HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy
Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.
Introduction
A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.
Key Things to Know
- 1
HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.
- 2
Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.
- 3
Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.
- 4
Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.
- 5
Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.
- 6
A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.
- 7
Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.
Key Decisions
HIPAA Authorization Requirements
Full legal name, date of birth, address, phone number, and other identifying information of the individual whose protected health information will be disclosed.
Include the patient's medical record number or other healthcare identifier if available.
New Mexico Requirements for HIPAA Authorization
The HIPAA Authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.
The authorization must include a description of the information to be used or disclosed, the name of the person(s) authorized to make the requested use or disclosure, the name of the person(s) to whom the covered entity may make the disclosure, an expiration date or event, and the signature of the individual and date.
The authorization must include a statement of the individual's right to revoke the authorization in writing, and either the exceptions to the right to revoke and a description of how to revoke, or a reference to the covered entity's notice of privacy practices.
The authorization must include a statement that information used or disclosed pursuant to the authorization may be subject to re-disclosure by the recipient and no longer protected by the Privacy Rule.
The authorization must comply with New Mexico's Medical Records Act which governs the confidentiality, disclosure, and patient access to medical records within the state.
The authorization must address electronic health records in accordance with New Mexico's laws regarding the maintenance and disclosure of electronic medical records.
For mental health records, the authorization must comply with additional protections provided under New Mexico law for confidentiality of mental health and developmental disabilities information.
The authorization must state that the covered entity may not condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs the authorization, with specific exceptions.
The authorization must not be combined with any other document to create a compound authorization, except as specifically permitted under HIPAA regulations.
For HIV-related information, the authorization must comply with New Mexico's specific provisions regarding the confidentiality of HIV test results and related information.
For substance abuse treatment records, the authorization must comply with both federal regulations and New Mexico state laws regarding the confidentiality of substance abuse patient records.
The authorization must address the disclosure of genetic information in compliance with both HIPAA and New Mexico's Genetic Information Privacy Act.
The authorization must address the special provisions for disclosure of minors' health information under both federal HIPAA regulations and New Mexico state law regarding minors' consent and confidentiality.
The covered entity must provide a copy of the signed authorization to the individual.
The authorization must be consistent with New Mexico's laws regarding health care decision-making, particularly as they relate to authorized representatives and health care powers of attorney.
The authorization must specifically state if it applies to psychotherapy notes, which require a separate authorization and cannot be combined with an authorization for other types of protected health information.
If the authorization is for marketing purposes, it must state if the marketing involves direct or indirect remuneration to the covered entity from a third party.
If the authorization involves the sale of protected health information, it must state that the disclosure will result in remuneration to the covered entity.
The authorization must comply with New Mexico's provisions regarding health information systems and health information exchanges operating within the state.
The authorization must be consistent with New Mexico's Patient Protection Act, which provides additional protections for patients' rights and confidentiality in healthcare settings.