Operations
How release of information works, and the 30-day clock
Records requests are a queue with legal deadlines attached, handled in most practices by whoever has a spare afternoon. This is how to run it as a tracked function with an audit trail that survives being asked about.
Records requests arrive constantly and belong to nobody. They come from patients, other providers, attorneys, payers, disability programmes and courts, through fax, portal, post and phone, and in most practices they are handled by whoever notices them.
That would be merely inefficient if it were not for the deadlines. Records requests carry obligations, and an obligation handled by whoever has a spare afternoon is an obligation that will be missed at some point.
Log everything, with a due date
The first requirement is a log: every request, recorded on arrival, with the requester, the type, the scope, the date received, the applicable due date and the current status.
Without dates the queue cannot be prioritised — every request looks equally urgent, which means the oldest one loses. With dates it becomes an ordinary queue with a clear order of work.
Validate before releasing
Four checks, in order, before anything leaves:
- Who is asking. Identity and authority of the requester, verified rather than assumed from the letterhead.
- What entitles them. Patient authorization, a legal instrument, a treatment relationship, or a payer’s contractual right — each with a different scope.
- What the authorization covers. Which dates, which record types, which providers. A request for one episode does not authorize the whole chart.
- Whether it is still valid. Authorizations expire and can be revoked.
Each check should leave a record. A release performed correctly with no evidence of the checks is a release that cannot be defended.
Release the minimum the request covers
In our experience the most common shortcut in this function is sending the entire chart because narrowing it takes longer. That is a disclosure decision made by accident, and it is exactly the kind of decision that gets asked about.
Assembling precisely what a request covers is slower per request and is the job. Where the scope is ambiguous, the answer is to ask the requester to clarify, not to resolve the ambiguity generously.
Track turnaround by type
Different request types carry different obligations and different practical expectations. Tracking them as one average hides the category that is running late, which is usually the one with the shortest deadline.
A simple report — open requests by type, with days elapsed against days allowed, and anything approaching its deadline flagged — is enough. What matters is that somebody reads it weekly.
What to define before handing over the queue
The policy
Who may authorize a release, what is excluded, how sensitive categories are handled, and what fees if any apply. This is the practice’s policy and must exist in writing before a seat applies it.
The validation standard
The four checks above, with the evidence required for each recorded in the log.
The escalation route
Anything unusual — a legal instrument, a request touching a sensitive category, a dispute about scope, a request from a party whose authority is unclear — goes to a named person at the practice. The seat does not decide these.
The delivery routes
How records are sent for each requester type, and what is never sent by which channel.
The retention of the log itself
Where the disclosure record lives and how long it is kept, which should follow the practice’s own retention policy.
How to assess it
- How many requests are open, by type, and how many are approaching a deadline?
- Were any deadlines missed, and what caused each one?
- Is every completed release accompanied by a full disclosure record?
- How many requests needed clarification, and how long did that take?
- How many were escalated, and were they resolved promptly?
- Is the log complete — does it include the requests that arrived by fax and phone, not just the portal?
The last question is usually the one that finds the gap.
How Soft Home Global staffs this
Soft Home Global provides trained full-time back-office seats from Rawalpindi, Pakistan. Medical records and release of information is published at $1,500 per seat per month, billed per seat with a one month minimum.
The seat works US hours inside your system: logging every request on arrival with its due date, validating requester and scope against your policy, assembling exactly what each request covers, releasing by the routes you approve, recording the disclosure in full, and reporting open requests against their deadlines every week.
Anything unusual is escalated to the person you name rather than resolved locally. The practice keeps the policy and the judgement; the seat keeps the queue moving and the record complete.
Where to start
Count what is open right now, by type, with the date each arrived. Most practices that have never run this as a tracked function find at least one request older than anybody realized, and no reliable way to prove what was released last year.
Both of those are fixed by the same thing: a log with dates, kept from arrival.
Questions people ask about this
- What does a release of information seat do?
- It logs incoming records requests, validates the requester’s authority and the scope of the authorization, assembles exactly what the request covers, releases it by the agreed route, records the disclosure, and tracks every request against its due date.
- Can release of information be outsourced?
- The processing can — logging, validation against the practice’s own rules, assembly, tracking and the disclosure record. What the practice must retain is the policy: who may authorize a release, what is excluded, and who decides anything unusual. The seat applies the policy; it does not write it.
- How much does a records seat cost?
- Soft Home Global publishes $1,500 per seat per month for a trained full-time medical records and release of information seat, billed monthly with a one month minimum.
- What has to be checked before records are released?
- Who is requesting, on what authority, what the authorization specifically covers, whether it is still valid, and whether any part of the record is excluded under the practice’s policy or applicable law. Each of those is a separate check and each should be recorded.
- Why does the disclosure record matter?
- Because a release without a record is indistinguishable from a leak when somebody asks about it later. What was released, to whom, under what authority, by whom and when — recorded at the time — is what makes the function defensible.
- How should records request turnaround be measured?
- Against the deadline that applies to each request type rather than as a single average. A patient request, an attorney request, a payer audit and a continuity-of-care request are different obligations, and an average hides the one that is late.
Where this connects
Next step
One seat. One month. Cancel any time.
Twenty minutes on a call is enough to tell whether this fits. If it does not, I will say so.
Or write to ops@softhomeglobal.com

