Contact Us

EHR vs. PHR: Data Ownership, Access, and Workflow Implications 

EHR vs. PHR: Data Ownership, Access, and Workflow Implications | Claimity

A patient calls your front desk asking for a copy of their last three years of visit notes. Another asks why the diagnosis on their insurance explanation of benefits does not match what they see in their online health record. A third contacts your billing team because the balance showing in the patient portal does not align with the statement they received in the mail. 

These conversations are happening in independent practices with increasing frequency, and they all trace back to the same underlying complexity: patients have more access to their health data than ever before, through more systems and channels than ever before, and the distinction between what your practice controls and what the patient controls is not always clear to either side of the relationship. 

The EHR versus PHR distinction is not just a technical or regulatory concept. It has direct implications for how independent practices manage patient access requests, how they design their billing and patient communication workflows, and how they ensure that the data flowing between clinical and financial systems maintains the integrity that clean billing depends on. 

Here is what we are covering: 

  • What EHRs and PHRs are, how they differ in ownership and purpose, and why that distinction matters operationally 
  • What the 21st Century Cures Act and information blocking rules require of independent practices in 2026 
  • How patient data access rights affect practice workflows across clinical and billing functions 
  • The tethered PHR model and how patient portals sit at the intersection of these two systems 
  • The workflow and compliance implications independent practices need to manage as patient data access expands 

The terms electronic health record and personal health record are used interchangeably in general conversation, but they describe fundamentally different systems with different ownership structures, different governance responsibilities, and different operational implications for the practices and patients that use them. 

An EHR is a digital record of a patient’s health information maintained by the healthcare provider or organization that created it. It is designed primarily for clinical use, to support care delivery, documentation, and coordination among providers. The practice or health system that maintains the EHR is the legal custodian of that record. The EHR contains information the provider documents: visit notes, diagnoses, orders, medication lists, lab results, and billing-relevant clinical data. It is governed by HIPAA, state medical records laws, and, since 2021, the information blocking provisions of the 21st Century Cures Act. 

A PHR is a health record that the patient controls. It allows the patient to collect, manage, and share health information from multiple sources, including data they input themselves and data they pull from provider EHRs through connected APIs. A PHR is not subject to HIPAA in the same way a provider EHR is, because HIPAA primarily governs covered entities, meaning healthcare providers, health plans, and their business associates. A PHR maintained independently by a patient, or by a consumer technology company on the patient’s behalf, falls outside HIPAA’s scope unless the company creating it is acting as a business associate of a covered entity. 

The Tethered PHR: Where the Lines Blur 

Between the fully provider-controlled EHR and the fully patient-controlled independent PHR lies a category that has become the most operationally relevant for independent practices: the tethered PHR. A tethered PHR is a patient-accessible view of data held in the provider’s EHR, offered through a patient portal or connected health app. The patient can view their data, and in some implementations they can add to it, but the underlying record remains in the provider’s control. 

Most patient portals offered by EHR vendors are tethered PHRs. The patient accesses their records through the portal, but they do not own or control the underlying system. This model has become the primary mechanism through which patients exercise their expanding data access rights, and it is the intersection point that carries the most immediate operational implications for independent practices. 

Why the Ownership Distinction Carries Legal Weight 

The ownership structure of health records determines who bears legal responsibility for their accuracy, security, completeness, and accessibility. For EHRs, that responsibility rests with the provider or health system. Practices must respond to patient access requests within defined timeframes, cannot withhold records in most circumstances, and face liability for data breaches involving records in their custody. 

For PHRs maintained outside the provider relationship, responsibility shifts to the patient and to whatever platform they use. But the critical operational point for independent practices is that the data a patient receives from your EHR and moves into their independent PHR is no longer under your governance. The practice cannot control how that data is stored, shared, or used once it has been transmitted to a patient-controlled system. That reality has compliance, liability, and workflow implications that every practice managing patient data access requests should understand. 

The 21st Century Cures Act, enacted in 2016 and with core provisions in effect since 2021 and strengthened through 2026, fundamentally changed the data access landscape for independent practices. Its information blocking provisions prohibit healthcare providers, health IT developers, and health information exchanges from taking actions that unreasonably interfere with the access, exchange, or use of electronic health information. 

