Skip to content

HIPAA Authorization

A HIPAA authorization is a signed form telling a doctor, hospital or health plan that it may share your health information with people you name. It is one of three routes federal privacy rules provide, and the other two need no signature, which is why the rule is narrower than the reputation around it.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The privacy rule bars a covered entity from using or disclosing your health information without a valid authorization, "except as otherwise permitted or required" by the rule itself. The exceptions are the interesting part.
  • A valid authorization has six required elements and three required statements, and five specific defects make it invalid, including an expiration date that has passed.
  • You can revoke it at any time, but the revocation has to be in writing and it does not undo anything already done in reliance on it.
  • A person with authority under state law to make your health care decisions is treated as you, without any authorization. That is most of what a healthcare power of attorney does.
  • A provider may also talk to family and close friends involved in your care without any form at all. It is permission, not an obligation, which is why a cautious hospital can still decline.

Definition

A HIPAA authorization is a written, signed permission allowing a covered entity to use or disclose your protected health information for a purpose the privacy rule does not otherwise permit. The governing provision is 45 CFR 164.508, headed "Uses and disclosures for which an authorization is required," whose general rule reads: "Except as otherwise permitted or required by this subchapter, a covered entity may not use or disclose protected health information without an authorization that is valid under this section."

The regulation calls the document simply an "authorization." The prefix is ours, added to distinguish it from every other kind of authorization a person signs, and the same document is commonly called a HIPAA release or a HIPAA release form. HIPAA itself is the Health Insurance Portability and Accountability Act of 1996; the privacy rule is the regulation written under it. One boundary is worth fixing before anything else: the rule binds a "covered entity," which 45 CFR 160.103 defines as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." An employer acting as an employer is not on that list, and neither is most of what people assume HIPAA reaches.

Advanced Explanation

The form itself is specified in unusual detail, which is why a form downloaded from one hospital is often rejected at another. Section 164.508(c)(1) sets six core elements a valid authorization must contain: a description of the information identified "in a specific and meaningful fashion"; the name or other specific identification of the person or class of persons authorized to make the disclosure; the name or other specific identification of the person or class of persons to whom it may be made; a description of each purpose, for which the phrase "at the request of the individual" is sufficient when the individual initiates it; an expiration date or an expiration event; and the individual's signature and date, with a description of the signer's authority if a personal representative signs.

On top of those, section 164.508(c)(2) requires three statements: the right to revoke in writing, with either the exceptions and the method or a reference to the entity's own privacy notice; whether treatment, payment, enrollment or eligibility can be conditioned on signing; and "the potential for information disclosed pursuant to the authorization to be subject to redisclosure by the recipient and no longer be protected by this subpart." That third statement is the one to read twice. Once information has lawfully reached someone who is not a covered entity, the privacy rule stops following it. Section 164.508(c)(3) adds a plain-language requirement, and (c)(4) requires the entity to give the individual a copy of the signed authorization.

Five defects make an authorization invalid, under section 164.508(b)(2): the expiration date has passed or the expiration event is known to have occurred; it was not filled out completely as to a required element; it is known to have been revoked; it violates the compound-authorization or conditioning rules; or "any material information in the authorization is known by the covered entity to be false." The first of those is the one that bites a document signed years in advance and then filed away, since an authorization written with a fixed expiration date can quietly stop working while everyone assumes it is in place. Revocation, under (b)(5), must be in writing, and it does not reach anything the entity has already done in reliance on it, or an authorization obtained as a condition of insurance coverage where other law lets the insurer contest a claim.

The two routes that need no signature are what make this page's subject narrower than its reputation, and omitting them teaches the wrong rule.

The first is the personal representative. Section 164.502(g)(1) requires a covered entity to "treat a personal representative as the individual for purposes of this subchapter," and (g)(2) supplies the test: "If under applicable law a person has authority to act on behalf of an individual who is an adult or an emancipated minor in making decisions related to health care, a covered entity must treat such person as a personal representative . . . with respect to protected health information relevant to such personal representation." That is a mandatory instruction, and it is most of what a healthcare power of attorney is buying. Section 164.502(g)(4) does the same after death for an executor, administrator or other person with authority over the estate, and (g)(5) lets an entity decline to treat someone as personal representative where it reasonably believes the individual has been or may be subjected to domestic violence, abuse or neglect by that person, or that doing so could endanger them.

The second is section 164.510(b), and its verb is the point. A covered entity "may . . . disclose to a family member, other relative, or a close personal friend of the individual, or any other person identified by the individual, the protected health information directly relevant to such person's involvement" in the individual's care or payment for it, and may notify such a person of "the individual's location, general condition, or death." Where the individual is present and able to decide, the entity may act on their agreement, on an unopposed opportunity to object, or on a reasonable inference from the circumstances. Where the individual is absent or incapacitated, it may act on professional judgment about their best interests. After death, subsection (b)(5) permits the same disclosure to people who were involved before it, "unless doing so is inconsistent with any prior expressed preference of the individual that is known to the covered entity."

So the honest description of what the signed form adds is a narrow one, and it is still worth having. Section 164.510(b) is a permission, not a duty. A hospital that reads it cautiously, or a staff member who has been told to, can decline to say anything and be entirely within the rule. An authorization removes the judgment call: it names the people, it names the information, and refusing to honor a valid one is a different posture from declining to exercise a discretion. That is the whole of the case for signing one, and it is enough.

One more provision belongs on any page about health information and death. Section 164.502(f) requires a covered entity to protect a deceased individual's information "for a period of 50 years following the death of the individual." Privacy does not lapse at the funeral, which is why the personal-representative route at (g)(4) matters to an executor settling an estate with medical bills in it.

