HIPAA Authorization: What You Need to Know to Protect Your Medical Privacy
Learn about HIPAA Authorization forms, why they matter for your healthcare privacy, and how to use them effectively regardless of your family or financial situation.
Introduction
A HIPAA Authorization is a legal document that gives healthcare providers permission to share your protected health information with specific people or organizations. Unlike the basic HIPAA privacy notices you routinely sign at doctor's offices, a HIPAA Authorization provides you with control over who can access your medical information beyond your direct healthcare providers. Whether you're married with children, single, or have significant assets to protect, understanding how to use HIPAA Authorizations effectively is crucial for maintaining privacy while ensuring your loved ones can help during medical emergencies.
Key Things to Know
- 1
HIPAA Authorizations are revocable at any time—you can change your mind about who has access to your information.
- 2
Without a HIPAA Authorization, healthcare providers may be legally prohibited from sharing your medical information, even with close family members.
- 3
Consider updating your HIPAA Authorization after major life events such as marriage, divorce, or when children reach adulthood.
- 4
Be specific about what information can be shared—you can exclude sensitive information like mental health records or genetic testing if desired.
- 5
Keep copies of your signed HIPAA Authorization with your other important documents and provide copies to your designated representatives.
- 6
A HIPAA Authorization works best when paired with other healthcare documents like an advance directive and healthcare power of attorney.
- 7
Different healthcare systems may have their own HIPAA Authorization forms, so you may need to complete multiple forms for different providers.
Key Decisions
HIPAA Authorization Requirements
Full legal name, date of birth, address, phone number, and other identifying information of the individual whose protected health information will be disclosed.
Include the patient's medical record number or other healthcare identifier if available.
Wyoming Requirements for HIPAA Authorization
The HIPAA Authorization must be written in plain language and contain specific elements including a description of the information to be disclosed, the person authorized to make the disclosure, the person to whom the disclosure may be made, an expiration date, and a statement of the individual's right to revoke the authorization.
The authorization must include a description of the information to be used or disclosed, the name of the person(s) authorized to make the requested use or disclosure, the name of the person(s) to whom the covered entity may make the disclosure, a description of each purpose of the disclosure, an expiration date or event, and the signature of the individual with date.
The authorization must include statements about the individual's right to revoke the authorization in writing, the ability or inability to condition treatment on the authorization, and the potential for information to be redisclosed by the recipient and no longer protected by HIPAA.
Wyoming law provides that medical records are confidential and privileged, and healthcare providers must maintain the confidentiality of patient information except as authorized by the patient or as otherwise permitted by law.
Special protections for mental health information requiring specific authorization for the release of mental health treatment records.
Federal regulations impose additional requirements for authorizations to disclose substance abuse treatment records from federally assisted programs, requiring specific elements beyond standard HIPAA authorizations.
Wyoming law provides additional protections for HIV/AIDS-related information, requiring specific authorization for disclosure of such information.
Authorizations involving genetic information must comply with the Genetic Information Nondiscrimination Act (GINA), which prohibits discrimination based on genetic information.
Wyoming law specifies when minors can consent to their own healthcare and when parents/guardians can access minors' health information, affecting authorization requirements for minors' records.
A covered entity may not condition treatment, payment, enrollment, or eligibility for benefits on whether the individual signs an authorization, except in limited circumstances.
The authorization must clearly state that the individual has the right to revoke the authorization at any time, though the revocation will not apply to information already disclosed in reliance on the authorization.
Provisions regarding healthcare agents' authority to access medical information and make healthcare decisions, which may affect HIPAA authorizations in the context of advance directives.
The covered entity must provide a copy of the signed authorization to the individual.
Wyoming law regarding durable powers of attorney for healthcare, which may include provisions for access to protected health information.
A separate authorization is required for the use or disclosure of psychotherapy notes, with specific exceptions.
Special requirements for authorizations for marketing purposes, including disclosure if the marketing involves remuneration to the covered entity.
An authorization for the sale of protected health information must state that the disclosure will result in remuneration to the covered entity.
Wyoming requirements for the retention of medical records, which may affect how long authorizations need to be maintained.
Federal and Wyoming laws governing the validity of electronic signatures on HIPAA authorizations, including compliance with the ESIGN Act and Wyoming's Uniform Electronic Transactions Act.
Restrictions on combining an authorization with any other document, with specific exceptions for research-related authorizations and certain other circumstances.