A Missing Signature Cost One Hospital $865,000
In 2019, a patient filed a complaint with the Office for Civil Rights after a hospital released her psychotherapy notes to a life insurance company. The hospital had a form on file — but it didn't specifically authorize the release of psychotherapy notes, which HIPAA treats as a separate category. The investigation snowballed. OCR found a pattern of sloppy authorization practices across the entire organization. What started as one patient's complaint turned into a costly corrective action plan.
I've seen variations of this story play out at clinics, dental offices, and health systems across the country. The authorization of release of health information sounds routine. It's anything but. A form with the wrong language, a missing element, or a staff member who doesn't understand the difference between consent and authorization can expose your organization to federal enforcement.
This guide breaks down what HIPAA actually requires, the mistakes I see most often, and how to build authorization processes your workforce can follow every time.
What Is an Authorization of Release of Health Information Under HIPAA?
A HIPAA authorization is a detailed, written document that gives a covered entity permission to use or disclose a specific individual's protected health information (PHI) for a purpose that isn't otherwise permitted by the Privacy Rule. It's not the same as consent for treatment. It's not the same as a Notice of Privacy Practices acknowledgment.
Think of it this way: HIPAA already permits certain uses of PHI — treatment, payment, and health care operations — without any authorization from the patient. But when someone outside that circle wants access, such as an employer, a life insurer, or a marketing firm, the patient must sign a valid authorization before you release a single page.
The authorization of release of health information puts the patient in control. It says: "I understand exactly what information will be shared, with whom, and for what reason — and I agree to it."
The Six Required Elements Every Authorization Must Contain
Under 45 CFR § 164.508, a valid authorization must include all of the following:
- A specific description of the PHI to be used or disclosed. "All medical records" is too vague. Specify dates of service, types of records, or conditions.
- The name or class of persons authorized to make the disclosure. Who is releasing the information?
- The name or class of persons to whom the disclosure will be made. Who is receiving it?
- A description of the purpose of the disclosure. "At the request of the individual" is acceptable if the patient initiates it.
- An expiration date or event. Open-ended authorizations are not valid.
- The individual's signature and date. Or the signature of a personal representative, with documentation of their authority.
Miss any one of these, and the authorization is defective. A defective authorization means you cannot legally release the PHI. Period.
Three Required Statements You Can't Skip
Beyond the six core elements, HIPAA also requires three statements on every authorization form:
- The individual's right to revoke the authorization in writing.
- The ability or inability to condition treatment, payment, enrollment, or eligibility on the authorization.
- The potential that the disclosed information could be re-disclosed by the recipient and no longer protected by HIPAA.
I've reviewed authorization forms from hundreds of organizations. At least a third are missing one or more of these required statements. That's a compliance gap hiding in plain sight.
The Difference Between Consent and Authorization — And Why It Matters
This is the single most common point of confusion I encounter during workforce training sessions. Staff members use "consent" and "authorization" interchangeably. They're not the same thing under HIPAA.
Consent (under 45 CFR § 164.506) is optional. A covered entity may obtain consent for treatment, payment, and health care operations, but it's not required by HIPAA. Many states require it, which adds to the confusion.
Authorization (under 45 CFR § 164.508) is mandatory for disclosures that fall outside treatment, payment, and operations. Marketing uses, sale of PHI, and disclosures to third parties like employers all require a signed authorization.
When your front desk hands a patient a "consent form" but the actual purpose is to release records to an attorney, you've got the wrong instrument. And if OCR comes knocking, "we thought consent covered it" won't hold up.
Real Enforcement: What Happens When Authorizations Go Wrong
OCR doesn't just pursue mega-breaches. They investigate authorization failures too, especially when patients file individual complaints. Here are patterns from real enforcement activity:
Improper disclosures without authorization are consistently among the top complaint categories HHS receives each year. According to the HHS enforcement highlights page, "impermissible uses and disclosures of PHI" has been the most common compliance issue investigated since the Privacy Rule took effect.
