HIPAA Release of Information: Authorization Guide & Requirements
What is a HIPAA Authorization?
A HIPAA authorization (also called "Release of Information" form) is a legal document signed by a patient that permits a healthcare provider to disclose the patient's protected health information (PHI) to a third party.
When Authorization is Required
- Routine disclosures: Sending records to another provider the patient is seeing
- Lawyer requests: Disclosure to patient's attorney
- Employer records: Sending records to employer or employer's insurance
- Insurance company requests: Submitting to insurance for coverage determinations
- Family members: Sharing information with spouse, parent, or adult children
- Patient request: When patient requests their own records to be sent elsewhere
When Authorization is NOT Required
- Treatment: Sharing within your practice for patient's care
- Payment: Submitting to insurance for billing purposes (routine billing)
- Healthcare operations: Using for quality improvement, credentialing, etc.
- Court order: Legal process requiring disclosure (subpoena, court order)
- Law enforcement: Valid law enforcement request
- Public health: Reporting to public health agencies (disease reporting, etc.)
- Emergency: When needed to protect patient or others in urgent situation
Required Elements of Valid Authorization
HIPAA specifies exact requirements for a valid authorization. Missing even one element makes the authorization invalid, and you cannot disclose without it.
Essential Elements (45 CFR § 164.508)
- Specific identification: Who is releasing the information (your practice name and address)
- Recipient identification: Who will receive the information (name and address of recipient)
- Records description: What specific records or types of information (dates, types of treatment)
- Purpose statement: Why the information is being disclosed (specific purpose)
- Expiration date: When the authorization expires (date or event)
- Patient signature: Signed and dated by patient or authorized representative
- Date of authorization: When the form was signed
Optional But Recommended Elements
- Right to revoke authorization (explain how patient can revoke)
- Statement about re-disclosure (whether recipient can share again)
- Expiration time/event specification
- Patient's initials next to each required element
- Vague purpose ("for my records" vs. "for orthopedic surgeon Dr. Smith for knee replacement surgery")
- No expiration date or too distant expiration ("valid forever")
- Generic authorization for "any and all records" without specific dates
- Recipient address incomplete or vague
- Unsigned or signed by someone other than patient without legal authority
Authorization Form Template & Examples
Proper Authorization Form Structure
Example 1: Proper Authorization
Good: "I authorize Dr. Smith's office to release my complete medical record from January 1, 2024 to December 31, 2024 to Dr. Sarah Johnson, Orthopedic Associates, 456 Oak Street, Springfield, IL for treatment of my knee injury. This authorization expires December 31, 2024."
Example 2: Improper Authorization
Bad: "Release all my medical records." [Missing: recipient, purpose, specific dates, expiration]
Example 3: HIPAA-Compliant Broad Authorization
Good (when appropriate): "I authorize Dr. Smith's office to release my complete medical record to my attorney, John Counsel, Esq., Counsel Law Firm, 789 Legal Ave, Chicago, IL for purposes of litigation support related to my workers' compensation claim filed in 2023. This authorization expires December 31, 2025."
Authorization Best Practices & Common Issues
1. Obtain Specific Authorizations for Sensitive Information
HIPAA requires a specific authorization for:
- Psychotherapy notes: Separate authorization required (never routinely released)
- Mental health records: Many states require separate authorization
- Substance abuse records: Federal law (42 CFR Part 2) requires separate specific authorization
- HIV/AIDS records: Many states require separate authorization
2. Handling Verbal Requests
If a patient calls and verbally requests records be sent:
- You MUST get written authorization before releasing
- Do not release based on verbal request alone
- Mail authorization form and request patient return it signed
- Or use electronic signing (DocuSign, etc.) for faster authorization
- Keep copy of signed authorization in patient file
3. Handling Family Member Requests
When family members request patient records:
- Adult patients: Require patient authorization (HIPAA default)
- Minors: Parent/guardian can request (they have legal authority)
- Deceased patients: Personal representative (executor, next of kin) can request
- Incapacitated patients: Guardian, POA, or court-appointed representative
4. Record Retention
Keep authorization forms permanently:
- Store with patient's medical record
- Keep for at least 6 years (HIPAA minimum) or per state law (often 7-10 years)
- Include copy of what was disclosed and when
- Helpful for defending against privacy complaints
5. Denying Requests Without Valid Authorization
If patient requests records but no valid authorization exists:
- Do not release
- Inform patient of authorization requirement
- Provide blank authorization form
- Give timeframe for returning signed form
- Document the interaction
Electronic Authorizations & eSignature
Are E-Signatures Valid for HIPAA Authorization?
Yes, electronic signatures are valid and increasingly common:
- HIPAA does not require wet-ink signatures
- Secure electronic signatures meet HIPAA requirements
- Must use reputable eSignature platform (DocuSign, HelloSign, etc.)
- Must verify signer identity
- Must maintain signed copy as part of medical record
Electronic Authorization Best Practices
- Use secure, authenticated eSignature platform
- Send via secure link (encrypted email, secure portal)
- Verify patient identity before sending
- Save signed copy to patient's EHR
- Set expiration date for signature deadline
Frequently Asked Questions
Yes, at any time.
Patient rights include:
- Revoking authorization in writing at any time
- Revocation effective immediately upon receipt (not retroactively)
- Revocation does not undo previous disclosures already made
If you receive written revocation, stop all further disclosures under that authorization. Acknowledge receipt in writing and file with authorization form.
Do NOT release records not listed in authorization.
Only release what is specifically authorized. If patient wants additional records:
- Contact patient for new or amended authorization
- Or obtain new authorization covering additional records
- Do not assume "complete medical record" means mental health if mental health is sensitive
Being overly generous with what you release ("I'll include additional records the patient might find helpful") is a HIPAA violation.
Generally no. Insurance billing is part of healthcare operations:
- Patient's treatment implicitly authorizes you to submit to insurance
- However, it's best practice to disclose that you will bill insurance
- Include in intake paperwork or privacy notices
- If patient objects to insurance submission, honor that request
Note: Submitting to insurance is routine; disclosing for OTHER purposes (employer liability, disability, etc.) requires separate authorization.
Substance abuse records have stricter rules (42 CFR Part 2):
- Requires federal compliance, not just HIPAA
- Must have separate, specific authorization form
- Standard HIPAA authorization is NOT sufficient
- Must include patient statement about re-disclosure restrictions
- Cannot condition treatment on authorization
Many practices incorrectly use standard HIPAA authorization for substance abuse records. Use the federal Form OAS 91, which is specifically designed for this purpose.
Yes, but limited by HIPAA and state law:
- Allowed charges: Reasonable reproduction costs (paper, copying, postage)
- HIPAA limit: Cannot charge for labor to prepare records (much debate)
- State variations: Some states allow higher fees; others are more restrictive
- Patient access: If patient requests their OWN records, fees are very limited ($0-$15 typically)
- Fee estimates: Provide patient with estimate before copying
Check your state's medical records access law—it often allows lower fees than HIPAA does.
Need Help With Release of Information Compliance?
Medcurity helps healthcare organizations develop and implement compliant Release of Information policies and procedures. We provide sample authorization forms, staff training, and audit services to ensure compliance.
Get ROI Compliance Support