HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy
Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.
Introduction
A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.
Key Things to Know
- 1
HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.
- 2
Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.
- 3
Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.
- 4
Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.
- 5
Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.
- 6
A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.
- 7
Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.
Key Decisions
HIPAA Authorization Requirements
Full legal name, date of birth, address, phone number, and other identifying information of the individual whose protected health information will be disclosed.
Include the patient's medical record number or other healthcare identifier if available.
Minnesota Requirements for HIPAA Authorization
The HIPAA Authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.
The authorization must be separate from other documents and cannot be combined with other legal permissions. It must be clearly distinguishable when combined with other documents.
Healthcare providers cannot condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs an authorization, with limited exceptions.
The authorization must include a statement of the individual's right to revoke the authorization in writing, and either the exceptions to the right to revoke and a description of how to revoke, or a reference to the corresponding notice of privacy practices.
The authorization must include a statement that information used or disclosed pursuant to the authorization may be subject to re-disclosure by the recipient and no longer protected by the Privacy Rule.
The authorization must comply with Minnesota's more stringent requirements for patient consent, which may exceed federal HIPAA standards in certain circumstances.
The authorization must include specific elements required by Minnesota law, including the name of the provider releasing the information, the name of the person or entity authorized to receive the information, the purpose of the disclosure, and the signature of the patient or legal representative.
Under Minnesota law, a patient authorization is valid for one year or for a lesser period specified in the authorization, which may be more restrictive than federal HIPAA requirements.
The authorization must inform patients of their right to revoke consent at any time, except to the extent that action has been taken in reliance thereon, in accordance with Minnesota law.
The authorization must specifically address the disclosure of mental health records, which receive special protection under Minnesota law and require specific consent.
The authorization must comply with both federal regulations (42 CFR Part 2) and Minnesota law regarding the disclosure of substance abuse treatment records, which require specific consent.
The authorization must specifically address the disclosure of HIV/AIDS-related information, which requires explicit consent under Minnesota law.
The authorization must address Minnesota's specific provisions regarding minors' consent to certain healthcare services and the disclosure of related information.
The authorization must specifically address the disclosure of genetic information, which is protected under both federal (GINA) and Minnesota law.
If using electronic signatures, the authorization must comply with both federal ESIGN Act requirements and Minnesota's Uniform Electronic Transactions Act.
The authorization must acknowledge that under Minnesota law, a provider may not charge a fee for copies of records requested by a patient or authorized representative if the request is for purposes of reviewing current medical care.
The authorization must acknowledge that the provider must maintain a record of the authorization and comply with both federal HIPAA and Minnesota record retention requirements.
The authorization must specifically address the disclosure of psychotherapy notes, which require a separate authorization under federal HIPAA regulations.
If the authorization is for marketing purposes, it must state if the marketing involves direct or indirect remuneration to the covered entity from a third party.
If the authorization is for research purposes, it must meet additional requirements under both federal and Minnesota law, including IRB or privacy board approval documentation.