- Owner
- Health Information Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 12 months
1.Purpose
To keep patient records complete, accurate, secure and available to authorized staff, while releasing information only to properly verified and authorized requesters.
2.Scope
Applies to the management of paper and electronic patient records, including release of information requests. Clinical documentation content standards are covered by separate department SOPs.
Definitions
- Release of information (ROI)
- A request from a patient, provider or third party for a copy of some or all of a patient's medical record.
- Authorization form
- A signed document from the patient or their legal representative permitting release of specific records to a named recipient.
- Retention schedule
- The facility's documented policy for how long different types of records must be kept before they can be destroyed.
- Chart deficiency
- A missing signature, order or required entry that must be completed before a record is considered complete.
3.Responsibilities
- Health Information Clerk
- Files and scans records, tracks chart deficiencies and processes routine release of information requests.
- Health Information Manager
- Oversees the department, approves complex or sensitive release requests, and manages the retention schedule.
- Provider
- Completes and signs documentation and clears assigned chart deficiencies within the required timeframe.
- Privacy Officer
- Reviews unusual or disputed release requests and investigates any suspected privacy breach.
RACI matrix
| Activity | Health Information Clerk | Health Information Manager | Provider | Privacy Officer |
|---|---|---|---|---|
| Track and clear chart deficiencies | R | A | R | - |
| Verify and process a release of information request | R/A | C | I | C |
| Approve a sensitive or disputed release request | I | R/A | I | R |
| Apply and execute the retention schedule | R | R/A | I | C |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- โEHR and document management system
- โChart deficiency tracking report
- โRelease of information authorization forms
- โRetention schedule policy document
- โSecure shredding or destruction service log
- โPhoto ID verification process for in-person requests
5.Procedure
- 5.1
Scan and file incoming documents
Health Information ClerkScan paper documents and file them into the correct patient record in the document management system within the timeframe set by department policy.
- 5.2
Run the chart deficiency report
Health Information ClerkRun the deficiency report on the schedule set by the department, identifying missing signatures, orders or required entries by provider.
- 5.3
Notify providers of deficiencies
Health Information ClerkSend deficiency notices to the responsible provider with a due date, and escalate to the medical staff office for repeated overdue deficiencies.
- 5.4
Complete assigned deficiencies
ProviderReview and complete assigned chart deficiencies, such as missing signatures or dictated notes, within the timeframe required by facility policy.
Checkpoint: Charts are marked complete only after every required signature and entry is present.
- 5.5
Receive a release of information request
Health Information ClerkLog the incoming request, whether from the patient, another provider or a third party, and identify the specific records and date range requested.
- 5.6
Verify the requester's identity and authority
Health Information ClerkConfirm the requester's identity with photo ID or an equivalent verification method, and confirm they are legally entitled to receive the records requested.
Checkpoint: Requester identity and legal authority are verified before any record is released.
- 5.7
Confirm a valid authorization
Health Information ClerkCheck that the signed authorization form covers the specific records, date range and recipient requested, and that it has not expired.
Warning: Never release records based on a verbal request alone or an authorization form that does not match the request.
- 5.8
Escalate sensitive or unclear requests
Health Information ManagerRoute requests involving sensitive record categories, minors, deceased patients or legal disputes to the health information manager or privacy officer for review before release.
- 5.9
Compile and release the records
Health Information ClerkCompile only the records covered by the authorization, redact any information outside its scope, and send them through an approved secure method.
- 5.10
Log the disclosure
Health Information ClerkRecord what was released, to whom, when and by what method in the disclosure tracking log required for accounting of disclosures.
- 5.11
Apply the retention schedule
Health Information ManagerReview records approaching the end of their retention period against the facility's retention schedule before scheduling destruction.
- 5.12
Destroy records securely
Health Information ManagerDestroy eligible records using an approved secure method, such as shredding or certified electronic destruction, and log the destruction with date and method.
6.Quality checks
- โChart deficiency rate stays below the facility's target for overdue items.
- โEvery release of information request has a verified requester identity on file.
- โDisclosure log entries match the volume of processed release requests.
- โNo record is destroyed before its retention period has expired.
7.Records
- โChart deficiency tracking report
- โRelease of information authorization forms
- โAccounting of disclosures log
- โRecord destruction log
8.KPIs
- โAverage chart deficiency completion time
- โRelease of information turnaround time
- โPercentage of requests verified before release
- โRecords destroyed on schedule versus overdue
9.Common mistakes
- โReleasing records based on a phone request without written authorization.
- โFiling a document into the wrong patient's record.
- โLetting chart deficiencies go untracked past the required completion window.
- โDestroying records without checking the retention schedule first.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.