OCR Fines Azul Vision $50,000 for Delayed HIPAA Right of Access
- Author: Venus Caruso

- 11 minutes ago
- 7 min read
On August 27, 2026, HHS Office for Civil Rights announced a $50,000 HIPAA settlement with Azul Vision, Inc., a California optometry and ophthalmology group, for a potential violation of the HIPAA Privacy Rule’s right of access. It is OCR’s 55th Right of Access Initiative enforcement action. A patient requested her records in January 2023 and did not receive them until January 2025, nearly two years later and only after OCR opened an investigation.
The HIPAA right of access is not a courtesy. Under 45 C.F.R. § 164.524, a covered entity must act on a request for protected health information within 30 calendar days, with one written 30-day extension. One unanswered request can produce a complaint, an investigation, a resolution payment, and two years of federal monitoring.
Azul Vision HIPAA Settlement: What OCR Found
Azul Vision operates optometry and ophthalmology services across 31 clinics in California. According to the published facts:
The individual requested access to her PHI on January 9, 2023.
The OCR received a complaint on April 27, 2023, alleging Azul Vision had not provided timely access.
The records were not produced until January 6, 2025, after the OCR had already opened the investigation.
The OCR determined that Azul Vision potentially failed to act timely under 45 C.F.R. § 164.524(b).
The resolution agreement was signed in mid-August 2026. Azul Vision paid $50,000 and accepted a two-year corrective action plan. While the agreement provides that Azul Vision does not admit liability and HHS does not concede that a civil money penalty could not be supported, that is standard settlement language. It is not a finding that a two-year delay complied with HIPAA.
HIPAA Right of Access Rules: 30 Days, One Extension
The Privacy Rule gives an individual, or that individual’s personal representative, the right to inspect or obtain a copy of PHI in a designated record set. That set typically includes medical and billing records a practice uses to make decisions about the individual.
When the 30-day HIPAA clock starts
A covered entity must act no later than 30 calendar days after receipt of the request by either granting the request and providing access or issuing a written denial. 45 C.F.R. § 164.524(b)(2) and (d).
If the practice cannot meet that deadline, it may take one additional period of no more than 30 days and only if, within the original 30 days, it sends a written statement of the reasons for the delay and the date it will finish. There is no second extension.
Format, fees, and HIPAA Business Associates
If the individual asks for an electronic copy of ePHI that is readily producible in that form and format, the practice must provide it that way.
The individual may direct the covered entity to send a copy to a third party.
Fees must be reasonable and cost-based. Allowable fees are labor for copying, supplies, postage, and an agreed summary or explanation.
The clock starts when a covered entity receives the request. Time spent forwarding the request to a billing vendor, cloud EHR, offsite storage vendor, imaging group, or another business associate of the covered entity counts against the 30 days.
A practice may require written requests only if it has informed individuals that it requires them.
Grounds for denying a request for access are limited (e.g., psychotherapy notes, information compiled for a legal proceeding, to name a couple). A legally permitted denial still must be in writing and issued within the same 30- or 60-day window.
Azul Vision Corrective Action Plan: What Two Years of OCR Monitoring Looks Like
The $50,000 resolution amount is smaller than many Security Rule and ransomware settlements. For a mid-size specialty group, the corrective action plan is the real cost. Here, for two years Azul Vision must run its right-of-access process under federal supervision.
The Corrective Action Plan (CAP) requires Azul Vision to:
Review and revise written policies on individual access, distribute them to the workforce within 60 days, obtain workforce certifications, and reassess the policies at least annually.
Train all workforce members on the HIPAA right of access and the implementing policies within 90 days; train new workforce within 30 days of start; document attendance; update training at least yearly.
Beginning 90 days after the effective date, submit regular lists of PHI access requests, including date received, date completed, format requested, format provided, number of pages (if provided in paper format), and any cost (excluding postage). If request for access was denied, in whole or in part, all denial documentation must be submitted to HHS consistent with 45 C.F.R. § 164.524(d).
Investigate workforce noncompliance with access policies and procedures, report those events to HHS within 30 days, and file annual reports attesting to policy and training compliance.
