This document describes how a patient's right to access their own protected health information (PHI) is satisfied for organizations using Cadence, and who is responsible for each part of that process.
EMStool LLC is a Business Associate — it provides the Cadence software platform that client organizations use to store and manage patient records. Each client organization (the agency running its own Cadence instance) is the Covered Entity under HIPAA.
Identity verification, deciding whether a request is valid, communicating with the patient, and meeting the 30-day regulatory deadline are entirely the responsibility of the client organization. EMStool LLC provides only the technical capability described in Section 3 below — it does not receive, evaluate, or respond to patient records requests on any client's behalf.
Cadence includes a "📄 Export Record" action on each patient's detail page, available to users with Account Administrator role or above. It produces a single printable page (saveable as PDF via the browser's print dialog) containing:
Every export automatically adds a timestamped note to the patient's record identifying who generated it and citing §164.524 — this is Cadence's audit trail of the disclosure, not a substitute for the client's own request-handling documentation (Section 5).
§164.524(c)(4) permits a reasonable, cost-based fee for copies in some circumstances — whether and how much to charge is the client organization's own policy decision, not something Cadence enforces or calculates. Each client organization is responsible for retaining its own documentation of the request and response (who asked, when, what was verified, what was sent, when) per its own retention policy.
This procedure exists because Cadence today is entirely staff-facing — there is no patient login or self-service portal. If a self-service patient portal is built in the future, this document will need a corresponding update; until then, every records request is a manual, staff-mediated process as described above.