The ONC’s 21st Century Cures Act final rule requires that patients be able to access their electronic health information through standardized APIs, including the FHIR R4 API, without special effort and without charge. This means that a patient using a third-party health app that supports the relevant standards can request access to their data directly from the provider’s EHR system, and the practice has a legal obligation not to block that access. The rule covers a broad scope of electronic health information, including clinical notes, diagnoses, medications, lab results, and other data that patients have historically had to request through formal medical records processes. 

For independent practices, this regulatory environment means that the question of whether a patient can access their data is largely settled by law. The operational question that remains is how to manage that access efficiently, securely, and in a way that does not create workflow disruptions that pull clinical and administrative staff away from other priorities. 

Information Blocking: What Counts as a Violation 

The information blocking prohibition is broader than many independent practices realize. It covers not just outright refusal to provide access, but also practices that unreasonably delay responses, impose unnecessary fees, use technical or administrative barriers that make access more difficult than it needs to be, or configure systems in ways that prevent data from being shared through standard APIs. 

Penalties for information blocking violations have escalated significantly. Providers found to have engaged in information blocking can face disincentives under Medicare and Medicaid programs, including adjustments to their MIPS performance scores. Health IT developers and networks face civil monetary penalties of up to $1 million per violation. The enforcement environment in 2026 is meaningfully more active than it was at initial implementation, and the ONC has signaled continued prioritization of information blocking investigations. 

For independent practices, ensuring that patient access workflows are designed for efficiency rather than friction, and that EHR configurations support rather than impede standard API-based data sharing, is both a compliance obligation and an operational necessity. 

Patient Right of Access Under HIPAA 

Separately from the 21st Century Cures Act, HIPAA’s Privacy Rule grants patients the right to access their designated health records within defined timeframes. For electronic records, practices must provide access within 30 days of a request, with one 30-day extension if needed. The HHS Office for Civil Rights has increased HIPAA Right of Access enforcement significantly over the past several years, with settlements issued against practices that delayed responses, imposed excessive fees, or directed patients to obtain records through unnecessarily cumbersome processes. 

The interaction between HIPAA access rights and the 21st Century Cures Act information blocking rules creates a layered compliance environment where independent practices must manage both the speed of record provision and the technical pathways through which records can be accessed. Understanding both frameworks and designing workflows that satisfy both simultaneously is the compliance reality for independent practices in 2026. 

The regulatory expansion of patient data access rights has direct operational consequences for independent practices that go beyond compliance management. As patients gain easier access to their health records through portals, APIs, and connected health apps, the volume of data-related patient inquiries, amendment requests, and discrepancy questions increases correspondingly. 

The Discrepancy Inquiry Problem 

When patients can view their health data through multiple channels, such as the practice portal, a connected health app, a health insurance portal, and a PHR aggregator, they sometimes encounter inconsistencies between what they see in different systems. A diagnosis that appears in one system but not another. A medication list that has not been updated across all connected records. A lab result that shows in the EHR but has not yet propagated to the patient-accessible portal. 

These discrepancies generate inquiries to the practice. The patient is not wrong to notice the inconsistency. But each inquiry requires staff time to investigate, explain, and in some cases correct. Practices that have not designed a clear triage process for data discrepancy inquiries find that these conversations consume front desk and clinical staff time in unpredictable and difficult-to-budget ways. 

Building a defined workflow for patient data inquiries, with clear routing for billing discrepancies to the billing team, clinical record questions to nursing or clinical staff, and portal access issues to designated support, reduces the operational impact of increased patient data access without reducing the quality of the response. 

Amendment Requests and Their Administrative Burden 

HIPAA gives patients the right to request amendments to their health records when they believe the information is incorrect or incomplete. Practices must respond to amendment requests within 60 days, either accepting the request and updating the record or providing a written denial with specific reasons. Accepted amendments must be communicated to identified persons or entities that received the original information. 

The amendment request process is administratively more complex than many practices account for. Tracking incoming requests, ensuring timely responses, documenting denials appropriately, and managing the notification requirement for accepted amendments all require structured workflows. Practices handling these requests informally, routing them through whoever receives the patient’s call or message, risk missing response deadlines and creating liability exposure that formal workflows would prevent. 

