- Owner
- Health Information Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 12 months
1.Purpose
To keep patient records complete, accurate, secure and available to authorized staff, while releasing information only to properly verified and authorized requesters.
2.Scope
Applies to the management of paper and electronic patient records, including release of information requests. Clinical documentation content standards are covered by separate department SOPs.
Definitions
- Release of information (ROI)
- A request from a patient, provider or third party for a copy of some or all of a patient's medical record.
- Authorization form
- A signed document from the patient or their legal representative permitting release of specific records to a named recipient.
- Retention schedule
- The facility's documented policy for how long different types of records must be kept before they can be destroyed.
- Chart deficiency
- A missing signature, order or required entry that must be completed before a record is considered complete.
3.Responsibilities
- Health Information Clerk
- Files and scans records, tracks chart deficiencies and processes routine release of information requests.
- Health Information Manager
- Oversees the department, approves complex or sensitive release requests, and manages the retention schedule.
- Provider
- Completes and signs documentation and clears assigned chart deficiencies within the required timeframe.
- Privacy Officer
- Reviews unusual or disputed release requests and investigates any suspected privacy breach.
RACI matrix
| Activity | Health Information Clerk | Health Information Manager | Provider | Privacy Officer |
|---|---|---|---|---|
| Track and clear chart deficiencies | R | A | R | - |
| Verify and process a release of information request | R/A | C | I | C |
| Approve a sensitive or disputed release request | I | R/A | I | R |
| Apply and execute the retention schedule | R | R/A | I | C |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- →EHR and document management system
- →Chart deficiency tracking report
- →Release of information authorization forms
- →Retention schedule policy document
- →Secure shredding or destruction service log
- →Photo ID verification process for in-person requests
5.Procedure
- 5.1
Scan and file incoming documents
Health Information ClerkScan paper documents and file them into the correct patient record in the document management system within the timeframe set by department policy.
- 5.2
Run the chart deficiency report
Health Information ClerkRun the deficiency report on the schedule set by the department, identifying missing signatures, orders or required entries by provider.
- 5.3
Notify providers of deficiencies
Health Information ClerkSend deficiency notices to the responsible provider with a due date, and escalate to the medical staff office for repeated overdue deficiencies.
- 5.4
Complete assigned deficiencies
ProviderReview and complete assigned chart deficiencies, such as missing signatures or dictated notes, within the timeframe required by facility policy.
Checkpoint: Charts are marked complete only after every required signature and entry is present.
- 5.5
Receive a release of information request
Health Information ClerkLog the incoming request, whether from the patient, another provider or a third party, and identify the specific records and date range requested.
- 5.6
Verify the requester's identity and authority
Health Information ClerkConfirm the requester's identity with photo ID or an equivalent verification method, and confirm they are legally entitled to receive the records requested.
Checkpoint: Requester identity and legal authority are verified before any record is released.
- 5.7
Confirm a valid authorization
Health Information ClerkCheck that the signed authorization form covers the specific records, date range and recipient requested, and that it has not expired.
Warning: Never release records based on a verbal request alone or an authorization form that does not match the request.
- 5.8
Escalate sensitive or unclear requests
Health Information ManagerRoute requests involving sensitive record categories, minors, deceased patients or legal disputes to the health information manager or privacy officer for review before release.
- 5.9
Compile and release the records
Health Information ClerkCompile only the records covered by the authorization, redact any information outside its scope, and send them through an approved secure method.
- 5.10
Log the disclosure
Health Information ClerkRecord what was released, to whom, when and by what method in the disclosure tracking log required for accounting of disclosures.
- 5.11
Apply the retention schedule
Health Information ManagerReview records approaching the end of their retention period against the facility's retention schedule before scheduling destruction.
- 5.12
Destroy records securely
Health Information ManagerDestroy eligible records using an approved secure method, such as shredding or certified electronic destruction, and log the destruction with date and method.
6.Quality checks
- →Chart deficiency rate stays below the facility's target for overdue items.
- →Every release of information request has a verified requester identity on file.
- →Disclosure log entries match the volume of processed release requests.
- →No record is destroyed before its retention period has expired.
7.Records
- →Chart deficiency tracking report
- →Release of information authorization forms
- →Accounting of disclosures log
- →Record destruction log
8.KPIs
- →Average chart deficiency completion time
- →Release of information turnaround time
- →Percentage of requests verified before release
- →Records destroyed on schedule versus overdue
9.Common mistakes
- →Releasing records based on a phone request without written authorization.
- →Filing a document into the wrong patient's record.
- →Letting chart deficiencies go untracked past the required completion window.
- →Destroying records without checking the retention schedule first.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.


