The Privacy Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) establishes national standards to protect individuals medical records and other personal health information. A central component of these regulations is the control over who has access to "Protected Health Information" (PHI). While the law permits healthcare providers to share information for treatment, payment, and healthcare operations without specific patient permission, any other use or disclosure generally requires a valid authorization from the patient.
This document outlines the requirements, scope, and procedures regarding the authorization for use or disclosure of protected health information. It serves as a guide to understanding when an individual's written permission is mandatory and what elements constitute a legally compliant authorization form.
Definition of Protected Health Information (PHI): PHI is any information relating to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual. This includes identifiers such as names, dates of birth, Social Security numbers, and medical record numbers.
Under the HIPAA Privacy Rule, a "covered entity" (such as a doctor, hospital, or health plan) is prohibited from using or disclosing PHI for purposes other than treatment, payment, or health care operations, unless the covered entity obtains a written authorization from the individual. This authorization acts as a permission slip, giving the covered entity explicit consent to handle the data in a specific manner defined by the document.
For an authorization to be valid under HIPAA, it must contain specific core elements and statements required by 45 CFR 164.508(c). A generic or vague permission slip is not sufficient. If an authorization lacks any of these elements, the use or disclosure based on that document would be a violation of HIPAA regulations. Below are the mandatory components:
While HIPAA allows for the flow of health information without patient consent for routine healthcare operations, there are specific scenarios where authorization is strictly required. These situations often involve sensitive information or uses of data that are not strictly necessary for the patient's immediate medical care.
Psychotherapy notes are notes kept by a mental health professional documenting or analyzing the contents of a conversation during a private counseling session. These notes are kept separate from the medical record. HIPAA requires a specific authorization to use or disclose psychotherapy notes, even for treatment purposes. This offers an extra layer of privacy for mental health records. However, there are exceptions for uses by the originator of the notes, for certain training programs, or in response to a court order.
Covered entities generally cannot use or disclose PHI for marketing purposes without an individual's authorization. "Marketing" is defined as making a communication about a product or service that encourages recipients of the communication to purchase or use the product or service. There are exceptions for face-to-face communications about health-related services or for filling prescriptions for a patient, but generally, if a hospital wants to sell patient lists to a third party for advertising, a valid authorization is mandatory.
A covered entity cannot sell PHI without an authorization. "Sale" is defined as the exchange of PHI for remuneration (money or anything of value) by the covered entity. This prohibition ensures that healthcare organizations do not monetize their patients' private medical data. Certain public health and law enforcement exceptions exist, but purely commercial transactions require explicit patient consent.
When researchers wish to use PHI for a research study, they must generally obtain authorization from the participants. This is often integrated into the "Informed Consent" process for the study. However, if the research is conducted on "de-identified" data (data stripped of all personal identifiers), authorization is not required because it is no longer considered PHI. Alternatively, researchers can apply for a waiver of authorization from an Institutional Review Board (IRB) or Privacy Board if the research meets specific criteria (minimal risk, impracticability to obtain authorization, etc.).
It is equally important to understand when an authorization is not required, as this facilitates the efficient operation of the healthcare system. The Privacy Rule permits the use and disclosure of PHI without the individual's authorization for the following purposes:
Patients retain the right to revoke their authorization at any time, provided they do so in writing. The revocation must be submitted to the covered entity (or the business associate). Once revoked, the covered entity must cease all uses and disclosures described in the authorization, except to the extent that it has already taken action in reliance on the authorization. For example, if a disclosure was made to a researcher minutes before the revocation letter arrived, the covered entity is not liable for that prior disclosure.
Furthermore, the Privacy Rule requires that covered entities obtain satisfactory assurances from their "business associates" (third parties that perform services involving PHI on behalf of the covered entity) that the business associate will appropriately safeguard the information. If a covered entity discloses information to a third party based on a patient's authorization, but receives assurance that the third party will not redisclose the information further (or will only do so consistent with the authorization), the chain of protection is maintained.
Compound authorizations (which authorize multiple uses or disclosures) are permitted as long as a copy of the authorization is provided to the individual. The language used in authorization forms must be written in plain language, ensuring that the individual can understand the nature of the consent they are giving.
The authorization for use or disclosure of protected health information is a fundamental right granted to patients under HIPAA. It places the control of personal medical data back into the hands of the individual. By strictly adhering to the content requirementsensuring specificity regarding what is shared, with whom, and for what purposecovered entities empower patients to understand and manage their health information privacy. Understanding the distinction between permitted uses for treatment, payment, and operations, and the need for explicit authorization for other purposes, is essential for compliance and for maintaining the trust between patients and healthcare providers.
