A therapist's office in Connecticut faxed 47 pages of psychotherapy notes to an employer — all because someone handed them a generic HIPAA release of information form that didn't specify what kind of PHI was being authorized. The patient never intended for those notes to leave the office. By the time the practice realized the mistake, the damage was done, and OCR came knocking.

I've seen variations of this story play out dozens of times. The form looks official. It has a signature. Everyone assumes it's valid. But a HIPAA release of information form that's missing even one required element isn't just sloppy — it can turn a routine records request into a reportable breach.

What Is a HIPAA Release of Information Form, Exactly?

Under the HIPAA Privacy Rule, a release of information form is a written authorization that allows a covered entity to use or disclose a patient's protected health information for purposes that aren't otherwise permitted. The technical term is an "authorization" under 45 CFR § 164.508.

This matters because HIPAA draws a sharp line. Some disclosures — treatment, payment, health care operations — don't require an authorization at all. But the moment you're sending records to an attorney, an employer, a life insurance company, or a family member who isn't involved in care, you need a valid, signed authorization form. No shortcuts.

The Six Core Elements OCR Demands on Every Form

Here's where most organizations trip up. They download a template from a random website, slap their logo on it, and assume they're covered. But HHS has spelled out exactly what a valid HIPAA release of information form must contain. Miss one, and the entire authorization is defective.

1. A Specific Description of the Information

"All medical records" is not specific enough in many contexts. Your form needs to describe the PHI to be disclosed in a meaningful way — dates of service, types of records, categories of information. This is especially critical in behavioral health, where psychotherapy notes carry extra protections.

2. Who Is Authorized to Make the Disclosure

Name the person or entity who will release the information. "My doctor" doesn't cut it. Use the practice name, provider name, or facility.

3. Who Will Receive the Information

Identify the recipient. An authorization that says "any interested party" is vague to the point of being invalid.

4. The Purpose of the Disclosure

Why is the information being released? "At the request of the individual" is an acceptable purpose. But the form still needs to state it explicitly.

5. An Expiration Date or Event

Every authorization must expire. This can be a specific date or a triggering event, like "upon completion of the legal case." Open-ended authorizations without expiration violate the rule.

6. The Individual's Signature and Date

Seems obvious, but I've audited practices where staff processed unsigned authorizations because "the patient said it was fine over the phone." That's not how this works.

Three Required Statements You're Probably Missing

Beyond those six elements, 45 CFR § 164.508 requires three statements on the form:

  • The individual's right to revoke the authorization in writing.
  • The ability (or inability) to condition treatment, payment, or eligibility on the authorization.
  • The potential for re-disclosure by the recipient, which could mean the information is no longer protected by HIPAA.

If your form doesn't include all three statements, it's defective. Period.

The $1.5 Million Mistake That Started With a Form

In 2019, OCR settled with Bayfront Health St. Petersburg for $85,000 after an impermissible disclosure of PHI. While that case involved issues beyond just forms, the pattern I've seen across OCR enforcement actions on the HHS enforcement page is consistent: organizations that don't have tight authorization processes eventually face consequences.

The Cignet Health case from 2011 resulted in a $4.3 million penalty — the first civil money penalty OCR ever imposed. Among the issues? Denying patients access to their records and failing to cooperate with OCR's investigation. But underlying it all was a fundamental failure to handle PHI disclosure properly.

Your authorization form is the front line of that process. If it's broken, everything downstream breaks with it.

Behavioral Health: Where Authorization Forms Get Dangerous

If your organization provides mental or behavioral health services, the stakes around your HIPAA release of information form multiply. Psychotherapy notes — the personal notes a therapist keeps separate from the medical record — require their own authorization. You cannot bundle them into a general release.

42 CFR Part 2, which governs substance use disorder records, adds another layer entirely. A standard HIPAA authorization form is not sufficient for Part 2 records. You need additional elements, including a statement that prohibits re-disclosure.

I've watched practices get this wrong because they use one generic form for everything. That's a compliance disaster waiting to happen. If your team handles behavioral health records, our HIPAA training for mental and behavioral health walks through exactly how these authorization requirements differ — and where the traps are.

Electronic Authorizations: Yes, They Count

With telehealth and patient portals now standard, many organizations accept electronic HIPAA release of information forms. This is permitted, but your e-signature process needs to comply with the ESIGN Act. That means the patient must clearly intend to sign, and you must retain a copy that's accessible and reproducible.

Here's what I tell every client: if you can't pull up the signed authorization within 30 seconds during an OCR audit, you don't really have it. Your EHR should log the date, time, IP address, and the exact version of the form the patient signed. Screenshots of a checkbox aren't enough.

Revocation: The Part Staff Forget About

Patients can revoke an authorization at any time, in writing. Your workforce needs to know what to do when that happens. I've seen organizations continue releasing records for months after a patient revoked consent — simply because no one flagged it in the system.

Build a revocation workflow. When a patient submits a written revocation, it should trigger an immediate update in your records management system, a notification to anyone processing releases, and documentation of the date the revocation was received. The covered entity must stop disclosures based on that authorization going forward, though disclosures already made in reliance on the valid authorization are not violations.

What Happens When You Get a Suspicious Request

Not every release of information request is legitimate. Social engineering attacks targeting healthcare organizations have surged. A caller claims to be from a law firm, sends over a convincing-looking authorization form, and your front desk releases records before anyone verifies the request.

This is a phishing vector that most workforce training programs completely ignore. Your staff needs to know how to verify the identity of requestors, confirm that authorization forms are valid, and escalate anything that feels off. Our phishing training for healthcare workers covers these social engineering tactics in detail.

Your 5-Minute Authorization Audit

Pull your organization's current HIPAA release of information form right now. Check it against this list:

  • Does it describe the specific PHI to be disclosed?
  • Does it name the disclosing entity and the recipient?
  • Does it state the purpose?
  • Does it have an expiration date or event?
  • Does it include the right-to-revoke statement?
  • Does it include the re-disclosure warning?
  • Does it include the conditioning statement?
  • Is there a signature line with a date?

If you're missing even one of these, your form is technically defective under 45 CFR § 164.508. Every disclosure you've made using that form could be considered impermissible.

When a Breach Starts With a Bad Form

If an impermissible disclosure happens because your authorization form was defective, you don't just have a paperwork problem — you may have a breach. Under the Breach Notification Rule, impermissible uses or disclosures of PHI are presumed to be breaches unless you can demonstrate a low probability of compromise through a four-factor risk assessment.

That means your incident response process kicks in. Your team needs to know how to assess the situation, document the risk analysis, and determine whether notification to HHS and the affected individual is required — all within the timelines HIPAA mandates. If your organization hasn't practiced this, our First 60 Minutes: Incident Response course builds exactly that muscle.

Stop Treating the Form Like an Afterthought

The HIPAA release of information form is one of the most frequently used compliance documents in healthcare, and one of the most frequently botched. It touches patients, providers, legal teams, insurers, and regulators. Getting it wrong has real consequences — financial penalties, reputational damage, and loss of patient trust.

Review your form today. Train your staff on what makes an authorization valid and what makes it garbage. And build the systems to track, honor, and revoke authorizations in real time. This isn't a "nice to have." It's the law, and OCR is watching.