| name | hipaa-records-request |
| description | Draft a HIPAA records request, itemized billing request, or follow-up / second-request email to a Skilled Nursing Facility or its corporate entity. Style is direct, specific, and deadline-driven rather than hostile — it confirms the requester's legal authority, enumerates exactly what is requested, cites the HIPAA 30-day access right (45 CFR 164.524) and 42 CFR 483.21(c) where discharge planning is at issue, sets a firm response date, and names the regulatory escalation path without threatening litigation. The escalation agencies it names are Ohio's; users in other states must substitute their own state survey agency, insurance regulator, and attorney general before sending. Use when the user says "draft a records request", "follow up on the records request", "second-request email to [facility]", "send a HIPAA letter", needs to escalate unanswered records requests, or wants a narrow supplement based on snf-document-map / snf-review missing-document findings. |
HIPAA Records Request
Draft a records / billing request email (or follow-up) in the user's voice. The user is usually acting as Medical and/or Financial Power of Attorney or another authorized representative and wants requests that are legally grounded, specific, and time-bounded — not hostile.
Inputs to collect
- Recipient — name, title, email, organization. If
case-context/case_profile.md exists, use it as the source of known facility/corporate contacts, but still confirm which entity should receive the current request.
- Request type — one of:
- First request (initial HIPAA records request)
- First request + itemized billing
- Second request / follow-up (prior request went unanswered — references the prior date and deadline)
- Escalation (prior second request unanswered — names specific agencies being notified next)
- Narrow supplement (missing specific documents identified during review, e.g., MDS Section Q, signed Medicaid application, physician certifications for a specific date range)
- OCR/readability remediation request (production appears incomplete or unusable because pages are image-only, illegible, corrupted, encrypted, or OCR-light)
- Deadline — firm business date for response. Default: 4 business days out.
- Specific items to request — let the user dictate; if unspecified for a first request, include the standard set (see below).
- Case/claim references — payer/plan case number, QIO case number, authorization numbers, anything that establishes the user's relationship to open payer disputes.
- Document-map or gaps source — for narrow supplements, read
document_map.md, document_map.json, <prefix>_Gaps.md, and/or case-context/open_questions.md if provided. Use only source-backed missing/indeterminate items.
Standard request items (first-request default set)
- Complete medical record from admission to present — physician orders, nursing notes, therapy (PT/OT/ST) notes and progress summaries, MDS assessments including Section Q, care plans, MAR/eMAR, TAR, vital signs/flow sheets, incident/accident reports, any peer review or utilization review correspondence with the payer.
- Fully itemized statement of charges — by date of service, revenue code or CPT/HCPCS, unit charge, payer adjudication status.
- Signed documents — admission agreement (all exhibits), arbitration agreement (if any), HIPAA authorizations, ROI, Medicaid application with signature page(s), financial POA paperwork, advance directives / code status forms.
- Confirmation of amounts the facility or corporate entity contends are owed personally, with calculation methodology and contractual/regulatory basis.
Narrow supplement from document-map / review gaps
When the request is based on /snf-document-map or /snf-review, split items into two groups before drafting:
- Missing / not found in text-readable material — request these as omitted records.
- OCR-indeterminate / unusable production — request cleaner copies or OCR-readable replacements; do not accuse the facility of omitting them unless the map/review supports that distinction.
Use the exact labels from the map where possible (MAR/eMAR, TAR, Vitals / Flow Sheets / Pulse Ox, MDS Section Q, Discharge Planning / Summary, Medicaid / PASSPORT, Billing / Itemized Charges / Invoices, etc.) and cite the review source generically: "our document-map review of the production identified the following missing or unreadable categories." Do not paste PHI-heavy snippets into the email unless necessary.
For OCR/readability remediation, ask for:
- Searchable/OCR-readable PDFs or native EMR export where available.
- Replacement pages for specific unreadable ranges, using
<source PDF> pp.<start>-<end>.
- Confirmation whether the unreadable pages are the facility's complete production or an export/scanning defect.
- A written index identifying which exported file contains each requested category.
Tone and structure (match existing user emails)
Use the user's established format:
**To:** <email>
**From:** {{POA_NAME}} ({{POA_ROLE}} for {{RESIDENT_NAME}}, DOB {{RESIDENT_DOB}})
**Date:** <full date>
**Subject:** <Request Type>, <Patient>, Response Required by <deadline>
Dear <Salutation>,
Body conventions:
- Open by identifying the request and prior context (if follow-up, state the exact prior date and whether the prior request was acknowledged).
- Invoke authority: "in my capacity as the duly appointed Medical and Financial Power of Attorney … documentation of that authority is on file and available again on request."
- Enumerate requested items as a numbered list.
- For narrow supplements, include a short table or numbered list separating
Not produced / not located from Unreadable or OCR-indeterminate items.
- Call out the business-office collection dynamic if payment is being sought concurrently with unanswered records (verbatim template: "I am not refusing to pay amounts that are actually owed. I am declining to remit payment on charges I have been given no opportunity to verify.").
- Cite the deadline in bold. Reference HIPAA 30-day access rule and, for discharge planning / records issues, 42 CFR 483.21(c).
- Escalation paragraph (for second requests or harder): name the agencies. Ask the resident's state first. For Ohio: Ohio Department of Health (Bureau of Long-Term Care Quality), Ohio Attorney General's Health Care Fraud Section, Ohio Department of Insurance, CMS. For any other state, do not substitute guessed agency names — name only CMS and the Long-Term Care Ombudsman program (both federal and portable), and write
[user: insert your state's nursing-facility survey agency and insurance regulator — verify before submission] for the rest. Frame as "I would much rather resolve this directly with you."
- Close with a confirmation-of-receipt request and the correct routing for all further correspondence.
- Signature:
{{POA_NAME}} / {{POA_ROLE}} for {{RESIDENT_NAME}} / {{POA_EMAIL}}.
Optional short reply
For second-request and later, also produce a short paste-ready reply to the local business office explaining why payment is being held pending itemization. Match the user's existing business-office response template if one exists in the case workspace.
Execution
- Draft the email as a markdown file in the user's workspace named
Email_<Recipient>_<Type>_<Date>.md to match existing naming convention (e.g., Email_Admin_Records_Followup_YYYY-MM-DD.md).
- Show the full draft to the user for approval.
- After approval, if the
gmail_create_draft tool is available, offer to create a Gmail draft. Otherwise, tell the user to copy from the markdown file.
- Propose appending an
admin-interaction-log entry recording that the email was sent, with the recipient, subject, and deadline.
- If
case-context/ exists, propose adding the request and deadline to document_index.md and deadlines.md via case-context-ledger.
Guardrails
- This drafts correspondence for user review; it is not legal advice or medical advice.
- Do not make legal claims the user hasn't authorized (e.g., don't threaten litigation). The established escalation path is regulatory/administrative, not tort.
- Do not soften the deadline or the enumerated items without the user's say-so.
- PHI: include the patient's name and DOB in the subject/body as needed for facility identification; do not include SSN or member ID unless the user explicitly adds them.
- Ohio-specific statutory citations are acceptable but flag any citation the user should verify (e.g., "confirm current Ohio Revised Code section").