/regulations

Minnesota Health Records Act Regulations for Healthcare in Minnesota

Explore key regulations of the Minnesota Health Records Act for healthcare providers and patients in Minnesota. Stay compliant and informed.

Contact Us

Reviewed by Jeff Harms

Director, Advisory Services at OCD tech

Updated June, 19

Minnesota Minnesota Health Records Act Main Criteria for Healthcare

Explore key Minnesota Health Records Act criteria for healthcare, ensuring patient privacy, data security, and compliance with state regulations.

Patient Consent Requirements

  • Minnesota requires written patient consent for nearly all disclosures of health records, which is more restrictive than HIPAA
  • Consent forms must include specific elements including who can release and receive information, expiration date, and statement of patient's right to revoke consent
  • Healthcare providers must implement consent tracking systems that can verify consent status before releasing any protected health information

Minor Consent Provisions

  • Minnesota law grants special privacy protections for minors seeking certain healthcare services (mental health, substance abuse, STI testing)
  • Systems must be configured to segregate minor-protected records from parents' access in patient portals
  • Healthcare providers must implement technical controls to prevent unauthorized disclosure of minor-protected information even to parents/guardians

Record Retention Requirements

  • Health records must be maintained for a minimum of 7 years after the last patient contact, longer than some federal standards
  • Electronic storage systems must include Minnesota-compliant backup protocols that ensure data integrity throughout the retention period
  • Proper destruction certification must be documented when disposing of records after the retention period expires

Health Record Access Timelines

  • Minnesota requires providers to furnish copies of health records within 7 business days for non-emergency requests (stricter than HIPAA's 30 days)
  • Providers must have expedited access procedures allowing records to be furnished immediately in emergency situations
  • Systems must maintain access request logs documenting compliance with these state-specific timelines

Breach Notification Requirements

  • Minnesota requires notification to affected patients no later than 4 business days after discovery of unauthorized access
  • Organizations must maintain a Minnesota-specific breach response plan that meets these accelerated notification timelines
  • The notification must include specific content elements required by Minnesota law beyond federal requirements

Release Fee Limitations

  • Minnesota law sets specific maximum fees that can be charged for copies of health records ($0.75 per page for paper records with different rates for electronic records)
  • Billing systems must be configured to automatically calculate compliant fees based on Minnesota's fee schedule
  • Providers must furnish records without charge to patients receiving public benefits or appealing denial of Social Security disability benefits

Secure Your Business with Expert Cybersecurity & Compliance Today
Contact Us

Achieve Minnesota Minnesota Health Records Act for Healthcare with OCD Tech—Fast & Secure

Don’t let security gaps slow you down. Partner with OCD Tech’s seasoned cybersecurity experts to tailor a robust, framework-aligned protection plan. From uncovering hidden vulnerabilities to mapping controls against Minnesota Health Records Act, we’ll streamline your path to certification—and fortify your reputation.

What is...

What is Minnesota Minnesota Health Records Act for Healthcare

 

Understanding the Minnesota Health Records Act (MHRA)

 

The Minnesota Health Records Act (MHRA) is a state law that governs how healthcare providers in Minnesota handle patient medical information. It provides additional protections beyond HIPAA (the federal healthcare privacy law) and contains Minnesota-specific requirements that all healthcare organizations in the state must follow.

 

Key Provisions of the Minnesota Health Records Act

 

  • The MHRA requires specific written patient consent for nearly all disclosures of health records, which is more restrictive than HIPAA
  • Minnesota law defines "health records" as any information, whether oral, written, electronic, or in any other form, that relates to the past, present, or future physical or mental health of a patient
  • Healthcare providers must obtain separate authorization for each release of information unless specific exceptions apply
  • Minnesota requires that consent forms include specific elements including the name of the patient, the specific information to be released, the specific purpose for the release, and an expiration date or event

 

Minnesota-Specific Patient Rights

 

  • Patients have the right to access their health records within 7 business days after submitting a written request (faster than HIPAA's 30-day timeframe)
  • Providers may charge patients state-regulated fees for copies of their health records ($0.75 per page for paper records, with a $10.00 retrieval fee)
  • Minnesota patients have a right to submit a written statement of disagreement with their records, which must be kept with and released alongside the disputed record
  • There are special protections for certain sensitive health information including mental health records, HIV/AIDS testing and treatment, and substance abuse treatment records

 

Key Differences Between MHRA and HIPAA

 

  • HIPAA allows many disclosures for treatment, payment, and healthcare operations without patient authorization, but the MHRA generally requires patient consent for these activities
  • Minnesota law has a narrower definition of "emergency" for when information can be shared without consent
  • The MHRA provides stronger protections for deceased patients (health records remain private for 50 years after death)
  • Minnesota prohibits the release of health records for marketing purposes without specific authorization

 

Exceptions to the Consent Requirement

 

  • Medical emergencies when the provider is unable to obtain consent
  • Disclosures mandated by law, such as reporting communicable diseases or suspected child abuse
  • Certain public health activities as authorized by law
  • Limited information sharing for internal quality improvement activities within a healthcare facility
  • Disclosures for healthcare facility directories, unless the patient has specifically opted out

 

Cybersecurity Implications for Minnesota Healthcare Providers

 

  • Healthcare organizations must implement stricter access controls to ensure that health information is only accessed with proper authorization
  • Systems must be designed to track and document patient consent for each disclosure of information
  • Electronic health record systems must have robust audit capabilities to monitor who accesses patient information and when
  • Organizations need technical safeguards to prevent unauthorized access, including encryption, multi-factor authentication, and secure transmission methods
  • Providers must have policies and procedures specific to Minnesota requirements, not just HIPAA compliance

