Skip to content

HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy

Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.

Introduction

A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.

0/5000

Key Things to Know

  1. 1

    HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.

  2. 2

    Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.

  3. 3

    Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.

  4. 4

    Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.

  5. 5

    Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.

  6. 6

    A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.

  7. 7

    Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.

Key decisions before you file

Before you file a HIPAA Authorization in South Dakota, a few decisions shape the document: which option to choose and what each one means. The HIPAA Authorization guide walks through them.

Open the HIPAA Authorization guide

Customize your HIPAA Authorization Template with DocDraft

South Dakota Requirements for HIPAA Authorization

  • Federal Authorization Requirement (45 CFR § 164.508(a)(1))

    A valid HIPAA Authorization must be obtained before a covered entity may use or disclose protected health information (PHI) for purposes not otherwise permitted by the Privacy Rule.

  • Core Elements of Authorization (45 CFR § 164.508(c)(1))

    A valid authorization must contain specific core elements including a description of information to be used/disclosed, persons authorized to make and receive the disclosure, expiration date/event, signature of individual, and right to revoke.

  • Plain Language Requirement (45 CFR § 164.508(c)(3))

    The authorization must be written in plain language that the individual can understand.

  • Copy to Individual (45 CFR § 164.508(c)(4))

    If a covered entity seeks an authorization from an individual, the covered entity must provide the individual with a copy of the signed authorization.

  • Prohibition on Conditioning (45 CFR § 164.508(b)(4))

    With limited exceptions, covered entities may not condition treatment, payment, enrollment, or benefits eligibility on an individual signing an authorization.

  • Revocation Rights (45 CFR § 164.508(b)(5))

    An individual may revoke an authorization at any time, provided that the revocation is in writing, except to the extent that the covered entity has taken action in reliance on the authorization.

  • Required Statements (45 CFR § 164.508(c)(2))

    The authorization must contain statements about the individual's right to revoke, ability or inability to condition treatment/payment on authorization, and potential for redisclosure by recipient.

  • Compound Authorizations (45 CFR § 164.508(b)(3))

    An authorization for use or disclosure of PHI may not be combined with any other document to create a compound authorization, with specific exceptions.

  • South Dakota Medical Records Access (SDCL § 34-12-15)

    South Dakota law provides patients the right to access their medical records and requires healthcare providers to comply with such requests within specific timeframes.

  • South Dakota Mental Health Records (SDCL § 27A-12-26)

    Special provisions apply to the disclosure of mental health records in South Dakota, requiring specific authorization for release of such information.

  • South Dakota Substance Abuse Records (SDCL § 34-20A-65)

    Disclosure of substance abuse treatment records requires specific authorization in accordance with both state law and federal regulations.

  • South Dakota HIV/AIDS Information (SDCL § 34-23-2)

    Disclosure of HIV/AIDS test results requires specific written authorization from the patient.

  • South Dakota Minor Consent Laws (SDCL § 34-23-16)

    Special provisions apply to authorizations for minors' medical information, particularly for treatments that minors can consent to without parental involvement.

  • South Dakota Genetic Information (SDCL § 34-14-22)

    Specific authorization is required for the disclosure of genetic testing information.

  • Marketing Disclosures (45 CFR § 164.508(a)(3))

    If the authorization is for marketing purposes that involve financial remuneration, this fact must be disclosed in the authorization.

  • Psychotherapy Notes (45 CFR § 164.508(a)(2))

    A separate authorization is required for the use or disclosure of psychotherapy notes, with limited exceptions.

  • South Dakota Electronic Signatures (SDCL § 53-12-30)

    South Dakota law recognizes electronic signatures as legally valid for medical authorizations, consistent with the Uniform Electronic Transactions Act.

  • Minimum Necessary Standard (45 CFR § 164.502(b))

    Even with a valid authorization, covered entities must make reasonable efforts to limit disclosure of PHI to the minimum necessary to accomplish the intended purpose.

  • South Dakota Telehealth Provisions (SDCL § 34-52-3)

    Special authorization provisions apply to telehealth services and the electronic transmission of medical information across state lines.

  • Research Authorizations (45 CFR § 164.512(i))

    Special requirements apply to authorizations for the use or disclosure of PHI for research purposes, including potential waiver provisions.

Frequently Asked Questions