HIPAA Compliance and Other Privacy Rules: What Southeast Michigan Medical Professionals Need to Know

Szura & Delonis, PLC

If you practice medicine in Southeast Michigan — whether in Detroit, Ann Arbor, Dearborn, Royal Oak, or anywhere across Wayne, Oakland, Macomb, or Washtenaw County — you already know that patient privacy isn’t just good practice. It’s federal law, backed by state statutes, and enforced with real financial and professional consequences.

Yet HIPAA compliance remains one of the most misunderstood areas of healthcare regulation. Physicians, practice administrators, and healthcare staff routinely ask the same questions: How do I properly respond to a medical records request? What counts as a reportable breach? Am I personally liable if my practice gets it wrong?

This post breaks down what HIPAA actually requires, how it interacts with Michigan-specific privacy rules, and where medical professionals most often run into trouble.

What HIPAA Actually Covers

The Health Insurance Portability and Accountability Act (HIPAA) sets the federal floor for protecting patient health information. Two rules matter most for day-to-day practice:

  • The Privacy Rule governs how protected health information (PHI) can be used and disclosed, and gives patients’ rights over their own records.
  • The Security Rule sets standards for safeguarding electronic PHI (ePHI) — think encryption, access controls, and audit logs.

A third piece, the Breach Notification Rule, requires covered entities to notify patients, the Department of Health and Human Services (HHS), and in some cases the media, when unsecured PHI is compromised.

If you’re a physician, dentist, therapist, hospital, clinic, or any business associate handling PHI on behalf of one, HIPAA almost certainly applies to you.

Michigan Privacy Law in Addition to HIPAA

HIPAA is a floor, not a ceiling. Michigan law generally adds additional obligations that Southeast Michigan providers can’t ignore:

  • Michigan’s Medical Records Access Act (MRAA) governs how quickly and in what format providers must furnish records to patients, and what they can charge for copies.
  • The Michigan Mental Health Code imposes stricter confidentiality standards for mental health and substance use treatment records than HIPAA alone requires.
  • Michigan’s Identity Theft Protection Act creates its own breach notification triggers and timelines, which can run alongside — not instead of — HIPAA’s federal requirements.

Where state law is more protective of patients than HIPAA, the stricter standard generally controls. Practices that comply with HIPAA alone, without checking Michigan-specific statutes, are often still out of compliance.

Responding to Medical Records Requests: Where Practices Get Tripped Up

Medical records requests are one of the most common — and most commonly mishandled — compliance touchpoints. A few recurring issues:

Missing the response deadline. Under HIPAA, covered entities generally must respond to a patient’s records request within 30 days, with one 30-day extension available if the patient is notified in writing. Michigan’s MRAA has its own timing and fee rules that can be stricter. Practices that default to “whenever we get to it” are exposed.

Overcharging for copies. Both HIPAA and Michigan law limit what you can charge for records. Flat per-page fees that don’t reflect actual labor and supply costs are a frequent source of complaints — and complaints often trigger broader compliance reviews.

Disclosing more than authorized. A records request for a specific date range or specific provider doesn’t authorize releasing the entire chart. Over-disclosure is a potential HIPAA violation even when the requester is the patient’s own attorney or insurer, if the authorization doesn’t cover the full scope released.

Third-party requests without proper authorization. Attorneys, family members, employers, and insurance companies frequently request records. Without a valid, specific HIPAA authorization — or an applicable exception — releasing records to these parties can constitute an impermissible disclosure.

Subpoenas versus authorizations. A subpoena alone is often not sufficient authority to release PHI under HIPAA. Providers served with subpoenas should understand the difference between a subpoena, a court order, and a qualified protective order before producing records.

Breach Notification: Know Your Triggers

Not every privacy incident is a reportable breach, but many providers either over-report out of caution or under-report out of uncertainty — both create problems. A breach analysis generally asks:

  1. Was PHI actually acquired, accessed, used, or disclosed in violation of the Privacy Rule?
  2. Does a recognized exception apply (e.g., good-faith unintentional access by an employee, acting within scope)?
  3. Based on a documented risk assessment, is there a low probability the information was compromised?

If the answer to the risk assessment favors the patient, notification obligations follow — to the individual, and depending on scale, to HHS and potentially local media. Michigan’s breach notification statute may impose additional or overlapping requirements. Documentation of the risk assessment itself is critical; regulators scrutinize the analysis, not just the outcome.

