------------------------+
| |
v v
[Designated Record Set (DRS)] [Non-DRS Data Systems]
- Clinical Medical Chart (EHR) - Psychotherapy Notes (§ 164.501)
- Patient Billing & RCM Ledgers - Litigation Anticipation Work Product
- Diagnostic Reports & DICOM/PACS - IT System Logs & Audit Trails
- Health Plan Claims & Case Management - Raw Source Data (summarized elsewhere)
- Clinical Portal Messages & Telehealth - Peer Review & Incident Reports
- Remote Patient Monitoring Data - Non-Decision Worksheets & Drafts
A. Psychotherapy Notes (45 CFR § 164.501)
Psychotherapy notes are notes recorded by a mental health professional documenting private counseling sessions that are maintained separately from the rest of the patient's medical and billing record. Under 45 CFR § 164.524(a)(1)(i), psychotherapy notes are explicitly excluded from the individual right of access and do not form part of the standard DRS. (Detailed in Section 4.2).
B. Litigation Anticipation and Legal Defense Work Product
Under 45 CFR § 164.524(a)(1)(ii), information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding is statutorily carved out from the right of access. This includes attorney-client privileged communications, attorney work product, legal risk assessments, and incident investigation files compiled specifically for litigation defense.
C. Administrative Raw Data, Audit Logs, and System Metadata
Information systems generate massive volumes of administrative data that are not part of the DRS:
- Audit Trails and Access Logs: IT security audit logs tracking user logons, record views, timestamps, and IP addresses are maintained for HIPAA Security Rule compliance (45 CFR § 164.312(b)). They are not used to make clinical or financial decisions about patients and are excluded from the DRS.
- Operational Metadata and Worksheets: Computer code, HL7 message headers, temporary server cache files, software debugging logs, and administrative workload balance sheets.
D. Temporary Drafts and Clinician Personal Reminders
Informal notes, scratchpads, or personal memory aids created by a clinician solely for personal convenience—and destroyed or discarded once a formal note is dictated or entered into the chart—are not part of the DRS, provided they were never shared with other clinicians or filed in an official record system.
E. Source Data vs. Summarized Diagnostic Reports
A major point of exam confusion involves diagnostic "source data":
- Source Data Rule: Raw test data such as EKG paper rhythm strips, continuous EEG waveforms, fetal monitor tracings, and pathology tissue blocks/slides generally do not need to be reproduced under a standard DRS access request if a formal, signed diagnostic report interpreting that source data is maintained in the DRS.
- Once the interpreting physician generates and signs the formal interpretive report (e.g., formal 12-lead EKG interpretation, surgical pathology report), that report constitutes the official record in the DRS.
F. Peer Review, Incident Reports, and Quality Improvement Records
Hospital incident reports (e.g., patient fall reports, medication error logs), root-cause analysis (RCA) investigations, morbidity and mortality (M&M) conference notes, and credentialing committee minutes are created for institutional quality improvement and risk mitigation. They are protected under state peer review statutes and are never used to make healthcare decisions about the individual patient; hence, they are excluded from the DRS.
4. The Architectural Divide: EHR vs. DRS
A critical failure mode in healthcare compliance is treating the Electronic Health Record (EHR) and the Designated Record Set (DRS) as synonymous. They are fundamentally different concepts:
| Dimension | Electronic Health Record (EHR) | Designated Record Set (DRS) |
|---|---|---|
| Core Nature | Technical software platform / clinical database (e.g., Epic, Oracle Cerner, MEDITECH) | Legal construct defined by federal regulation (45 CFR § 164.501) |
| Scope | Typically restricted to clinical charting, orders, and direct ambulatory/inpatient notes | Enterprise-wide: encompasses clinical, financial, diagnostic, portal, and external BA records |
| Governing Standard | ONC Health IT Certification standards, technical data specifications | HIPAA Privacy Rule (§ 164.501, § 164.524, § 164.526) |
| Billing Data | May contain basic demographic or registration data, but rarely contains full revenue cycle ledgers | Fully includes all itemized bills, claims, adjudication files, EOBs, and payment ledgers |
| Ancillary Archives | Frequently interfaces with, but does not house, raw PACS DICOM images or offsite paper charts | Mandates inclusion of all PACS imaging, LIS data, and legacy physical paper charts |
| Patient Access Rights | Patient portals display a filtered subset of EHR data | Patient access rights legally apply to the entirety of the DRS across all systems |
The Distributed DRS Dilemma
Modern healthcare delivery relies on highly fragmented IT ecosystems. An individual patient's DRS does not live in a single database. It is distributed across:
- The core enterprise EHR;
- Independent Picture Archiving and Communication Systems (PACS);
- Specialized Laboratory Information Systems (LIS) and blood bank software;
- Standalone Revenue Cycle Management (RCM) and patient billing platforms;
- Cloud-hosted patient engagement and telemedicine applications;
- Third-party Business Associates (e.g., external billing vendors, outsourced transcription services, cloud storage archives, digital release-of-information processors);
- Off-site physical record warehouses holding legacy paper charts.
