Try Interactive Demo
No-code database platforms are transforming the way web apps are…
Template Marketplace
Use Knack’s Patient Portal Template to give patients, providers, and…
A complete EHR for solo mental health practitioners. Manage patient…
Knack’s Telemedicine App Template gives healthcare providers, clinics, and independent…

What Is a HIPAA Authorization Form? Requirements and How to Build One

  • Written By: Samantha Suser
What Is a HIPAA Authorization Form? Requirements and How to Build One

A HIPAA authorization form is not the same thing as a general patient consent. It is a specific legal document that permits a covered entity to use or disclose protected health information for purposes that fall outside what HIPAA already allows without patient permission. Most healthcare organizations use authorization forms regularly, and most of them get at least one element wrong. A missing expiration date, a vague description of the PHI involved, or a form that bundles two separate authorizations into one document can make the whole thing legally defective.

Key takeaways

  • A HIPAA authorization form permits a covered entity to use or disclose PHI for purposes not already covered by treatment, payment, or healthcare operations. It is required any time one of those three exceptions does not apply.
  • The Privacy Rule sets six required elements. Every element must appear on the form. A single missing element makes the authorization legally defective and any disclosure based on it an impermissible one.
  • Authorization forms are distinct from consent forms. Consent covers permission to treat. Authorization covers permission to use or disclose PHI for a specific purpose.
  • Authorization forms must be written in plain language and stored for a minimum of six years from the date signed or the date when they were last in effect.
  • Patients can revoke a HIPAA authorization at any time in writing. Your organization must have a documented process for receiving, recording, and acting on revocations.
  • Knack Health lets healthcare teams build digital authorization forms connected to a structured patient record, with role-based access and record change logs built into the same HIPAA-ready environment.

What is a HIPAA authorization form?

A HIPAA authorization form is a written, patient-signed document that gives a covered entity permission to use or disclose protected health information (PHI) for a specific, stated purpose. HIPAA’s Privacy Rule permits covered entities to use and disclose PHI without patient authorization for three purposes: treatment, payment, and healthcare operations. Any use or disclosure that falls outside those three categories generally requires a signed authorization before PHI can leave the organization.

The authorization is not a formality. It is a legal instrument. When an organization discloses PHI based on a defective authorization, HHS treats that disclosure as impermissible, regardless of whether the organization believed the form was valid. A pattern of authorization failures can trigger corrective action by the Office for Civil Rights, separate from any individual breach notification obligation.

Authorization forms are also sometimes called HIPAA release forms or release of information forms when the purpose is releasing records to a third party. The name varies by context and organization, but all of them must meet the same legal requirements to be valid. The HIPAA release of information guide covers the release workflow specifically, including how to receive, validate, and fulfill ROI requests. This post focuses on what makes the authorization itself legally valid.

When is a HIPAA authorization form required?

Authorization is not required for treatment, payment, or healthcare operations. A covered entity can share a patient’s PHI with another treating provider without authorization. A hospital can send a patient’s records to their insurance company for billing purposes without authorization. A practice can discuss a patient’s case internally for quality improvement purposes without authorization. The Privacy Rule permits these flows without patient sign-off.

Authorization applies to disclosures that fall outside those three categories. Common situations that require a signed HIPAA authorization form include the following.

Disclosures to employers or life insurers. If a patient’s employer or a life insurance company requests health information for employment screening or underwriting purposes, an authorization is required before any PHI is disclosed.

Marketing communications. HIPAA requires authorization for most marketing communications that involve PHI. There are narrow exceptions for face-to-face communications and promotional gifts of nominal value, but broadly, using patient information to send marketing material requires authorization.

Sale of PHI. Any sale of PHI to a third party requires a specific authorization that explicitly states that the disclosure will result in remuneration.

Psychotherapy notes. Psychotherapy notes have heightened protection under HIPAA. Covered entities must obtain authorization for most uses and disclosures of psychotherapy notes, including for treatment, payment, and healthcare operations, with a narrow set of specific exceptions.

Substance use disorder records. Additional protections under federal law (beyond HIPAA) apply to substance use disorder treatment records. These records require authorization in most circumstances, and the requirements are more stringent than standard HIPAA authorization.

Patient-initiated disclosures. When a patient requests that their records be sent to a specific third party, such as a personal attorney, a school, or a family member not involved in their care, authorization from the patient is generally required.

When in doubt about whether a specific disclosure requires authorization, the safest practice is to obtain one. An unnecessary authorization creates a minor documentation step. A missing required authorization creates a compliance violation.

The six required elements of a valid HIPAA authorization form

The Privacy Rule specifies six core elements that every HIPAA authorization form must include. A form that is missing any one of them is legally defective, even if the patient signed it. Organizations frequently make the mistake of assuming that a signed form is a valid form. In practice, it is not valid if the required elements are incomplete or vague.

1. A specific description of the PHI to be used or disclosed

The description must be specific enough for the patient to understand exactly what information will be shared. Vague language like “all medical records” or “any and all health information” does not satisfy this requirement. Instead, the description should identify the information by type, by date range, or by the condition or episode of care it relates to. For example: “Records related to treatment for knee surgery, September 2024 through March 2025” is specific. “Medical records” is not.

2. The name or specific identification of who is authorized to make the disclosure

This is typically the covered entity itself, a specific department, or a named individual within the organization. The form must identify who is disclosing the information, not just who is receiving it.

