Medcurity Get Compliance Help

HIPAA Release of Information: Authorization Guide & Requirements

Quick Answer: HIPAA requires a signed authorization form before releasing patient records. The authorization must specify: who is releasing information, who receives it, what records, the purpose, expiration date, and be signed by the patient or authorized representative. Without valid authorization, disclosure is a HIPAA violation and potential breach.

What is a HIPAA Authorization?

A HIPAA authorization (also called "Release of Information" form) is a legal document signed by a patient that permits a healthcare provider to disclose the patient's protected health information (PHI) to a third party.

When Authorization is Required

When Authorization is NOT Required

Rule of Thumb: If disclosing to someone OUTSIDE your practice for purposes OTHER than treatment, payment, or healthcare operations, you likely need authorization. When in doubt, get authorization.

Required Elements of Valid Authorization

HIPAA specifies exact requirements for a valid authorization. Missing even one element makes the authorization invalid, and you cannot disclose without it.

Essential Elements (45 CFR § 164.508)

  • Specific identification: Who is releasing the information (your practice name and address)
  • Recipient identification: Who will receive the information (name and address of recipient)
  • Records description: What specific records or types of information (dates, types of treatment)
  • Purpose statement: Why the information is being disclosed (specific purpose)
  • Expiration date: When the authorization expires (date or event)
  • Patient signature: Signed and dated by patient or authorized representative
  • Date of authorization: When the form was signed

Optional But Recommended Elements

Common Mistakes:
  • Vague purpose ("for my records" vs. "for orthopedic surgeon Dr. Smith for knee replacement surgery")
  • No expiration date or too distant expiration ("valid forever")
  • Generic authorization for "any and all records" without specific dates
  • Recipient address incomplete or vague
  • Unsigned or signed by someone other than patient without legal authority

Authorization Form Template & Examples

Proper Authorization Form Structure

RELEASE OF INFORMATION AUTHORIZATION I authorize [PROVIDER/PRACTICE NAME] at [ADDRESS] to release my health information to: Name/Organization: _________________ Address: __________________________ The following information may be released: ☐ Complete medical record ☐ Record dates: FROM ___/___/___ TO ___/___/___ ☐ Specific records: [specify: lab results, mental health, imaging, etc.] Purpose of disclosure: [SPECIFIC PURPOSE - e.g., "For treatment by Dr. Jane Smith, orthopedic surgeon" OR "For disability insurance claim evaluation"] This authorization expires on: ___/___/___ [DATE] I understand that I may revoke this authorization at any time by written notice to [PRACTICE NAME]. I understand that information released may be subject to re-disclosure by the recipient. Patient Signature: __________________ Date: __________ Patient Name (print): __________________________ If authorized representative: Name & Relationship: ________ Legal authority (guardianship, POA): ______________

Example 1: Proper Authorization

Good: "I authorize Dr. Smith's office to release my complete medical record from January 1, 2024 to December 31, 2024 to Dr. Sarah Johnson, Orthopedic Associates, 456 Oak Street, Springfield, IL for treatment of my knee injury. This authorization expires December 31, 2024."

Example 2: Improper Authorization

Bad: "Release all my medical records." [Missing: recipient, purpose, specific dates, expiration]

Example 3: HIPAA-Compliant Broad Authorization

Good (when appropriate): "I authorize Dr. Smith's office to release my complete medical record to my attorney, John Counsel, Esq., Counsel Law Firm, 789 Legal Ave, Chicago, IL for purposes of litigation support related to my workers' compensation claim filed in 2023. This authorization expires December 31, 2025."

Authorization Best Practices & Common Issues

1. Obtain Specific Authorizations for Sensitive Information

HIPAA requires a specific authorization for:

2. Handling Verbal Requests

If a patient calls and verbally requests records be sent:

3. Handling Family Member Requests

When family members request patient records:

4. Record Retention

Keep authorization forms permanently:

5. Denying Requests Without Valid Authorization

If patient requests records but no valid authorization exists:

Policy Recommendation: Create a written Release of Information policy that includes: timeline for responding to requests (typically 30 days), fees allowed under HIPAA (reasonable reproduction costs), format options (paper, electronic), and denial procedures.

Electronic Authorizations & eSignature

Are E-Signatures Valid for HIPAA Authorization?

Yes, electronic signatures are valid and increasingly common:

Electronic Authorization Best Practices

Frequently Asked Questions

Can a patient revoke an authorization?

Yes, at any time.

Patient rights include:

  • Revoking authorization in writing at any time
  • Revocation effective immediately upon receipt (not retroactively)
  • Revocation does not undo previous disclosures already made

If you receive written revocation, stop all further disclosures under that authorization. Acknowledge receipt in writing and file with authorization form.

What if authorization doesn't list all needed records?

Do NOT release records not listed in authorization.

Only release what is specifically authorized. If patient wants additional records:

  • Contact patient for new or amended authorization
  • Or obtain new authorization covering additional records
  • Do not assume "complete medical record" means mental health if mental health is sensitive

Being overly generous with what you release ("I'll include additional records the patient might find helpful") is a HIPAA violation.

Do I need authorization to bill insurance?

Generally no. Insurance billing is part of healthcare operations:

  • Patient's treatment implicitly authorizes you to submit to insurance
  • However, it's best practice to disclose that you will bill insurance
  • Include in intake paperwork or privacy notices
  • If patient objects to insurance submission, honor that request

Note: Submitting to insurance is routine; disclosing for OTHER purposes (employer liability, disability, etc.) requires separate authorization.

What's required for substance abuse records release?

Substance abuse records have stricter rules (42 CFR Part 2):

  • Requires federal compliance, not just HIPAA
  • Must have separate, specific authorization form
  • Standard HIPAA authorization is NOT sufficient
  • Must include patient statement about re-disclosure restrictions
  • Cannot condition treatment on authorization

Many practices incorrectly use standard HIPAA authorization for substance abuse records. Use the federal Form OAS 91, which is specifically designed for this purpose.

Can we charge for releasing records?

Yes, but limited by HIPAA and state law:

  • Allowed charges: Reasonable reproduction costs (paper, copying, postage)
  • HIPAA limit: Cannot charge for labor to prepare records (much debate)
  • State variations: Some states allow higher fees; others are more restrictive
  • Patient access: If patient requests their OWN records, fees are very limited ($0-$15 typically)
  • Fee estimates: Provide patient with estimate before copying

Check your state's medical records access law—it often allows lower fees than HIPAA does.

Need Help With Release of Information Compliance?

Medcurity helps healthcare organizations develop and implement compliant Release of Information policies and procedures. We provide sample authorization forms, staff training, and audit services to ensure compliance.

Get ROI Compliance Support