HIPAA Hot Takes, No. 1: Introducing a New Series and Addressing Disclosure of PHI for Treatment Purposes by Kirsten Leloudis

Does your job require you to know the ins and outs of HIPAA? Are you a HIPAA Privacy Officer within a North Carolina local health department or state agency? Is reading about medical confidentiality in your free time your idea of fun? If yes, then welcome! Today I am introducing a new series on the Coates’ Canons blog titled “HIPAA Hot Takes!” Each post in this series will briefly answer one frequently asked question about HIPAA. These posts will not include true “hot takes”- I won’t be advancing novel or controversial interpretations of the law- but they will address common misconceptions and points of confusion related to HIPAA.

And now, on to the first post in this series, which tackles a perennial question related to sharing information for treatment purposes.

Question: A HIPAA-covered health care provider (Provider A) needs to send a patient’s medical records to another health care provider (Specialist B) so that Specialist B can provide care to the patient. Is Provider A required to obtain a signed authorization from the patient before she can send the records to Specialist B?

Answer: No, HIPAA does not require a signed authorization for sharing a patient’s protected health information (PHI) between health care providers for treatment purposes. But how do we arrive at that conclusion? Let’s start with what constitutes an “authorization” under HIPAA. An authorization is a written document that must satisfy the criteria set out at 45 C.F.R. 164.508(b), including being written in plain language and containing specific pieces of information. An authorization is signed by a patient (or their legal representative, if applicable) and serves as documentation that permission was given for a HIPAA covered entity to use or disclose that patient’s PHI with specific parties and for specific purposes. (For more information about authorization form requirements, see pages 6-13 of this bulletin). 45 C.F.R. 164.508(a1) explains when an authorization is required: “Except as otherwise permitted or required by this subchapter, a covered entity may not use or disclose protected health information without an authorization that is valid under this section.” The takeaway: An authorization is necessary for a covered entity to release someone’s PHI unless there is a specific provision elsewhere in HIPAA that says otherwise.

45 C.F.R. 164.506 is an example of a HIPAA provision that creates an exception to the requirement to obtain an authorization before sharing PHI. This part of the law establishes the permissible uses and disclosures of PHI for treatment, payment, and health care operations (sometimes referred to as “TPO” purposes). Under 45 C.F.R. 164.506(c)(2), the law allows a “covered entity” (in this scenario, Provider A) to disclose PHI for the treatment activities of another health care provider (here, Specialist B). As noted in paragraph (a) of this HIPAA provision, an authorization is not required when disclosing PHI for TPO purposes.

The legal analysis does not stop there, though. The terms “health care provider” and “treatment” both have particular definitions under HIPAA. “Health care provider” is defined at 45 C.F.R. 160.103 to mean “a provider of services (as defined in section 1861(u) of the Act, 42 U.S.C. 1395x(u)), a provider of medical or health services (as defined in section 1861(s) of the Act, 42 U.S.C. 1395x(s)), and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.” The term “treatment” is defined at 45 C.F.R. 164.501 to mean “the provision, coordination, or management of health care and related services by one or more health care providers, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another.” Taken together, these definitions clearly apply to our scenario in which Provider A needs to send the patient’s health information to Specialist B so that Specialist B can render appropriate care to the patient.

Although HIPAA does not require a covered entity to obtain an authorization before sharing PHI with a health care provider for treatment purposes, practitioners across North Carolina have told me that it is common for fellow health care providers to insist on receiving a signed authorization before they will release a patient’s records directly to another health professional for treatment purposes. While not mandated by HIPAA, some organizations elect to require a signed authorization to release PHI for treatment purposes as a matter of organizational policy.  Practitioners should review their own organization’s policies and consult with their HIPAA Privacy Officer and/or legal counsel if they have questions about their organization’s preferred practices.  

Future Posts in this Series

Do you have suggested topics for future blog posts in this new series, “HIPAA Hot Takes?” Send me your ideas at kirsten@sog.unc.edu.

ABOUT THE AUTHOR