 

Penalties for MHRA Violations

 

  • Individuals who violate the MHRA may face civil liability to the patient
  • Healthcare providers can be subject to professional discipline for improper disclosure of health records
  • Intentional violations may result in criminal penalties including gross misdemeanor charges
  • The Minnesota Department of Health can impose administrative penalties for violations
  • MHRA violations may also constitute HIPAA violations, potentially triggering federal penalties as well

 

Best Practices for MHRA Compliance

 

  • Develop Minnesota-specific consent forms that meet all MHRA requirements
  • Implement staff training programs that emphasize the stricter Minnesota requirements
  • Conduct regular security risk assessments that address both HIPAA and MHRA requirements
  • Establish clear procedures for patient requests to access their records
  • Maintain detailed documentation of all disclosures, including the specific consent obtained
  • Implement data breach response plans that address both federal and Minnesota notification requirements
  • Regularly audit systems and practices to ensure ongoing compliance

 

Recent Updates and Developments

 

  • Minnesota has expanded provisions for sharing information through Health Information Exchanges (HIEs) while maintaining consent requirements
  • The state has clarified rules regarding telehealth services and the sharing of information across state lines
  • There are ongoing efforts to harmonize state and federal requirements while maintaining Minnesota's stronger privacy protections
  • Minnesota has enhanced requirements for notifying patients of breaches involving their health information

 

Read More

Looking for compliance insights across other regions, industries, and regulatory frameworks? Explore our collection of articles covering key compliance requirements and best practices tailored to different sectors and locations.

SOC 1

New Jersey

Legal / Accounting / Consulting

SOC 1 Regulations for Legal / Accounting / Consulting in New Jersey

Explore SOC 1 regulations for legal, accounting, and consulting firms in New Jersey to ensure compliance and secure client trust.

Learn More

SOC 2

New Jersey

Insurance

SOC 2 Regulations for Insurance in New Jersey

Explore SOC 2 regulations for insurance in New Jersey to ensure compliance and data security in the insurance industry.

Learn More

FERC Standards

Florida

Energy / Utilities

FERC Standards Regulations for Energy / Utilities in Florida

Explore FERC standards and regulations shaping Florida's energy and utilities sector for compliance and efficiency.

Learn More

RCRA

Texas

Energy / Utilities

RCRA Regulations for Energy / Utilities in Texas

Explore key RCRA regulations impacting Texas energy and utilities for compliance and environmental safety.

Learn More

CFATS

Texas

Energy / Utilities

CFATS Regulations for Energy / Utilities in Texas

Explore CFATS regulations for energy and utilities in Texas to ensure compliance and enhance facility security.

Learn More

ISO 13485

Florida

Pharmaceutical / Biotech / Medical Devices

ISO 13485 Regulations for Pharmaceutical / Biotech / Medical Devices in Florida

Explore ISO 13485 regulations for pharmaceutical, biotech, and medical devices in Florida to ensure compliance and quality management.

Learn More

Customized Cybersecurity Solutions For Your Business

Contact Us

Frequently asked questions

What services does OCD Tech provide?

OCD Tech offers a comprehensive suite of cybersecurity and IT assurance services, including SOC 2/3 and SOC for Cybersecurity reporting, IT vulnerability and penetration testing, privileged access management, social engineering assessments, virtual CISO (vCISO) support, IT general controls audits, WISP development, and compliance assistance for frameworks like CMMC, DFARS, and FTC Safeguards.

Which industries does OCD Tech serve?

OCD Tech specializes in serving highly regulated sectors such as financial services, government, higher education, auto dealerships, enterprise organizations, and not-for-profits throughout New England.

How long does an IT security assessment take?

Typically, OCD Tech’s on-site work spans 1–2 days, depending on complexity and number of sites, followed by 1–2 weeks of analysis and reporting to deliver clear, actionable recommendations.

Why should I get SOC 2 compliant?

SOC 2 reporting demonstrates to clients and prospects that an organization follows best-in-class controls over security, availability, processing integrity, confidentiality, and privacy—boosting trust, meeting RFP/due diligence requirements, and helping secure contracts. OCD Tech helps organizations achieve and maintain this compliance.

Can OCD Tech help me with federal cybersecurity regulations?

Yes—OCD Tech provides guidance for compliance with DFARS (NIST 800‑171), CMMC (Levels 1–3), and FTC Safeguards, ensuring organizations meet specific government or industry-based cybersecurity mandates.

What is a virtual CISO (vCISO), and do I need one?

A virtual CISO delivers strategic, executive-level cybersecurity leadership as a service. OCD Tech’s vCISO service is ideal for organizations lacking a full-time CISO and helps build programs, define policy, oversee risk, and guide security maturity.

Does OCD Tech offer ongoing security training or audits for staff?

Absolutely. OCD Tech provides tailored internal IT Audit training and security awareness sessions, plus annual reviews of Written Information Security Programs (WISP), such as Massachusetts 201 CMR 17 and other state or industry-specific controls.

Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

OCD Tech

25 BHOP, Suite 407, Braintree MA, 02184

844-623-8324

https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
SOC 2 ® Readiness Assessment
SOC 2 ®
SOC 3 ®
SOC for Cybersecurity ®
IT Advisory Services
IT Vulnerability Assessment
Penetration Testing
Privileged Access Management
Social Engineering
WISP
General IT Controls Review
IT Government Compliance Services
CMMC
DFARS Compliance
FTC Safeguards vCISO

Industries

Financial Services
Government
Enterprise
Auto Dealerships