Keep all CAP documentation for six (6) years. An uncured breach of the CAP can support a civil money penalty after a 30-day cure period.
HIPAA Access Compliance Checklist
The following items are examples drawn from 45 C.F.R. § 164.524 and the Azul Vision CAP. They are not a complete list of required actions.
Assign one person who is accountable for access requests. HIPAA already requires a privacy official. That official, or a records custodian the official designates, should own the process from intake through fulfillment (i.e., receiving the request, verifying identity and authority, logging dates, meeting the 30 day deadline or issuing the one written extension, and sending the records or a written denial). Other staff may take the call or pull the chart. However, accountability should not be split among front desks, locations, or “whoever is in today.” In a multi-location group, local staff can collect the request, but one named person should be responsible for whether the practice met § 164.524. If the OCR asks who handled the delay, the answer should be a name, not a department.
Start the 30-day clock when the request is received; not when the file looks “complete.” HIPAA counts calendar days from receipt of the access request. Intake staff should log the receipt date the same day the request arrives. The Privacy Rule measures compliance from that date. A missing log does not stop the clock; it only makes the delay harder to defend. A covered entity may require requests in writing, but only if it has informed individuals of that requirement, typically in the Notice of Privacy Practices and at the point of service. If that requirement was not disclosed, a verbal request, portal message, or email should still start the clock. Waiting for a “complete” packet, a wet signature, or an internal form the patient was never told to use is how a timely request becomes a late one on paper. Identity verification should proceed in parallel as it does not reset the receipt date.
Keep a written tracking log for every access request. The log is how the practice proves the 30-day deadline, the single extension, and the final response. At a minimum it should capture the date received, name of the individual (and personal representative, if any), how identity and authority were verified, form and format requested, form and format delivered, where it was sent, fee quoted (if any), date of any written extension notice, date the practice granted access, issued a denial, or completed the production, and the staff member responsible. The tracking log should be built as an ordinary business record, not as something assembled after a complaint. The log does not start the legal clock. The receipt does. But, the log is what the practice will have to produce if the OCR asks what happened to the request.
Set an earlier internal deadline. Build a review point well before day 30, such as day 15 or day 20, so there is time to finish the production or send the one written extension HIPAA allows.
Map the designated record set before the request arrives. The right of access applies to PHI in a designated record set, including medical and billing records and other records used to make decisions about the individual. In a typical practice, that is more than a chart in an EHR. It often includes imaging, practice-management billing files, patient-completed intake forms, and records a business associate holds for the practice. If staff do not know where those records live, the 30-day clock is already running while they hunt. Identify the locations in the HIPAA policy, and require business associate agreements to support timely fulfillment. Vendor delays do not start a new deadline. Time spent forwarding the request to a business associate still counts against the covered entity’s 30 days.
Train the workforce that actually receives the request, not only the privacy official. Front desk, call center, portal administrators, and clinic managers are usually the people who take the first notice of an access request. If they do not know that the 30 days have started, the practice is already behind. General annual HIPAA training is not enough unless it covers this rule in operational terms (e.g., calendar days and not business days, one written extension, electronic copies when readily producible, third party directives, the difference between a patient’s own request and a subpoena or attorney authorization, and where to log the request). New workforce members who will handle requests should be trained before assigning them to access requests. Azul Vision’s CAP used 30 days from start. Ensure to keep workforce training attendance records.
Do not improvise details. If access will be denied in whole or in part, issue a written denial that satisfies 45 CFR 164.524(d) before the deadline runs. A template is a suitable operations tool that can be helpful to document the details required under the rule.
A repeat request is a warning, not a new clock. The OCR starts its 30-day count from the original receipt date. A second patient request or an OCR complaint letter does not restart the deadline.
If you would like to explore how Venus Caruso can assist with your HIPAA compliance needs, reach out to schedule a complimentary consultation using the contact form.
This post provides general information only. It is not, and should not be, construed as legal advice or a legal opinion on any particular matter or set of facts. Reading this post does not create an attorney-client relationship. Laws and regulations can change, and specific situations may require different approaches. Do not act or refrain from acting based solely on this post.
Always consult a qualified attorney for advice tailored to your specific circumstances.



