ChartRequest vs Ontellus: PI Record Retrieval in 2026
The best medical record retrieval service for a personal injury law firm is the one that supports the firm’s actual legal request paths, exposes every request and fee, and delivers complete records, bills, images, and certifications into a controlled matter workflow. ChartRequest, Ontellus, and ChartSwap represent different service and exchange models; none should win solely because its website promises speed.
A defensible shortlist starts before the demo. Separate patient right-of-access, authorization-supported disclosure, subpoena, court-order, and provider-discovery work. Then test each finalist with partial delivery, a rejected authorization, a duplicate request, a missing bill, an imaging request, a custodian fee, and a secure downstream share. A status dashboard is useful only if its states match what staff must do next.
This review was completed July 22, 2026. It provides operational information, not legal, medical, privacy, or compliance advice. Counsel should determine the lawful request route, authority, scope, fee rules, retention, and disclosure requirements for each jurisdiction and set of facts.
TL;DR
Put ChartRequest on the shortlist when a managed retrieval workflow, request aging, provider follow-up, and a legal-team dashboard are central requirements.
Put Ontellus on the shortlist when retrieval must connect to controlled third-party review and viewing evidence; verify the broader retrieval scope separately from its Secure Share feature.
Put ChartSwap on the shortlist when its requester-provider exchange reaches the custodians the firm actually uses and its per-transaction economics are transparent.
Do not ask “Who is fastest?” Ask for median, 80th-percentile, and oldest-open age by request type, plus what the vendor excludes from its clock.
Keep legal-route selection, scope, relevance, dispute strategy, certification need, and matter-readiness decisions with qualified firm personnel.
HIPAA access allows 30 days plus one possible 30-day extension.
ChartSwap says its exchange processes over 4,000 requests daily.
The illustrative expected case reaches payback in 8.4 months.
Quick-answer FAQs up top
What is the best medical record retrieval service for a PI firm?
There is no universal winner; the best fit covers the firm’s custodians and request routes while making ownership, aging, fees, and completeness visible. Shortlist ChartRequest, Ontellus, and ChartSwap, then run the same scenario test against all three.
Is a HIPAA authorization the same as a right-of-access request?
No. They are distinct mechanisms with different operational and legal questions. Counsel should select the route; the workflow should store the selected authority, signed document, scope, recipient, expiration, and reviewer without silently converting one route into another.
Can a retrieval vendor request medical bills too?
Often, but the firm should verify bills as a separate deliverable. A “complete” records request can still lack itemized bills, billing affidavits, imaging, or certification, so each component needs its own requested, received, validated, and waived state.
How should a firm compare turnaround time?
Compare like with like. Request median and tail age by provider and deliverable, define when the clock starts and stops, and distinguish first file received from a quality-checked complete packet.
What security proof should a law firm request?
Ask for the security materials appropriate to the engagement, access model, auditability, subcontractors, incident process, retention, deletion, and contract terms. A badge or broad “HIPAA compliant” statement does not establish that the proposed matter workflow is safe or legally appropriate.
Should a small firm outsource every request?
Not necessarily. A low-volume firm with concentrated providers and a disciplined internal process may spend less using an exchange or controlled in-house workflow. Managed retrieval becomes more attractive when provider discovery, repeated follow-up, exceptions, and status reconstruction consume meaningful capacity.
Who this is for
This matrix is for plaintiff-firm legal operations leaders, litigation support managers, case managers, paralegals, and attorneys responsible for dozens or hundreds of open record components. It is especially relevant when the firm has multiple offices, more than one intake or case-management system, inconsistent requester practices, or no reliable answer to “Which matters are blocked by records?”
The buyer should already know who can approve a request, what constitutes sufficient authority, where original documents live, who may receive PHI, and when an incomplete packet blocks demand preparation or expert review. If those decisions are undocumented, buying a vendor first merely digitizes ambiguity. The detailed medical-record release request workflow is a useful precursor for mapping authorization and release controls.
