HIPAA Authorization Form (2024)

HIPAA Authorization FormCompliancy Group2023-11-22T15:20:13-05:00

The HIPAA Privacy Rule requires that an individual provide signed authorization to a covered entity, before the entity may use or disclose certain protected health information (PHI).

Under the Privacy Rule and in accordance with the minimum standards, doctors, nurses, hospitals, laboratory technicians, and other health care providers that are covered entities may use or disclose PHI (e.g., protected health information, X-rays, laboratory and pathology reports, diagnoses, and other medical information) without the patient’s authorization, for treatment purposes.

HIPAA Authorization Form (1)

A HIPAA authorization form gives covered entities permission to use protected health information for purposes other than treatment, payment, or health care operations. Continue reading to find out what authorization to disclose health information is needed.

When Must HIPAA Authorization be Obtained?

HIPAA regulations outline the uses and disclosures of PHI that require an authorization be obtained from a patient/plan member before that person’s PHI can be shared or used. HIPAA Authorization forms are required before:

  • The covered entity can use or disclose PHI whose use or disclosure is otherwise not permitted by the HIPAA Privacy Rule
  • The covered entity can use or disclosure of PHI for marketing purposes. If the marketing communication involves direct or indirect remuneration to the covered entity from a third party, the authorization must state that such remuneration is involved.
    • Note: Prior authorization for marketing is not required when:
      • Communication occurs face to face between the covered entity and the individual; or
      • When the communication involves a promotional gift of nominal value.

What Information Must a HIPAA Authorization Contain to be Valid?

The law requires that a HIPAA authorization form contain specific “core elements” to be valid. In a HIPAA agreement form, these elements include:

  • A description of the specific information to be used or disclosed.
  • The name or other specific identification of the person(s), or class of persons, authorized to make the requested use or disclosure.
  • The name or other specific identification of any third parties (persons or classes of persons) to whom the covered entity may make the requested use or disclosure.
  • A description of each purpose of the requested use or disclosure.
  • An expiration date or an expiration event that relates to the individual or the purpose of the use or disclosure.
    • The signature of the individual, and the date.

What Required Statements Must the HIPAA Authorization Form Contain?

In addition to the core elements, the HIPAA authorization must contain statements adequate to place the individual on notice of all of the following:

  • The individual‘s right to revoke the authorization in writing
  • The exceptions to the right to revoke (an individual may revoke an authorization in writing except when the covered entity has taken action in reliance on the authorization).
  • The covered entity may not condition treatment, payment, enrollment or eligibility for benefits on whether the individual signs the authorization, except that:
    • A covered health care provider may condition the provision of research-related treatment on provision of an authorization for such research
    • A health plan may, to make eligibility or enrollment determinations, may condition enrollment in the health plan or eligibility for benefits on provision of an authorization.
  • The potential for information disclosed in to the authorization to be subject toHIPAA redisclosureby the recipient and no longer be protected by the Privacy Rule.

HIPAA regulations also require that the HIPAA authorization must be written in plain language on the HIPAA form.

In addition, whenever a covered entity seeks a HIPAA authorization from an individual for a PHI use or disclosure, the covered entity must provide the individual with a copy of the signed HIPAA form authorization.

What About Psychotherapy Notes?

The Privacy Rule defines psychotherapy notes as notes recorded by a health care provider who is a mental health professional documenting or analyzing the contents of a conversation during a private counseling session or a group, joint, or family counseling session. These notes are separate from the rest of the patient’s medical record.

Psychotherapy notes do not include any information about:

  • Medication prescription and monitoring
  • Counseling session start and stop times
  • The modalities and frequencies of treatment furnished
  • Results of clinical tests.
  • Summaries of diagnosis
  • Functional status
  • Treatment plans
  • Symptoms
  • Prognosis
  • Progress to date
  • Information maintained in a patient’s medical record

Psychotherapy notes contain particularly sensitive information. These notes constitute the personal notes of the therapist – notes that that usually are not required or useful for treatment, payment, or health care operations purposes (other than by the mental health professional who created the notes)

Therefore, the Privacy Rule generally requires a covered entity to obtain a patient’s authorization prior to a disclosure of psychotherapy notes for any reason, including a disclosure for treatment purposes to a health care provider other than the originator of the notes.

What About Substance Abuse Disorders?

Generally, covered entities cannot use or disclose substance abuse and treatment records, without patient authorization.

There are two exceptions to this rule:

For the particular purpose of treating a patient with a substance abuse disorder, HIPAA permits disclosure of protected health information (PHI) without patient consent. PHI may also be used or disclosed without patient authorization to lessen a threat of serious and imminent harm to the health or safety of the patient or others.

Modernize Your Compliance

Say goodbye to spreadsheets and hello to automated software!

Learn More

Modernize Your Compliance

HIPAA Authorization Form (2)

HIPAA Authorization Form (2024)

FAQs

What makes a HIPAA authorization valid? ›

The name(s) or other specific identification of person(s) or class of persons authorized to make the requested use or disclosure. The name(s) or other specific identification of the person(s) or class of persons who may use the PHI or to whom the covered entity may make the requested disclosure.

Should you agree to HIPAA authorization? ›

Should you sign a HIPAA authorization form? In most cases, the answer is yes. HIPAA is designed to protect patients' sensitive health information. Following all HIPAA rules can help to protect healthcare professionals from legal trouble and allow them to better serve their patients.

