Minnesota Health Records Act
MN Health Records Act
Health
Minnesota's health privacy statute, stricter than HIPAA in key respects, generally requires a signed and dated patient consent before a provider (or anyone who received records from a provider) releases health records, even for many treatment and payment disclosures, with limited exceptions such as emergencies and current treatment within related entities. It also gives patients rights to see and copy their records within 30 days at capped fees, and lets patients sue for unauthorized release.
- Where
- Minnesota
- Citation
- Minn. Stat. 144.291 to 144.298 (including 144.2925)
- Status
- In force
- Enforced by
- Patients by civil action; licensing boards through disciplinary action (144.298)
- People can sue
- Yes
- Penalties
- Anyone who negligently or intentionally requests or releases records in violation of the Act, forges or alters consent forms, obtains records under false pretenses, or intentionally accesses a record locator service without authorization is liable to the patient for compensatory damages plus costs and reasonable attorney fees; violations may also be grounds for professional discipline (144.298).
- Applies to
- Health care providers and persons who receive health records from providers (144.293, subd. 2)
- Group purchasers and health information exchanges operating record locator or patient information services (144.293, subd. 8)
- Protects patients, including representatives and, for minors, parents or guardians (144.291, subd. 2(g))
What a privacy notice must say
- Provide patients a clear and conspicuous written notice of disclosures that may be made without consent and of their rights to access and copy their records.Minn. Stat. 144.292, subd. 4
Rights it gives people
- Give patients complete and current information on diagnosis, treatment, and prognosis, and copies of their records, within 30 days of a written request, charging no more than the statutory fee caps (no fee for copies to review current care).Minn. Stat. 144.292, subds. 2, 5-6
Practices it requires
- Do not release a patient's health records without a signed and dated patient consent, specific authorization in Minnesota law, or a representation from a provider holding such consent; consents generally last one year.Minn. Stat. 144.293, subds. 2, 4
- Record locator services must keep audit logs of provider access and let patients opt out; group purchasers may not require provider participation.Minn. Stat. 144.293, subd. 8 · Only if: Applies to providers, group purchasers, and health information exchanges using record locator or patient information services
Other duties
- Document in the patient's record any release made without patient consent as authorized by law, and document releases made on another provider's representation of consent.Minn. Stat. 144.293, subd. 9
- The Act must be construed to protect patient health record privacy more stringently than the HIPAA Privacy Rule (45 C.F.R. part 164), as 'more stringent' is defined in 45 C.F.R. 160.202.Minn. Stat. 144.2925
Sources
- Official text
- Minn. Stat. 144.291 (Office of the Revisor of Statutes)
- Minn. Stat. 144.292
- Minn. Stat. 144.293
- Minn. Stat. 144.298
- Minn. Stat. 144.2925 (added by Laws 2024, ch. 127)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Recent amendments not dated: Laws 2024, ch. 127, art. 66 (144.292, 144.293), Laws 2025, ch. 20, s. 118 (144.291), and Laws 2026, ch. 127, art. 1, s. 29 (144.293, subd. 7); their effective dates were not confirmed, so last_amended is null. | The Act was recodified from former 144.335 by Laws 2007, ch. 147, art. 10; the original effective date was not verified. | Sections 144.294 to 144.297 (mental health records, records for external research, etc.) were not read.
Research reference, not legal advice.