
The Health Information Privacy Reform Act (HIPRA) would reach well beyond traditional HIPAA-covered organizations. The Senate-reported version of S. 3097 would direct the Department of Health and Human Services (HHS), in consultation with the Federal Trade Commission (FTC), to establish privacy, security, and breach notification standards for certain health information handled by regulated entities and service providers.
For healthcare providers and health information management teams, Section 3 is the part that deserves the closest operational attention. It addresses patient-directed access to protected health information. It also addresses fee rules that could depend on who receives the information.
That recipient distinction matters because ROI teams already work across multiple legal pathways. A patient may obtain their own records, direct records to another provider, or send them to a third party. Each scenario can raise different questions about access, authority, fees, and fulfillment.
This article is for informational purposes only and does not constitute legal advice. Healthcare organizations should consult qualified legal or compliance counsel regarding specific requests and requirements.

The Health Information Privacy Reform Act, or HIPRA, is the federal proposal analyzed here. In the Senate-reported version, HIPRA would establish broader privacy, security, and breach notification protections for certain health information, including data that may sit outside the traditional HIPAA framework. The bill also addresses access, data minimization, government access, minimum necessary requirements, de-identification, and preemption.
For ROI operations, HIPRA Section 3 is narrower and more concrete. It focuses on patient-directed access to protected health information and how specified federal fee provisions would apply to different recipients.
HIPRA Section 3 would make recipient classification a more explicit part of the fee analysis. Under the reported language, the referenced federal fee provisions would apply only to three recipient categories. Those categories are the individual or personal representative, the individual’s healthcare provider or its business associate, and a personal health record managed and controlled by the individual.
Section 3(a) is narrower in scope than Section 3(b). It applies when an individual directs a covered entity or business associate to transmit, produce, or provide access to PHI contained in an electronic health record to a designated person. In that setting, the bill would allow advance payment of fees permitted under applicable state law, subject to Section 3(b). It could also require the recipient to accept terms, limitations, and conditions contained in the individual’s request. Under the reported text, those accepted terms would become legally binding on the recipient.
Section 3(b), by contrast, addresses how the referenced federal fee provisions apply to protected health information provided to the listed recipient categories. That scope difference matters because the EHR-specific condition in Section 3(a) should not be treated as a blanket rule for every patient-directed disclosure.
Section 3(e) adds another boundary. It says the subsection (a) fee or condition should not apply when an individual or personal representative receives or accesses PHI on the individual’s behalf and at the individual’s direction for a personal health record selected, managed, and controlled by that individual or representative. It also preserves existing rights and responsibilities under HITECH § 13405(e).
Operationally, the key question is straightforward: who is receiving the information, and in what legal capacity are they acting?

