{"@context":"https://schema.org","@type":"Article","headline":"Third-party access direction","description":"Learn how Ciox limits the HIPAA third-party directive to electronic PHI in an EHR and why fees and alternate disclosure routes remain separate.","url":"https://finnihealth.com/resources/glossary/third-party-access-direction","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Third-party access direction","item":"https://finnihealth.com/resources/glossary/third-party-access-direction"}]}}
Glossary term

Third-party access direction

Learn how Ciox limits the HIPAA third-party directive to electronic PHI in an EHR and why fees and alternate disclosure routes remain separate.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

direct PHI transmission request send records to third party

A third-party access direction is an individual's signed written request for a covered entity to transmit an electronic copy of PHI in an electronic health record directly to a designated person or entity. The request identifies the recipient and destination. A 2020 federal court order limits this mandatory HIPAA pathway; broader record transfers need another valid route or voluntary agreement.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

The Ciox order limits the mandatory route

HHS's notice about the Ciox order says the court vacated the third-party directive where it extended beyond an electronic copy of PHI in an electronic health record transmitted in electronic form. HHS also says the HIPAA access fee limit applies to a person's request for their own records and does not apply to a request to transmit records to a third party. Treat contrary language that remains visible in 45 CFR 164.524 or older guidance in light of the court order.

The request still needs precise fields

For the mandatory electronic-EHR route, record the individual, signature, designated recipient, destination, PHI scope, date range, electronic format, received date, identity verification, and delivery evidence. Confirm that the requested information is in an EHR and can be supplied electronically. A portal label or scanned paper file does not establish those facts.

Read the request as an instruction, not as permission to choose a convenient recipient or expand the scope. Resolve an ambiguous email address, organization name, or date range with the individual before sending. Use the covered entity's reasonable identity-verification process without creating unnecessary barriers. When the individual chooses an unencrypted channel after being informed of the relevant risk, document that choice and follow the entity's approved workflow.

Confirm the output before transmission. The case record should reconcile requested categories to produced files, test whether files open, and preserve the exact destination used. A successful server response shows that a transmission occurred; it does not establish that the designated recipient obtained a complete and readable copy.

Broader transfers use another pathway

Other records may move through the individual's own access request, a valid HIPAA authorization, a permitted treatment disclosure, another applicable permission, or a voluntary process the covered entity offers. HHS access guidance remains effective only to the extent consistent with Ciox. Classify the route before applying its form, fee, timing, denial, and security rules. State law may create broader access rights or tighter deadlines.

Route classification changes the operational rules. A person may ask for a copy for personal use and later forward it. A provider may request PHI for treatment under a permitted disclosure. A lawyer, insurer, or application may receive records under an authorization or another valid mechanism. Staff should explain the available choices without steering the person toward a route solely because it is easier for the practice.

The individual-access fee limitation applies when the individual asks for copies for themselves. According to HHS's Ciox notice, that limitation is unavailable for the direct third-party transmission. Any fee still needs a lawful basis under the applicable route, applicable state law, and the entity's disclosed policy. Keep the fee calculation with the route decision.

Example with destination checks

A practice receives eight fictional transfer requests. Three request electronic EHR copies sent electronically and contain every direction element. Two are requests for copies sent to the individuals themselves. Two include authorizations initiated for third-party disclosures. One lacks a recipient destination. Route classification is 7 of 8 requests; readiness is measured again within each route.

For the three electronic-EHR directions, suppose two deliveries reconcile to the requested file counts and one secure message omits an attachment. Direction-form completeness is 3 of 3, while verified delivery completeness is 2 of 3. The omitted attachment remains an open fulfillment issue even though the request form and destination were valid.

Third-party direction checklist

  • Identify whether the request fits the Ciox-limited electronic-EHR pathway.
  • Capture the individual's signature, PHI scope, recipient, and clear destination.
  • Verify identity and authority under the entity's reasonable process.
  • Confirm the information is maintained in an EHR and can be sent electronically.
  • Apply the form, timing, fee, denial, and security rules for the classified route.
  • Reconcile the production to the requested categories and date range.
  • Test file readability and transmit only to the designated destination.
  • Retain the request, route decision, fee basis, production, and delivery evidence.

Owner controls

Separate the electronic-EHR direction, individual access request, and authorization templates. Preserve the original request, route decision, fee basis, recipient verification, transmission evidence, and correction history. A successful send does not prove the destination was correct or every file was readable.

Audit requests moved between routes, because handoffs can reset ownership or create conflicting fee decisions. Track missing destination fields, clarification time, misdirected transmissions, failed delivery, unreadable files, and rework. Review forms and training whenever HHS guidance, court orders, or state access rules change.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni