{"@context":"https://schema.org","@type":"Article","headline":"Part 2 intermediary 30-day response deadline","description":"Learn the Part 2 requirement that an intermediary answer a valid written disclosure-list request within 30 or fewer days after receipt, with clock controls.","url":"https://finnihealth.com/resources/glossary/part-2-intermediary-30-day-response-deadline","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 intermediary 30-day response deadline","item":"https://finnihealth.com/resources/glossary/part-2-intermediary-30-day-response-deadline"}]}}
Glossary term

Part 2 intermediary 30-day response deadline

Learn the Part 2 requirement that an intermediary answer a valid written disclosure-list request within 30 or fewer days after receipt, with clock controls.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

30 days for Part 2 disclosure list intermediary request response clock

The Part 2 intermediary response deadline is 30 or fewer days after receipt of the patient's written request. The intermediary should timestamp receipt, verify request and consent scope promptly, assign an owner, calculate the due date, search the full three-year window, review required fields, deliver securely, and document completion. Internal clarification should not silently restart the regulatory clock.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.24(b)(1) requires the intermediary to respond in 30 or fewer days after receiving the patient's written request. The provision does not state a routine extension. Identity and consent verification, source retrieval, field review, and secure delivery therefore need to fit inside a controlled clock that starts at receipt.

Receipt starts the clock

Current 42 CFR 2.24(b)(1) requires response in 30 or fewer days. Define received status across mail, portal, email, fax, hand delivery, and misrouted queues; record timestamp, calendar rule, due date, owner, escalation, and completion event.

Run verification and search in parallel

Verify identity and the matching general-designation consent while preserving the original receipt date. Start source discovery, legacy retrieval, recipient normalization, duplicate handling, field validation, and delivery planning early.

Measure the mature cohort

Use § 2.31 to validate the designation. On-time response rate equals requests answered by the applicable deadline divided by valid written requests whose deadline fell in the period. Keep late and open requests in the denominator.

Define receipt across every channel

List approved and reasonably expected channels, including mail, portal, email, fax, hand delivery, secure message, branch office, and vendor intake. Time-stamp the earliest receipt by the organization or route that policy treats as the intermediary's receipt. Preserve envelope, header, upload, routing, and handoff evidence.

Train staff to forward misdirected requests immediately. A request sitting in an unmonitored inbox or general records queue can consume the period even though the privacy team has not opened it. Set alerts for failed routing and weekends or holidays.

Calculate and protect the due date

Record receipt date and time, time zone, calendar convention, due date, owner, backup, milestones, and escalation dates. Counsel should approve how the organization handles date-only requests, nonbusiness days, and other boundary questions. Use an earlier internal target so review and delivery failure do not push completion past day 30.

Identity, authority, and general-designation consent still must be verified. Ask focused questions quickly and preserve the original clock unless a qualified interpretation supports different treatment. Do not use routine clarification as an invisible reset.

Run workstreams in parallel

While intake validates the requester and consent, records teams can identify source systems and preserve the relevant three-year logs. Data owners can normalize recipients, dates, payload descriptions, corrections, retries, and duplicates. Delivery staff can confirm accessible format, address, and secure channel.

Use daily or risk-based monitoring for approaching deadlines, missing system owners, vendor delays, unresolved consent matches, source gaps, review backlog, and failed delivery. Escalate to privacy leadership and counsel before the response becomes late.

Define a complete response event

“Respond” should be tied to an approved, reproducible completion event. Record the final list, reviewer, delivery timestamp, recipient identity and destination, method, transmission result, receipt or availability evidence, and any safe patient communication. Preparing a file or assigning a ticket does not establish delivery.

If no in-scope disclosures occurred, provide a reviewed response that accurately explains the result without overstating what was searched. If delivery fails, protect the list, contact the patient through an approved route, retry promptly, and document whether the original deadline was met.

Measure the mature denominator

For a reporting period, include valid written requests whose due dates fell in that period. Count a request on time only when the approved response event occurred by its deadline. Keep late responses and still-open requests in the denominator; report withdrawn, duplicate, invalid, and disputed requests separately with defined reasons.

Review oldest open items, days to completion, failure reasons, source and vendor delays, corrected responses, delivery failures, complaints, and repeat errors. Fix intake, routing, staffing, integrations, retention, and escalation rather than merely changing the status field.

Example

Eleven valid requests have deadlines this month. Nine are securely delivered by their due dates; one is late and one remains open. On-time completion is 9 of 11 requests.

Thirty-day-response checklist

  • capture the earliest receipt and preserve evidence across every request channel;
  • calculate due date, milestones, owner, backup, and escalation using an approved method;
  • verify identity and consent while searching and reconciling sources in parallel;
  • monitor legacy retrieval, vendors, field review, accessible format, and delivery risks;
  • define completion as an approved response delivered through the verified channel; and
  • report all matured valid requests, including late and open work, with correction plans.

The 30-day requirement is an end-to-end service clock. Internal handoffs and ticket states do not change what the patient experiences.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni