The Question That Trips Up Even Experienced Compliance Officers

Last year, I watched a compliance officer at a mid-size hospital freeze during an audit when the reviewer asked a deceptively simple question: an authorization is required for which of the following HIPAA disclosures? She knew the Privacy Rule inside and out — or thought she did. But when presented with a list of scenarios, she second-guessed herself on three of them.

She's not alone. This question shows up on every HIPAA certification exam, every workforce training quiz, and — most critically — in every real-world decision your staff makes about releasing protected health information (PHI). Getting it wrong doesn't just cost you points on a test. It costs real money and real trust.

Let's break down exactly which uses and disclosures of PHI require a signed authorization, which ones don't, and where the gray areas hide.

What HIPAA Authorization Actually Means

A HIPAA authorization is a detailed, written document that gives a covered entity permission to use or disclose PHI for purposes that fall outside the standard permitted uses. It's not a consent form. It's not a notice of privacy practices acknowledgment. It's a specific, revocable, time-limited permission slip.

Under the HIPAA Privacy Rule — found at 45 CFR Part 164, Subpart E — covered entities can use and disclose PHI without authorization for treatment, payment, and healthcare operations (TPO). They can also disclose PHI without authorization in about a dozen other specific situations. Everything else? You need that signed authorization.

Uses and Disclosures That Require Authorization

Here's the direct answer. The Privacy Rule at 45 CFR § 164.508 requires an authorization for these categories:

1. Marketing Communications

If your organization wants to send patients communications that encourage them to purchase or use a product or service, that's marketing under HIPAA. You need a signed authorization. The only exceptions are face-to-face communications and promotional gifts of nominal value.

This is where I've seen organizations stumble the most. A dermatology practice sending emails about a new cosmetic product line using their patient list? That's marketing. They needed authorizations they never obtained.

2. Sale of PHI

Any disclosure of PHI where the covered entity receives direct or indirect remuneration requires authorization. Period. The HITECH Act tightened this significantly. If money is changing hands in exchange for patient data, the patient must authorize it.

3. Psychotherapy Notes

Psychotherapy notes — the personal notes a mental health professional keeps separate from the medical record — get the highest level of protection under HIPAA. Using or disclosing these notes almost always requires authorization, even for treatment purposes by another provider.

There are narrow exceptions: the originator of the notes can use them for treatment, and they can be disclosed for certain law enforcement or oversight activities. But in practice, you should default to requiring authorization.

4. Research Purposes (With Limited Exceptions)

Using PHI for research generally requires individual authorization unless the covered entity obtains an Institutional Review Board (IRB) or Privacy Board waiver. I've consulted with academic medical centers that assumed their IRB approval alone covered them. It doesn't — you need to specifically address the HIPAA authorization requirement separately from informed consent for the study.

This is the catch-all. Any use or disclosure that doesn't fall under treatment, payment, healthcare operations, or one of the specifically permitted categories (public health, law enforcement, judicial proceedings, etc.) requires authorization. Sharing a patient's information with their employer for non-treatment reasons? Authorization. Sending PHI to a life insurance company? Authorization.

Uses and Disclosures That Do NOT Require Authorization

Understanding what doesn't need authorization is equally important. Your workforce needs to recognize both sides of this line.

Treatment, Payment, and Healthcare Operations

A surgeon sharing your operative report with the physical therapist handling your rehab? No authorization needed — that's treatment. Your billing department sending a claim to the insurance company? Payment. Your quality improvement team reviewing patient charts for outcomes data? Healthcare operations.

Public Health Activities

Reporting communicable diseases to public health authorities, reporting adverse events to the FDA, notifying individuals about potential exposure — none of these require authorization.

Victims of Abuse, Neglect, or Domestic Violence

Covered entities can report suspected abuse or neglect to government authorities without authorization, as required by law.

Health Oversight, Judicial Proceedings, and Law Enforcement

Responding to a court order, cooperating with HHS during a compliance investigation, or disclosing PHI to law enforcement under specific conditions — these are all permitted without authorization.

Disclosures to the Individual

This one seems obvious but gets overlooked on exams. A patient has a right to access their own PHI. You don't need them to sign an authorization to give them their own records.

The $5.55 Million Lesson From Advocate Medical Group

When authorization requirements get ignored, OCR doesn't look the other way. In 2016, Advocate Medical Group paid $5.55 million to settle HIPAA violations with the Office for Civil Rights. While the case centered on physical safeguards and ePHI breaches affecting approximately 4 million patients, the investigation exposed systemic gaps in how the organization handled PHI — including authorization and disclosure controls.

I've seen it in smaller organizations, too. A three-provider clinic in the Midwest disclosed a patient's substance abuse records to a family member without authorization. The patient filed a complaint with OCR. The investigation uncovered that the clinic had no written authorization policies at all. The corrective action plan consumed six months and tens of thousands of dollars in consultant fees.

What a Valid HIPAA Authorization Must Contain

Even when you know authorization is required, a poorly drafted form can be just as bad as no form at all. Under the Privacy Rule, a valid authorization must include:

  • A specific description of the PHI to be used or disclosed
  • The name or class of persons authorized to make the disclosure
  • The name or class of persons to whom the disclosure will be made
  • A description of the purpose of the use or disclosure
  • An expiration date or event
  • The individual's signature and date
  • A statement about the right to revoke the authorization
  • A statement that information disclosed may be subject to re-disclosure and no longer protected

Missing any one of these elements renders the authorization defective. I review authorization forms for clients regularly, and roughly half of them are missing at least one required element when I first see them.

How to Train Your Workforce to Get This Right

Knowing when an authorization is required for which of the following HIPAA scenarios isn't just an exam question — it's a daily operational decision. Every person in your organization who touches PHI needs to understand this distinction.

Generic annual training won't cut it. Your workforce needs scenario-based learning that forces them to apply the rules. Our HIPAA training catalog includes modules specifically designed around authorization requirements, with real-world scenarios that mirror what your staff actually encounters.

Front desk staff need to know they can't release records to an attorney without authorization. Nurses need to understand that discussing a case with a patient's family member may require authorization depending on the circumstances. Billing teams need to recognize when a payer request crosses the line from payment operations into something that requires patient sign-off.

Build Authorization Checks Into Your Workflow

Don't rely on individual judgment alone. Build checkpoints into your EHR and records release process. Before any disclosure that isn't clearly TPO, your system should prompt staff to verify authorization status. Create a simple decision tree and post it where records requests get processed.

If you're building or updating your compliance program, our compliance training courses walk through how to create these workflows step by step.

The Bottom Line for Your Organization

The Privacy Rule draws a clear line. Treatment, payment, healthcare operations, and a defined list of public interest activities don't require authorization. Marketing, sale of PHI, psychotherapy notes, and most research do. Everything outside the permitted categories does.

Your staff makes these decisions dozens of times a week. Every incorrect release of PHI without proper authorization is a potential breach notification event, an OCR complaint, and a trust violation with your patients.

Get specific with your training. Get specific with your authorization forms. And when in doubt, get the signature before you release the records. Browse our HIPAA training programs to make sure your entire workforce understands exactly where that line falls.