3.3 Release of Information (ROI) & Authorization Procedures
Key Takeaways
- The HIPAA Privacy Rule permits disclosures of Protected Health Information (PHI) without patient consent strictly for Treatment, Payment, and Healthcare Operations (TPO).
- A valid HIPAA authorization form must contain 9 mandatory core elements; missing any single element renders the authorization invalid.
- Psychotherapy notes, substance use disorder records (42 CFR Part 2), and HIV status require explicit, separate written authorization and cannot be combined with general releases.
- Covered entities must log all non-exempt disclosures in an Accounting of Disclosures tracking system and retain these records for 6 years.
Release of Information (ROI) & Authorization Procedures
Release of Information (ROI) is one of the most legally sensitive responsibilities performed by an Electronic Health Record Specialist. The EHRS must navigate federal HIPAA Privacy rules, state privacy mandates, court orders, and special federal confidentiality statutes to ensure patient data is disclosed appropriately while preventing unauthorized access.
1. Disclosures: TPO vs. Written Patient Authorization
Under the HIPAA Privacy Rule, disclosures of Protected Health Information (PHI) are divided into two primary categories:
1. Disclosures Permitted Without Authorization (TPO)
PHI may be disclosed without a signed patient authorization exclusively for Treatment, Payment, and Healthcare Operations (TPO):
- Treatment: Sharing information between consulting physicians, nursing staff, laboratories, or referring specialists for direct patient care.
- Payment: Submitting diagnostic codes and claims to health insurance plans or Medicare for reimbursement.
- Healthcare Operations: Internal quality improvement, clinical auditing, accreditation (e.g., Joint Commission), compliance reviews, and employee training.
2. Disclosures Requiring Written Authorization
Any disclosure of PHI that falls outside of TPO (or a legally mandated statutory exception such as public health reporting or court orders) strictly requires a valid, signed written HIPAA Authorization from the patient or their legal personal representative.
2. Core Components of a Valid HIPAA Authorization
For a written authorization to be legally enforceable, HIPAA dictates that it must contain all 9 mandatory core elements. If any element is missing or incomplete, the authorization is defective and the EHRS must reject the request.
| # | Mandatory Core Element | Description / Requirement |
|---|---|---|
| 1 | Patient Identification | Patient full legal name, date of birth, and Medical Record Number (MRN). |
| 2 | Description of PHI | Specific, clear description of the records to be released (e.g., "Operative reports from Jan 2025 encounter"). |
| 3 | Disclosing Entity | Name or class of persons/facilities authorized to make the disclosure (e.g., "Metro Health System"). |
| 4 | Recipient Name/Entity | Specific name or organization authorized to receive the requested PHI. |
| 5 | Purpose of Disclosure | Specific purpose (e.g., "Life insurance underwriting") or "At the request of the individual". |
| 6 | Expiration Date or Event | Explicit calendar date (e.g., "12/31/2026") or triggering event (e.g., "End of litigation"). |
| 7 | Right to Revoke Statement | Clear instructions on how the patient can revoke the authorization in writing, plus exceptions. |
| 8 | Redisclosure Warning | Notice that information disclosed pursuant to the authorization may be subject to redisclosure by the recipient. |
| 9 | Signature and Date | Signature of patient or legal representative, date signed, and description of representative's authority. |
3. High-Sensitivity Records Requiring Explicit Authorization
Certain categories of medical data are subject to heightened statutory privacy protections and cannot be released under a standard general medical ROI authorization.
-
Psychotherapy Notes:
- Notes recorded by a mental health professional documenting private counseling sessions, maintained separately from the rest of the medical record.
- Always requires a standalone authorization dedicated exclusively to psychotherapy notes.
-
Substance Use Disorder (SUD) Records (42 CFR Part 2):
- Federally protected records from specialized addiction treatment facilities under 42 CFR Part 2.
- Requires explicit authorization containing a specific notice prohibiting the recipient from re-disclosing the information without further written consent.
-
HIV/AIDS & Communicable Disease Records:
- State laws strictly require explicit written consent specifically naming HIV/AIDS test results or status before release.
-
Genetic Information (GINA):
- Protected under the Genetic Information Nondiscrimination Act; requires explicit consent.
4. Accounting of Disclosures & Legal Demands
Accounting of Disclosures Tracking
Under HIPAA, patients have the legal right to request an Accounting of Disclosures, which lists disclosures of their PHI made by the covered entity.
- Retention Period: Disclosures must be logged and tracked for 6 years.
- Exemptions from Accounting: Covered entities do not need to log disclosures made for:
- Treatment, Payment, and Healthcare Operations (TPO).
- Disclosures made directly to the patient.
- Disclosures authorized by a signed HIPAA authorization form.
- Incidentals permitted under HIPAA.
- Response Timeline: The facility must respond to an Accounting of Disclosures request within 30 days (a single 30-day extension is permitted with written notice).
Subpoenas vs. Judicial Court Orders
When handling legal demands for patient records, the EHRS must distinguish between different types of legal documents:
[ Legal Demand Received ]
├── Court Order (Signed by Judge) ───────> Fulfill Immediately as Ordered
└── Attorney Subpoena (No Judge Signature) ─> Require HIPAA Authorization OR Proof of Notice / Protective Order
- Court Order (Signed by a Judge): Mandatory legal order. The facility must comply and release the exact records specified in the order without requiring patient authorization.
- Subpoena Issued by an Attorney: Does not automatically authorize record release. The EHRS must verify that the subpoena is accompanied by:
- A valid signed HIPAA authorization from the patient, OR
- Written proof that reasonable efforts were made to notify the patient and allow time for an objection, OR
- A qualified protective order filed with the court.
An EHRS receives a written request from an attorney for a patient's complete medical chart. The authorization form submitted lacks an expiration date or expiration event. What action should the EHRS take?
Under HIPAA Privacy regulations, which of the following PHI disclosures MUST be recorded in the facility's Accounting of Disclosures log?
A facility receives an attorney-issued subpoena duces tecum for medical records without a judge's signature or a signed HIPAA authorization. What must the EHRS verify before releasing any records?