HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy
Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.
Introduction
A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.
Key Things to Know
- 1
HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.
- 2
Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.
- 3
Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.
- 4
Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.
- 5
Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.
- 6
A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.
- 7
Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.
Key Decisions
HIPAA Authorization Requirements
Full legal name, date of birth, address, phone number, and other identifying information of the individual whose protected health information will be disclosed.
Include the patient's medical record number or other healthcare identifier if available.
Massachusetts Requirements for HIPAA Authorization
The authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.
The authorization must be separate from other documents and cannot be combined with other legal permissions. It must be clearly distinguishable when combined with other documents.
Healthcare providers cannot condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs an authorization, with limited exceptions.
The authorization must include a statement of the individual's right to revoke the authorization in writing, and the exceptions to the right to revoke, together with a description of how to revoke.
The authorization must include a statement that information used or disclosed pursuant to the authorization may be subject to re-disclosure by the recipient and no longer protected by the Privacy Rule.
Massachusetts law provides patients the right to access, inspect, and obtain copies of their medical records, and an authorization must not restrict these rights.
Special provisions apply to the disclosure of mental health records in Massachusetts, requiring specific authorization language for the release of psychotherapy notes and mental health information.
Massachusetts law requires specific written consent for the release of HIV/AIDS test results and related information, which must be addressed in the HIPAA authorization if such information may be disclosed.
Massachusetts has specific requirements for authorizing the disclosure of substance use disorder treatment information, which must be addressed in the authorization.
Massachusetts law provides special protections for genetic information and requires specific authorization for its disclosure.
The authorization must contain core elements including description of information to be used/disclosed, name of person authorized to make the disclosure, name of person to whom disclosure may be made, purpose of disclosure, expiration date/event, and signature of individual with date.
Massachusetts law allows minors to consent to certain types of healthcare without parental knowledge, and these provisions must be reflected in authorizations involving minors.
A separate authorization is required for the use or disclosure of psychotherapy notes, with specific exceptions outlined in federal regulations.
If the authorization is for marketing purposes that involve financial remuneration, this must be disclosed in the authorization.
An authorization for the sale of protected health information must state that the disclosure will result in remuneration to the covered entity.
Massachusetts has specific requirements for notification in the event of unauthorized disclosure of protected health information, which should be referenced in the authorization.
Massachusetts recognizes a strong public policy in favor of patient confidentiality, which must be acknowledged in the authorization.
The covered entity must provide a copy of the signed authorization to the individual.
Massachusetts has specific requirements regarding electronic health records and electronic signatures that must be addressed if the authorization will be executed or maintained electronically.
Federal regulations specify when an authorization for the use or disclosure of protected health information may be combined with other documents.