About the job
Key Responsibilities
Intake & Tracking
- Efficiently receive, log, and track all incoming medical records requests via email, patient portal, secure fax, mail, subpoenas, court orders, and payer and Medicare requests.
- Utilize approved templates to acknowledge receipt and maintain continuous status communication.
Authorization & Legal Validation
- Verify the identity and authority of requestors to ensure compliance.
- Thoroughly validate authorizations regarding scope, purpose, expiration, and minimum necessary standards.
- Identify records requiring special protections (e.g., 42 CFR Part 2, psychotherapy notes, HIV/STD results, minor records, third-party information).
- Review subpoenas, court orders, payer audits, and Medicare documentation requests meticulously.
- Escalate legal, complex, or ambiguous requests to Privacy/Compliance and the Lead Accounting Assistant.
Clinical & Provider Clearance
- Route all proposed record disclosures to treating clinicians and psychiatric/psych prescribing providers for review and written approval before release.
- Document approvals, restrictions, redactions, or holds in the ROI log accurately.
- Place releases on hold and escalate if providers identify clinical risks or contraindications.
Record Preparation & Fulfillment
- Retrieve designated records from the EHR or document repository efficiently.
- Assemble, paginate, label, and redact records in accordance with policy and provider guidance.
- Utilize secure encryption and approved delivery methods (secure email, portal, or secure fax).
- Maintain comprehensive documentation including date/time, recipient, contents, delivery method, and authorizing documents.
Timeliness, Quality & Audits
- Meet internal SLAs and all federal/state response timelines, including CMS requirements for Medicare records.
- Conduct quality checks prior to release to ensure accuracy and compliance.
- Participate in ROI, payer, and Medicare audits and promptly remediate findings.
Compliance & Information Security
- Strictly adhere to HIPAA, privacy, confidentiality, and records retention standards.
- Apply the minimum necessary standard for all disclosures.
- Follow remote security protocols including VPN, MFA, approved devices, and private workspace requirements.
- Immediately report and escalate potential privacy incidents or misdisclosures per policy.
Collaboration & Communication
- Work closely with Privacy/Compliance teams and other stakeholders to ensure seamless operations.