The Billing Data Accuracy Dimension 

One workflow implication of increased patient data access that is particularly relevant to the billing function is the intersection between clinical record accuracy and billing accuracy. When patients access their EHR data through a portal or connected app and compare it to their billing statement or explanation of benefits, they sometimes identify coding or documentation discrepancies that they then query with the practice. 

A patient who sees a diagnosis code on their EOB that they do not recognize, or a procedure listed on their billing statement that they believe does not match what they received, is raising a data integrity question that touches both the clinical record and the billing workflow. These inquiries require coordination between the billing and clinical teams to investigate and resolve, and they are happening with increasing frequency as patient data access becomes more ubiquitous. 

The practices best positioned to handle these inquiries efficiently are those where clinical documentation and billing codes are already well-aligned. When the coded claim accurately reflects what is documented in the visit note, and both are accessible to the billing team for reference, patient inquiries about billing accuracy can be resolved quickly and confidently. When clinical and billing data are fragmented across disconnected systems, the investigation process is slower, more labor-intensive, and more likely to produce an unsatisfying answer for the patient. 

For most independent practices, the patient portal is where the EHR versus PHR distinction becomes most practically relevant. The portal is the primary mechanism through which patients exercise their data access rights, view their records, and interact with the practice’s clinical and financial systems. 

Understanding what the portal provides, what it does not, and how it connects to both the clinical EHR and the billing infrastructure behind it is essential for practices trying to manage patient data access workflows effectively. 

What a Well-Designed Patient Portal Should Provide 

A well-designed patient portal serves as a tethered PHR that gives patients access to their core health information without requiring them to navigate formal records request processes. At a minimum, it should provide access to: 

  • Visit summaries and after-visit notes in a format patients can understand 
  • Current medication lists, diagnosis history, and allergy information 
  • Lab results with context sufficient for patient comprehension 
  • Billing statements, payment history, and current account balance 
  • The ability to make payments, set up payment plans, and ask billing questions without calling the office 
  • Secure messaging for non-urgent clinical and administrative inquiries 

When these elements are available through a single integrated portal, the volume of phone-based data inquiries decreases, the patient’s experience of accessing their information improves, and the practice’s ability to fulfill its data access obligations under HIPAA and the 21st Century Cures Act becomes more efficient. 

Where Portals Fall Short 

Many patient portal implementations provide clinical data access without providing a meaningful financial data experience. A patient can view their visit notes but cannot easily understand their billing statement or make a payment without leaving the portal. This bifurcation between clinical access and financial access means that patients with billing questions still need to call the front desk, and the practice’s billing team still receives inquiries that a well-designed integrated portal would have answered automatically. 

The gap between clinical portal access and financial portal functionality is one of the most significant workflow inefficiencies in independent practice operations. Patients who can access their clinical records digitally and conveniently expect the same from their billing experience. When the billing experience falls short of that expectation, it produces the calls, delays, and payment friction that independently increase the practice’s administrative burden and reduce its patient collection rates. 

API Connectivity and the Expanding PHR Ecosystem 

As the 21st Century Cures Act’s FHIR API requirements have taken effect, patients using third-party health apps can increasingly pull clinical data from provider EHRs directly into independent PHR platforms. Apple Health, Google Health, and other consumer health apps support FHIR-based data retrieval from compatible EHRs, allowing patients to aggregate their health records from multiple providers into a single patient-controlled record. 

For independent practices, this means that clinical data documented in the EHR may flow to patient-controlled apps and platforms beyond the practice’s direct control. Managing this data flow appropriately, ensuring it is technically enabled as required by law, and designing patient communication that helps patients understand what data sharing means for their privacy and record management, is part of the operational responsibility that expanded API connectivity creates. 

The boundary between provider-controlled EHR data and patient-controlled PHR data is not just an operational line. It is a security boundary where specific risks require deliberate management. 

In 2024, the HHS Office for Civil Rights tracked 831 major health data breaches affecting more than 182 million people. Major incidents involving Change Healthcare, Ascension, and Kaiser Permanente dominated the headlines, but the underlying vulnerabilities, insufficient access controls, inadequate monitoring of data sharing pathways, and third-party risk from connected apps and services, are present in healthcare organizations of all sizes including independent practices. 