How to Remember

Three doors, and only one of them has a signature on it. You signed something is an authorization. Somebody can decide for you is a personal representative. Somebody is helping look after you is the family-and-friends permission, which a provider may use and does not have to.

Used in a Sentence

“Marcus signed a HIPAA authorization naming his two adult children, so the cardiology practice could return their calls about his test results instead of telling them to ask him.”

How It Works

  1. Check who you are dealing with. The privacy rule reaches health plans, health care clearinghouses, and providers who transmit health information electronically in a covered transaction. Something outside that list is governed by other law, not by this form.

  2. Name people specifically. The rule accepts a class as well as an individual, but a form that says "my family" leaves the entity to decide who qualifies, which is the outcome the form exists to avoid.

  3. Decide the expiration deliberately. An expiration date or event is a required element, and an authorization whose date has passed is invalid on its face. An expiration event tied to the purpose ages better than a date chosen because a blank had to be filled.

  4. Expect institution-specific forms. Because the required elements are detailed, providers commonly insist on their own paper. Signing the form at each practice you actually use is more reliable than carrying one document everywhere.

  5. Revoke in writing if you change your mind. Oral revocation is not what the rule provides for, and revocation does not reach disclosures already made in reliance.

A hypothetical showing what each route reaches. Ana, who is 71, is admitted after a fall. Her daughter has driven her to appointments for two years and is at the bedside. Her son lives abroad. Ana signed a healthcare power of attorney naming her daughter, and a HIPAA authorization naming both children.

The daughter's access does not depend on the authorization at all. She has authority under state law to make Ana's health care decisions, so section 164.502(g)(2) requires the hospital to treat her as Ana herself for information relevant to that role. The son's access does. He is not a decision-maker and he is not present, and the family-and-friends permission reaches information "directly relevant to such person's involvement" in her care, which is thin ground for someone who has not been involved. The authorization names him, so the discretion disappears.

Change one fact. Suppose Ana had signed nothing. The hospital may still discuss her care with the daughter under section 164.510(b), because she is a close relative involved in it, and may use professional judgment about Ana's best interests while Ana cannot decide. It is not obliged to, and it may reasonably decline as to the son. Nothing in that outcome is a failure of the rule; it is the difference between a permission and an instruction.

Pros and Cons

What a signed authorization does

  • It converts a discretion into an instruction, so the question stops being whether a particular member of staff is comfortable talking to your family.
  • It reaches people the family-and-friends permission does not obviously cover, such as an adult child who lives far away or a friend who is not involved in day-to-day care.
  • It can be written narrowly, naming particular information and particular people, rather than opening the whole record.
  • It is revocable in writing at any time, so it is not a decision that has to be got right permanently.
  • It costs nothing to sign at the practices you already use, and providers generally have their own compliant form ready.

Its limits, and the things people expect of it that are not true

  • It binds only covered entities. An employer acting as an employer, and most organizations that hold health information for other reasons, are outside the rule entirely.
  • Once information reaches someone who is not a covered entity, the privacy rule no longer protects it, and the form has to say so.
  • An expiration date that has passed makes it invalid, so a document signed once and filed can stop working silently.
  • It is not a substitute for a healthcare power of attorney. It permits information to flow; it appoints nobody to decide anything.
  • Providers frequently want their own version, so one universal form is less reliable in practice than several institution-specific ones.
  • It has no effect on a provider's willingness to return a call promptly, which is a service question rather than a privacy one.

People Also Asked

Answers to the most frequently asked questions.

What is the difference between a HIPAA authorization and a healthcare power of attorney?
One moves information and the other appoints a decision-maker. A HIPAA authorization tells a covered entity it may share your health information with people you name. A healthcare power of attorney gives someone authority under state law to make your medical decisions, which under 45 CFR 164.502(g) also requires the entity to treat them as you for information relevant to that role. Most complete plans include both, because the authorization can name people who are not, and should not be, your decision-maker.
Without one, can a hospital tell my family anything?
Often yes, and this is the most misunderstood part of the rule. Under 45 CFR 164.510(b) a covered entity may disclose to a family member, other relative, close personal friend or anyone you identify the information directly relevant to their involvement in your care, and may notify them of your location, general condition or death. The operative word is "may." It is a permission a cautious institution can decline to use, which is exactly what a signed authorization removes.
Can I cancel a HIPAA authorization?
Yes, at any time, but the revocation has to be in writing. Two things survive it under 45 CFR 164.508(b)(5): anything the covered entity has already done in reliance on the authorization, and an authorization obtained as a condition of obtaining insurance coverage where other law gives the insurer the right to contest a claim or the policy itself.
Does HIPAA still apply after someone dies?
Yes, and for a long time. 45 CFR 164.502(f) requires a covered entity to comply with the privacy rule as to a deceased individual's information "for a period of 50 years following the death of the individual." Subsection (g)(4) then supplies the access route: an executor, administrator or other person with authority under state law over the deceased individual's estate must be treated as a personal representative for information relevant to that role.
Who does HIPAA actually bind?
A "covered entity," defined at 45 CFR 160.103 as a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a transaction covered by the rule. Separately, 45 CFR 160.102(b) applies the standards to a business associate "where provided," so a vendor handling information on a covered entity's behalf is reached too, but by a different provision and only as far as that provision goes. It is a rule about the health care system rather than a general privacy statute, so a great many organizations that hold health information about you are not answerable to it at all.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Code of Federal Regulations. "45 CFR § 164.508 — Uses and disclosures for which an authorization is required."
  2. Code of Federal Regulations. "45 CFR § 164.510 — Uses and disclosures requiring an opportunity for the individual to agree or to object."
  3. Code of Federal Regulations. "45 CFR § 160.103 — Definitions."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor