A HIPAA authorization is legally valid only if it contains six core content elements and three required statements about your rights, all set out in federal regulation at 45 CFR § 164.508. Miss one, and the entire form is defective. That means any health information released under it was disclosed without proper permission, and the covered entity that acted on it committed a Privacy Rule violation. The HIPAA authorization requirements below apply whether you are the patient about to sign, the provider drafting the form, or the attorney reviewing one that landed on your desk.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
The Six Core Elements
Every valid authorization must include all six of the following under 45 CFR § 164.508(c)(1). If any one is missing or left blank, the authorization is not valid and a covered entity cannot legally act on it.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
- A specific and meaningful description of the information to be used or disclosed. Vague language like “all medical records” is a red flag. Better forms reference particular dates of service, record types such as lab results or imaging, or a defined treatment episode.
- The name or specific identification of the person or entity authorized to make the disclosure. This could be a named provider, hospital, or health plan.
- The name or specific identification of the person or entity who will receive the information. This can be an individual, an organization, or a defined class of recipients.
- A description of the purpose of the disclosure. If you initiated the authorization and don’t want to explain, writing “at the request of the individual” is enough.
- An expiration date or expiration event. A calendar date works (“June 30, 2027”), and so does a triggering event (“upon conclusion of the pending litigation”). Research authorizations get more flexibility and can use phrases like “end of the research study” or even “none.”
- The signature of the individual and the date. A personal representative can sign on your behalf if they have legal authority to do so.
Electronic signatures are allowed. The Privacy Rule permits authorizations to be obtained electronically, provided the signature method is valid under applicable law.2U.S. Department of Health & Human Services. How Do HIPAA Authorizations Apply to Electronic Health Information Standard e-signature platforms generally work, but the provider should confirm the method complies with any relevant state electronic signature law.
The Three Required Statements About Your Rights
Beyond those six content elements, 45 CFR § 164.508(c)(2) requires the form to include three statements. These put you on notice of your rights and the practical limits of the form’s protection.
Right to Revoke
The form must tell you that you can revoke the authorization in writing at any time. It must also explain how to revoke, either directly on the form or by referring you to the provider’s Notice of Privacy Practices. The statement has to describe the exceptions to revocation, the main one being that the covered entity does not have to undo disclosures it already made while the authorization was still in effect.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required A written revocation is only effective once the covered entity that was authorized to make the disclosure actually receives it. Telling a third party you want to revoke does nothing.3U.S. Department of Health & Human Services. Can an Individual Revoke His or Her Authorization
Whether Signing Is a Condition of Treatment or Coverage
The authorization must state whether the covered entity can refuse to treat you or deny benefits if you decline to sign. In almost every situation, the answer is no: a provider cannot condition treatment, payment, or eligibility on your signing an authorization. There is a narrow exception for health plans, which can condition enrollment or eligibility on your signing an authorization if the plan requests it before you enroll and needs the information for eligibility determinations or underwriting. Even then, the authorization cannot involve psychotherapy notes.
Re-Disclosure Warning
The form must warn you that once your information reaches the recipient, it may no longer be protected by the Privacy Rule and could be shared again. This matters most when the recipient is not itself a covered entity. If you authorize your hospital to send records to an employer or a life insurance company, HIPAA no longer governs what that recipient does with the data.
Extra Content Required for Marketing and Data Sales
Two situations add another required disclosure on top of the standard elements. If a covered entity is paid by a third party to send you marketing communications, the authorization must say so. A hospital paid by a pharmaceutical company to contact you about a new drug has to disclose that financial arrangement on the form.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required For any sale of protected health information, the authorization must state that the disclosure will result in payment to the covered entity. The dollar amount doesn’t matter; if money changes hands in exchange for your data, the form has to say so before you sign.
Psychotherapy notes carry their own structural rule. An authorization to release psychotherapy notes has to stand alone. It cannot be combined with an authorization for any other type of health information, and it cannot be bundled into a consent form for treatment. The legal definition is narrower than most people expect: only the therapist’s private session notes kept separate from the rest of the medical record qualify. Medication records, session start and stop times, treatment frequency, clinical test results, and summaries of diagnosis, treatment plan, symptoms, prognosis, or progress fall outside that definition and follow the ordinary rules.4eCFR. 45 CFR 164.501 – Definitions
What Makes an Authorization Defective
Even a form that looks complete can be void. The regulation lists five conditions that make an authorization defective, and a covered entity that knows about any of them cannot act on it.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
- The expiration date has passed, or the covered entity knows the triggering expiration event has already occurred.
- Any required core element is missing or left blank.
- The covered entity knows the individual revoked the authorization in writing.
- The authorization violates the compound authorization rules or the rules against conditioning treatment on signing.
- The covered entity knows that material information in the authorization is false.
Most compliance failures in practice come from the second category. Someone processes a form without checking whether it expired or whether a required field was left blank, and information goes out under a document that never had legal effect.
When You Don’t Need an Authorization at All
Not every use of your health information requires a signed authorization, and understanding the line keeps you from asking for a form when one isn’t needed. Covered entities can share your records for treatment, payment, and healthcare operations without a separate authorization.5eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations Your doctor can send lab results to a specialist for a referral, your insurer can process a claim, and a hospital can run internal quality reviews under the general consent you sign at check-in.
Authorization becomes mandatory once a use or disclosure falls outside those routine categories. The regulation specifically requires authorization for three heightened uses: psychotherapy notes, marketing, and the sale of protected health information. Beyond those, the catch-all rule is that any use or disclosure not otherwise permitted or required by the Privacy Rule needs a valid authorization. Sending your records to a life insurance company, sharing information with your employer for a reason unrelated to a workplace injury claim, or releasing records to a family member who is not your personal representative all require one.
Who Can Sign for Someone Else
The signature element is only valid if the person signing has authority to do so. A personal representative under HIPAA is someone with legal authority to make healthcare decisions for another person, and covered entities must treat that representative the same as the individual for authorization purposes.6U.S. Department of Health & Human Services. Guidance – Personal Representatives
A parent is generally the personal representative of an unemancipated minor child and can sign on the child’s behalf.7U.S. Department of Health & Human Services. The HIPAA Privacy Rule and Parental Access to Minor Childrens Medical Records A parent loses that status for specific health information in three situations: the minor consented to the care on their own and state law didn’t require parental consent, a court or court-appointed person authorized the care, or the parent agreed to a confidential relationship between the minor and the provider. A provider can also decline to recognize the parent as personal representative if the provider reasonably believes, based on professional judgment, that the minor has been or may be subjected to abuse or neglect by that parent, or that recognizing the parent’s authority would endanger the child.
For adults who cannot make their own decisions, a legal guardian or a person holding a healthcare power of attorney can act as personal representative. Broad authority puts the representative in the individual’s shoes for all Privacy Rule purposes; authority limited to specific healthcare decisions limits the representative to authorizing disclosures relevant to those decisions.