When a patient connects a third-party health app to a practice’s EHR through the FHIR API, the practice has fulfilled its data-sharing obligation. But the data that leaves the EHR and enters the third-party app is now subject to that app’s security practices, privacy policy, and business model, none of which are under the practice’s control. Patients who are not aware of this dynamic may not understand that the data they retrieve from the practice’s EHR and store in a consumer app is no longer protected by HIPAA once it reaches that app. 

What Practices Can and Cannot Control 

Practices can control the technical implementation of their EHR’s API access configuration, ensuring that authentication requirements are robust, access logging is enabled and reviewed, and data sharing is technically limited to the scope the patient has authorized. They can also provide patient education about the privacy implications of connecting third-party apps to their health records, helping patients make informed choices about which apps to authorize and what data to share. 

What practices cannot control is what happens to data once it is in patient hands or in a non-HIPAA-covered app. The legal responsibility for that data shifts with its ownership. Understanding this boundary clearly, and communicating it to patients who ask about their data access rights, is part of the responsible management of the EHR-PHR interface that independent practices need to navigate. 

The workflow implications of expanded patient data access converge most practically at the intersection of clinical and financial records. When patients access their health data and encounter questions about billing, the quality of the answer the practice can provide depends directly on how well its clinical and financial systems are integrated. 

A patient whose visit note is accessible through the portal but whose billing statement comes from a disconnected system is encountering the exact data fragmentation that produces the discrepancy inquiries described earlier in this blog. The clinical record says one thing. The billing statement, generated by a separate system without full visibility into the clinical documentation, may reflect different or incomplete information. The patient notices. The billing team gets a call. The investigation requires pulling records from two disconnected systems. The process takes longer and produces more uncertainty than it needs to. 

Claimity’s approach to this challenge is architectural. The platform’s AI coding engine reads clinical documentation directly from the connected EHR, meaning that the codes assigned to each claim are derived from what is actually documented in the clinical record rather than from a separate manual coding process. When a patient accesses their visit note through the practice portal and then reviews their billing statement, the diagnosis and procedure information in both reflects the same underlying clinical documentation. The alignment between clinical and billing data is not a reconciliation step that happens after the fact. It is built into the coding workflow. 

The patient-facing billing experience within Claimity’s platform functions as the financial layer of the tethered PHR relationship. Patients access their billing statements, view payment history, make payments through multiple channels, and manage payment plans through a mobile-friendly portal that connects directly to the practice’s AR system. When the billing data patients see through the portal is accurate, current, and aligned with their clinical records, the volume of billing-related data inquiries decreases, and the financial access experience reinforces rather than undermines patient trust in the practice. 

Managing the EHR-PHR landscape effectively in 2026 does not require a technology overhaul or a new compliance program. It requires deliberate attention to a set of operational practices that address the most common workflow and compliance gaps. 

Audit Your Patient Data Access Workflows 

Review how your practice currently handles patient requests for record access, amendment requests, and data discrepancy inquiries. Map the current workflow from request receipt through response delivery and identify the specific steps that introduce delay, require manual coordination between teams, or lack a defined owner. The most common gaps are: no defined routing for billing versus clinical data inquiries, no tracking system for amendment request timelines, and no documented process for responding to API-based data access requests from third-party apps. 

Verify Your EHR’s FHIR API Configuration 

Confirm with your EHR vendor that the FHIR R4 API required by the 21st Century Cures Act is enabled and configured correctly. Ensure that access logging is turned on and that you have a process for reviewing access logs periodically. Know which third-party apps have active connections to your EHR data and confirm that each connection was authorized by the relevant patient rather than opened through a configuration default. 

Align Clinical and Billing Data Flows 

Evaluate whether your current billing workflow produces claims that accurately reflect your clinical documentation. If your billing team regularly encounters situations where the clinical record and the billing data are inconsistent, that inconsistency will surface in patient data access inquiries with increasing frequency as portal and API access expands. Addressing the clinical-billing alignment gap now reduces both the compliance risk and the operational burden of patient data discrepancy management. 