How to fill out a HIPAA authorization form? ›

How do I fill out a HIPAA release form?
  1. Provide instructions. ...
  2. Name the patient and individual authorized to use or disclose their PHI. ...
  3. Describe the information. ...
  4. Specify recipients. ...
  5. Specify the purpose of disclosure. ...
  6. Specify the time period. ...
  7. Detail their revocation rights. ...
  8. Obtain the patient's signature.
Oct 19, 2023

What are the 8 requirements of a valid authorization to release information? ›

Elements:
  • A description of the PHI.
  • The name of the person making the authorization.
  • The name of the person or organization who is authorized to receive the PHI.
  • A description of the purpose for the use or disclosure.
  • An expiration date for the authorization.
  • The signature of the person making the authorization.
Feb 18, 2020

What are the requirements for a valid authorization? ›

be written in plain language:

A description of the information to be used or disclosed that identifies the information in a specific and meaningful fashion. 2. The name or other specific identification of the person or class of persons, authorized to make the requested use or disclosure.

Does a HIPAA authorization need to be notarized? ›

A: No. The HIPAA Privacy Rule does not require you to notarize authorization forms or have a witness. Though taking the time to fill out an authorization form and get a patient's signature is an extra step, it's an important one that you can't afford to overlook.

What happens if you decline HIPAA authorization? ›

Refusing to sign the acknowledgement does not prevent a provider or plan from using or disclosing health information as HIPAA permits. If you refuse to sign the acknowledgement, the provider must keep a record of this fact.

Can HIPAA authorization be revoked? ›

Answer: A research subject may revoke his/her Authorization at any time. The revocation must be in writing. An oral discussion between the subject and member of the research team does not revoke a HIPAA authorization.

What is a HIPAA release of information authorization form? ›

A HIPAA authorization form, also known as a HIPAA release form, is a document that individual signs for their health provider before the entity may use or disclose their protected health information (PHI). HIPAA authorizes the sharing of PHI for the following purposes: Treatment. Payment.

What is an example of a HIPAA authorization? ›

I hereby authorize use or disclosure of protected health information about me as described below. I understand that the information used or disclosed may be subject to re-disclosure by the person or class of persons or facility receiving it, and would then no longer be protected by federal privacy regulations.

What must a written authorization form include? ›

An authorization must specify a number of elements, including a description of the protected health information to be used and disclosed, the person authorized to make the use or disclosure, the person to whom the covered entity may make the disclosure, an expiration date, and, in some cases, the purpose for which the ...

How long is a HIPAA authorization valid? ›

A stand alone Medical Records Release and Authorization to Use and Disclose Health Information Form will state that this authorization does not have an expiration date (unless superceded by state or local laws).

Can HIPAA authorization be verbal? ›

Yes, HIPAA does allow verbal consent in specific situations. While the general rule mandates written authorization for the use and disclosure of protected health information (PHI), exceptions exist.

What is the difference between consent and authorization in HIPAA? ›

Purpose: Consent covers treatment, payment, and healthcare operations, whereas authorization is required for other specific purposes. Mandatory vs. Voluntary: Consent is optional, and patients can choose to provide or withhold it. In contrast, authorization is mandatory for certain activities.

What information must be on the authorization form for the release of patient? ›

Releasing patient records without proper authorization violates HIPAA regulations. The form must have a valid signature, date, and purpose of the release of the request. If the patient's information is incorrect or incomplete, it may lead to the release of the wrong medical records.

What information is required to validate HIPAA? ›

The following 18 identifiers are considered “personally identifiable” under HIPAA:
  • Name.
  • Address.
  • Dates, other than year, related to an individual or their care (e.g. birth date, date of admission, discharge date)
  • Phone numbers.
  • Fax numbers.
  • Email addresses.
  • Social Security number.
  • Medical record number.

What are two required elements of an authorization needed to disclose PHI? ›

What are two required elements of an authorization needed to disclose PHI? Response Feedback: All authorizations to disclose PHI must have an expiration date and provide an avenue for the patient to revoke his or her authorization.

Which of these are valid authorization elements? ›

  • description of specific information to be used/disclosed.
  • exact name of entity authorized to disclose PHI.
  • to whom, by specific name, entity is disclosing information.
  • description of purpose or "at request of individual"
  • exact time frame and expiration date.

What is a HIPAA compliant authorization form? ›

A HIPAA authorization form, also known as a HIPAA release form, is a document that individual signs for their health provider before the entity may use or disclose their protected health information (PHI). HIPAA authorizes the sharing of PHI for the following purposes: Treatment. Payment. Healthcare Operations.

Top Articles
Latest Posts
Article information

Author: Edwin Metz

Last Updated:

Views: 5794

Rating: 4.8 / 5 (58 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Edwin Metz

Birthday: 1997-04-16

Address: 51593 Leanne Light, Kuphalmouth, DE 50012-5183

Phone: +639107620957

Job: Corporate Banking Technician

Hobby: Reading, scrapbook, role-playing games, Fishing, Fishing, Scuba diving, Beekeeping

Introduction: My name is Edwin Metz, I am a fair, energetic, helpful, brave, outstanding, nice, helpful person who loves writing and wants to share my knowledge and understanding with you.