Skip to main content
v2026.11,610 entries · CC-BY 4.0

Direct comparison

Designated Record Set vs Legal Health Record

One is defined at 45 CFR 164.501; the other appears nowhere in HIPAA. What each governs, and what an institutional policy must state about both.

Ask about Designated Record Set vs Legal Health Record

Answers are drawn from this comparison and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

How do Designated record set, Legal health record compare side by side?

The table below compares Designated record set, Legal health record across 15 procurement-relevant dimensions, from is it defined in hipaa? through primary sources.

Side-by-side comparison

DimensionDesignated record setLegal health record
Is it defined in HIPAA?Yes, at 45 CFR 164.501. The phrase appears sixteen times across part 164.No. A direct search of the current text of 45 CFR part 164 returns zero occurrences of 'legal health record' or 'legal medical record'. It is a health information management construct, not a regulatory term.
Who defines its contentsThe regulation, by function. Three categories: the medical records and billing records about individuals maintained by or for a covered health care provider; a health plan's enrollment, payment, claims adjudication and case or medical management record systems; and anything 'used, in whole or in part, by or for the covered entity to make decisions about individuals'.The organisation, by policy. Because there is no federal definition, the contents are whatever the institution's written policy says they are - which is why the policy has to exist and has to be specific.
What 'record' meansDeliberately broad. 164.501 defines record as 'any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity'. Format and system are irrelevant.Typically narrower and more clinical, and usually defined by document type and source system rather than by function. Practice varies by institution.
Billing recordsExpressly included. 164.501(1)(i) names 'the medical records and billing records about individuals maintained by or for a covered health care provider' in the same breath.Commonly excluded, because the purpose is to define the clinical business record for evidentiary use. This is one of the most frequent points of divergence between the two definitions.
The 'decisions about individuals' catch-allThis is the clause that pulls in systems people forget: care management notes, decision-support outputs, and any other grouping actually used to make decisions about the individual, wherever it lives.No equivalent catch-all. An institutional legal health record definition that enumerates systems will simply omit anything not on the list - which is fine for its own purpose and wrong if used to answer an access request.
Right of accessThis is the operative boundary. 164.524(a)(1) gives an individual the right to inspect and obtain a copy of PHI about them 'in a designated record set', for as long as it is maintained there.Has no role in the access right. Producing the legal health record in response to a 164.524 request is under-production unless the two definitions happen to coincide.
Access timelinesThe covered entity must act on a request no later than 30 days after receipt, with one extension of no more than 30 days permitted, on written notice of the reasons and the expected completion date.Not applicable. Litigation production timelines come from court rules and subpoena response deadlines, not from HIPAA.
Right to amend164.526(a)(1) gives the individual a right to have PHI or a record amended 'in a designated record set'. Action is due within 60 days, with one 30-day extension.No amendment framework of its own. Note the interaction: one of the four permitted grounds for denying an amendment at 164.526(a)(2) is that the information 'is not part of the designated record set' - so a wrong designated record set definition directly produces wrong amendment denials.
Grounds for denying an amendmentExactly four, at 164.526(a)(2): not created by the covered entity (unless the originator is no longer available); not part of the designated record set; would not be available for inspection under 164.524; or is accurate and complete.Not a factor. But because two of the four grounds are defined by reference to the designated record set, the institution's designated record set policy is doing the work in an amendment denial whether or not anyone reads it.
Information blocking scopeNow load-bearing beyond HIPAA. 45 CFR 171.102 defines electronic health information as ePHI 'to the extent that it would be included in a designated record set as defined in 45 CFR 164.501, regardless of whether the group of records are used or maintained by or for a covered entity', excluding psychotherapy notes and information compiled in anticipation of litigation.No role. An organisation that scoped its EHI to its legal health record would be scoping information blocking obligations to the wrong set - and note that the Part 171 definition explicitly reaches beyond covered entities.
Litigation productionNot the governing concept. The designated record set defines patient rights, not what an institution asserts as its official record in court.This is its purpose. The legal health record is what the organisation designates as its official business record, produces under subpoena or court order, and is prepared to authenticate.
Excluded either wayPsychotherapy notes and 'information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding' are excluded from the right of access at 164.524(a)(1) and from EHI at 171.102 - though the second exclusion is about the access right, not about whether the material exists.Institutional policies generally exclude attorney work product, incident reports and peer review material for the same reason, often reinforced by state peer review privilege statutes that vary considerably.
What a policy must actually sayWhich systems and record types fall inside the designated record set, including systems outside the EHR; how the 'used to make decisions' test is applied; who decides when a new system is added; and how the boundary is communicated to whoever fulfils access and amendment requests.Which documentation constitutes the official business record; who authenticates it; what is excluded and on what basis; and - critically - an explicit statement that the legal health record is narrower than the designated record set and is not the boundary for patient rights.
A real institutional exampleThe University of Nebraska Medical Center maintains a policy titled 'Access and Amendment to Designated Record Set' (Policy 6059) that also states that UNMC, The Nebraska Medical Center, UMA and UDA are 'one affiliated covered entity (ACE) for purposes of HIPAA and may share PHI with one another'.The affiliated covered entity point generalises: where an academic medical centre operates as an ACE, the designated record set boundary crosses corporate entities, which is exactly the sort of thing a narrowly drafted legal health record definition will not capture.
Primary sources45 CFR 164.501 (definition), 164.524 (access), 164.526 (amendment), 45 CFR 171.102 (EHI) - all readable free on eCFR.No primary source exists, because there is no federal definition. Cite your own policy, and any state statute that defines the medical record for evidentiary or retention purposes.