Firms still defining the handoff between request, upload, review, and matter filing should map it with the broader legal document collection automation blueprint before scoring vendors. That prevents the comparison from ending at “file downloaded.”
| Retrieval path | Operational trigger | Required control | Never automate as fact |
|---|---|---|---|
| Individual right of access | Client or personal representative requests access | Verify identity/authority, scope, format, receipt date | That every third-party request qualifies |
| Authorization-supported disclosure | Counsel approves a signed authorization | Version, expiration, recipient, provider requirements | That a signature cures every defect |
| Subpoena or court process | Counsel selects litigation route | Jurisdiction, service, objections, proof, deadline | Legal sufficiency or response obligation |
| Provider discovery | Treatment history indicates another custodian | Source, confidence, human confirmation | That a named provider treated the client |
| Supplemental request | Packet is incomplete or new treatment exists | Missing component, prior request ID, date range | That the first delivery is complete |
HHS itself warns against collapsing the routes. According to HHS’s medical-records page, the Privacy Rule generally gives an individual access to 2 named record categories—medical records and billing records—and that page was reviewed May 30, 2025. It also says search or retrieval labor cannot be charged on that individual access path. State law, the Ciox order, litigation procedure, and the specific requester still require legal review.
Do not buy a managed service if the firm handles only a handful of predictable requests, cannot name a process owner, or expects software to decide legal authority. Do not buy orchestration when the selected vendor and case-management system already provide a complete, monitored handoff with an adequate exception queue.
How the automation works
1. Open one request component, not one vague matter task
Create a separate component for each custodian, date span, and deliverable: records, itemized bills, imaging, certification, affidavit, or other counsel-approved item. Link it to the matter without placing unnecessary PHI in notifications or reporting views. Assign an owner and target date.
2. Route authority to human review
Present the candidate route, available authorization, client relationship, requested scope, and known provider rules to qualified staff. The reviewer chooses the route and confirms the packet. Automation may check missing signatures, dates, or identifiers; it should not declare an authorization, subpoena, or court order legally sufficient.
For individual access, timing must be modeled accurately. According to HHS right-of-access guidance, a covered entity generally must act within 30 calendar days and may take one extension of up to 30 additional calendar days when it gives the required written notice. Those are outer limits for that pathway, not a service-level promise for every legal request.
3. Submit with a collision-resistant key
Generate a key from matter, custodian, component, date span, and approved request version. Before sending, search the vendor and internal ledger for an active or completed equivalent. If a retry occurs, reuse the key. A duplicate check should never suppress a deliberate supplemental request; it should show the possible match to staff.
US Tech Automations can configure this step to pull an approved request from a supported source, validate required staging data, create the vendor/API submission when technically available, persist both IDs, and route a rejected or ambiguous submission to a named queue. ChartRequest, Ontellus, ChartSwap, and the firm’s case system are custom/API connections only if their current interfaces, plans, and contracts support the design.
4. Normalize status without erasing vendor detail
Keep the raw vendor state and map it to a smaller operational state such as prepared, sent, acknowledged, provider action, fee review, partial, exception, complete, or closed. Store every change with timestamp, source, and actor. Never overwrite “partial” with “complete” merely because a file arrived.
In an illustrative worked example, a firm stages 438 components across 160 matters and records each received file with the real HL7 FHIR field DocumentReference.status; 301 references are current, 19 are superseded after corrected deliveries, 4 are entered-in-error, 37 components remain partial, and 12 duplicate submission attempts are stopped by the internal key. HL7 defines 3 allowed R4 values for that field, but the firm’s request states remain separate because document validity does not prove packet completeness or legal usability.
5. Validate the packet and downstream share
Compare the received manifest to the approved request. Check client, custodian, service dates, page range, component type, duplicates, gaps, file readability, certification, and virus scan as applicable. Route clinical relevance, evidentiary sufficiency, or legal strategy to qualified reviewers.