The same records can trigger different access and fee questions depending on the recipient. These common scenarios show why classification belongs at intake.
A patient obtaining their own records falls within the recipient categories identified in Section 3(b). Current HIPAA Right of Access rules also remain central to this scenario, including the requirements in 45 C.F.R. § 164.524.
Section 3(b) also includes the individual’s healthcare provider and that provider’s business associate. That makes a transmission to another healthcare provider different from a request that sends the same records to an unrelated third-party recipient.
An attorney acting only as a third-party recipient does not fall within the three categories listed in Section 3(b). The analysis can differ when someone qualifies as the individual’s personal representative. HHS explains that personal representative status depends on authority under state or other applicable law. For a living adult, that generally means legal authority to make healthcare decisions on the individual’s behalf. An attorney’s job title alone does not establish that status.
That distinction means a patient signature by itself may not answer every operational question. The ROI workflow may still need to capture the recipient and the recipient’s legal capacity. It also needs the information requested and the legal pathway supporting the disclosure.
HIPRA would not create the difference between patient access and third-party requests from scratch.
Under current HHS Right of Access guidance, the HIPAA patient access fee limitation is cost-based. A covered entity generally may charge only a reasonable fee made up of allowable costs such as copying labor, supplies, postage, and labor to prepare a summary or explanation if the individual chooses and agrees to the fee.
The current framework also reflects the 2020 Ciox Health, LLC v. Azar decision. In its Right of Access court order notice, HHS states that the fee limitation in 45 C.F.R. § 164.524(c)(4) applies to an individual’s request for access to their own records. It does not apply to an individual’s request to transmit records to a third party.
State law can add another layer, especially in third-party request contexts. Medical record fee statutes vary by jurisdiction, and our state-by-state medical record copying fees show how those limits and requirements differ across states.
The practical significance of HIPRA is therefore not that state law fees would suddenly matter for the first time. Section 3 could place more explicit federal statutory language around how the recipient affects the fee analysis in the circumstances it covers.
For example, a patient-directed EHR transmission to an attorney acting solely as a third-party recipient could put Section 3(a)’s state law fee provision into play. That does not make every fee authorized by state law permissible. The request still has to be evaluated against the proposal’s limits and other applicable federal requirements.
HIPRA Section 3 also contains an information blocking safeguard. It says the section should not permit a covered entity or business associate to deny, delay, or condition a patient-directed transmission in a prohibited way. The analysis therefore cannot stop at whether state law permits a fee. The federal information blocking framework may also need evaluation.
Under the Manner Exception at 45 C.F.R. § 171.301, an actor that fulfills an EHI request in the manner requested does not have to make associated fees satisfy the separate Fees Exception in § 171.302. If the actor cannot fulfill the request that way and uses an alternative manner under the exception, associated fees must satisfy § 171.302.
The Fees Exception at 45 C.F.R. § 171.302 has its own requirements and exclusions. One exclusion involves fees based in part on electronic access by an individual, personal representative, or another person or entity designated by the individual. Section 171.302 defines electronic access as an internet-based method that makes EHI available when requested without manual effort to fulfill the request. Not every electronic patient-directed transmission described in HIPRA necessarily fits that definition.
Falling outside an exception does not automatically prove information blocking. It means the actor cannot rely on that particular exception. The broader rule and other potentially applicable exceptions still need to be evaluated.
The broader rules for information blocking enforcement in healthcare also matter when access or exchange friction could create compliance risk.

The strongest response to a proposal like HIPRA is not to rebuild a workflow around language that may change. The goal is to capture enough information to apply the right rule to each request.
Those questions are useful even if the HIPRA bill changes. They also help teams avoid a broader ROI problem. One default workflow should not be applied to requests with different legal requirements.
In practice, that review may reach intake fields, recipient status checks, federal and state pricing logic, prepayment procedures, exception escalation, and the documentation kept with each request. The point is not to add steps to every request. It is to make sure the workflow captures the facts needed to route each request correctly.
Medical record fulfillment can require intake, identity and authority checks, record location, pricing, payment, fulfillment, delivery, and documentation. The compliance burden grows when those decisions depend on request type, recipient, jurisdiction, record format, and changing federal requirements.
Our platform applies pricing logic based on state and federal statutes, while our release of information software centralizes request tracking and detailed audit trails. Together, those capabilities help teams apply pricing rules more consistently while preserving a detailed history of each request. Legal interpretation still belongs with the organization and its counsel. The software helps operationalize established policies once those rules are defined.
That is the operational lesson HIPRA reinforces. A workflow should distinguish request types and route them through the right rules. It should also preserve a record of what happened. Staff should not have to reconstruct the decision later from email, spreadsheets, or disconnected systems.
If recipient type, fee rules, payment status, and fulfillment history live across separate tools, a centralized ROI workflow may reduce the friction of managing those decisions across disconnected systems.
Schedule a personalized consultation to see how ChartRequest can support a more consistent, auditable, and adaptable medical record release process.
This article analyzes the Senate-reported version of S. 3097. The analysis is specific to that version rather than a live legislative status tracker. Organizations should confirm the current bill text and governing law before making operational changes.
No. The Senate-reported proposal would add or clarify health information requirements. It would not replace the existing HIPAA framework.
Section 3 would make the recipient more important to the fee analysis. For certain patient-directed EHR transmissions, it would also allow advance payment of fees permitted under applicable state law. The proposal’s limits and other federal requirements would still apply.
Potentially. An attorney acting only as a third-party recipient is not one of the recipient categories listed in Section 3(b). The analysis can differ if the person qualifies as the individual’s personal representative under applicable law. ROI teams should classify the recipient by legal capacity rather than title alone.
The Senate-reported text gives HHS 180 days after enactment to amend existing guidance as necessary to implement Section 3(a) and 3(b). That makes guidance issued after enactment an important source for how Section 3 would operate in practice if the proposal became law.