The Part 2 intermediary response deadline is 30 or fewer days after receipt of the patient's written request. The intermediary should timestamp receipt, verify request and consent scope promptly, assign an owner, calculate the due date, search the full three-year window, review required fields, deliver securely, and document completion. Internal clarification should not silently restart the regulatory clock.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.24(b)(1) requires the intermediary to respond in 30 or fewer days after receiving the patient's written request. The provision does not state a routine extension. Identity and consent verification, source retrieval, field review, and secure delivery therefore need to fit inside a controlled clock that starts at receipt.
Receipt starts the clock
Current 42 CFR 2.24(b)(1) requires response in 30 or fewer days. Define received status across mail, portal, email, fax, hand delivery, and misrouted queues; record timestamp, calendar rule, due date, owner, escalation, and completion event.
Run verification and search in parallel
Verify identity and the matching general-designation consent while preserving the original receipt date. Start source discovery, legacy retrieval, recipient normalization, duplicate handling, field validation, and delivery planning early.
Measure the mature cohort
Use § 2.31 to validate the designation. On-time response rate equals requests answered by the applicable deadline divided by valid written requests whose deadline fell in the period. Keep late and open requests in the denominator.
Define receipt across every channel
List approved and reasonably expected channels, including mail, portal, email, fax, hand delivery, secure message, branch office, and vendor intake. Time-stamp the earliest receipt by the organization or route that policy treats as the intermediary's receipt. Preserve envelope, header, upload, routing, and handoff evidence.
Train staff to forward misdirected requests immediately. A request sitting in an unmonitored inbox or general records queue can consume the period even though the privacy team has not opened it. Set alerts for failed routing and weekends or holidays.
Calculate and protect the due date
Record receipt date and time, time zone, calendar convention, due date, owner, backup, milestones, and escalation dates. Counsel should approve how the organization handles date-only requests, nonbusiness days, and other boundary questions. Use an earlier internal target so review and delivery failure do not push completion past day 30.
Identity, authority, and general-designation consent still must be verified. Ask focused questions quickly and preserve the original clock unless a qualified interpretation supports different treatment. Do not use routine clarification as an invisible reset.
Run workstreams in parallel
While intake validates the requester and consent, records teams can identify source systems and preserve the relevant three-year logs. Data owners can normalize recipients, dates, payload descriptions, corrections, retries, and duplicates. Delivery staff can confirm accessible format, address, and secure channel.
Use daily or risk-based monitoring for approaching deadlines, missing system owners, vendor delays, unresolved consent matches, source gaps, review backlog, and failed delivery. Escalate to privacy leadership and counsel before the response becomes late.
Define a complete response event
“Respond” should be tied to an approved, reproducible completion event. Record the final list, reviewer, delivery timestamp, recipient identity and destination, method, transmission result, receipt or availability evidence, and any safe patient communication. Preparing a file or assigning a ticket does not establish delivery.
If no in-scope disclosures occurred, provide a reviewed response that accurately explains the result without overstating what was searched. If delivery fails, protect the list, contact the patient through an approved route, retry promptly, and document whether the original deadline was met.
Measure the mature denominator
For a reporting period, include valid written requests whose due dates fell in that period. Count a request on time only when the approved response event occurred by its deadline. Keep late responses and still-open requests in the denominator; report withdrawn, duplicate, invalid, and disputed requests separately with defined reasons.
Review oldest open items, days to completion, failure reasons, source and vendor delays, corrected responses, delivery failures, complaints, and repeat errors. Fix intake, routing, staffing, integrations, retention, and escalation rather than merely changing the status field.
Example
Eleven valid requests have deadlines this month. Nine are securely delivered by their due dates; one is late and one remains open. On-time completion is 9 of 11 requests.
Thirty-day-response checklist
- capture the earliest receipt and preserve evidence across every request channel;
- calculate due date, milestones, owner, backup, and escalation using an approved method;
- verify identity and consent while searching and reconciling sources in parallel;
- monitor legacy retrieval, vendors, field review, accessible format, and delivery risks;
- define completion as an approved response delivered through the verified channel; and
- report all matured valid requests, including late and open work, with correction plans.
The 30-day requirement is an end-to-end service clock. Internal handoffs and ticket states do not change what the patient experiences.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni