Key takeaways
An authorization for disclosure of information is the HIPAA document that lets your practice release patient PHI to a third party for non-routine purposes.
A valid authorization needs nine elements, from a specific description of the records to a warning that the recipient may re-disclose them.
Treatment, payment, and healthcare operations disclosures need no written authorization. Almost every other disclosure does.
Practice management software like Pabau captures signed authorizations into the patient record and logs every disclosure for audits.
Download your free authorization for disclosure of information template
A ready-to-use HIPAA-compliant authorization form covering patient details, designated recipients, disclosure purposes, expiration dates, consent declarations, and signature blocks.
Download templateAn authorization for disclosure of information is HIPAA’s written permission slip. It lets a patient authorize your practice to share their protected health information (PHI) with a named third party.
This template keeps your practice compliant while it handles the record releases, insurance disclosures, and family communications that come up every week.
The ninth element is the one to read twice. HIPAA requires the form to warn the patient that the recipient may pass the records on, not to promise that they won’t.
What is an authorization for disclosure of information?
Under the HIPAA Privacy Rule (45 CFR § 164.508), an authorization for disclosure of information is a written document. It permits a covered entity to use or disclose a patient’s PHI beyond the purposes HIPAA already allows.
HIPAA lets covered entities disclose PHI without written patient consent for treatment, payment, and healthcare operations, known together as TPO. Covered entities include practices, hospitals, therapists, and health plans.
Any disclosure outside those three categories needs a signed authorization from the patient. Common scenarios that require one include:
- Releasing records to an attorney for a personal injury case
- Sharing a treatment summary with a family member
- Sending psychiatric history to a school system
- Transferring records to an employer for a disability determination
Without a valid signed authorization, each of those disclosures is a HIPAA violation. That exposes your practice to Office for Civil Rights (OCR) enforcement action and financial penalties.
Required elements of a valid HIPAA authorization form
A valid HIPAA authorization under 45 CFR § 164.508 must contain nine required items. Six are core elements and three are required statements. Miss one and the authorization is legally invalid, which means the disclosure cannot proceed.
- Specific description of the information to be disclosed: Name the exact records. “All mental health treatment notes from January 2024 to present” works, “medical records” does not.
- Name or class of the persons authorized to make the disclosure: Name the releasing party, such as your practice or its medical records department. HIPAA treats this as a separate element from the recipient below.
- Name or class of the persons authorized to receive the information: Identify the recipient by name, title, or category, such as “John Smith, Esq.” or “defendant’s legal counsel”.
- Purpose of the disclosure: State why the information is being released, such as “for use in workers’ compensation claim” or “for continued care coordination”.
- Expiration date or event: Set a date or condition after which the authorization expires, such as “December 31, 2026” or “upon completion of legal case”.
- Patient signature and date: Take the patient’s signature, or that of an authorized personal representative, with the date signed. E-signatures are acceptable where state law allows them.
- Statement of the right to revoke: Tell the patient they may revoke the authorization in writing at any time. Add that revocation does not reach disclosures already made in reliance on it.
- Statement on conditioning: Confirm that treatment, payment, or health plan enrollment does not depend on whether the patient signs. 45 CFR § 164.508(b)(4) sets out three narrow exceptions.
- Statement about re-disclosure: Warn the patient that the recipient may re-disclose the information once they have it, and that HIPAA may no longer protect it. 45 CFR § 164.508(c)(2)(iii) requires this warning. It is a risk notice to the patient, not a promise that the recipient will keep the records private.
That last element is where template wording most often goes wrong. Some forms promise that the recipient will not pass the records on, which HIPAA does not ask for and your practice cannot enforce.
A prohibition on re-disclosure does exist in federal law, but it belongs to a different rule. 42 CFR § 2.32 requires that notice for substance use disorder records held by a Part 2 program.
This template includes all nine elements pre-built, so your staff can fill the blanks without dropping a required field.
When is a written authorization required?
Most record releases a practice handles in a week need no authorization at all. The rule turns on why the information is going out.
Authorization is not required when the disclosure is for treatment, payment, or healthcare operations. Those disclosures can go ahead without written patient approval:
- Sending records to a specialist who is treating the patient
- Billing an insurance company for a visit
- Sharing an order and sample with a referral lab
- Using de-identified data for quality improvement
- Discussing care with other clinicians involved in the case
Insurance work involves a different kind of authorization. The prior authorization process covers payer approval for treatment, and insurance eligibility verification confirms a patient’s coverage. Neither one calls for a HIPAA authorization form.
