Client record requests need a clear, repeatable process
A client emails your practice asking for “all of my records.” Another wants notes sent to a new therapist. A parent asks for a minor’s treatment history. A lawyer sends a signed release. Each request may look simple at first, but the response requires careful handling.
Behavioral health records often include sensitive clinical details, treatment goals, risk assessments, diagnoses, family information, and references to other people. Clinicians need a process that protects privacy, supports the client’s right to access information, and creates a clear record of what was requested, reviewed, released, or denied.
This article is practical guidance for therapists, counselors, social workers, psychologists, psychiatrists, and behavioral health practice owners. It is not legal advice. Clinicians should follow applicable federal and state laws, payer requirements, professional ethics, and organizational policies. If a request involves a subpoena, court order, custody dispute, substance use treatment records, minors, safety concerns, or uncertainty about disclosure, consult qualified legal or compliance support before releasing records.
Start by identifying the type of request
Not every request for records is the same. Before gathering documents, clarify who is asking, what they are asking for, why they need it, and where the records should go.
Common request types include:
- Client access request: The client asks to inspect or receive a copy of their own records.
- Third-party authorization: The client signs a release allowing records to be sent to another provider, attorney, school, employer, or agency.
- Parent or guardian request: A parent, guardian, or legally authorized representative asks for records involving a minor or dependent adult.
- Legal request: A subpoena, court order, or attorney request seeks records for litigation, disability review, custody proceedings, or another legal matter.
The request type affects the next steps. A client access request may follow one workflow, while a subpoena or court order may require additional review. A signed release does not always mean every document should be sent without review. It must be evaluated against the client’s authorization, applicable law, and clinical privacy considerations.
Verify identity and authority before reviewing records
Verification should happen before records are prepared or shared. The goal is to confirm that the requestor is who they say they are and has the authority to receive the information.
For a current client, verification may involve confirming information already in the clinical record, using a secure client portal, or checking a government-issued ID if the request is made in person. For a former client, use extra care if contact information has changed. A request from a new email address should not be treated as automatically valid.
For a third party, confirm that the authorization is complete and current. A useful authorization typically identifies the client, the recipient, the information to be released, the purpose of disclosure, the expiration date or event, and the client’s signature. Some practices also require the authorization to specify the date range of records being requested.
Requests involving parents, guardians, personal representatives, executors, or legal decision-makers may require documentation of authority. Examples include custody orders, guardianship papers, healthcare power of attorney documents, or other legal paperwork. State laws can vary, especially for minors receiving certain types of behavioral health or substance use services.
Clarify exactly what records are being requested
Broad requests can create unnecessary work and increase the risk of over-disclosure. If a client asks for “everything,” the practice may still need to clarify what that means in practical terms. Does the client want progress notes, treatment plans, intake paperwork, assessments, billing records, correspondence, or a summary letter?
A clear request should answer three questions:
- Which records? For example, progress notes, intake assessment, diagnosis, treatment plan, discharge summary, or medication management notes.
- Which dates? For example, records from January 1 through June 30, the last six sessions, or the current episode of care.
- Which destination? For example, the client, a new therapist, a primary care provider, an attorney, or a school office.
Clarification protects the client and the clinician. A new provider may only need a treatment summary and current treatment plan. A disability reviewer may request specific records tied to a date range. A client may want records for personal use but prefer not to receive highly detailed notes that mention family members or sensitive history.
If the request is unclear, document the clarification attempt. A short message such as, “Please confirm whether you are requesting progress notes from all sessions or a treatment summary covering the requested period,” can prevent confusion later.
Know the difference between progress notes and psychotherapy notes
Behavioral health clinicians often use the phrase “therapy notes” casually, but record requests require more precision. Progress notes are part of the clinical record. They typically document the date of service, presenting issues, interventions, client response, risk factors, progress toward treatment goals, diagnosis, plan, and other clinically relevant information.
Psychotherapy notes may be treated differently from the general clinical record. These are generally personal notes recorded by a mental health professional documenting or analyzing the contents of a counseling session and kept separate from the rest of the medical record. They are not the same as progress notes, treatment plans, medication records, billing records, or clinical summaries.
In practice, many therapists do not keep separate psychotherapy notes. They keep progress notes only. If your practice does maintain separate psychotherapy notes, store them separately and handle requests with added care. Do not assume they should be released with the general chart unless the request and applicable rules support that disclosure.
Clear naming helps. Label documents consistently as “Progress Note,” “Treatment Plan,” “Intake Assessment,” or “Discharge Summary.” Avoid using “therapy notes” as a catch-all term in your record request workflow because it can create confusion for clients, attorneys, staff, and clinicians.
