Key Takeaways
An authorization for release of confidential information is a legally required form that allows patients to permit healthcare providers to share protected health information (PHI) with named recipients.
HIPAA regulations require authorizations to include: description of information, recipient name, purpose, expiration date/event, patient signature and date, and the right to revoke without penalty (45 CFR § 164.508).
Substance use disorder (SUD) records fall under stricter 42 CFR Part 2 confidentiality rules and require a separate, specific authorization with enhanced language and protections.
Practice management software like Pabau automates authorization collection through digital forms and stores signed documents securely, cutting out manual paper workflows.
Download your free authorization for release of confidential information template
A HIPAA-compliant consent form covering patient details, information to be released, purpose of disclosure, recipient information, expiration date, patient rights, signature, and regulatory compliance language for mental health, therapy, and general healthcare practice workflows.
Download templateSharing a patient’s records with anyone outside treatment, payment, or healthcare operations requires their written permission first. Whether you’re a therapist releasing mental health records, a primary care physician sending files to a specialist, or an addiction treatment provider handling substance use disorder confidentiality, the authorization for release of confidential information form is what makes that disclosure legal.
HIPAA civil penalties range from roughly $145 to $73,011 per violation. The annual cap reaches $2,190,294 per violation category, and HHS adjusts these figures periodically for inflation. On top of that, state-level privacy laws add even stricter penalties.

This guide explains what an authorization for release of confidential information is, when it’s legally required, and how to complete it correctly. It also shows how practice management software like Pabau collects, signs, and stores these forms with a complete audit trail, so you can keep every disclosure defensible without the paper.

What is an authorization for release of confidential information?
An authorization for release of confidential information is a signed legal document that lets a healthcare provider disclose a patient’s protected health information (PHI) to a named third party. It records the patient’s explicit consent, which HIPAA requires for most disclosures outside treatment, payment, and healthcare operations.
A Notice of Privacy Practices only informs patients of their rights, and a general consent-to-treatment form does the same. An authorization is more specific. It names exactly what information you can share, with whom, for what purpose, and for how long. Without it, sharing patient records, even with another healthcare provider, counts as a breach.
- Legal basis: 45 CFR § 164.508 (HIPAA Privacy Rule)
- Typical use cases: sharing records with family members, employers, insurance companies, attorneys, other practices, or researchers
- Not required when: disclosure is for treatment, payment, healthcare operations, legal subpoenas (with court order), or public health reporting
- Signature requirement: must be signed and dated by the patient (or legal guardian for minors/incapacitated individuals)
- Revocation right: patients can revoke in writing at any time, except where action has already been taken
How to complete and use the form
Completing and collecting these forms correctly is the difference between a compliant practice and a HIPAA liability. Follow these five operational steps to keep every authorization legally defensible and clinically appropriate.
Confirm eligibility and complete the form
- Determine if the disclosure requires authorization. First, check the purpose of the disclosure. Treatment-related sharing, payment-related sharing, and healthcare operations don’t need a separate authorization — standard NPP consent already covers them. Examples include consulting another provider on a patient’s care (including telehealth consultations), a billing inquiry, or credentialing. However, all other disclosures require a mandatory authorization, such as family member requests, legal proceedings, employer verification, and third-party research.
- Complete all required elements before the patient sees the form. Staff should pre-fill the practice name, practice address, provider name, date, and the recipient’s name and title. Do NOT leave blanks: incomplete authorizations aren’t legally valid, and recipients or regulators may reject them. The patient is then responsible for their name, date of birth, signature, and date of signature.
Collect, document, and track the signed form
- Have the patient sign and date in person (or via esignature). Because electronic signatures are legally binding under the U.S. Federal ESIGN Act (15 U.S.C. § 7001), digital collection is compliant. Collect a wet signature only if your state requires it; esignature alone is sufficient in most US jurisdictions. Keep the signed copy in the patient record. Then send the original or a certified copy to the recipient promptly.
- Document the release in the patient chart. Note the date the patient signed the authorization, the recipient, the purpose, and the date and time you sent the information. This audit trail proves compliance during a regulatory review or patient dispute.
- Set a calendar reminder for the expiration date. Additionally, most authorizations are valid for 6 months to 1 year (specify in the form). After expiration, you cannot release information under that authorization — the patient must sign a new form. For ongoing disclosures like treatment coordination, consider an authorization that expires on a specific event instead of a calendar date. For example, you might use language such as “upon discharge from treatment.”
Who this form is for
Any practice that holds patient information and receives requests to share it needs a compliant authorization process. For example, common users include:
- Mental health practices (therapy, psychology, psychiatry): therapists and counselors routinely receive requests from family members, employers, courts, or educational institutions to release mental health records. In this setting, mental health records carry heightened confidentiality protections.
- Therapy practices and counseling centers: psychologists and licensed therapists managing patient consent for record-sharing with other providers or third parties.
