Colorado’s medical records laws give you the right to see, copy, and correct your health information, cap what providers can charge for those copies, set deadlines for their responses, and impose serious penalties when providers mishandle your data. The rules come from three main places: Colorado Revised Statutes Title 25, HIPAA, and the 21st Century Cures Act. Together they cover access, fees, privacy, retention, breach notices, and enforcement.
How to Access Your Records
Under Colorado Revised Statutes § 25-1-802, licensed healthcare practitioners must let you or your personal representative inspect your records at reasonable times and on reasonable notice. The statute reaches physicians, dentists, chiropractors, nurses, optometrists, psychotherapists, and other licensed professionals. A companion statute, § 25-1-801, covers records held by hospitals, clinics, and other healthcare facilities.1Justia. Colorado Code 25-1-802 – Patient Records in Custody of Individual Health-Care Providers2Justia. Colorado Code 25-1-801 – Patient Records in Custody of Health-Care Facility
To request records, submit a signed and dated written authorization to the provider or facility. A personal representative can do this on your behalf using a HIPAA-compliant authorization. HIPAA gives the provider 30 days to act on your request. They can take one 30-day extension, but only by notifying you in writing with the reason and a date they’ll respond.3eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information
Denials are narrow. Under 45 CFR 164.524(a), a provider may withhold records in limited situations, such as when a licensed professional determines access would endanger your life or physical safety, or when the records are psychotherapy notes.
What Copies Can Cost
Inspecting your records at the facility is free. The Colorado statute prohibits charging a fee just to let you look at your own file.2Justia. Colorado Code 25-1-801 – Patient Records in Custody of Health-Care Facility
For paper copies, § 25-1-801 caps what a healthcare facility can charge:
- First 10 pages: $18.53 flat
- Pages 11 through 40: $0.85 per page
- Pages 41 and beyond: $0.57 per page
Electronic copies are governed by federal rules, which override the state per-page schedule. HIPAA lets a provider charge a flat $6.50 to cover labor, supplies, and postage for an electronic copy. Providers may instead calculate actual costs or use a schedule based on average labor, but the $6.50 flat option is a practical ceiling for most patient requests. A large quoted fee for electronic records is worth pushing back on.4HHS.gov. Is $6.50 the Maximum Amount That Can Be Charged to Provide Individuals With a Copy of Their PHI?
Electronic Records and Information Blocking
The 21st Century Cures Act requires healthcare organizations to release finalized clinical information electronically without delay. That covers clinical notes, lab results, and other data in your electronic record. Providers cannot hold finalized information back or release it on their own schedule.
The law defines “information blocking” as any practice likely to interfere with your ability to access, exchange, or use your electronic health information. Providers who block information face Medicare consequences, including loss of meaningful use credit, lower payment adjustments, and possible exclusion from Medicare shared savings programs.5Federal Register. 21st Century Cures Act – Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking
Several exceptions apply. The ones most likely to matter to a patient are the harm exception (when release could endanger someone), the privacy exception (when a state or federal privacy law prohibits disclosure), and the infeasibility exception (when the provider genuinely lacks the technical ability to fulfill the request). Psychotherapy notes and non-finalized information like draft notes or unconfirmed lab results sit outside the information blocking rules entirely.
Sending Records to a Third-Party App
HIPAA lets you direct your provider to send your electronic health information to an app of your choosing. The provider generally cannot refuse if the data is readily producible in the format the app uses. A provider cannot deny the request because the app might share your data for research, or because the app doesn’t encrypt data at rest. Those risks are yours to accept.6HHS.gov. The Access Right, Health Apps, and APIs
Fixing Errors in Your Records
If information in your file is wrong, HIPAA gives you the right to request an amendment. Submit a written request identifying the disputed information and explaining why it should change. The provider has 60 days to act, with one available 30-day extension if they notify you in writing.7eCFR. 45 CFR 164.526 – Amendment of Protected Health Information
A provider can deny the request only on specific grounds, such as finding the record already accurate or determining that a different provider created the entry. A denial must be in writing, explain the basis, and tell you that you can file a statement of disagreement. That statement becomes a permanent part of your record and must accompany any future disclosure of the disputed information. Errors in a medical file can drive wrong diagnoses, insurance denials, and complications in later care, so the amendment process is worth using when you spot a mistake.
Privacy Rules That Apply in Colorado
HIPAA sets the federal baseline for how covered entities (providers, health plans, and clearinghouses) can use and share your protected health information without your authorization. Colorado adds provider-specific confidentiality duties on top.