Authorization is required for close to everything else:
- Releases to attorneys or law firms
- Disclosure to family members, outside emergencies and incapacity
- Releases to employers or schools
- Sharing records with researchers
- Any use of PHI for marketing
- Disclosure of psychotherapy notes
Psychotherapy notes carry a special rule. They need a separate, standalone authorization that cannot be combined with a general medical record release.
If a patient calls and asks you to send records to their lawyer, the answer is yes, once they sign. The signed form documents their approval, which is the evidence HIPAA compliance rests on.
How to fill out the authorization form
Completing the form correctly comes down to the blanks. A vague or incomplete field can make the authorization legally insufficient.
- Identify the patient and the records: Fill in the patient’s full legal name, date of birth, and medical record number. In the information section, give exact dates and document types. Write it as “all clinical notes, lab results, and imaging from January 15, 2024 through August 18, 2026”.
- Name who releases and who receives: Identify the party releasing the records. Then write the full name, title, and organization of whoever will receive the information. Where the recipient is an organization, name the specific attorney or department if you can.
- State the purpose clearly: Borrow the wording from the patient’s own request. “For medical purposes” is too vague. “For use in workers’ compensation claim WC-2026-4521” holds up.
- Set an expiration date: Choose a calendar date, such as December 31, 2026, or an event, such as completion of the legal proceeding. Left blank, the authorization may be read as open-ended in some states.
- Collect the signature and date: The patient or their legal representative signs and dates the form. For digital signature capture, document that your state law and your own policy accept e-signatures.
- Add a witness or countersignature if required: Some states and clinical settings ask for a witness signature or a clinician countersignature. Check your state health department and your malpractice carrier before you finalize the form.
Once signed, store the original or a scanned copy in the patient’s medical record. Many practices lean on patient data security tools that link signed authorizations to the record automatically. That removes the risk of a lost paper form and leaves an audit trail for compliance reviews.
Authorization vs consent: Key differences
Clinicians and front-desk staff often use consent and authorization interchangeably. HIPAA treats them as two different documents.
Consent is a general agreement to receive treatment. It is usually a one-page form saying the patient agrees to counseling with a named clinician, or to blood work. Consent covers the clinical relationship and the patient’s willingness to be treated.
Authorization grants permission to disclose PHI. It deals with where a patient’s existing records can travel, rather than with whether they accept care.
A patient who consents to therapy has not authorized release of their therapy notes to their employer. That needs its own authorization form, and confusing the two leads to inadvertent disclosures.
Using separate, clearly labeled forms for consent and authorization prevents the mistake. It also shows regulators that your practice knows the difference.
Patient rights: Revocation and conditions
Patients keep rights over an authorization after they sign it, and your practice has to honor them.
A patient may revoke an authorization in writing at any time. The revocation takes effect once your practice receives it.
Revocation does not reach disclosures you already made in reliance on the form. You cannot pull back records that have gone out, but you can stop any further release under that authorization.
Your practice also cannot condition treatment, payment, or health plan enrollment on whether a patient signs. 45 CFR § 164.508(b)(4) sets out narrow exceptions:
- Research-related treatment, where the authorization covers the use of PHI for that research.
- Health plan enrollment or eligibility, where the authorization supports an eligibility or underwriting decision.
- Care provided solely to create PHI for a third party, such as a pre-employment physical.
Compound authorizations are restricted too. Under 45 CFR § 164.508(b)(3), an authorization generally cannot be combined with another document, with limited exceptions such as research studies.
Give each disclosure purpose its own authorization. That lets a patient approve what they want and refuse what they don’t.
Common compliance mistakes to avoid
Mistake 1: Releasing records without an authorization when one is required. If a patient’s attorney calls for records and you fax them because the patient is theirs, you have violated HIPAA. The patient must sign before anything goes to an attorney. A phone call from someone claiming to be the patient is not enough.
Mistake 2: Using a generic template that skips HIPAA’s required elements. A form saying “I give permission to release my medical records” is too vague. It has no specific description of the information, no expiration date, and no statement of patient rights. All nine elements have to be present, or the authorization fails.
Mistake 3: Treating verbal permission as enough. HIPAA requires a written authorization. A patient saying “yes, send my records to my doctor” does not satisfy the regulation.
Mistake 4: Releasing more information than the form authorizes. If the authorization covers mental health treatment notes only, do not add billing records, appointment history, or risk assessment scores. Send only what the form covers. Over-disclosure is a common audit finding.