Common questions

Common questions about Designated record set vs Legal health record

Are the designated record set and the legal health record the same thing?

+

No, and the difference is not merely terminological. The designated record set is defined in regulation at 45 CFR 164.501 and sets the boundary of the individual's rights of access and amendment. The legal health record is an institutional designation with no federal definition - a direct search of the current text of 45 CFR part 164 returns zero occurrences of the phrase. In most institutional policies the designated record set is the broader of the two, because it expressly includes billing records and because its third limb captures anything 'used, in whole or in part, by or for the covered entity to make decisions about individuals', wherever that information lives. The legal health record is typically the clinical subset an organisation will produce and authenticate in litigation.

What exactly does 45 CFR 164.501 define as the designated record set?

+

A group of records maintained by or for a covered entity that is either: the medical records and billing records about individuals maintained by or for a covered health care provider; the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or used, in whole or in part, by or for the covered entity to make decisions about individuals. The same section then defines 'record' extremely broadly, as 'any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity'. That breadth is deliberate: the test is functional, not system-based, so a spreadsheet used to make decisions about patients is inside the designated record set even though it is not in the EHR.

Which one governs a patient's request for their records?

+

The designated record set, without qualification. 45 CFR 164.524(a)(1) gives the individual a right to inspect and obtain a copy of protected health information about them 'in a designated record set', for as long as it is maintained there, subject to two exclusions - psychotherapy notes, and information compiled in reasonable anticipation of, or for use in, a civil, criminal or administrative proceeding. The covered entity must act within 30 days of receipt, with one permitted extension of no more than 30 days on written notice giving the reasons and the completion date. Fulfilling a 164.524 request from a legal health record definition is a common and consequential error: it produces a smaller set than the statute requires, and it does so invisibly, because the requester has no way to know what was omitted.

Why does the designated record set now matter for information blocking?

+

Because the information blocking regulations borrowed the definition. 45 CFR 171.102 defines electronic health information as electronic protected health information as defined in 45 CFR 160.103 'to the extent that it would be included in a designated record set as defined in 45 CFR 164.501, regardless of whether the group of records are used or maintained by or for a covered entity', excluding psychotherapy notes and information compiled in anticipation of litigation. Two consequences follow. An institution's designated record set boundary is now doing double duty - it scopes HIPAA rights and it scopes information blocking obligations. And the 'regardless of whether' clause deliberately extends the concept beyond covered entities, so actors who are not covered entities still have to reason about what would be in a designated record set.

How does the boundary affect amendment requests?

+

Directly, because two of the four permitted denial grounds are defined by reference to it. 45 CFR 164.526(a)(2) allows a covered entity to deny an amendment request only where the information was not created by the covered entity (unless the individual gives a reasonable basis to believe the originator is no longer available to act), is not part of the designated record set, would not be available for inspection under 164.524, or is accurate and complete. The second and third grounds both turn on the designated record set. An institution whose designated record set definition is narrower than the regulation requires will therefore issue amendment denials that are wrong on their face. Amendment decisions are due within 60 days of receipt, with one extension of up to 30 days on written notice.

What should an institutional policy actually state?

+

At minimum, six things. First, that the designated record set and the legal health record are distinct, and which one governs which process. Second, an enumeration of systems and record types inside the designated record set that goes beyond the EHR - registries, care management systems, decision-support outputs, billing systems, and any departmental system used to make decisions about individuals. Third, how the 'used to make decisions about individuals' test is applied when a new system is procured, and who makes that call. Fourth, what constitutes the legal health record, who authenticates it, and what is excluded and why. Fifth, whether the organisation operates as an affiliated covered entity, because that changes the boundary across corporate entities. Sixth, an explicit instruction that access and amendment requests are fulfilled against the designated record set, not the legal health record.

Do university and health system policies actually distinguish them?

+

Some do, and the ones that rank well in search do so because an institutional policy document is genuinely the right format for this question - there is no single federal answer to copy. The University of Nebraska Medical Center, for example, maintains a policy titled 'Access and Amendment to Designated Record Set' (Policy 6059), and its guidance also records that UNMC, The Nebraska Medical Center, UMA and UDA constitute one affiliated covered entity for HIPAA purposes and may share protected health information with one another. That last point is worth generalising: in an academic medical centre the designated record set can span legally separate organisations, which is exactly the situation a narrowly system-based legal health record definition will fail to describe.

Which one do we produce in response to a subpoena?

+

The legal health record is the concept that governs what you assert as your official business record, but the legal instrument governs whether you may release anything at all and how much. Under 45 CFR 164.512(e) a court order authorises disclosure of only the protected health information expressly authorized by the order, while a subpoena with no court order requires satisfactory assurances from the requesting party before any disclosure is permitted. Minimum necessary under 164.502(b) applies to a permissive disclosure, which is the basis for producing what the instrument identifies rather than the whole record. So the sequence is: establish the legal authority first, then scope the production, then apply your legal health record definition to what you assemble and authenticate.

Is the designated record set always larger than the legal health record?

+

In practice it usually is, for two structural reasons - it expressly includes billing records, and its third limb sweeps in anything used to make decisions about individuals regardless of which system holds it. But this is a pattern in how institutions draft, not a rule of law, and there is no federal requirement that the legal health record be a subset. What is fixed is the direction of the risk: because patient access and amendment rights are measured against the designated record set, defining that set too narrowly creates statutory exposure, whereas defining the legal health record too narrowly creates evidentiary and litigation exposure. They are different failure modes with different owners, which is another reason the policy should name both explicitly rather than treating them as one concept with two names.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.