Executive summary. An authorization is a specific permission. It names the information involved, who may disclose it, who may receive it, and for what purpose.
Definition
A HIPAA authorization is an individual’s written permission for a use or disclosure of protected health information when authorization is required.
Know what the form needs to communicate
A valid authorization contains required elements and statements. Use the approved form, and do not reword key language for a one-off request.
Match the authorization to the disclosure in front of you. A broad form does not make every future use appropriate.
Track validity and revocation
Record when an authorization was signed, its expiration date or event, and any revocation received. Make the current status visible to the people handling the disclosure.
Before acting, confirm that the recipient, the information, and the purpose match the active authorization. Send anything uncertain to privacy review.
Frequently asked questions
Is consent always the same as authorization?
No. The terms can carry different legal and operational meanings. Use the specific HIPAA rule and any applicable state requirements for the situation.
Referenced standards and further reading
- HHS OCR: Authorizations ↗U.S. Department of Health and Human Services
Related articles
HIPAA Security Rule risk analysis: scope, evidence, decisions →
The minimum necessary standard in operational design →
Business associate relationships: map the work, not the logo →