Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

Authorization to use and disclose health information

Avatar photo Maja Popovska
Last Updated: August 19, 2026
Key takeaways

Key takeaways

An authorization to use and disclose health information is a form that permits a specific PHI disclosure. It covers uses beyond treatment, payment, and healthcare operations.

A valid form needs eight elements under 45 CFR 164.508. Miss any one and the authorization is defective, so the disclosure is not permitted.

One of those eight is the redisclosure notice. It warns the patient that the recipient may share the information again, outside HIPAA’s protection.

Mental health, substance abuse, HIV, and genetic records need extra authorization language. State law and 42 CFR Part 2 often add requirements on top of HIPAA.

Pabau captures the authorization by e-signature and files it in the patient record. Every disclosure made under it is logged for your accounting of disclosures.

Download your free authorization to use and disclose health information form

The form covers patient identification, the records to be released, the named recipient, the purpose, and the expiration date. It also carries the revocation, redisclosure, and no-conditioning statements HIPAA requires.

Download template

An authorization to use and disclose health information is a form that lets a covered entity share a patient’s protected health information, or PHI. A covered entity is your practice, hospital, or health plan. The authorization covers disclosures that fall outside treatment, payment, and healthcare operations.

Under the HIPAA Privacy Rule (45 CFR 164.506), you can share patient information for treatment, payment, and routine operations without a separate form. A patient may want records sent to a disability insurer, mental health notes shared with an employer, or imaging released for a second opinion. Each of those needs a signed authorization that meets specific federal requirements.

The form must contain every element in 45 CFR 164.508 to be valid. A missing element makes the authorization defective, and a defective authorization is not one you can act on. Disclosing PHI without a valid one exposes your practice to findings from the HHS Office for Civil Rights, fines, and patient complaints.

When is a HIPAA authorization required?

You need an authorization whenever you disclose PHI for a reason outside treatment, payment, and healthcare operations. Routine care disclosures do not need one. The requests below come up most often.

  • Disability evaluations: An employer, insurer, or government agency wants records to assess work capacity or benefit eligibility.
  • Workers’ compensation claims: The insurer needs clinical notes to process the claim, which makes this routine work for physical therapy practices.
  • Legal proceedings: An attorney or court asks for records as evidence. A subpoena or court order may apply instead.
  • Marketing and research: Using patient information for clinical trials, surveys, or promotional activity needs authorization.
  • Release to family or caregivers: Sharing records with a relative needs written consent unless the patient is incapacitated. A parent or guardian signs for a minor, the same way they sign a medical consent form.
  • Third-party billing review: Some payers audit patient records, and the authorization confirms the disclosure is permitted.

You don’t need an authorization for treatment, payment, or routine healthcare operations. That covers sharing notes with a treating specialist, submitting a claim to an insurer, or calling a pharmacy about medications.

HIPAA compliance in Pabau
Pabau’s compliance tools keep every signed authorization with the patient record, so you can prove a disclosure was permitted.

The eight required elements

The HIPAA Privacy Rule mandates eight elements, and missing one invalidates the whole form. The eight apply whatever your practice calls the document. A HIPAA authorization form and a medical release form both have to clear the same bar.

Required element What it must include Why it matters
Description of PHI Name the exact records, such as mental health notes from 2024, or imaging reports only. Keeps the disclosure narrow and leaves the patient in control of what leaves your practice.
Named recipients Identify each person or organization receiving the information by name, title, or category. Limits the disclosure to intended parties and supports your audit trail.
Purpose of disclosure State why the records are being released, such as a disability evaluation or a claim review. Shows the patient understood the intended use and blocks unrelated secondary uses.
Expiration date or event Give a date, such as December 31, 2026, or an event, such as the end of the study. Caps how long the authorization lives. Without it, the form is invalid.
Patient signature Take a handwritten or electronic signature, plus the date it was signed. Proves the patient authorized the disclosure knowingly and voluntarily.
Right to revoke Explain that the patient can revoke in writing, and say exactly how to do it. Required by 45 CFR 164.508(c)(2)(i). Leaving it out invalidates the form.
No conditioning of treatment State that you cannot refuse treatment because the patient declines to sign. Required by 45 CFR 164.508(c)(2)(ii), and it protects patients from pressure.
Redisclosure notice Warn the patient that the recipient may share the information again, outside HIPAA’s protection. Required by 45 CFR 164.508(c)(2)(iii). The patient decides knowing the records can travel further.

When an authorization is defective

Even a fully completed form can be one you may not act on. 45 CFR 164.508(b)(2) lists the defects that make an authorization invalid on its face.

  • The expiration date has passed, or you know the expiration event has happened.
  • A required element is missing or filled in incompletely.
  • You know the patient already revoked it.
  • The form is bundled with another document, which the rule allows only in narrow cases.
  • You know that material information on the form is false.

Check the expiration before every disclosure, not only at signing. Acting on a defective authorization is an impermissible disclosure, and that becomes a HIPAA violation you have to assess and document.

Sensitive records that need extra language

Some records need heightened language on the form and clear a second regulatory bar on top of HIPAA.

  • Mental health and psychotherapy notes: The form must say explicitly that these notes are being released. State rules in California and New York go further, which matters for mental health practices.
  • Substance abuse treatment records: These fall under 42 CFR Part 2, which sets stricter consent rules than HIPAA. You need a separate Part 2 consent form.
  • HIV and AIDS status: Many states bar disclosure without specific written consent, even to another treating provider.
  • Genetic information: The Genetic Information Nondiscrimination Act (GINA) restricts disclosure to employers and may call for extra consent language.
  • Reproductive health: Some states, including California and Texas, require patient consent before you share abortion, contraception, or fertility records.

