Bindinglaw

US · guidance

CMS SOM App. C, Tag D5801

§493.1291 Standard: Test report

activein force · 2026-07-22 – presentas-observed

(a) The laboratory must have an adequate manual or electronic system(s) in place to

ensure test results and other patient-specific data are accurately and reliably sent

from the point of data entry (whether interfaced or entered manually) to final

report destination, in a timely manner. This includes the following:

Interpretive Guidelines §493.1291(a)

The regulations apply to manual as well as automated record systems (e.g., a laboratory

information system or LIS). Regardless of the means used to transmit laboratory results,

routine checks should be conducted to verify that transmissions are being accurately and

reliably conveyed to the final report destination.

For CLIA purposes, the final report destination for test results is considered to be the

authorized person and/or their designated personal representative (a personal

representative is generally a person authorized under applicable law to make health care

decisions for the individual). See 45 CFR §164.502(g). Additional individuals or

entity(s) who are responsible for using the test results may also receive test results from

the laboratory if they are designated by the authorized person on the test requisition. As

of April 7, 2014, a new CLIA regulation was added at § 493.1291(l) in order to provide

patients with more access to laboratory test report(s). In accordance with amendments to

the HIPAA Privacy Rule, the new regulation states: “Upon request by a patient (or the

patient's personal representative), the laboratory may provide patients, their personal

representatives, and those persons specified under 45 CFR 164.524(c)(3)(ii), as

applicable, with access to completed test reports that, using the laboratory's

authentication process, can be identified as belonging to that patient”. The HIPAA

Privacy Rule preempts contrary state laws on patient access to laboratory test report(s),

but where a HIPAA-covered laboratory can continue to comply with both the HIPAA

Privacy Rule and state law, it must frame its policies and procedures in a way that

complies with both laws. Further, the HIPAA Privacy Rule does not preempt more

stringent state laws, even if contrary to the Privacy Rule. CLIA laboratories that are not

subject to HIPAA will have discretion to provide patients with direct access to their

laboratory test reports, subject to any applicable state laws that may constrain access.

To ensure the accurate, timely, confidential, and easily understood reporting of patient

test results to the authorized person, their personal representative (if applicable) and

others who are identified as responsible for using the test results on the requisition, a

laboratory may contract with another entity to assist in the delivery of patient reports in a

manner that complies with all applicable laws, including the CLIA regulatory and

statutory requirements. Please note that if the laboratory is subject to HIPAA and the

entity with which it contracts meets the HIPAA definition of a business associate, see 45

CFR §160.103 (definition of “business associate”), the laboratory’s contract or other

written arrangement with its business associate must contain the elements specified at 45

CFR §164.504(e).

Probes §493.1291(a)

How does the laboratory ensure that transmitted reports are legible and the information

received at the final destination was the same data sent by the laboratory?

If the laboratory uses a LIS or facsimile, what security measures have been instituted to

ensure that transmitted reports go directly from the device sending reports to the

authorized person, their personal representative (if applicable), and others who are

identified as responsible for using the test results on the requisition?

How does the laboratory ensure data safety for internal and external electronic

communications?

§493.1291 Standard: Test report.

(a)(1) Results reported from calculated data.

(a)(2) Results and patient-specific data electronically reported to network or

interfaced systems.

(a)(3) Manually transcribed or electronically transmitted results and patient-specific

information reported directly or upon receipt from outside referral laboratories,

satellite or point-of-care testing locations.

Interpretive Guidelines §493.1291(a)(3)

Manually transcribed or electronically transmitted results from an outside referral

laboratory or from within the laboratory system (e.g., satellite or point-of-care testing

locations) must be periodically verified for accuracy and timely reporting.

History

Rev. 233; Issued: 09-12-25; Effective: 09-12-25; Implementation: 09-12-25

Provenance

Source
cms.gov
Retrieved
2026-07-22
Edition
som-2026-07-22
Content hash
1bd5dedfb1630e882a2d538aab0e7d29bb17be0a318b2f06a0135fad4a9ca7ee
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS SOM App. C, Tag D5801 — §493.1291 Standard: Test… · binding.law