In many cases, the problem isn't malice. It's process failure. A staff member releases records based on a verbal request. An old authorization form without an expiration date gets treated as still valid. A personal representative signs the form, but nobody documents their authority. Each of these is a violation.
The Compound Risk Most Practices Overlook
Here's what I tell every client: authorization failures rarely stay isolated. When OCR investigates one bad disclosure, they audit your entire authorization process. They look at your forms, your policies, and your workforce training records. If they find systemic issues — and they usually do — the corrective action plan multiplies fast.
That's why building the process right from the start matters far more than fixing it after a complaint.
Psychotherapy Notes: The Authorization Trap
HIPAA carves out psychotherapy notes for extra protection under 45 CFR § 164.508(a)(2). These notes require their own separate authorization — distinct from any general authorization of release of health information the patient may have already signed.
A general authorization that says "all medical records" does not cover psychotherapy notes. The authorization must specifically reference them. I've seen behavioral health practices get tripped up on this repeatedly, especially when responding to attorney subpoenas or insurance requests.
If your organization handles any mental health records, make sure your authorization forms and your staff training address this distinction explicitly.
How to Build an Authorization Process That Actually Works
Having the right form is only half the battle. You need a process your entire workforce can follow consistently. Here's the framework I recommend:
Step 1: Audit Your Current Forms
Pull every authorization form your organization uses. Compare each one against the six required elements and three required statements from 45 CFR § 164.508. Flag any form that's missing components. I guarantee you'll find at least one gap.
Step 2: Create a Verification Checklist
Give your staff a simple checklist to verify before processing any authorization. Is the form complete? Is the signature dated? Has the expiration date passed? Is a personal representative signing, and if so, is their authority documented? This takes sixty seconds and prevents the most common errors.
Step 3: Train Every Person Who Touches PHI
Workforce training isn't optional — it's required under the HIPAA Privacy Rule. And generic training that skims over authorization requirements isn't enough. Your team needs scenario-based training that walks through real situations: the attorney who calls demanding records, the employer who faxes over an incomplete form, the family member who insists they have the right to access a patient's file.
Our HIPAA training catalog includes courses designed to give your workforce practical, specific guidance on authorization requirements and PHI disclosure rules.
Step 4: Document Everything
Keep copies of every signed authorization alongside the records of what was disclosed, to whom, when, and by which staff member. Under the HIPAA Privacy Rule, you must retain authorization documentation for six years. If OCR ever investigates, your documentation is your defense.
Can a Patient Revoke an Authorization?
Yes. A patient can revoke any authorization of release of health information at any time, as long as they do so in writing. The revocation applies to future disclosures — you're not required to claw back information already released in good faith before the revocation.
Your organization must have a clear process for receiving and acting on revocations. Document the revocation, update the patient's file, and notify any staff involved in ongoing disclosures. This is another area where scenario-based HIPAA training pays for itself — staff who've practiced handling revocations in training handle them correctly in the real world.
State Laws Can Add Requirements — Don't Ignore Them
HIPAA sets the federal floor, not the ceiling. Many states impose additional requirements on the authorization of release of health information. Some states require specific language about HIV/AIDS records, substance abuse treatment, or genetic information. Others mandate particular form formats or notarization.
The HIPAA preemption rule is straightforward: when state law is more protective of the patient's privacy, the state law applies. Your forms and processes need to account for both federal and state requirements. If you operate in multiple states, this gets complicated fast — which is exactly why it belongs in your compliance program and your training curriculum.
Your Authorization Process Is Only as Strong as Your Training
Every authorization failure I've investigated traces back to the same root cause: someone in the workforce didn't understand the rules. Not because they were careless, but because nobody taught them. The receptionist who accepted a verbal authorization over the phone. The medical records clerk who released psychotherapy notes under a general authorization. The office manager who kept processing disclosures on a form that expired two years ago.
These aren't bad people. They're untrained people. And under HIPAA, the covered entity bears the responsibility for that gap.
Build your authorization forms correctly. Create verification checklists. And invest in workforce training that covers real authorization scenarios your staff will actually face. That's how you protect your patients, your organization, and yourself.