A dental records release form should identify the patient, requested records, recipient, and delivery instructions—but the correct form depends on the request. A patient asking for their own records is exercising an access right; that does not automatically require a HIPAA authorization. Another provider's treatment request and an outside party's authorization-based request follow different pathways.
Front desk teams should use forms approved by the practice's privacy official and qualified counsel. State rules and special record protections can add requirements. The checklist below helps staff route and complete requests; it is not a universal legal form.
Choose the pathway before handing out a form
| Request received | Route it as | First question to resolve |
|---|---|---|
| Patient wants a copy for themselves | Individual access | Which records and delivery format are requested? |
| Someone claims to be the patient's legal representative | Representative review and applicable access process | Does their authority cover this request? |
| Another dentist requests records for treatment | Provider treatment disclosure | Who is requesting, and for what treatment purpose? |
| Patient directs an electronic record to another person | Review the applicable third-party access directive | Does this request fall within that right? |
| Insurer, attorney, employer, or other outside party requests records | Privacy review of authorization or other legal basis | What authority permits or requires this particular disclosure? |
HIPAA generally permits provider-to-provider treatment disclosures without patient authorization. It requires authorization for disclosures not otherwise permitted or required. An access request, treatment consent, and acknowledgment of the privacy notice serve different purposes. HHS summary of the HIPAA Privacy Rule
Do not assume a subpoena, letterhead, matching last name, or payment relationship settles the question. Route uncertain authority to the designated reviewer. The family-member authority guide explains why a helper and a personal representative are not interchangeable.
Why third-party requests need their own review
HHS's Ciox court-order notice narrows the access right's third-party directive to certain electronic-health-record requests. It also states that HIPAA's access fee limitation applies to individuals obtaining their own records, not requests to transmit records to a third party. Own-record access rights remain intact. Do not apply older guidance that treats all third-party requests identically. HHS notice on the right-of-access court order
For a request within that directive, verify written, signed instructions identifying the recipient and where to send the electronic record. Have the privacy reviewer confirm the applicable pathway before processing.
Build a short intake section for every request
Use an approved, protected request record with these operational fields:
Received: Date, channel, and staff member. Patient match: Identifiers needed under the office's verification procedure. Requester: Patient, representative, provider, or other party. Requested material: Record categories and date range, including images if requested. Recipient: Person or organization and exact destination. Delivery: Requested format and method; any agreed alternative. Routing: Request type, responsible reviewer, and due date. Status: Received, clarification needed, preparing, sent, or unresolved.
These are workflow fields, not a demand that every requester complete every box. For example, the patient may simply want their entire record. Avoid forcing a narrower date range or requiring a reason for their own access request.
Record an upcoming appointment date if volunteered so the team can prioritize communication. Do not promise delivery before you know what is needed, and do not treat a routine scheduling note as the formal request record.
Check an authorization only when that pathway applies
Use the approved authorization template and review its scope, validity, expiration, and revocation status. Check that it identifies the information, authorized discloser, recipient, purpose as applicable, and required signing information. The privacy official should maintain the template's required rights statements and any special provisions.
A general “I consent” statement may not supply a valid authorization. HHS explains that authorization has specific required elements and serves a different function from voluntary consent. HHS: Consent and authorization
If an outside party's request is broader than the authorization, do not expand it yourself. Identify the mismatch and obtain the review or clarification needed. If representative authority is unclear or contested, keep the request visible while the qualified reviewer resolves it.
For the patient's own access, avoid attaching an unrelated disclosure authorization, marketing permission, or liability waiver to the process.
Track time, format, and charges separately
For HIPAA individual access, the practice generally must act within 30 calendar days of receipt. One extension of up to 30 additional days is permitted when its conditions are met, including timely written reasons and a completion date. State law may provide greater access rights.
Electronic records must be provided in a requested electronic format when readily producible, or an agreed readable alternative. Applicable fees are limited and require advance notice. Unpaid treatment bills do not justify denying the patient access. HHS's access FAQs address these timing, format, fee, and unpaid-balance rules. HHS right-of-access FAQs
Have the privacy owner set the actual due date under applicable rules. Set an earlier internal checkpoint so an archive problem or missing vendor response does not first appear on the deadline. Sending work to a records vendor is not completion.
Keep the billing account separate from the release status. If a permitted copying fee applies, record its approved calculation and notice; do not substitute the patient's treatment balance for that fee.
Verify the package before sending
Use a final comparison between the request and the prepared package:
- Is this the correct patient, with no material from another chart?
- Does the package contain the requested categories and dates?
- Were images or attachments missed because they live in a separate system?
- Can the files be opened in the agreed format?
- Does the destination match the verified request exactly?
- Has an unresolved authority or restriction question been reviewed?
A second check of the recipient is particularly useful for fax numbers, email addresses, and similar organization names. Keep the transmission method within the practice's approved procedures while honoring applicable patient access and delivery rights. Escalate an unusual delivery request instead of automatically refusing it.
Preserve the original chart. A request for records does not authorize editing it. If the patient also disputes an entry, create a linked record-correction request and maintain separate statuses.
Close on delivery evidence, not an attempted send
Record what was released, to whom, how, when, and by whom. Save the relevant transmission result or receipt under the records policy. A failed upload, bounced email, or incomplete fax remains open; contact the requester through the approved channel to resolve the problem.
For example, a patient requests their notes and images for themselves. Staff prepare the notes, but the imaging export fails. “Records emailed” would hide an incomplete request. Record notes delivered, images pending, the assigned owner, and the next update date.
Refer any proposed denial to the privacy official for the applicable legal basis, response, and review requirements. Front desk staff should not invent a refusal because a request is inconvenient. Include this workflow in the office HIPAA review and check whether completed cases show both a correct release and a clear final outcome.



