Patient access to medical information is a legal right. Fulfilling that right can be considerably more complicated. In this blog, BridgeHead’s Vice President of Global Marketing, John McCann, looks at the operational challenges facing health information teams trying to locate complete patient records scattered across healthcare organisations – and explores how a more coherent approach to data management can make the process faster, easier and less risky.
Why Subject Access Requests and Release of Information are the bane of every health information manager’s life – and how to break the cycle
Somewhere in your organisation right now, a clock is ticking. It started the moment a patient asked a simple, entirely reasonable question: please can you provide me with my medical records?
In the UK and Ireland, organisations have one month to respond. In the US, it is 30 calendar days. Across Canada, around 30 days is a common starting point (although the precise deadline depends on the province and circumstances).
The request lands. You may hear an audible reaction from the office of the health information manager, along the lines of, “Oh no, not another one!” – or perhaps such commentary is reserved for the inner voice. But, trust me, it’s there.
For those tasked with fulfilling the request, it puts a stopwatch on yet another item competing for attention on an already full to-do list. For those ultimately accountable for information governance, privacy or compliance, it also creates a live regulatory obligation.
Either way, the countdown has begun. And it rarely stops just because nobody is entirely sure where all the information is.
SARs, ROIs and patient access: different terminology, similar problem
Requests for patient information are called different things depending on where your healthcare organisation is based.
In the UK and Ireland, patients can exercise their right of access through a Subject Access Request (SAR) under data protection law. In the US, Release of Information (ROI) describes the broader health information management function, while HIPAA’s individual Right of Access is the closer legal equivalent for patients requesting their own information. Canada has no single national term or rulebook for patient access, with rights and response requirements largely governed through provincial legislation.
The legal details differ, but the operational expectation is remarkably similar: find the information the patient is entitled to receive and provide it within a relatively short statutory window.
That sounds perfectly reasonable if you imagine a hospital as having one highly organised database containing everything ever recorded about a patient. It’s a rather less reasonable proposition if you’ve ever actually tried to assemble somebody’s full medical history.
The patient record is rarely in one place
Healthcare organisations hold patient information across an extraordinary collection of sources and systems. There’s the electronic health record – EHR, EPR or EMR depending on where you live – alongside PACS and RIS for imaging, laboratory systems, document management platforms, departmental applications and an often remarkable collection of legacy systems that nobody particularly wants but nobody can switch off because the information inside them still matters. Then there’s paper. That might be sitting in a department, occupying shelves somewhere in the hospital basement or residing peacefully in a warehouse several miles away, blissfully unaware that a statutory clock is ticking.
You might reasonably bring a degree of scepticism to this point given that I represent a healthcare data management software vendor. But this is not a problem invented to sell software – quite the opposite. It is a challenge healthcare organisations keep putting in front of us.
For example, Diane Aldridge, Deputy Commissioner at Saskatchewan’s Office of the Information and Privacy Commissioner, specifically warns healthcare organisations that information responsive to an access request may exist in file drawers, legacy systems, EMRs and EHRs, electronic documents, images, databases, registries and back-up media. In larger organisations, searches may need to span multiple facilities, programme areas and information systems.
And that experience is echoed in our conversations with customers across North America, Ireland and the NHS. Finding the patient is often easy; finding all of the information associated with the patient is another matter altogether. No wonder access requests can send information managers into a flat spin.
None of this is anyone’s fault, exactly. It is what happens when clinical systems are implemented one procurement cycle at a time, sometimes over decades, while the underlying data strategy struggles to evolve at the same pace. But the consequence is that one perfectly reasonable patient request can trigger multiple searches across multiple systems and teams – creating more work, more hand-offs and more opportunities for something important to be overlooked.
And there can be a lot of requests
The operational burden becomes clearer when you look at the numbers.
In the UK, Mid and South Essex NHS Foundation Trust disclosed receiving 11,408 health-record access requests in a single year – more than 31 a day, weekends included. Of those, 1,622, or around 14%, exceeded its one-month guideline.
In the US, the Office for Civil Rights’ 2024 Report to Congress shows that Right of Access remains one of the most frequently raised HIPAA issues. Among 28,228 complaints resolved during the year, Right of Access was the second most frequently alleged issue, appearing in 541 complaints. While those were allegations rather than proven violations, the figure still shows how prominently patient access continues to feature in regulatory activity.
Canada provides an interesting counterpoint. Ontario’s Information and Privacy Commissioner reported 117,595 requests for access to personal health information in 2024, almost 12% more than the previous year. The IPC also reported that nearly 98% were answered within 30 days – demonstrating that high request volumes do not inevitably translate into missed deadlines. But they still represent a substantial workload – and the more readily information can be found, the easier that workload becomes to manage.
