Patients Have a Right to Their Records: What the Azul Vision Settlement Teaches Small Healthcare Practices
A small Healthcare practice may not have a dedicated compliance team, release-of-information department, or full-time IT manager. Patient record requests may arrive through different channels, land with the wrong person, or remain in an inbox while staff manage clinical priorities.
That creates an access gap.
When PHI is involved, an inconsistent process is not merely inconvenient. It can damage patient trust, create operational disruption, and expose a practice to serious financial consequences.
The recent Azul Vision settlement is a clear reminder: patient access requests require ownership, tracking, and timely action.
What happened in the Azul Vision settlement?
According to the HHS Office for Civil Rights press release, OCR announced a settlement with Azul Vision, Inc. on August 27, 2026.
Azul Vision is a California optometry and ophthalmology provider. HHS OCR described the matter as its 55th HIPAA Right of Access enforcement action.
The public record states that:
A patient requested access to PHI in January 2023.
The provider did not provide timely access within HIPAA’s required 30-day period.
A complaint was filed with OCR in April 2023.
The requested records were not delivered until January 2025, after OCR opened an investigation.
The settlement amount is $50,000.
The agreement includes a two-year corrective action plan.
This article does not speculate about the provider’s intent or make claims beyond the public record. The lesson for small Healthcare practices is practical: a patient request needs a defined workflow from intake through delivery. If no one owns the request, the deadline can pass before anyone recognizes the risk.
The HIPAA Right of Access: What small practices need to know
The HIPAA Privacy Rule generally gives individuals a right to inspect and obtain copies of PHI maintained in a designated record set.
The HHS OCR Right of Access guidance explains that a covered entity generally must act on a valid access request within 30 calendar days.
“Act” may mean providing access or issuing an appropriate written denial. When permitted, one written extension of up to 30 additional calendar days may be available. The practice must provide written notice within the initial 30-day period that explains the reason for the delay and states the new completion date.
That means a practice should not treat 60 days as its normal response window. The standard is generally 30 days. The extension is limited, must be properly communicated, and should not become a substitute for an organized process.
State law or other applicable requirements may impose shorter deadlines. Practices should consult qualified legal or compliance professionals when evaluating their specific obligations.
The practical Right of Access workflow
A dependable process should create a record of what happened, who was responsible, and when each step was completed.
Use this workflow as a starting point:
Intake: Record when the request was received, how it arrived, and what records or delivery method the patient requested.
Validation: Confirm the request and identity-verification requirements under the practice’s approved procedures.
Assignment: Name the person responsible for coordinating the response.
Scope review: Identify the relevant designated record set and determine whether additional departments, systems, or vendors must be involved.
Deadline tracking: Calculate the 30-day response deadline and place it where the responsible staff member will see it.
Response: Document when access was provided or when a written denial was issued.
Extension: If an extension is permitted and necessary, document the reason, written notice, and new completion date.
Delivery: Record how the PHI was delivered and when the request was completed.
Closeout: Retain the supporting evidence according to the practice’s policies and applicable requirements.
This workflow is administrative, but it protects something deeply personal: a patient’s ability to obtain information about their own care.
The safeguards that support financial survival
Right of Access requests do not exist separately from the rest of a practice’s HIPAA responsibilities. A small Healthcare organization needs administrative safeguards that show its security and privacy processes have an owner.
1. Access Tracking
Access Tracking is the first safeguard because PHI cannot be protected when a practice does not know who can reach it.
Maintain a current record of:
Workforce roles and assigned access levels
Vendor or contractor access
Access changes after role changes
Terminated or inactive accounts
Approvals and business reasons for access
Technical controls such as MFA and encryption are important hooks for reducing unauthorized access. But the administrative question remains: who has access, why do they have it, and when was it reviewed?
2. Incident Reporting
Small mistakes can become major problems when they are not reported, reviewed, and documented.
Your process should make it simple for staff to report events such as:
PHI sent to the wrong recipient
Lost or stolen devices
Suspected unauthorized access
Misdirected patient records
Unusual login or system activity
Incident reporting is not about assigning blame. It is about ensuring the practice can identify what happened, preserve relevant information, escalate appropriately, and determine what action is required.
3. Awareness Training
Every team member who handles PHI needs to understand the practice’s procedures.
Training should cover:
Patient access requests and where to send them
Identity verification and secure delivery
Recognizing phishing and suspicious messages
Reporting suspected incidents
Appropriate use of EHR and other Healthcare systems
Protecting PHI in conversations, documents, devices, and email
Completion records matter. A practice should be able to show who received training, when it was completed, what topics were covered, and what follow-up occurred when training was missed.
4. Risk Analysis
A risk analysis helps a practice understand where PHI is created, received, maintained, or transmitted: and where its processes could fail.
Consider:
Where patient access requests arrive
Whether requests can be lost in shared inboxes
Which systems contain PHI
Which employees and vendors can access those systems
How records are retrieved and delivered
What happens during staff absences or system outages
Whether incident and access records are reviewed
HHS provides guidance on conducting a HIPAA Security Rule risk analysis. NIST’s SP 800-66 Revision 2 also offers a practical cybersecurity resource for HIPAA-regulated entities.
A risk analysis is not a one-time exercise. Changes to staff, systems, vendors, locations, and workflows can create new risks to PHI.
5. Policies Tracking
Policies should not sit in a forgotten folder.
Track:
Current policy versions
Required annual reviews
Workforce acknowledgements
Policy changes
Assigned owners
Follow-up actions
For Right of Access, the policy should clearly explain where requests go, who owns them, how deadlines are tracked, how extensions are handled, and how delivery is documented.
How Veri-Hub supports a survival-focused approach
Veri-Hub is a Security and Access Management System designed to help small Healthcare practices organize the administrative safeguards they must maintain.
It can support:
Access tracking for workforce members and vendors
Incident reporting with time-stamped records
Awareness training assignments and completion records
Risk analysis documentation
Policy maintenance, acknowledgements, and review tracking
Veri-Hub does not replace the practice’s EHR, legal review, records-release procedures, or professional judgment. It also does not guarantee compliance or prevent enforcement.
Its value is structure and visibility. When responsibility is clear and evidence is organized, practice leaders can identify gaps sooner and respond with greater confidence. That can mean less scrambling, stronger process ownership, and more peace of mind when an audit, patient concern, or internal review requires answers.
The Azul Vision settlement demonstrates why this matters. A request that remains untracked can become a prolonged operational problem. A prolonged problem can require policy changes, workforce training, monitoring, reporting, and significant financial resources.
For a small practice, $50,000 is not an abstract number. It can affect payroll, equipment, staffing, growth, and the ability to keep the doors open.
Protecting the practice starts before the request arrives
Patients have a right to their records. Your practice needs a process that respects that right while protecting PHI at every step.
Do not wait for an access request to discover that:
No one knows who receives the request
There is no reliable deadline tracker
Staff are unsure how to handle an extension
Delivery is not documented
Policies are outdated
Training records are incomplete
Access permissions have not been reviewed
We live this experience. With my background as an RN, BSN, more than 30 years in Healthcare, and more than 25 years implementing EHR systems, I understand how quickly administrative gaps can become clinical, financial, and operational burdens.
The choice is straightforward: build an organized, audit-ready process: or risk facing consequences that could threaten the financial survival of the practice.
Veri-Hub is a practical survival tool for staying organized, protecting PHI, and keeping your Healthcare practice prepared.
Visit Veri-Se3ure or book a consultation to discuss how your practice can strengthen access tracking, training records, incident reporting, risk analysis, and policy maintenance. This article is educational and is not legal advice or a guarantee of compliance.



Comments