EMStool LLC — Cadence MIH Scheduling Platform

Patient Right of Access — Records Request Procedure

Policy #: HIPAA-SEC-008 Effective Date: July 15, 2026 Version: 1.0 Next Review: July 15, 2027

1. Purpose

This document describes how a patient's right to access their own protected health information (PHI) is satisfied for organizations using Cadence, and who is responsible for each part of that process.

45 CFR §164.524 (the HIPAA Privacy Rule's "right of access") requires a covered entity to provide an individual, upon request, with a copy of the PHI in their designated record set — generally within 30 days, extendable once by 30 additional days with written notice to the individual.

2. Division of Responsibility

EMStool LLC is a Business Associate — it provides the Cadence software platform that client organizations use to store and manage patient records. Each client organization (the agency running its own Cadence instance) is the Covered Entity under HIPAA.

EMStool does not manage these requests

Identity verification, deciding whether a request is valid, communicating with the patient, and meeting the 30-day regulatory deadline are entirely the responsibility of the client organization. EMStool LLC provides only the technical capability described in Section 3 below — it does not receive, evaluate, or respond to patient records requests on any client's behalf.

3. Technical Export Capability (What EMStool Provides)

Cadence includes a "📄 Export Record" action on each patient's detail page, available to users with Account Administrator role or above. It produces a single printable page (saveable as PDF via the browser's print dialog) containing:

Every export automatically adds a timestamped note to the patient's record identifying who generated it and citing §164.524 — this is Cadence's audit trail of the disclosure, not a substitute for the client's own request-handling documentation (Section 5).

4. Request Handling Steps (Client Organization)

  1. Receive the patient's request through whatever channel your organization designates (phone, email, in person, etc.)
  2. Verify the requester's identity per your organization's own verification policy
  3. Locate the patient's record in Cadence and use the Export Record action
  4. Deliver the exported record to the patient in the form and format they requested (electronic or paper), within 30 days of the request
  5. If a 30-day extension is needed, provide the patient written notice of the extension and the reason, within the initial 30-day period

5. Fees & Record Retention

§164.524(c)(4) permits a reasonable, cost-based fee for copies in some circumstances — whether and how much to charge is the client organization's own policy decision, not something Cadence enforces or calculates. Each client organization is responsible for retaining its own documentation of the request and response (who asked, when, what was verified, what was sent, when) per its own retention policy.

6. Scope Note

This procedure exists because Cadence today is entirely staff-facing — there is no patient login or self-service portal. If a self-service patient portal is built in the future, this document will need a corresponding update; until then, every records request is a manual, staff-mediated process as described above.