Ontellus shows why delivery controls deserve their own test. According to Ontellus, Secure Share describes a 4-step flow—approve a recipient, select records, optionally set a viewing expiration, and send—and offers viewing reports. That page evaluates sharing functionality, not the legality of a request or the completeness of a retrieval.
After validation, the firm can hand approved artifacts into its legal document collection recipe, preserving the vendor request ID and original controlled copy. US Tech Automations can then monitor missing components, draft reminders, reconcile delivery manifests, and open exceptions through a partner-supported implementation; human staff retain request authority and final matter-readiness decisions.
| Exception | Machine check | Evidence shown to reviewer | Human decision |
|---|---|---|---|
| Rejected authority | Vendor code, packet version | Form, rejection, route, recipient | Correct, change route, or stop |
| Partial delivery | Requested vs received manifest | Missing bills/images/dates | Supplement, accept, or clarify |
| Duplicate packet | Hash, custodian, dates | Both deliveries and request IDs | Supersede, merge, or retain |
| Unexpected fee | Quote vs invoice | Fee lines, route, provider notice | Approve, challenge, or reroute |
| Wrong-client risk | Identifier mismatch | Minimum necessary comparison | Quarantine and investigate |
| Stalled request | Age and last action | Timeline, owner, next step | Escalate, extend, or close |
Benchmarks
Public vendor numbers are useful for diligence questions, not for forecasting a firm’s result. According to ChartRequest, its May 2026 buyer guide uses 7 comparison areas: turnaround, cost clarity, dashboard visibility, communication, legal workflow support, security/compliance, and proof. The page is vendor-authored, so a finalist should demonstrate each area with the firm’s scenarios and references.
Network scale also needs verification at custodian level. According to ChartSwap, the vendor reports more than 190,000 providers and over 4,000 daily requests plus 95% of U.S. legal requesters. Those are vendor claims, not proof that a particular hospital, billing entity, geography, or request type will transact through the exchange.
Build a baseline from 60 to 90 days of the firm’s own work. Sample both completed and still-open requests so fast successes do not hide the tail.
| Illustrative metric | Current baseline | 90-day control target | Measurement rule |
|---|---|---|---|
| Components submitted with approved route | 71% | 98% | Route approval / submitted |
| First-pass accepted packets | 76% | 90% | No authority correction |
| Components with visible next action | 58% | 96% | Owner + action + due date |
| Duplicate submissions per 1,000 | 31 | 5 | Confirmed equivalent requests |
| Delivered packets missing a requested item | 18% | 7% | Manifest validation |
| Staff handling minutes per component | 24 | 13 | Active-time sample |
| Open components older than 45 days | 84 | 35 | Cohort aging |
Every value is illustrative, not an industry or vendor benchmark. Segment by route, custodian, component, provider geography, vendor, and matter stage.
Tool / build comparison
Do not interpret “best” as one ranked list. These candidates represent different operating models, and the public pages do not expose enough current contractual detail to score price, provider coverage, or service levels conclusively.
The destination also changes the handoff test. Use the Filevine versus Clio Manage PI comparison to decide which system should own matter documents, activities, and downstream review before asking a retrieval vendor to demonstrate its export.
| Option | Strongest reason to test | Scenario to demonstrate | Contract question |
|---|---|---|---|
| ChartRequest / CaseBinder | Managed legal retrieval and status workflow | Rejected authorization plus missing bill | Included follow-up, aging, fees, export |
| Ontellus | Retrieval ecosystem plus controlled expert sharing | Records, bills, IME share, expired access | Retrieval scope vs add-on scope |
| ChartSwap | Requester-provider exchange | In-network and out-of-network custodians | Transaction and custodian fees |
| Internal build | Concentrated providers and unique controls | Duplicate-safe submission and manifest check | Maintenance, portal changes, security |
| Orchestrated stack | Good tools with weak cross-system handoffs | Vendor delivery to matter-ready queue | API rights, monitoring, exit export |
A neutral scorecard should weight coverage and legal-path fit before cosmetics. Give every finalist the same synthetic or approved test data.