When the patient access request process breaks down
Then there’s what happens when organisations simply can’t keep up.
In December 2024, the UK Information Commissioner reprimanded United Lincolnshire Teaching Hospitals NHS Trust after the Trust reported failing to respond to 32% of SARs within the statutory timeframe during the period examined. The regulator also raised concerns about backlog management and the Trust’s ability to accurately report its performance.
The US Office for Civil Rights has also repeatedly taken action over delayed patient access. In one recent case, Memorial Healthcare System agreed to pay US$60,000 after a patient waited approximately nine months to receive requested records.
In Canada, Ontario’s Information and Privacy Commissioner can also impose administrative monetary penalties under the Personal Health Information Protection Act (PHIPA), a power introduced in 2024.
But fines and reprimands are only part of the equation. My personal view, based on conversations with customers on both sides of the Atlantic, is that the bigger impact is the staff time spent searching, chasing, escalating, clearing backlogs, responding to complaints and potentially explaining to a regulator why a seemingly straightforward request became anything but.
A patient access request is a data architecture stress test
None of this is a story about incompetence; it is a story about data strategy and architecture. A patient access request asks a deceptively simple question: can you reliably identify and retrieve the information you hold about one patient, wherever it was created and however old it is?
The law doesn’t care that your EHR and imaging systems were bought a decade apart from vendors that have never spoken to one another. It doesn’t particularly care that another record is sitting inside an application everybody stopped using in 2017. It just wants the information the patient is legally entitled to receive – complete and on time.
The law is not asking healthcare organisations to solve their data architecture issues. It simply exposes the consequences when they haven’t. In that sense, a patient access request is not the data problem. It is one of the moments when the data problem becomes measurable.
How a Clinical Data Repository can simplify patient access requests
A Clinical Data Repository doesn’t rewrite the regulation. It changes what an organisation is capable of doing inside it. BridgeHead’s HealthStore® Clinical Data Repository consolidates live and legacy patient information – including discrete clinical data, documents and medical images – into a governed, searchable repository. Where the relevant information is held within HealthStore, the fulfilment process can change dramatically.
Instead of searching separately across multiple originating systems, the health information manager can search for the patient once, select the relevant information held within the repository, retrieve or print it as required, with auditing and traceability around access and activity. For the person actually fulfilling the request, that can mean retrieval measured in minutes rather than days.
Clinical review, governance sign-off and the final decision about what should be disclosed remain exactly where they belong – with the healthcare organisation, not the software. What changes is much of the ‘hide-and-seek’ mission that comes before it. Fewer systems to search. Fewer hand-offs. And fewer opportunities to overlook something.
And for the health information manager staring at yet another request, with the statutory clock already running, the benefit is considerably less theoretical: less time hunting for the record and more time actually fulfilling the request.
There is another ROI worth mentioning
Of course, organisations may not invest in a Clinical Data Repository solely to make SAR or ROI fulfilment easier.
The same underlying data management approach can support wider strategic objectives, including longitudinal access to patient information, legacy application retirement, enterprise imaging consolidation and business continuity, while also making clinical data available for research, analytics and AI initiatives.
Though that broader return on investment matters, in this particular story, it is the supporting act. For the health information team responsible for assembling a patient’s information against a ticking clock, the immediate value proposition is refreshingly simple: finding the information becomes quicker and easier.
The takeaway
Patient access requests are not going away. Healthcare organisations cannot control when the next one arrives, how complicated the patient’s history will be or how many different applications have touched that history over the years. What they can control is how difficult it is to discover, assemble and manage the information required to answer it.
If your SAR or ROI process still begins with an email ‘round-robin’ asking multiple departments whether they have information about a particular patient, the problem might not really be the access-request process at all. It may be telling you something much more important about your underlying data strategy and architecture. And that is worth discovering before the clock starts ticking again.
If access requests still mean searching across multiple clinical systems, legacy applications, departmental stores, and paper records, we’d be interested to hear how you are tackling the challenge. If useful, we can also share how HealthStore® can help consolidate that information and simplify retrieval. You can reach me at john.mccann@bridgeheadsoftware.com or connect with me on LinkedIn.
Working in tech marketing for almost 30 years, and specifically in health tech for the last 15 years, John is passionate about the issues faced by healthcare providers and is convinced that technology, when specified and implemented correctly, can be a ‘game changer’ in the delivery of patient care.
At BridgeHead Software, John is working to disrupt the myopia around healthcare applications instead supporting the view that data (and not applications) is the strategic asset by which patient outcomes and experience can be improved.
If you would like to learn how BridgeHead’s Clinical Data Repository, HealthStore®, can help reduce the pressure on your health information management teams…



