Key Takeaways
An authorization for release of protected health information is a legal document that allows healthcare providers to disclose a patient’s PHI to a third party, as required by 45 CFR §164.508.
Valid authorizations must include six core elements — patient ID, description of PHI, recipient identification, purpose of disclosure, expiration date, and patient signature — plus three mandatory statements required by the HIPAA Privacy Rule.
Authorization is required for most disclosures outside treatment, payment, and healthcare operations (TPO); state laws can impose stricter requirements than federal HIPAA rules.
Pabau’s digital forms platform captures, stores, and audits patient authorizations in real time, eliminating paper form handling and ensuring practice compliance with zero manual filing steps.
Download your free authorization for release of protected health information
Authorization for release of protected health information
A standardized consent form that allows healthcare providers to legally share patient medical records and health information with specified third parties, while ensuring compliance with HIPAA Privacy Rule requirements. Ready to use, customizable, and HIPAA-compliant.
Download templateWhat is an authorization for release of protected health information?
An authorization for release of protected health information is a written legal document that permits a covered entity (healthcare provider or health plan) to disclose a patient’s protected health information to a specified third party.
This form is the foundation of HIPAA Privacy Rule compliance and is required whenever a provider wants to share PHI for reasons outside treatment, payment, or standard healthcare operations. It covers general PHI disclosures — full medical records, lab results, or billing history released to any third party. For a minor’s records shared specifically with a parent or guardian, use our HIPAA authorization form instead.
The authorization form operationalizes 45 CFR §164.508, the federal regulation that governs all PHI disclosures. Without a valid, signed authorization, sharing patient medical records — even with the patient’s verbal consent — violates HIPAA and exposes your practice to regulatory fines and liability. The template below satisfies all core and required elements under this regulation.
When is an authorization for release of protected health information required?
HIPAA authorizations are required for most disclosures of patient records outside the Treatment, Payment, and Healthcare Operations framework, known as TPO. The key distinction: TPO disclosures (sharing records with another provider for direct patient care, filing insurance claims, or running practice operations) do NOT require patient authorization. Everything else does.
- Requires authorization: Disclosures to employers, life insurance companies, legal representatives, school districts, courts, researchers, or any third party outside the direct care relationship.
- Does not require authorization: Using or disclosing PHI for treatment (e.g. referral to a specialist), billing or claims submission, or practice operations (e.g. credentialing, accreditation, quality review).
- Exceptions to authorization: Law enforcement requests, public health reporting, serious threats to safety, and court orders typically override the need for patient-signed authorization — though some states add stricter requirements for sensitive record types (mental health, HIV, substance use disorder). Practices that track mental health severity with tools like the DASS-21 depression, anxiety, and stress scale should treat those results with the same heightened confidentiality.
Required elements of a valid authorization form
A legally binding authorization under 45 CFR §164.508 must include six core elements and three mandatory statements. Missing any one element invalidates the entire form and makes any disclosure legally risky. Pair this form with a standard client information template so patient identifiers stay consistent across every document in the file.
Beyond these six core elements, three mandatory statements must also appear on every form:
- The patient’s right to revoke the authorization in writing at any time.
- Whether treatment, payment, or eligibility for benefits is conditioned on providing the authorization (it cannot be).
- Notice that information disclosed to the recipient may be re-disclosed and is no longer protected by HIPAA.
How long is an authorization valid?
Every authorization must specify an expiration date or event. HIPAA allows expired authorizations to be removed from patient records and securely destroyed, limiting the window during which old PHI can be re-disclosed. Most clinical authorizations expire 6 to 12 months from the signature date, though specific legal or insurance matters may warrant longer or shorter periods.
Once the expiration date passes, the covered entity may not disclose PHI under that authorization. A patient may also revoke the authorization in writing before expiration, and any revocation takes effect immediately for future disclosures (though past disclosures already made remain valid).
State-specific requirements and stricter standards
HIPAA sets a federal floor, but many states add further requirements for sensitive record types. Federal law already requires a separate authorization for nearly all uses and disclosures of psychotherapy notes, including most treatment, payment, and healthcare operations purposes, under 45 CFR §164.508(a)(2).
States build on that federal floor. California’s Confidentiality of Medical Information Act (CMIA) and Texas regulations, for example, require explicit patient authorization for HIV records and genetic testing results even when federal HIPAA would permit a blanket TPO disclosure. Practices operating across multiple states must follow the stricter standard in each jurisdiction.
Substance use disorder records, governed by 42 CFR Part 2, require a separate, more restrictive authorization form than standard HIPAA. If your practice treats patients with addiction or recovery services, use our authorization for release of confidential information template instead, which builds in the required Part 2 language.