| Evaluation dimension | Weight | ChartRequest | Ontellus | ChartSwap |
|---|---|---|---|---|
| Custodian and request coverage | 20% | Test | Test | Test |
| Route and authority controls | 15% | Test | Test | Test |
| Status, aging, and ownership | 15% | Test | Test | Test |
| Records, bills, images, certification | 15% | Test | Test | Test |
| Fee visibility and invoice detail | 10% | Test | Test | Test |
| PHI security and audit evidence | 10% | Test | Test | Test |
| Case-system handoff and export | 10% | Test | Test | Test |
| Support and implementation | 5% | Test | Test | Test |
Scores are intentionally blank until the firm observes the scenarios. Require security review, contract review, reference calls, sample invoices, complete export, deletion/retention behavior, accessibility, business continuity, support escalation, and current pricing.
Cost and payback
Use the firm’s handling data rather than a vendor productivity claim. Labor is only one input: include vendor charges, custodian fees, implementation, security/legal review, integration, training, ongoing administration, and retained quality review.
According to the U.S. Bureau of Labor Statistics, the May 2024 median for paralegals and legal assistants was $61,010 annually or $29.33 hourly, with legal-services median pay of $59,800. Those are occupational wages, not loaded firm cost or retrieval-handling benchmarks.
Let Q be monthly components, M current active minutes, A automated or vendor-removed share, R retained review minutes, L loaded hourly cost, S monthly service and support, and I one-time implementation. Monthly net is Q × ((M × A − R) ÷ 60) × L − S; simple payback is I ÷ monthly net when net is positive.
| Illustrative input | Low volume | Expected case | High volume |
|---|---|---|---|
Components per month (Q) | 180 | 650 | 1,800 |
Current minutes/component (M) | 18 | 26 | 31 |
Handling removed (A) | 30% | 52% | 61% |
Retained review minutes (R) | 4 | 5 | 7 |
Loaded hourly cost (L) | $42 | $48 | $55 |
Monthly service/support (S) | $800 | $1,100 | $5,000 |
One-time implementation (I) | $9,000 | $28,000 | $82,000 |
| Illustrative output | Low volume | Expected case | High volume |
|---|---|---|---|
| Gross capacity value/month | $1,134 | $7,030 | $31,207 |
| Retained-review cost/month | $504 | $2,600 | $11,550 |
| Net after service/month | -$170 | $3,330 | $14,657 |
| Annual operational net | -$2,040 | $39,960 | $175,884 |
| Simple payback | None | 8.4 months | 5.6 months |
| Net with 25% lower handling removal | -$794 | $1,573 | $6,851 |
These results are illustrative and depend heavily on an assumed $1,100 expected-case monthly service cost, not a vendor quote. The expected 8.4-month payback disappears quickly if recurring cost, retained review, or handling removal differs. A firm should publish one approved model with its actual quote and observed pilot data.
Key Takeaways
The legal request route is a controlled input, not a vendor default.
ChartRequest, Ontellus, and ChartSwap should face the same custodian, exception, fee, and handoff tests.
“Delivered” is not “complete”; validate records, bills, images, certification, dates, and duplicates separately.
Measure the long tail, not a best-case turnaround average.
Preserve raw vendor status, cross-system IDs, source documents, decisions, and retries.
A firm that cannot define an owner and matter-readiness rule is not ready to automate this workflow.
US Tech Automations builds, runs, and supports custom AI workflows and offers a self-managed option. For a monitored retrieval ledger, exception queue, and controlled case-system handoff, review the agentic workflow platform. The firm and qualified counsel remain responsible for legal route, request scope, PHI permissions, vendor diligence, and final use of the records.
About the Author

Helping businesses leverage automation for operational efficiency.
Related Articles
See how AI agents fit your team
US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.
View pricing & plans