Under 45 CFR § 164.524, when an individual requests access to their Designated Record Set, the covered entity is legally obligated to retrieve, compile, and produce responsive records from all of these distributed repositories—not merely what is readily printable from the primary EHR.
5. Hybrid Entities and Distributed Business Associate Systems
Managing Hybrid Entities (45 CFR § 164.103 & § 164.105)
A hybrid entity is a single legal entity whose business activities include both covered and non-covered functions. Typical examples include:
- A large university that operates an academic medical center or student health clinic alongside academic departments and campus housing.
- A municipal government that operates an emergency medical services (EMS) department and public health clinic alongside police, fire, and administrative departments.
- A manufacturing corporation that operates an onsite employee health and wellness clinic alongside corporate manufacturing operations.
[HYBRID LEGAL ENTITY]
|
+---------------------------+---------------------------+
| |
v v
[Designated Healthcare Component] [Non-Covered Components]
- Academic Hospital / Student Clinic - University Registrar / Admissions
- EMS / Public Health Division - Municipal Police / Fire / Parks
- Onsite Employee Wellness Clinic - Corporate HR / Manufacturing Lines
| |
v v
SUBJECT TO HIPAA & DRS RULES EXEMPT FROM HIPAA & DRS
- Maintains official Designated Record Set - Governed by FERPA, state law, or ADA
- Physical & technical firewalls required - No HIPAA Right of Access applies
To comply with HIPAA, a hybrid entity must satisfy three strict requirements:
- Formal Designation: The entity must formally document in its compliance policies the specific healthcare components that perform covered functions.
- Organizational Firewalls: The entity must establish administrative, physical, and technical safeguards to prevent PHI from flowing impermissibly from covered healthcare components to non-covered components (e.g., ensuring a university health center does not share student clinical records with academic deans or the registrar without authorization).
- DRS Delineation: Only the records created, maintained, or received by the designated healthcare component fall within the DRS. Records held by the non-covered component (such as student education records governed by FERPA, or employment records held by HR in its role as employer) are legally excluded from HIPAA and the DRS.
Enforcing DRS Compliance Across Business Associates
Under 45 CFR § 164.502(e) and § 164.504(e), covered entities routinely contract with Business Associates (BAs) to perform billing, claims processing, data analytics, or medical transcription. When a BA creates, receives, maintains, or transmits PHI that forms part of the covered entity's DRS:
- The underlying Business Associate Agreement (BAA) must contain explicit contractual language requiring the BA to make PHI available to the covered entity within statutory timelines to satisfy patient access requests (§ 164.524) and amendment requests (§ 164.526).
- If an individual requests their complete billing ledger, and the covered entity utilizes an external billing agency, the covered entity cannot excuse non-compliance by claiming the records reside with a third party. The covered entity remains strictly accountable for retrieving the BA's records and providing them to the patient.
Exam Tips and Candidate Traps
[!IMPORTANT] EHR vs. DRS Scope: A classic CHPS exam scenario describes a hospital fulfilling a patient's access request by exporting only the records visible in the primary EHR, ignoring the external billing agency's ledgers and the standalone PACS imaging server. Candidates must identify this as a direct violation of 45 CFR § 164.524. The Designated Record Set legally encompasses all clinical, financial, and decision-making data across the entire enterprise, including Business Associates.
[!TIP] Audit Trails Are Not DRS Records: When a patient submits a request under § 164.524 demanding "all records about me, including every audit log showing who opened my chart," the covered entity is legally required to provide the clinical and billing records, but may exclude the IT audit logs. Audit trails are administrative security records under 45 CFR § 164.312(b), not clinical or billing records used to make decisions about the individual. (Note: Disclosures outside TPO may be subject to an Accounting of Disclosures under § 164.528, but internal EHR audit logs do not belong in the DRS).
[!WARNING] Source Data Carve-Out Caveat: If a candidate sees a question regarding raw test tracings (like an EKG rhythm strip or an EEG monitor feed), check whether a formal signed physician interpretation exists. If the formal interpretive report is in the chart, the raw source tracings are excluded from the required DRS production unless facility policy or state law explicitly mandates their retention and release.
A former inpatient submits a formal written request to a medical center's Health Information Management (HIM) department stating: 'I demand a complete copy of my entire Designated Record Set, including all clinical charts, all billing statements, and the full EHR security audit log showing the name of every nurse and doctor who viewed my chart.' How must the HIM Director respond under 45 CFR § 164.501 and § 164.524?
A patient requests their complete medical record from an outpatient cardiology clinic. The clinic produces all physician clinical notes, lab results, and the formal 12-lead electrocardiogram (EKG) diagnostic report signed by the attending cardiologist. However, the patient files an OCR complaint alleging the clinic violated HIPAA by withholding the raw, continuous paper EKG telemetry strips generated during their stress test. How is this evaluated under HIPAA Designated Record Set standards?
A large public university operates an academic hospital, an outpatient student health clinic, a law school, and an undergraduate residential program. The university has formally declared itself a hybrid entity under 45 CFR § 164.103, designating the hospital and student health clinic as its healthcare components. The hospital utilizes an outsourced third-party billing agency. An individual requests access to their complete DRS. Which data systems must the university include in its production?