How to fill out the authorization form correctly
Common errors invalidate the form. Here’s how to complete each field:
- Patient information: Ensure the patient prints their full legal name (as it appears in the medical record), date of birth, and any medical record number or practice patient ID. Mismatched names across records can cause delays or rejections.
- Specific PHI description: Rather than “all records”, specify a date range or record type. Example: “All clinical notes and lab results from January 1, 2024 to June 30, 2024” is clearer than “medical records”.
- Recipient details: Obtain the full name, title, organization, and address of the person who will receive the PHI. Verify this information is correct before the patient signs — discrepancies can prevent disclosure.
- Purpose statement: Write the specific reason. “For insurance review” is acceptable; “for research purposes” requires additional regulatory steps and may need ethics board approval.
- Expiration date: Use a specific date (e.g. “December 31, 2024”) or event trigger (e.g. “upon settlement of legal claim”). Avoid ambiguous terms.
- Signature and date: The patient must sign and print their name in the presence of an authorized practice staff member (or via digital signature if your practice uses HIPAA-compliant e-signature software). The date must match the signature date.
Digital authorization workflows and compliance automation
Paper authorizations require manual filing, periodic audits, and error-prone retrieval workflows. Digital forms platforms like Pabau capture authorizations directly into patient records with automatic timestamping and e-signature verification, creating an auditable disclosure trail that satisfies regulatory inspections.
When a patient signs the digital form, the authorization is instantly stored, linked to their profile, and accessible during future disclosure requests — eliminating the “lost form” problem that plagues paper systems. The same principle applies to nursing documentation more broadly: digital records create the audit trail regulators expect.
Book a demo with Pabau to see how digital authorization workflows integrate with your patient records and compliance audit logs.
Storing and revoking authorizations
Once signed, store the original authorization with the patient’s medical record or in a secure, dedicated location indexed by patient name and date. If going paperless, scan the original and store the scanned image alongside the digital medical record. Ensure access is restricted to authorized clinical staff only.
To revoke, the patient submits a written revocation (email, letter, or form). Upon receipt, immediately notify any third party who has previously received PHI under that authorization that future requests will be denied. Document the revocation date in the patient record.
Conclusion
A properly completed authorization for release of protected health information is the legal gateway for sharing patient records outside routine care and billing workflows. The template above satisfies 45 CFR §164.508 and is ready to customize for your practice’s specific disclosures.
Practices managing hundreds of authorizations per year benefit from digital forms automation that prevents the incomplete submissions and lost-form errors that trigger HIPAA violations. Whether you use paper or digital, verify every element is complete before the patient signs — a single missing field voids the entire document.
Frequently asked questions
What is authorization to release protected health information?
Authorization to release protected health information is a written legal document signed by a patient that permits a healthcare provider to disclose the patient’s medical records and health information to a named third party for a specified purpose, as required by HIPAA Privacy Rule 45 CFR §164.508.
When is a HIPAA authorization required?
HIPAA authorization is required for disclosures outside treatment, payment, and healthcare operations (TPO). Sharing records with employers, insurance companies, legal representatives, schools, or any party not directly involved in the patient’s care requires a signed authorization. TPO disclosures (referrals to other providers, billing submissions, accreditation) do not require authorization.
What are the six required elements of an authorization form?
The six core elements are: patient identification (name, DOB, medical record number), description of PHI to be disclosed, name and address of recipient, purpose of disclosure, expiration date or event, and patient signature with date. Additionally, three mandatory statements (right to revoke, no conditioning of treatment, re-disclosure notice) must appear on the form.
Can a patient revoke their authorization?
Yes, a patient may revoke their authorization at any time in writing. Revocation takes effect immediately for future disclosures; however, disclosures already made before revocation remain valid. Document the revocation date in the patient record and notify any third party who received PHI under the revoked authorization.
What is the difference between HIPAA consent and HIPAA authorization?
HIPAA consent (for TPO) is a simpler acknowledgment that the patient allows the provider to use and disclose PHI for treatment, payment, and healthcare operations. HIPAA authorization (for non-TPO) is a more detailed, specific legal document that names the recipient, states the purpose, sets an expiration date, and includes mandatory statements. Authorization requires far more specificity than consent.
How long is an authorization valid?
Authorization validity is determined by the expiration date or event specified on the form. Most clinical authorizations last 6-12 months from the signature date. Once expired, the covered entity may not disclose PHI under that authorization. The form must never state “never” or “unlimited” as an expiration — HIPAA requires a specific end date or triggering event.