- Primary care and general practice: family medicine doctors, primary care physicians, and nurse practitioners managing patient requests to transfer records to specialists or new practices. Our HIPAA compliance checklist for primary care covers related documentation requirements.
- Addiction treatment and substance use disorder (SUD) programs: practices treating patients for alcohol or drug abuse fall under 42 CFR Part 2 (federal substance use confidentiality rules), which require enhanced authorization language and stricter protections. See our addiction treatment plan template for related documentation.
- Occupational therapy, physical therapy, and rehabilitation practices: therapists releasing patient progress notes to insurance companies or referring physicians, often billed under codes like CPT code 97162.
- Integrative medicine and functional medicine practices: practitioners coordinating care with conventional medical providers and requesting patient consent to share records, frequently through a HIPAA-compliant CRM.
Benefits of using this form
Compliance and legal benefits
Legal protection: A signed, properly completed authorization shields your practice from HIPAA violations and state privacy law breaches. It documents informed patient consent and creates an audit trail. Regulators, including HHS Office for Civil Rights, CMS, and state health departments, expect to see this trail during compliance reviews and breach investigations.
In addition, some practices pair this with a broader HIPAA authorization form template for general-purpose disclosures.
Efficiency and trust benefits
Workflow efficiency: Because standardized authorization forms reduce administrative burden, staff save time on every disclosure. Staff don’t have to custom-write disclosure letters or negotiate scope with patients. Instead, the form clarifies exactly what the practice is sharing, with whom, and why.
Digital patient intake forms also eliminate manual printing, scanning, and filing, so staff reclaim hours they would otherwise spend chasing paperwork.
Patient transparency: An authorization ensures patients understand what records the practice is releasing and to whom. This builds trust and reduces disputes over “I didn’t know you were sharing my information with my employer.” Clear, HIPAA-aligned language, stored in a secure EHR, helps patients feel in control of their own data.
Regulatory readiness: Regulators frequently cite missing or incomplete authorizations during inspections. Practices that keep a signed, complete authorization for every disclosure clear HHS OCR audits and state health department reviews faster and with fewer findings. Many track this with dedicated HIPAA compliance software that flags a missing authorization before an audit does.
Pro Tip
Audit your current authorization process: pull 10 random patient records from the last 3 months, and verify that every disclosure has a signed authorization on file (records sent to specialists, insurance companies, family members, or other practices). If any disclosures lack signed authorizations, document the finding and put a corrective action plan in place. This self-audit is your best defense against future compliance findings.
State-specific variation in authorization requirements
While HIPAA sets the federal floor, individual states additionally impose stricter requirements for release of confidential information. A form that meets federal HIPAA standards may not comply with your state’s privacy laws.
- California (CMIA): the California Confidentiality of Medical Information Act requires authorizations to be signed and dated, carry an expiration date, and spell out the patient’s right to revoke. A generic HIPAA form often falls short, so many California practices use dual forms that combine HIPAA and CMIA language.
- Texas: Texas Occupations Code § 159.005 requires authorizations for mental health records; the form must include the specific information being released and the named recipient. Blanket authorizations are not permitted.
- Tennessee: Tennessee Code Annotated § 33-3-107 governs mental health records disclosure, so many Tennessee authorizations reference both state law and HIPAA for full compliance.
- Massachusetts: Mass.gov DPH publishes a model authorization for release of confidential information; many practices in Massachusetts use this as the baseline and customize it.
Best practice: obtain your state’s model authorization (if available) and cross-reference it with your HIPAA form. If your state has stricter language requirements, integrate them into your standard template. When in doubt, consult your state’s health department or a healthcare attorney.
Electronic signatures on this form
The U.S. Federal ESIGN Act (15 U.S.C. § 7001) permits electronic signatures on healthcare documents, so an electronically signed authorization is legally equivalent to a wet signature and binding under federal law.
- Electronic signature platforms (Docusign, Adobe Sign, HelloSign): HIPAA-compliant esignature services maintain audit logs showing who signed, when, and from which IP address. These are admissible as evidence in regulatory reviews.
- Patient portal esignature: if your practice uses a patient portal with digital forms capability, patients can sign authorizations directly on their mobile device or computer. The system records the timestamp and stores the signed PDF in the patient record automatically.
- Hybrid approach (wet + digital): some practices print the form, have the patient sign it in the office, and then scan and store the PDF in the EHR. This hybrid approach covers both traditional and digital workflows.
- State-level exceptions: a small number of states (e.g., some territories, specific healthcare contexts) may require wet signatures for certain documents. Check your state’s eSignature laws if you’re unsure; when in doubt, collect both.
Electronic collection is faster, reduces manual filing errors, and creates an automatically timestamped audit trail. Read more about running a paperless, HIPAA-compliant practice if you’re still relying on printed forms.
To streamline authorization collection, book a demo and see how Pabau’s digital forms handle the full workflow: electronic signature capture, automatic document storage, and compliance audit trails in one place.