Penalties: What’s Actually at Stake

HIPAA violations carry tiered civil penalties based on the level of culpability, ranging from a few hundred dollars per violation for unknowing violations to well over $1 million per year for uncorrected willful neglect. Beyond fines:

  • Corrective action plans and years of OCR monitoring
  • State licensing board referrals
  • Civil liability exposure through related state-law claims
  • Reputational harm that follows a practice long after the fine is paid

For an individual physician or a small Southeast Michigan practice, even a mid-tier penalty combined with legal fees and lost patient trust can be existential.

Business Associate Agreements Should Not Be Optional

Every vendor that touches PHI on your behalf — billing companies, IT support, cloud storage providers, transcription services, even some consultants — should have a signed Business Associate Agreement (BAA). Practices that skip this step, or that use outdated boilerplate BAAs, may remain liable when their vendor mishandles data. Reviewing BAAs should be a standing item in any compliance audit, not a one-time formality from when the practice opened.

Practical Compliance Steps for Southeast Michigan Practices

  • Conduct an annual HIPAA risk assessment and document it
  • Train staff on records-request procedures and PHI disclosure limits at onboarding and annually thereafter
  • Maintain a written breach response protocol with clear roles and timelines
  • Audit current Business Associate Agreements for gaps
  • Confirm records-request fee schedules comply with both HIPAA and Michigan’s MRAA
  • Designate a privacy officer, even in small practices, to field records requests and potential breach issues consistently

When to Talk to a Healthcare Law Attorney

Not every compliance question needs a lawyer, but certain situations warrant one before you act, not after:

  • You’ve received a subpoena or third-party request for records and aren’t sure what you’re authorized to disclose
  • You suspect a breach has occurred and need help with the risk assessment or notification timeline
  • OCR or the Michigan Attorney General’s office has contacted your practice
  • You’re negotiating or drafting Business Associate Agreements
  • An employee has raised a compliance concern internally and you want to handle it correctly from the start

Southeast Michigan providers face the same federal scrutiny as anyone else in the country, layered with Michigan-specific statutes that out-of-state guidance often misses. A quick consult before responding to a records request or reporting a breach is almost always cheaper than untangling a mistake afterward.

Frequently Asked Questions

How long do I have to respond to a patient’s medical records request in Michigan? Generally, 30 days under HIPAA, with a possible 30-day extension if you notify the patient in writing. Michigan’s Medical Records Access Act imposes its own timing and fee requirements that can be more restrictive — check both before responding.

Can I charge whatever I want for copies of medical records? No. Both HIPAA and Michigan law limit fees to reasonable, cost-based amounts. Flat, high per-page charges are a common source of complaints.

Do I have to report every unauthorized access to PHI as a breach? Not necessarily. A documented risk assessment determines whether an incident meets the breach threshold or falls under a recognized exception. The key is documenting that analysis, not just reaching a conclusion.

What should I do if I receive a subpoena for a patient’s records? Don’t assume a subpoena alone authorizes disclosure. Confirm whether it’s accompanied by a valid authorization, court order, or qualified protective order before producing records — and when in doubt, get legal guidance first.


This post is intended for general informational purposes and does not constitute legal advice. Every provider’s compliance obligations depend on the specific facts. If you have questions about a records request, a potential breach, or a compliance concern involving your Southeast Michigan practice, consult a healthcare law attorney before taking action.

Client Reviews

Rick Delonis was outstanding for me in a business matter. Only providing professional information and execution. He was always there to answer anything I needed.

Brian Klanow

This firm has been handling my legal work for nearly 10 years. They have excelled when it comes to reviewing my business contracts, handling articles of incorporation for my entities and, most importantly...

Dan

These guys are the best. They really took care of me when I needed them the most. Very honest and truly care about their clients. I would highly recommend Rick Delonis and the other partners at this law firm to...

John

Being a landlord sometimes is not all it's cracked up to be. Being new to the game mistakes will be made and can be very costly if not handled correctly. After initial negotiations failed our case went to trial...

Francis

Address

Southfield Office
29777 Telegraph Rd
#2401

Southfield, MI 48034

Office

Contact Us

Fill out the form or call us at (248) 716-3600 to reach us.

We Accept the Following Payment Solutions

Payment Methods