Skip to content

HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy

Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.

Introduction

A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.

0/5000

Key Things to Know

  1. 1

    HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.

  2. 2

    Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.

  3. 3

    Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.

  4. 4

    Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.

  5. 5

    Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.

  6. 6

    A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.

  7. 7

    Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.

Key decisions before you file

Before you file a HIPAA Authorization in Tennessee, a few decisions shape the document: which option to choose and what each one means. The HIPAA Authorization guide walks through them.

Open the HIPAA Authorization guide

Customize your HIPAA Authorization Template with DocDraft

Tennessee Requirements for HIPAA Authorization

  • Federal Authorization Requirements (45 CFR § 164.508(c))

    The HIPAA Authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.

  • Core Elements of Authorization (45 CFR § 164.508(c)(1)(i))

    The authorization must include a description of the information to be used or disclosed that identifies the information in a specific and meaningful fashion.

  • Identification of Parties (45 CFR § 164.508(c)(1)(ii)-(iii))

    The authorization must identify the persons or class of persons authorized to make the requested use or disclosure, and the persons or class of persons to whom the covered entity may make the requested disclosure.

  • Purpose of Disclosure (45 CFR § 164.508(c)(1)(iv))

    The authorization must include a description of each purpose of the requested use or disclosure. The statement 'at the request of the individual' is sufficient when an individual initiates the authorization and does not provide a statement of purpose.

  • Expiration Requirements (45 CFR § 164.508(c)(1)(v))

    The authorization must include an expiration date or expiration event that relates to the individual or the purpose of the use or disclosure.

  • Signature and Date (45 CFR § 164.508(c)(1)(vi))

    The authorization must be signed by the individual and dated. If signed by a personal representative, a description of the representative's authority must be provided.

  • Right to Revoke (45 CFR § 164.508(c)(2)(i))

    The authorization must include a statement of the individual's right to revoke the authorization in writing, and either the exceptions to the right to revoke and a description of how to revoke, or a reference to the covered entity's notice of privacy practices.

  • Ability or Inability to Condition Treatment (45 CFR § 164.508(c)(2)(ii))

    The authorization must include a statement about whether the covered entity may condition treatment, payment, enrollment, or eligibility for benefits on the authorization.

  • Potential for Redisclosure (45 CFR § 164.508(c)(2)(iii))

    The authorization must include a statement that information used or disclosed pursuant to the authorization may be subject to redisclosure by the recipient and no longer protected by the Privacy Rule.

  • Copy to Individual (45 CFR § 164.508(c)(4))

    The covered entity must provide the individual with a copy of the signed authorization.

  • Tennessee Medical Records Act Compliance (Tenn. Code Ann. § 68-11-304)

    The authorization must comply with Tennessee's Medical Records Act which governs the confidentiality, disclosure, and patient access to medical records in Tennessee.

  • Tennessee Mental Health Records (Tenn. Code Ann. § 33-3-105)

    Special provisions for the disclosure of mental health records, which may require additional protections beyond standard HIPAA requirements.

  • Tennessee HIV/AIDS Information (Tenn. Code Ann. § 68-10-113)

    Specific requirements for the disclosure of HIV/AIDS-related information, which is subject to heightened confidentiality protections under Tennessee law.

  • Tennessee Substance Abuse Records (Tenn. Code Ann. § 33-3-110)

    Requirements for the disclosure of substance abuse treatment records, which may be subject to both federal regulations (42 CFR Part 2) and Tennessee state law.

  • Tennessee Genetic Information (Tenn. Code Ann. § 56-7-2702)

    Provisions related to the disclosure of genetic information, which may have specific protections under Tennessee law.

  • Tennessee Electronic Signatures (Tenn. Code Ann. § 47-10-101 et seq.)

    Requirements for electronic signatures on HIPAA Authorizations in accordance with Tennessee's Uniform Electronic Transactions Act.

  • Tennessee Minor Consent Laws (Tenn. Code Ann. § 63-6-223)

    Special provisions for authorizations related to minors' protected health information, including situations where minors can consent to certain treatments without parental involvement.

  • Tennessee Physician-Patient Confidentiality (Tenn. Code Ann. § 63-2-101)

    Requirements related to the physician-patient privilege and confidentiality obligations under Tennessee law.

  • Prohibition on Sale of PHI (45 CFR § 164.508(a)(4))

    The authorization must explicitly state if the disclosure will result in direct or indirect remuneration to the covered entity from a third party.

  • Tennessee Health Information Exchange (Tenn. Code Ann. § 68-11-1501 et seq.)

    Requirements related to the disclosure of protected health information to or through Tennessee's health information exchanges.

Frequently Asked Questions