Review records before releasing them
Preparing records is not the same as exporting a chart and sending it. A clinician or qualified staff member should review what will be released and confirm that it matches the request and authorization.
The review should consider:
- Scope: Are the documents within the date range and record type requested?
- Recipient: Is the information being sent to the correct person or organization?
- Third-party information: Do the records include details about family members, partners, group participants, or other people?
- Special protections: Do any records involve substance use treatment, HIV-related information, reproductive health information, minors, or other specially protected content under applicable law?
Third-party information deserves close attention in behavioral health documentation. A couples therapy note might include details about both partners. A family therapy note may mention a sibling. A group therapy record could include names or disclosures from other participants. Depending on the situation, redaction, a summary, a separate authorization, or legal guidance may be appropriate.
Risk-related content also requires careful review. Records involving suicidal ideation, homicidal ideation, abuse reporting, safety planning, or mandated reporting may be releasable in some circumstances, but the clinician should understand the request and document the basis for the disclosure decision.
Use a standard decision process for release, denial, or partial release
A record request should not depend on memory or improvisation. Use a standard decision process so similar requests receive similar handling.
A practical decision process may look like this:
- Log the request date. Record how the request arrived and who received it.
- Verify identity and authority. Confirm the requestor’s identity and legal or client-authorized right to receive records.
- Clarify scope. Identify record type, date range, recipient, and delivery method.
- Review the records. Check for scope, sensitive content, third-party information, and special handling issues.
After those steps, determine whether the practice will release the records, release part of the records, ask for more information, deny the request, or seek legal guidance. Some denials may require a written explanation or review process. The specific requirements depend on the type of request and applicable law.
Partial release is sometimes the most appropriate response. For example, a clinician may provide the requested progress notes but withhold documents outside the authorized date range. In another case, a treatment summary may meet the receiving provider’s needs better than sending years of detailed session notes. The client’s authorization and applicable rules should guide that decision.
Prepare the records in a way that is organized and readable
Clients and receiving providers should be able to understand what they received. Disorganized exports create confusion and can make the practice look careless, even when the documentation itself is sound.
Before sending records, organize them by type and date. Include a cover page or cover letter when appropriate. The cover letter can identify the client, the date range, the records included, the recipient, and the method of delivery. It should not add unnecessary clinical commentary.
A simple cover letter might state:
Enclosed are records for Jordan Smith, date of birth 04/12/1989, covering services from 01/03/2026 through 04/28/2026. The enclosed documents include intake assessment, treatment plan, and individual therapy progress notes for the requested date range. These records are provided in response to the signed authorization dated 05/02/2026.
If redactions are made, document what was redacted and why, using the level of detail your policy requires. Do not alter the clinical meaning of a note. Redaction should be handled carefully and consistently.
Send records through a secure and appropriate method
The delivery method should match the client’s request, the sensitivity of the records, and the practice’s privacy policies. Common options include a secure client portal, encrypted email, secure fax, certified mail, or in-person pickup with identity verification.
Email deserves special care. Some clients may ask for records by regular email because it feels convenient. If your practice allows that option, follow your policy for explaining risks and documenting the client’s preference. Many practices prefer a secure portal or encrypted delivery for behavioral health records.
For mail, confirm the address before sending. For fax, confirm the number and recipient. For portal delivery, confirm that the correct client account is active. Small errors can create privacy issues, such as sending records to an outdated email address or a fax number copied from an old referral form.
Do not send more than requested. If the authorization names a new psychiatrist and asks for medication-related records, sending unrelated family therapy notes may be outside the scope. The safest workflow is specific, documented, and limited to the approved request.
Document every step of the request
The record request process should leave a clear administrative trail. If questions arise months later, the practice should be able to show what happened without relying on staff memory.
Your request log may include:
- Date the request was received and the deadline used by the practice.
- Name and contact information of the requestor.
- Verification steps completed.
- Records released, withheld, denied, or still pending.
Add enough detail to explain the decision. For example: “Received signed authorization from client requesting progress notes from 02/01/2026 to 03/31/2026 be sent to ABC Counseling Group. Identity verified through portal. Released six individual therapy progress notes via secure fax on 04/04/2026.”
If the request is denied or delayed, document the reason and any communication sent to the client or requestor. If legal counsel or a compliance officer was consulted, document that consultation according to your policy.
Special situations that require extra care
Some record requests are routine. Others are not. These situations deserve additional review before disclosure.
Requests involving minors
Minor consent and parent access rules vary by state and service type. A parent may have access in many situations, but there can be exceptions for certain confidential services, custody restrictions, or situations where disclosure may not be appropriate. Ask for legal documentation when needed, such as custody orders or guardianship papers.