Patient rights: Expiration and the right to revoke

Every authorization ends. It expires on a stated date or when a stated event happens, and a form with neither is invalid. After it expires, you cannot release anything further under it.

Patients can revoke at any time, in writing. An email, a letter, or a portal message all count. Once you receive it, future disclosures stop. Revocation does not undo disclosures you already made in good faith. Your form needs clear revocation instructions, usually a mailing address, an email, or a portal link.

Track authorizations, expiration dates, and revocations in a centralized patient record. Consistent data protection habits keep that log usable when an auditor asks who received what, and when.

Comprehensive EMR & patient record management
Pabau’s patient records hold the signed authorization, its expiration date, and every disclosure logged against it.

How to fill out the form step by step

Work through it with the patient section by section, so nothing comes back blank.

  1. Patient information: Collect the full name, date of birth, medical record number, and a phone number or email. Check it against the chart to confirm you have the right patient.
  2. Records to be released: Be specific. “All psychiatric notes from January 2024 onward” or “the completed PCL-5 and MRI images” beats “all medical records.”
  3. Recipients: Give the full name, title, organization, and mailing address of everyone authorized to receive the records.
  4. Purpose: Write the reason out plainly, such as a disability evaluation for a short-term disability claim.
  5. Expiration: Pick a date, usually 30 to 90 days out, or an event such as the close of the workers’ compensation case.
  6. Signature and date: The patient signs, or a legal representative signs if the patient lacks capacity. E-signature capture handles this in seconds and leaves a permanent audit record.
  7. Final check: Run the eight elements before you file or send the form. One blank line is enough to make it defective.

How Pabau captures and tracks authorizations

Paper authorizations carry their own risks. Forms go missing, fields come back blank, expiration dates pass unnoticed, and nothing links the authorization to the disclosure it permitted.

Practice management software like Pabau moves the whole thing into the patient record. Patients complete and e-sign the authorization on their own device before the visit, using digital intake forms. The signed form attaches straight to their patient portal record. Your front desk can pull it up while a records request is still on the phone.

Automations flag authorizations that are about to expire, so access closes on time instead of weeks late. Pabau also logs every disclosure made under an authorization, which is what your HIPAA accounting of disclosures obligation asks for. You can show exactly who received which records, and when.

Every Pabau subscription includes the forms, records, and audit tools described here. Going paperless and HIPAA-compliant is part of the standard setup, and no feature sits behind a higher tier.

Capture and track every HIPAA authorization

Pabau’s digital forms collect the authorization by e-signature before the visit and file it in the patient record. Expiring authorizations get flagged, and every disclosure made under one is logged for your accounting of disclosures.

Pabau clinic management dashboard

Conclusion

Downloading the form is the quick part. The work that protects you comes after the signature. Check the expiration before each release, honor a revocation the day it lands, and log what you sent.

Do that and a records request stops being a scramble. You can answer it in minutes, and you can prove afterwards that the disclosure was permitted. Skip it and a form that looked perfect in March becomes a defective authorization in September.

The trade-off worth remembering is specificity. A narrow authorization takes longer to complete and protects both of you. A broad one is faster and much harder to defend. Book a demo to see how Pabau captures authorizations, flags expiry dates, and logs disclosures for you.

Continue your research

Continue your research

Releasing records to Medicare? Medicare consent to release form covers the CMS version of this authorization, with the fields Medicare expects to see.

Need a records release for a dental practice? Dental records release form applies the same eight elements to dental charts and imaging.

Training your team on PHI handling? HIPAA training for employees sets out what staff need to know before they process a records request.

Documenting an emergency assessment? Primary trauma survey walks through the structured assessment that ends up in the record you may later disclose.

Measuring how patients rate your practice? Patient satisfaction survey collects structured feedback you can act on.

Frequently asked questions

What is the difference between HIPAA authorization and HIPAA consent?

Practices often use a general consent form as blanket permission for routine treatment, payment, and healthcare operations. That form does not need the eight elements. An authorization is a separate, specific form for disclosures outside those three purposes, such as a disability review, a legal request, or research. It gives the patient tighter control over their PHI.

How long is a HIPAA authorization valid?

A HIPAA authorization expires on the date or event specified on the form. It can run 30 days or several years. That depends on the patient’s preference and the purpose of the disclosure. If no expiration date or event is listed, the authorization is invalid.

Can a patient revoke their HIPAA authorization after signing it?

Yes. Patients can revoke in writing at any time. The revocation takes effect when you receive it and stops future disclosures. It does not undo disclosures you already made in good faith before it arrived.

Can I disclose PHI created after the authorization was signed?

Yes, unless the authorization expressly limits disclosure to records created before a stated date. Most authorizations cover PHI from the signing date forward, up to the expiration date.

Do mental health records require special authorization language?

Yes. Psychotherapy notes and mental health records need explicit language saying they are being released. California and New York impose additional requirements. Include a specific line on the form, such as “I authorize release of my mental health and psychotherapy notes.”

Can the recipient share the information again?

Often yes. If the recipient is not a covered entity, HIPAA no longer protects the information once you send it. That is why the form must carry a statement warning the patient that the recipient may redisclose it.

×