42 CFR Part 2: Authorization for substance use disorder records
Substance use disorder (SUD) treatment records are among the most heavily protected health information in the US healthcare system. They fall under 42 CFR Part 2 (federal substance use confidentiality regulations), which imposes stricter rules than standard HIPAA.
- Written consent before disclosure: a federally assisted SUD program cannot release records for most purposes without the patient’s written consent or a qualifying court order, and those records cannot be used against the patient in legal proceedings without consent. That is a higher bar than HIPAA, which lets providers share records for treatment, payment, and operations without a separate authorization.
- A general authorization is not enough: you cannot use a standard medical-records authorization to release SUD information. The consent must specifically cover SUD treatment records and include the elements Part 2 requires. Practices offering behavioral health counseling alongside SUD treatment should confirm both service lines use the correct form.
- Restrictions on re-disclosure: recipients generally cannot pass SUD records to a third party without a new, separate consent from the patient. Each disclosure must carry a notice stating that Part 2 prohibits unauthorized re-disclosure.
- Required re-disclosure notice: the disclosure must include this statement: “This information has been disclosed to you from records protected by federal confidentiality rules (42 CFR Part 2). Federal law prohibits any further disclosure of this information except as specifically allowed by the written consent of the person to whom it pertains or as otherwise permitted by 42 CFR Part 2.”
SUD practices and addiction treatment programs must use a separate authorization form built for substance use disorder records. The Pabau template above includes standard HIPAA language, so SUD practices should customize it to add the 42 CFR Part 2 disclosures and prohibitions.
Consult the full text of 42 CFR Part 2 for the exact required consent language for your program type.
Conclusion
An authorization for release of confidential information is the legal cornerstone of patient privacy in healthcare. Whether you’re releasing mental health records, SUD treatment information, or general medical records, a signed, complete form protects your practice. It also respects patient autonomy and ensures compliance with HIPAA, state privacy laws, and regulations like 42 CFR Part 2.
Download the free template above, customize it for your state and specialty, and integrate it into your patient intake workflow. For streamlined digital collection, schedule a demo with Pabau. You’ll see how practice management software automates authorization workflows and keeps your practice audit-ready.
Continue your research
Need guidance on HIPAA compliance beyond authorizations? Compliance management features help practices audit documentation, audit trails, and regulatory readiness across all patient touchpoints.
Looking for a template for a specific treatment type? Group therapy informed consent and psychiatric evaluation templates are available alongside authorization forms.
Documenting mental health assessments? Our newly published anxiety nursing diagnosis template gives you a structured starting point.
Managing broader patient documentation? Our diabetes medication list and EMT patient assessment templates are also available for practices handling chronic care and emergency intake.
Frequently asked questions
What is an authorization for release of confidential information?
An authorization for release of confidential information is a signed, written legal document that permits a healthcare provider to disclose a patient’s protected health information (PHI) to a named third party. It is required by HIPAA (45 CFR § 164.508) for most non-treatment, non-payment, and non-operations disclosures.
When is an authorization for release of confidential information legally required?
An authorization is required whenever you disclose PHI for purposes other than treatment, payment, or healthcare operations. Common triggers include requests from family members, employers, insurance companies, attorneys, educational institutions, or researchers. Disclosures for treatment coordination with another provider, billing inquiries, or credentialing do not require a separate authorization.
Can patients revoke an authorization?
Yes. Patients have the right to revoke an authorization in writing at any time, except where action has already been taken in reliance on the authorization (45 CFR § 164.508(b)(5)). Keep a dated record of revocations and immediately halt further disclosures under that authorization.
Are electronic signatures legally valid on authorization forms?
Yes. Electronic signatures are legally binding under the U.S. Federal ESIGN Act (15 U.S.C. § 7001) and are HIPAA-compliant. Esignature platforms like Docusign and patient portal signing systems create timestamped audit logs and are admissible as evidence in regulatory reviews.
What is 42 CFR Part 2 and how does it affect authorizations?
42 CFR Part 2 is a federal regulation that governs substance use disorder (SUD) treatment records. It imposes stricter confidentiality rules than HIPAA and requires a separate, specific authorization with mandated language. SUD practices must use a dedicated form that includes SAMHSA-required disclosures and prohibitions on re-disclosure.
What are the consequences of releasing patient information without authorization?
HIPAA civil penalties range from roughly $145 to $73,011 per violation, with an annual cap of up to $2,190,294 per violation category (figures adjusted periodically by HHS), plus potential civil lawsuits from the patient. State privacy laws (California CMIA, Texas Occupations Code, etc.) impose additional penalties. A single unauthorized disclosure can trigger regulatory investigations and reputational damage.
Who can sign an authorization for release of information?
The patient signs their own authorization. For a minor, a patient who lacks capacity, or a deceased patient, a parent, legal guardian, or personal representative signs on their behalf and must show documentation of that authority. Record the signer’s name, relationship, and authority on the form.