Subpoenas and court orders
A subpoena is not the same as a court order. Do not assume every legal-looking request requires immediate disclosure. Follow your organizational policy and seek qualified guidance, especially if the request is broad, contested, or involves sensitive behavioral health records.
Couples, family, and group therapy records
Multi-person services can create complex access questions. The record may contain information about more than one participant. Your policy should address who may request the record, whose authorization is needed, and how third-party information will be handled.
Client requests to amend records
A client may disagree with a diagnosis, risk statement, or description of an event and ask to amend the record. Have a process for reviewing amendment requests. If the record is changed, document the change according to policy. If the request is denied, the client may have rights to submit a statement of disagreement depending on applicable rules.
Common mistakes that create avoidable problems
Many record request problems come from speed, uncertainty, or inconsistent workflows. A few minutes of review can prevent hours of cleanup later.
- Sending the full chart when only a summary was requested. This may disclose more information than necessary.
- Skipping identity verification. A familiar name in an email inbox is not enough.
- Missing state-specific requirements. Federal rules are only part of the picture.
- Failing to document the release. Without a log, the practice may struggle to explain what was sent.
Another frequent issue is vague language in forms. A release that says “send my records” without naming the recipient, date range, or purpose may need clarification. Clear forms reduce back-and-forth and help clinicians avoid making assumptions.
A practical example from a therapy practice
A former client requests records for the past year because they are transferring to a new therapist. The request arrives by email and includes the new therapist’s name but no signed authorization.
The practice replies with its standard release form and asks the client to specify the records and date range. The client completes the form, requesting the intake assessment, current treatment plan, and progress notes from the last six months. The practice verifies the client’s identity through the secure portal.
The clinician reviews the records and notices that two progress notes include detailed information about the client’s sibling. The clinician follows the practice policy, prepares the records within the authorized date range, and redacts limited third-party information where appropriate. The records are sent through secure fax to the receiving therapist. The practice logs the request, verification, records released, delivery method, and release date.
This process is not complicated, but it is deliberate. The practice avoids sending records without authorization, avoids over-disclosure, and keeps a clear trail of what occurred.
Use templates and organized notes to make requests easier
Record requests are harder when documentation is inconsistent. If one note includes interventions in a clear section, another buries them in a paragraph, and another lacks a treatment goal reference, preparing records takes longer. Structured documentation makes review easier.
Consistent progress notes often include:
- Service date, modality, participants, and duration.
- Presenting concern or session focus.
- Interventions provided and client response.
- Progress toward goals, risk factors, and plan.
SOAP, DAP, BIRP, GIRP, and other structured formats can all work if they fit the service and payer expectations. The key is consistency. A structured note helps the clinician quickly confirm what happened in the session and whether the record fits the request.
Templates can also reduce unclear or overly broad language. For example, a progress note template with separate fields for “client report,” “clinical intervention,” “client response,” and “plan” is easier to review than a long narrative note with mixed clinical and administrative details.
How AutoNotes can support record request workflows
AutoNotes helps behavioral health professionals create structured, editable progress note drafts from session details. For record requests, that structure may support faster review because notes are organized by service type and clinical elements such as interventions, client response, progress, and plan.
AutoNotes is not a substitute for legal review, clinical judgment, or practice policies. It does not decide whether a record should be released. The clinician remains responsible for reviewing, editing, finalizing, and managing documentation according to applicable laws, payer requirements, ethical standards, and organizational rules.
Where AutoNotes can help is the day-to-day documentation foundation. More consistent notes can make it easier to identify the relevant record, confirm the service type, review the content, and prepare records when a valid request arrives. Service-specific templates for individual therapy, group therapy, intake sessions, assessments, and treatment planning can help clinicians keep records organized before a request ever comes in.
If documentation backlog is making record requests harder to manage, consider testing an AI-assisted workflow that keeps you in control of the final note. Start your free trial to see how AutoNotes can help you create structured, editable clinical note drafts faster.
Build a record request policy your practice can follow
A good record request policy should be short enough for staff to use and specific enough to guide real decisions. It should define who receives requests, who verifies identity, who reviews records, who approves release, and how the release is documented.
At minimum, your policy should address:
- Accepted request methods and required forms.
- Identity and authority verification steps.
- Review process for sensitive records and third-party information.
- Approved delivery methods and release documentation.
Train clinicians and administrative staff on the policy. Review it periodically, especially after changes in laws, payer contracts, technology, or practice structure. Solo clinicians can use the same approach on a smaller scale: a standard form, a request log, a checklist, and a documented review process.
Client record requests are part of clinical practice. With clear forms, consistent documentation, careful review, and a written workflow, therapists can respond in a way that respects client access, protects privacy, and reduces last-minute administrative stress.