Mistake 5: Failing to track authorizations and disclosures. Mental health practices face particular pressure around disclosure documentation. Keep a log of every disclosure, with the date, the recipient, the information sent, and the authorization it relied on.
That log is your proof of compliance. HIPAA compliance software can build it as the disclosures happen.
Related templates
- Authorization for release of protected health information
- Controlled substance agreement
- HIPAA medical release form
- HIPAA privacy policy template
- Medical consent form for adults
How Pabau captures signed authorizations and tracks disclosures
Paper medical forms create a familiar bottleneck. A patient requests a release and you print a form. They fill it in, then someone scans and files it, and staff track by hand what was sent.
When an OCR audit asks for evidence that an authorization existed before a specific disclosure, that answer sits in a filing cabinet.
Practice management software like Pabau moves the whole sequence into the patient record. You build the authorization once as a digital form, send it ahead of the visit, and collect the signature on screen.
The signed copy files itself against the patient, with the date it was signed. Your system logs when the form went out, when it came back, and who signed it.
That changes what an audit feels like. You open the patient’s file and the authorization sits beside the notes it relates to. Nobody works through folders to prove a release was approved.

Digital forms also carry your own practice language. A therapy practice can add a line about psychotherapy note restrictions, and a physical therapy practice can name the workers’ compensation carrier. A med spa can state that treatment photos fall outside the authorization.
Capture signed authorizations inside the patient record
Pabau’s digital forms capture signed authorizations straight into the patient record, log every disclosure, and keep audit-ready evidence in one place.
Conclusion
The authorization form is a short document with outsized consequences. Get the nine elements right and a record release is routine. Get one wrong and the same release becomes a reportable violation.
Pay closest attention to the ninth element, which generic templates often state backwards. Your form warns the patient that the recipient may re-disclose the records, and that HIPAA protection ends there.
Then decide whether paper can keep up. Manual filing holds while volumes are low, and it stops holding the moment an auditor asks for one signed form from three years ago.
Download the template, check your state health department for stricter rules, and start a disclosure log if you don’t keep one. Book a demo to see how Pabau captures signed authorizations and tracks every disclosure for you.
Continue your research
Not sure how long a signed form has to stay on file? How long to keep medical records sets out the retention rules state by state.
Need your team to apply the disclosure rules consistently? HIPAA training for employees covers what the training has to include and how often to run it.
Handling photo releases as well as record releases? Before and after photo consent form explains what a med spa needs on the form before publishing images.
Want the wider filing system around these forms? Medical records management walks through storage, access, and retention across the whole patient record.
Frequently asked questions
What is an authorization for disclosure of information?
An authorization for disclosure of information is a written HIPAA document. It lets a covered entity release a patient’s protected health information to a third party for purposes outside treatment, payment, and healthcare operations. Nine elements make it valid. They include a description of the records, who may release them, who may receive them, the purpose, an expiration date, and the patient’s signature. The ninth element is a warning to the patient. Once the recipient has the records they may re-disclose them, and HIPAA may no longer protect the information (45 CFR § 164.508(c)(2)(iii)).
When is a HIPAA authorization required vs not required?
Authorization is NOT required for treatment, payment, and healthcare operations (TPO). Those disclosures are permitted automatically. Authorization IS required for nearly all other disclosures: releases to attorneys, employers, schools, family members (non-emergency), researchers, marketing use, and psychotherapy notes. When in doubt, get a written authorization.
Can a patient revoke an authorization after signing?
Yes. Patients may revoke an authorization in writing at any time. The revocation takes effect once your practice receives it. However, revocation does not apply to disclosures already made before your practice received it. It covers only future disclosures under that authorization.
Is a verbal authorization sufficient under HIPAA?
No. HIPAA requires a written authorization for any disclosure outside of TPO. A patient saying “yes, send my records” verbally does not satisfy the regulation. The authorization must be signed and documented in the patient’s medical record.
What is the difference between consent and authorization?
Consent is the patient’s agreement to receive treatment. Authorization is the patient’s permission to disclose their existing medical information to a third party. A patient who consents to therapy has not automatically authorized release of their therapy notes to their employer. That needs a separate authorization form.
How long is a HIPAA authorization valid?
The authorization itself remains valid until the expiration date or event specified in the form. Common expiration dates are one or two years, or “upon completion of the legal case.” Once expired, the authorization cannot be used for new disclosures. You have to obtain a new one. However, the obligation to keep the signed authorization in the medical record is permanent.