July 30, 2026

QUESTION:
A patient recently requested a list of all individuals who accessed her medical record.  Do we have to give it to her?

ANSWER FROM HORTYSPRINGER ATTORNEY DAN MULHOLLAND:
A patient has the right of access under HIPAA to her protected health information (PHI) contained in a “designated record set.” 45 CFR §164.524(a)(1).  A “designated record set” is defined as including:

    • Medical records and billing records about individuals maintained by or for a covered health care provider.
    • Enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan.
    • Other records used, in whole or in part, by or for the covered entity to make decisions about individuals.

The patient in question seems to be requesting copies of the audit logs showing who accessed her records and when.  The audit logs are security/audit controls required under the HIPAA Security Rule (45 CFR §164.312(b)) for compliance and breach detection, not for clinical or decision-making purposes.  Therefore, they are not part of a “designated record set” and thus the patient does not have a right of access to that information.

Another section of the HIPAA regulations gives patients the right to ask for an accounting of disclosures of their PHI.  45 CFR §164.528(a).  However, this does not include disclosures for treatment, payment or health care operations.  The audit log would record access for treatment, payment or health care operations so the information in the audit log would not be subject to the disclosure accounting rule.

Of course, if the patient brought suit against the hospital, she would be able to get access to the audit logs and other parts of the electronic health record through normal discovery procedures.

If you have a quick question about this, e-mail us at info@hortyspringer.com.