A hospital in Texas released ten years of a patient's psychiatric records to an employer — all because a front-desk employee accepted an authorization form that was missing a required element. No expiration date. No description of the specific information to be disclosed. Just a signature at the bottom and a vague reference to "all medical records." That single piece of paper triggered an OCR complaint, a costly internal investigation, and a complete overhaul of the organization's disclosure workflows. I've seen variations of this story play out at clinics, health plans, and business associates across the country. HIPAA authorizations seem simple until they're not — and "not" usually means a breach.
This post breaks down what a valid authorization actually requires under the HIPAA Privacy Rule, where organizations consistently stumble, and what you should build into your training program right now to keep your workforce out of trouble.
What Are HIPAA Authorizations, Exactly?
An authorization under HIPAA is a detailed, written document that gives a covered entity permission to use or disclose a patient's protected health information (PHI) for purposes that aren't otherwise permitted by the Privacy Rule. Treatment, payment, and health care operations don't require one. Marketing to a patient using PHI, selling PHI, and most disclosures to employers or life insurers do.
Think of it this way: consents are broad. Authorizations are narrow, specific, and loaded with required elements. If your staff treats them as interchangeable, you have a problem.
The Privacy Rule at 45 CFR Part 164, Subpart E spells out when authorizations are required and exactly what they must contain. Yet I consistently find organizations that haven't updated their authorization forms — or their training — in years.
The Six Elements Every Valid Authorization Must Include
HHS doesn't leave this to interpretation. A valid authorization under 45 CFR § 164.508 must contain all of the following core elements:
- A specific description of the PHI to be used or disclosed. "All records" doesn't cut it. Name the type of information — lab results, psychotherapy notes, substance abuse treatment records.
- The name or specific identification of the person(s) authorized to make the disclosure. Which covered entity or individual is releasing the information?
- The name or specific identification of the person(s) to whom the disclosure will be made. Who's receiving it?
- A description of each purpose of the requested use or disclosure. "At the request of the individual" is acceptable if the patient initiates it, but the field can't be blank.
- An expiration date or expiration event. Open-ended authorizations are invalid. Period.
- The individual's signature and date. If a personal representative signs, include their authority to act.
Miss even one of these, and the authorization is defective. A defective authorization means the disclosure was unauthorized. An unauthorized disclosure means you've potentially breached the Privacy Rule.
Required Statements You Can't Skip
Beyond the six core elements, valid HIPAA authorizations must also include three specific statements:
- The individual's right to revoke the authorization in writing.
- The ability or inability to condition treatment, payment, enrollment, or eligibility on the authorization.
- The potential for the disclosed information to be re-disclosed by the recipient and no longer protected by HIPAA.
I've reviewed forms from large health systems that omitted the re-disclosure warning entirely. That single omission made every authorization processed on that form defective.
The $5.5 Million Mistake: When Authorizations Go Wrong at Scale
OCR doesn't just issue warning letters. They impose penalties that reshape organizations. In 2017, Memorial Healthcare System paid $5.5 million to settle HIPAA violations that included employees accessing PHI without authorization. While the root issue involved impermissible access rather than paper authorizations, the lesson is the same: every disclosure of PHI must have a lawful basis, and that basis must be documented and verifiable.
If your team can't articulate the difference between a permissible use under the Privacy Rule and a situation requiring a signed authorization, you're operating on borrowed time. Our HIPAA Introduction Training 2026 course walks through these distinctions with real-world scenarios your staff will actually remember.
Psychotherapy Notes: The Authorization Trap Nobody Sees Coming
Here's where even experienced privacy officers get burned. Psychotherapy notes — the personal notes a mental health professional keeps separate from the medical record — carry extra protection under HIPAA. They require their own standalone authorization, separate from any other authorization for medical records.
You can't bundle psychotherapy notes into a general authorization form. The authorization for psychotherapy notes cannot be combined with an authorization for other types of PHI. Full stop.
I worked with a behavioral health clinic that had been using a single combined form for three years. Every disclosure of psychotherapy notes during that period was technically a HIPAA violation. The remediation effort consumed months.
Substance Abuse Records Add Another Layer
If your organization handles substance use disorder (SUD) treatment records under 42 CFR Part 2, you face even stricter authorization requirements. These records carry federal protections beyond HIPAA, and the authorization forms must meet both sets of requirements. Mixing these up isn't a gray area — it's a compliance failure with teeth.
When Your Staff Becomes the Weakest Link
Most authorization failures I investigate trace back to workforce members who never received specific training on what makes an authorization valid. They see a signed form and assume they're covered. They don't check for an expiration date. They don't verify the description of PHI matches what's being released.
This is exactly the kind of scenario covered in Accessing Records: If It's Not Your Job, It's a Breach. The course addresses the critical difference between having a form on file and having a valid authorization on file.
Your front-desk staff, your HIM department, your billing team — they all touch authorizations. And they all need to know when to stop, verify, and escalate rather than just process.
What Happens When a Patient Revokes an Authorization
Patients can revoke HIPAA authorizations at any time, in writing. Your organization must honor that revocation — except for actions already taken in reliance on the original authorization.
The operational question is: does your staff know what to do when a revocation arrives? Do they know where to document it? Who to notify? How to halt a pending disclosure?
If a breach happens because someone processed a disclosure after a revocation was received but before it was logged in the system, your organization bears the liability. Build the revocation workflow into your training. Build it into your EHR. And test it.
Research Authorizations: A Frequently Mishandled Category
Covered entities involved in research must obtain HIPAA authorizations (or a waiver from an IRB or privacy board) before using PHI for research purposes. These authorizations can include a general description of future research if certain conditions are met, but the rules are precise.
I've seen academic medical centers assume that IRB approval replaces the need for a HIPAA authorization. It doesn't. They serve different legal purposes. The IRB governs ethical research conduct. The HIPAA authorization governs the individual's right to control their PHI.
How to Audit Your Authorization Process Today
Here's a practical checklist I use with clients:
- Pull ten recently processed authorizations at random.
- Check each one against the six required core elements and three required statements.
- Verify that psychotherapy notes were not bundled into general authorizations.
- Confirm that no disclosures were made after a revocation was received.
- Review whether the PHI actually disclosed matched the PHI described in the authorization.
If you find defects — and in my experience, most organizations do on the first audit — treat them as training opportunities rather than just documentation fixes. The form is only as good as the person reviewing it before hitting "send."
The First 60 Minutes After an Unauthorized Disclosure
When someone on your team discloses PHI based on a defective or revoked authorization, the clock starts immediately. You have a potential breach, and your incident response plan needs to activate. Under the Breach Notification Rule, you must assess whether the disclosure compromises the PHI and notify affected individuals, HHS, and potentially the media depending on the scale.
Our First 60 Minutes: Incident Response course walks your team through exactly what to do in those critical early moments — who to call, what to document, and how to contain the damage before it multiplies.
Stop Treating Authorizations Like Paperwork
HIPAA authorizations aren't a checkbox. They're a legal mechanism that protects your patients' most sensitive information and shields your organization from enforcement actions. Every element matters. Every staff member who touches them needs to understand what they're looking at and what's at stake.
If your authorization forms haven't been reviewed by legal counsel this year, schedule that review. If your workforce training doesn't include a module on valid authorizations, fix that gap. The organizations that get burned aren't the ones that skip authorizations entirely — they're the ones that think they're doing it right when they're not.