Educate Patients About Their Data Access Rights and Responsibilities 

Patients who understand what data they can access, how to access it, and what happens to their data when they share it with third-party apps make better informed choices and generate fewer misdirected inquiries to the practice. A simple patient-facing summary of their data access rights, the tools available to exercise them, and the privacy implications of connecting third-party apps to their records reduces both inquiry volume and the risk of patients inadvertently sharing sensitive health data with apps whose data practices they have not fully reviewed. 

The distinction between EHRs and PHRs is not purely theoretical. It carries specific legal obligations, workflow implications, and data governance responsibilities that affect how independent practices manage patient relationships, respond to data access requests, and maintain the clinical-billing alignment that billing accuracy depends on. 

The regulatory direction is clear and consistent: patients will continue to gain more access to more of their health data through more channels as FHIR API adoption expands, patient portal capabilities improve, and consumer health apps connect increasingly sophisticated data aggregation tools to provider EHR systems. Practices that design their workflows around this reality, rather than treating expanded patient data access as an occasional compliance event, are better positioned to manage both the operational and financial implications of a healthcare data environment that is becoming more patient-centric every year. 

The practices that navigate this well are not the ones with the most sophisticated technology. They are the ones that have built operational clarity around who is responsible for what when patients ask questions about their data, have ensured that clinical and billing records are aligned closely enough to withstand patient scrutiny, and have designed patient-facing access tools that answer questions proactively rather than generating calls to the front desk. 

If your practice is evaluating how to improve the alignment between your clinical documentation, billing accuracy, and patient-facing data access experience, explore how integrated clinical-billing infrastructure can reduce the operational burden of patient data inquiries while strengthening the financial accuracy that both billing performance and patient trust depend on. 

What is the difference between an EHR and a PHR?

An EHR is a digital health record maintained and controlled by a healthcare provider or organization. It is subject to HIPAA, state medical records laws, and the information blocking provisions of the 21st Century Cures Act. A PHR is a health record controlled by the patient, allowing them to aggregate and manage health data from multiple sources. PHRs maintained independently by patients or consumer technology companies outside a covered entity relationship are not subject to HIPAA in the same way provider EHRs are. A tethered PHR, such as a patient portal that provides patient access to a provider’s EHR data, sits between these two models and is the most practically relevant category for independent practices. 

What does the 21st Century Cures Act require of independent practices?

The 21st Century Cures Act’s information blocking provisions prohibit independent practices from taking actions that unreasonably interfere with patient access to their electronic health information. This includes enabling FHIR R4 API access so patients can retrieve their data through third-party health apps, responding to access requests without unreasonable delay or unnecessary fees, and ensuring that EHR configurations support rather than impede standard data-sharing pathways. Violations can result in disincentives under Medicare and Medicaid programs, including MIPS performance score adjustments. 

Who legally owns the data in an EHR?

The legal ownership of EHR data is nuanced and varies by state law, but in general, the healthcare provider or organization is the legal custodian of the EHR record, while the patient retains a property interest in the information contained within it and has legally defined rights to access and correct that information. EHR vendors do not own the data. The practice or health system that creates and maintains the record bears legal responsibility for its accuracy, security, and accessibility. 

How does patient portal access relate to the EHR vs. PHR distinction? 

A patient portal that provides access to data from a provider’s EHR is a tethered PHR. The patient can view and in some cases interact with the data, but the underlying record remains in the provider’s control. This is different from an independent PHR where the patient controls the underlying system. Most patient portals offered by EHR vendors function as tethered PHRs. When patients connect their portal data to third-party health apps through FHIR APIs, that data may leave the tethered environment and enter a fully patient-controlled PHR where HIPAA protections no longer apply. 

What are the workflow implications of expanded patient data access for billing teams? 

Expanded patient data access increases the likelihood that patients will notice discrepancies between their clinical records and their billing statements when the two are not well aligned. This generates billing inquiry volume that the team must investigate and resolve across clinical and financial systems. Practices with strong clinical-to-billing data alignment, where coded claims accurately reflect clinical documentation and both are accessible to the billing team, handle these inquiries more efficiently and with greater confidence than practices where clinical and billing data are fragmented across disconnected systems.