Your Right to Access Medical Records for G-Code Services
Your Explanation of Benefits shows a G-code was billed. But what service did you actually receive? The only way to know is through your medical record. You have a legal right to access this information.
How do I access my medical records for a G-code service?
Under HIPAA (45 CFR 164.524), you have a legal right to access your medical records within 30 days of request. For G-code services, request the encounter notes, care plans, screening tools, and assessments from the date of service. These records are essential for verifying what service was performed and for building an appeal if your claim was denied.
Why This Matters
Many patients don't understand what services they received when they see a G-code on their EOB. The EOB shows a code and a charge - but not what happened. Your medical record is the only way to verify what service was actually provided and whether it was documented properly.
This is especially important if:
- →You want to understand what G-code service you received
- →Your claim was denied and you're preparing an appeal
- →You question whether a service was actually performed
- →You're involved in a legal matter requiring medical documentation
Your Legal Right Under HIPAA
The Law: 45 CFR § 164.524
The HIPAA Privacy Rule provides individuals with a legal, enforceable right to see and receive copies upon request of the information in their medical and other health records maintained by their health care providers and health plans.
Source: HHS.gov - Individuals' Right under HIPAA to Access their Health Information
Your Rights Include:
- ✔Access to your "designated record set" - medical and billing records
- ✔Response within 30 days (one 30-day extension allowed)
- ✔Choice of format - electronic or paper
- ✔Reasonable, cost-based fees only
- ✔Access regardless of whether you've paid your bill
- ✔Right to have records sent directly to a third party
Providers CANNOT:
- ✘Require you to appear in person when you request a mailed copy
- ✘Force you to use a web portal as the only option
- ✘Create unreasonable barriers to access
- ✘Deny access because you haven't paid a bill
- ✘Charge excessive or unreasonable fees
The "Designated Record Set"
Under HIPAA, you have access to your Protected Health Information (PHI) in the "designated record set," which includes:
- • Medical records
- • Billing and payment records
- • Insurance information
- • Clinical laboratory test results
- • Medical images (X-rays, etc.)
- • Wellness program files
- • Clinical case notes
- • Enrollment records
- • Claims adjudication records
- • Any records used for decisions about you
Exclusions: Psychotherapy notes (kept separately), information compiled for legal proceedings, and certain quality improvement records not used for decisions.
What Records to Request for G-Code Verification
Different G-codes require different documentation. Use this checklist to ensure you request the right records for your situation.
For Any G-Code
- ☐Encounter notes from the specific date of service
- ☐Provider's assessment and plan documented during the visit
- ☐Diagnoses recorded for the encounter
- ☐Billing records showing codes submitted
For G2211 (E/M Complexity Add-on)
HIGH DENIAL RISKG2211 requires evidence of a longitudinal care relationship, not just a single visit.
- ☐Care plan documentation showing ongoing management
- ☐Notes from prior visits establishing the relationship
- ☐Claims history showing pattern of care
- ☐Chronic condition management documentation
For G0438/G0439 (Annual Wellness Visit)
HIGH VOLUMEAWV codes have specific documentation requirements defined by CMS.
- ☐Health Risk Assessment (HRA) - the complete questionnaire
- ☐Medical and family history documentation
- ☐Current provider list
- ☐Screening schedule for next 5-10 years
- ☐Personalized prevention plan
For G0136 (SDOH Assessment)
EMERGINGSDOH codes require documented assessments and resulting actions.
- ☐SDOH assessment tool used (specific instrument)
- ☐Assessment findings documented
- ☐Interventions or referrals made based on findings
- ☐Follow-up plan for identified needs
For G0320/G0321 (Telehealth Home Health)
TELEHEALTHRemote service codes require specific telehealth documentation.
- ☐Telehealth encounter documentation
- ☐Technology platform used for the encounter
- ☐Duration of the telehealth session
- ☐Integration with care plan
How to Make a Records Request
Follow these steps to request your medical records. Most providers accept written requests; some may require their own form.
Identify the Provider or Facility
Your records request goes to the provider who performed the service - usually shown on your EOB or claim statement.
Submit a Written Request
While providers may require a written request, they cannot create unreasonable barriers. Your request should include:
- • Your full name and date of birth
- • Specific dates of service you need records for
- • Types of records requested (encounter notes, assessments, etc.)
- • Preferred format (electronic or paper)
- • Where to send the records
- • Your signature and date
Sample Request Language
"Pursuant to my rights under HIPAA (45 CFR § 164.524), I am requesting copies of my complete medical records for dates of service [DATE(S)], including but not limited to: encounter notes, care plans, assessments, and any documentation supporting G-code [CODE] billed on [DATE]. Please provide these records in electronic format to [EMAIL/ADDRESS]."
Specify Your Preferred Format
You have the right to request records in your preferred format. Providers must accommodate if the format is "readily producible."
Electronic Options:
- • PDF via secure email
- • Patient portal download
- • CD/USB drive
- • Direct transmission to third party
Paper Options:
- • Mailed copies
- • In-person pickup
- • Fax (for short records)
Wait and Follow Up
Providers have 30 days to respond (60 days with extension). If you don't receive a response, follow up in writing and reference HIPAA.
Timeline:
- • Day 1: Submit request
- • Day 14: Follow up if no acknowledgment
- • Day 30: Deadline for response (or extension notice)
- • Day 60: Final deadline if extension taken
What to Do If Your Request Is Denied or Delayed
Denials are rare under HIPAA and must be for specific legal reasons. If your request is denied or unreasonably delayed, you have recourse.
Legitimate Denial Reasons (Limited)
Providers can only deny access in specific circumstances:
- •Psychotherapy notes maintained separately
- •Information compiled for legal proceedings
- •Information subject to Clinical Laboratory Improvements Amendments (CLIA)
- •Access could cause substantial harm (requires clinical judgment)
Your Recourse Options
1. Request Written Explanation
If denied, the provider must give you a written explanation of the reason and inform you of your right to request a review.
2. Request Internal Review
You can ask another licensed professional at the organization to review the denial.
3. File Complaint with OCR
If you believe your HIPAA rights were violated, file a complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services.
Key Takeaways
- 1.You have a legal right to access your medical records under HIPAA - regardless of bill payment.
- 2.Providers must respond within 30 days (60 with extension).
- 3.Request specific records based on the G-code you're verifying.
- 4.EOBs don't show documentation - only the medical record reveals what was actually performed.
- 5.Denials are rare and must be for specific legal reasons. You can appeal.
This content is for informational purposes only and does not constitute legal advice. HIPAA requirements and state laws may vary. Consult with qualified professionals for specific guidance. Last updated: December 2025.