For licensed mental health professionals, Colorado law prohibits therapists, counselors, and psychologists from disclosing confidential communications you make during treatment without your consent. The protection covers session content and advice given during the professional relationship.8Justia. Colorado Revised Statutes 12-245-220 – Disclosure of Confidential Communications HIPAA-covered entities follow the federal privacy rules, and the state confidentiality statute fills gaps for practitioners who may not qualify as covered entities.
Colorado’s broader consumer privacy law, SB21-190, largely exempts personal data already governed by HIPAA and other federal health privacy laws. For traditional healthcare providers, HIPAA and the Colorado medical records statutes remain the frameworks that matter.
Extra Protection for Sensitive Categories
Substance Use Disorder Treatment
Under 42 CFR Part 2, records from substance use disorder treatment programs require a strict written consent before disclosure. The consent must name the patient, identify who can make the disclosure and who can receive it, describe the specific information, state the purpose, include an expiration date or event, and be signed and dated. Even other treating providers cannot receive these records without meeting every element.9eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records
Consent for use in court proceedings cannot be combined with consent for any other purpose. Every disclosure must carry a written notice explaining that the records are federally protected and generally cannot be used against the patient in legal proceedings without a court order.
Reproductive Healthcare
A 2024 amendment to the HIPAA Privacy Rule prohibits covered entities and business associates from using or disclosing protected health information to investigate, impose liability on, or identify any person for seeking, obtaining, providing, or facilitating reproductive healthcare that was lawful where it was provided. The rule applies when the care was lawful under the state law where it occurred or protected by federal law.10Federal Register. HIPAA Privacy Rule to Support Reproductive Health Care Privacy In Colorado, where reproductive healthcare remains broadly legal, this adds a federal layer of protection for those records.
How Long Providers Keep Records, and How They Destroy Them
The Colorado Medical Board’s policy recommends that licensed physicians and physician assistants retain patient records for at least seven years after the last date of treatment. For minors, the recommendation is seven years after the last treatment date or seven years after the patient turns 18, whichever comes later. This is a Board guideline rather than a statutory mandate, but a provider who departs from it invites professional scrutiny.
HIPAA does not mandate one disposal method, but records must be rendered unreadable and unrecoverable. Paper records should be shredded, burned, or pulped. Electronic records can be cleared by overwriting with non-sensitive data, degaussed, or physically destroyed through shredding, melting, or incineration.11HHS.gov. Frequently Asked Questions About the Disposal of Protected Health Information Deleting files or reformatting a hard drive isn’t enough, because standard recovery tools can pull that data back.
When Your Data Is Breached
Colorado § 6-1-716 requires the entity that maintained the data to investigate a suspected breach and notify affected residents as quickly as possible, and no later than 30 days after determining a breach occurred.12Justia. Colorado Code 6-1-716 – Notification of Security Breach
The notice must include the date or estimated date of the breach, a description of the information involved, and contact information for the entity. If the breach reaches 500 or more Colorado residents, the entity must also notify the Colorado Attorney General within the same 30 days. Breaches affecting more than 1,000 residents trigger an added obligation to notify the nationwide consumer reporting agencies.
A breach of encrypted data generally does not trigger notification unless the encryption key was also compromised. Law enforcement can ask for a brief delay if notification would interfere with a criminal investigation; the 30-day clock restarts once law enforcement clears the notice.
Penalties for Violations
HIPAA runs on two enforcement tracks. The Office for Civil Rights administers civil penalties, and the Department of Justice prosecutes criminal cases. Civil amounts adjust annually for inflation.
Civil Penalties
The 2025 inflation-adjusted amounts, published in January 2026, follow a four-tier structure based on culpability:
- Tier 1 (did not know): $141 to $71,162 per violation, up to $2,134,831 per calendar year
- Tier 2 (reasonable cause, not willful neglect): $1,424 to $71,162 per violation, up to $2,134,831 per calendar year
- Tier 3 (willful neglect, corrected within 30 days): $14,232 to $71,162 per violation, up to $2,134,831 per calendar year
- Tier 4 (willful neglect, not corrected within 30 days): $71,162 to $2,134,831 per violation, up to $2,134,831 per calendar year
The gap between tiers is wide. A provider that self-corrects a problem quickly faces a fraction of the exposure of one that ignores it.13Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
Criminal Penalties
Federal criminal prosecution is reserved for knowing violations, with penalties that escalate by intent:
- Knowing violation: up to $50,000 in fines and one year in prison
- Under false pretenses: up to $100,000 and five years
- Intent to sell, transfer, or use data for commercial advantage, personal gain, or malicious harm: up to $250,000 and ten years
These penalties reach individuals, not just organizations. A hospital employee who snoops on a celebrity’s chart or sells patient data to a third party can be prosecuted personally.14Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information