Part 2 of 2: Seven years after OCR’s first HIPAA Right of Access enforcement action, case #55 shows why timely access to medical records remains a compliance issue for healthcare providers.
A patient waited nearly two years for her medical records. Now Azul Vision will pay $50,000 and spend two years under a corrective action plan.
OCR Director Paula M. Stannard has made the agency’s position clear: OCR should not have to investigate a covered entity for a patient to receive their requested medical records.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its 55th HIPAA Right of Access enforcement action, reaching a $50,000 settlement with Azul Vision, Inc.
The August 27, 2026 settlement involved a potential violation of the HIPAA Privacy Rule after a patient waited nearly two years to receive requested health information.
According to OCR, the patient requested access to her protected health information (PHI) in January 2023. After she did not receive the requested records, a complaint was filed with OCR in April 2023. The patient ultimately received access to her records in January 2025, almost two years later and only after OCR had started its investigation.
OCR determined that Azul Vision potentially failed to take timely action as required by HIPAA’s Right of Access standard.
The case reinforces a simple compliance lesson: organizations need to know when an access request arrives, who is responsible for it, and how long it has been open.
The HIPAA Privacy Rule generally requires covered entities to act on an individual’s request for access to PHI within 30 calendar days. When an organization cannot complete the request, HIPAA permits one additional 30-day extension which requires written notice of the delay be sent to the individual.
A request that sits unanswered for months can expose an organization to regulatory action.
$50,000 Settlement and Two Years of Monitoring
Under the resolution agreement, Azul Vision agreed to:
The payment is only one consequence. Regulatory monitoring, policy revisions, workforce training, and ongoing reporting create additional costs and demands on an organization.
You don’t need to be a large hospital system to have a Right of Access problem. A request can come into your practice, be passed to another employee, and then get buried among emails, paperwork, and everyday responsibilities.
Meanwhile, the compliance clock keeps moving.
Can your practice answer these four questions today?
If those answers aren’t readily available, it may be time to review how your practice manages access requests.
Tools such as uRISQ’s Data Subject Access Request module can help provide a structured way to manage, assign, document, and track requests through completion.
Azul Vision marks the 55th enforcement action under OCR’s HIPAA Right of Access Initiative.
The lesson is straightforward: receiving a patient records request starts a compliance process that needs to be tracked through completion.
Healthcare organizations should not depend solely on emails, spreadsheets, or individual employees remembering deadlines. A documented and repeatable process can help identify open requests, maintain accountability, and reduce the risk that a patient waits months or nearly two years for access to their health information.
After 55 Right of Access enforcement actions, healthcare providers should be asking a simple question:
Are our procedures actually working?
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |

