Skip to content

HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy

Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.

Introduction

A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.

0/5000

Key Things to Know

  1. 1

    HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.

  2. 2

    Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.

  3. 3

    Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.

  4. 4

    Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.

  5. 5

    Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.

  6. 6

    A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.

  7. 7

    Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.

Key decisions before you file

Before you file a HIPAA Authorization in New Jersey, a few decisions shape the document: which option to choose and what each one means. The HIPAA Authorization guide walks through them.

Open the HIPAA Authorization guide

Customize your HIPAA Authorization Template with DocDraft

New Jersey Requirements for HIPAA Authorization

  • Federal Authorization Requirements (45 CFR § 164.508(c))

    The HIPAA Authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.

  • Core Elements of Authorization (45 CFR § 164.508(c)(1))

    The authorization must include a description of the information to be used or disclosed, the name of the person(s) authorized to make the requested use or disclosure, the name of the person(s) to whom the covered entity may make the disclosure, an expiration date or event, and the signature of the individual and date.

  • Required Statements (45 CFR § 164.508(c)(2))

    The authorization must include statements about the individual's right to revoke the authorization in writing, the ability or inability to condition treatment on the authorization, and the potential for information to be redisclosed by the recipient and no longer protected by HIPAA.

  • New Jersey Health Information Exchange (N.J.A.C. 8:57-3.19)

    For authorizations involving the New Jersey Health Information Exchange (NJHIN), the document must comply with state-specific requirements for electronic health information exchange and explicitly state whether data may be shared through the NJHIN.

  • Mental Health Records (N.J.S.A. 30:4-24.3)

    For disclosure of mental health records in New Jersey, the authorization must specifically indicate that mental health information is being disclosed and may require additional protections beyond standard HIPAA requirements.

  • HIV/AIDS Information (N.J.S.A. 26:5C-1 et seq.)

    New Jersey law requires specific and explicit authorization for the disclosure of HIV/AIDS-related information, with clear statements about the purpose of disclosure and potential consequences of release.

  • Substance Use Disorder Records (N.J.S.A. 26:2B-15; 42 CFR Part 2)

    For substance use disorder records, both federal regulations (42 CFR Part 2) and New Jersey law require specific authorization elements beyond HIPAA, including explicit consent for each disclosure and prohibition on redisclosure.

  • Genetic Information (N.J.S.A. 10:5-45)

    New Jersey's Genetic Privacy Act requires specific authorization for the disclosure of genetic information, with explicit statements about the purpose and limitations of disclosure.

  • Minors' Health Information (N.J.S.A. 9:17A-4; N.J.S.A. 9:17A-1 et seq.)

    For minors in New Jersey, special rules apply to authorizations for certain sensitive services (reproductive health, substance use, mental health) that minors can consent to without parental involvement, requiring compliance with both HIPAA and state minor consent laws.

  • Prohibition on Remuneration (45 CFR § 164.508(a)(4))

    The authorization must disclose if the disclosure will result in remuneration to the covered entity from the recipient of the PHI, as required by the HITECH Act amendments to HIPAA.

  • Marketing Disclosures (45 CFR § 164.508(a)(3))

    If the authorization is for marketing purposes, it must state if the marketing involves direct or indirect remuneration to the covered entity from a third party.

  • Research Participation (45 CFR § 164.508(c)(1)(v))

    For research-related disclosures, the authorization must meet specific requirements including a description of the research study, expiration tied to the research, and statements about conditions for treatment related to research participation.

  • Psychotherapy Notes (45 CFR § 164.508(b)(3)(ii))

    For disclosure of psychotherapy notes, a separate authorization specific to psychotherapy notes is required and cannot be combined with authorizations for other health information.

  • New Jersey Patient Safety Act (N.J.S.A. 26:2H-12.23 et seq.)

    For disclosures related to patient safety events or information reported to Patient Safety Organizations, the authorization must comply with New Jersey's Patient Safety Act protections and explicitly state that such information is being disclosed.

  • Electronic Signatures (N.J.S.A. 12A:12-1 et seq.)

    New Jersey follows the Uniform Electronic Transactions Act, allowing for electronic signatures on HIPAA Authorizations if proper authentication and security measures are in place to verify the signer's identity.

  • Compound Authorizations (45 CFR § 164.508(b)(3))

    HIPAA prohibits combining authorizations with other documents (like consent to treatment) except in specific circumstances. The authorization must be separate or clearly distinguishable from other documents.

  • Copy to Individual (45 CFR § 164.508(c)(4))

    The covered entity must provide a copy of the signed authorization to the individual, as required by federal HIPAA regulations.

  • New Jersey Medical Records Access (N.J.A.C. 8:43G-15.3)

    The authorization must comply with New Jersey's laws regarding patient access to medical records, including provisions for reasonable fees for copies and timelines for providing access.

  • Specially Protected Information (N.J.S.A. 26:4-41)

    New Jersey law requires that authorizations for specially protected health information (including sexually transmitted diseases, tuberculosis, and certain other conditions) contain specific statements about the sensitivity of the information being disclosed.

  • Revocation Process (45 CFR § 164.508(c)(2)(i); N.J.A.C. 13:35-6.5)

    The authorization must describe the process for revocation, including where and how to submit a revocation request, in compliance with both federal HIPAA requirements and New Jersey state law.

Frequently Asked Questions