3. The name or specific identification of who will receive the PHI

The patient must know exactly who will receive their information. A vague recipient description like “any healthcare provider” or “as needed” is not valid. The recipient must be specifically identified by name or by class, such as “the patient’s primary care physician, Dr. Jane Smith, at [practice name].”

4. A description of the purpose of the disclosure

The form must describe why the covered entity is sharing the PHI. If the patient is initiating the request themselves, the description “at the request of the individual” satisfies this requirement. In other cases, the purpose must be clearly stated, such as “for life insurance underwriting” or “for legal proceedings in the matter of [case].”

5. An expiration date or expiration event

The authorization cannot be open-ended. It must either specify a date on which it expires or an event that will mark the end of the authorization’s validity. “One year from the date signed” satisfies this requirement. “End of the research study” satisfies it in a research context. An authorization with no expiration at all is invalid.

6. The patient’s signature and the date signed

The patient must sign and date the form. If the patient is a minor or lacks legal capacity to sign, the patient’s personal representative must sign instead, and your organization must document the representative’s authority to do so.

Beyond the six required elements, the Privacy Rule also requires that the form include three required statements, sometimes called the “required statements” or “notification elements.”

Right to revoke. The form must inform the patient that they have the right to revoke the authorization at any time in writing, and must describe how to do so.

Conditioning prohibition notice. The form must state whether treatment, payment, enrollment, or eligibility for benefits is conditioned on signing the authorization. In most cases, the statement will be that treatment is not conditioned on providing this authorization. (There are narrow exceptions, such as research-related treatment.)

Potential for re-disclosure. The form must advise the patient that the recipient may re-disclose the information and that HIPAA protections may no longer apply once the information leaves the covered entity.

All three required statements must appear on the form. A form that has all six core elements but omits a required statement is still defective.

Authorization forms vs. consent forms: the key distinction

Authorization and consent are different documents that serve different purposes under HIPAA, and conflating them is one of the more common compliance errors in healthcare settings.

Consent is a patient’s agreement to receive treatment. A signed consent for treatment allows a provider to treat the patient and to use or share PHI in the ways necessary to carry out that treatment, billing, and standard healthcare operations. Consent for treatment is often obtained at registration and covers a broad range of routine uses.

Authorization is a patient’s permission for a specific, non-routine use or disclosure of their PHI. It is narrower and more specific than consent. It identifies exactly what information is being shared, with whom, for what purpose, and for how long.

In practice, the difference is this: a clinic can share a patient’s records with a specialist treating the same patient without authorization, because that is treatment. However, if that same clinic wants to share the patient’s records with the patient’s employer, or with a researcher, or with a journalist covering a story, an authorization is required for each of those disclosures.

The Privacy Rule also prohibits combining certain types of authorizations. Organizations cannot combine an authorization for psychotherapy notes with an authorization for any other type of PHI. Similarly, they cannot combine an authorization tied to research involving treatment with a general authorization for other purposes. Each authorization must stand alone.

What makes a HIPAA authorization form defective

Several patterns consistently produce defective authorization forms in practice. Knowing them in advance is faster than discovering them in an enforcement review.

Vague PHI description. “All medical records” or “any health information” does not satisfy the specificity requirement. If a reviewer cannot tell precisely what information is covered by reading the form, the description is insufficient.

Missing expiration. An authorization with no expiration date or event is invalid. This is one of the most common single errors in authorization forms across healthcare organizations.

Compound authorizations. Combining multiple authorizations into one form creates problems when patients want to revoke one but not the other. In certain contexts, such as psychotherapy notes, compound forms are explicitly prohibited.

Undated signatures. A signature without a date leaves the authorization period ambiguous and creates record-keeping problems when determining whether the authorization was in effect at the time of a specific disclosure.

Missing required statements. The three required statements (right to revoke, conditioning prohibition notice, re-disclosure warning) are frequently omitted from authorization forms built informally or adapted from general templates without HIPAA review.

Forms that are not in plain language. The Privacy Rule requires that authorization forms be written so patients can read and understand them. Dense legal language does not satisfy this requirement.

How long must HIPAA authorization forms be retained?

Covered entities must retain authorization forms for a minimum of six years from the date of creation or from the date the authorization was last in effect, whichever is later. This retention requirement applies to both signed authorizations and declined or revoked ones. Your organization’s record retention policy must reflect this minimum.

Storing authorization forms in a compliant environment, rather than in a general email inbox or an unstructured file folder, makes the retention and retrieval requirement significantly easier to meet. A system with record change logs provides an auditable history of when a form was submitted, who accessed it, and whether it was subsequently revoked or modified.

Patient rights regarding HIPAA authorizations

Patients retain several rights with respect to authorization forms that healthcare organizations must actively support.

The right to revoke. A patient can revoke a HIPAA authorization at any time in writing. The revocation takes effect when the organization receives it. Consequently, your organization must have a documented process for receiving, recording, and acting on revocations. The revocation does not apply retroactively: disclosures already made in reliance on the valid authorization are not undone by a later revocation. However, no further disclosures should occur after the revocation is received.

The right not to be conditioned. In most circumstances, a covered entity cannot condition treatment, payment, or enrollment on a patient’s willingness to sign an authorization. Patients cannot be refused care because they decline to authorize a non-routine disclosure.

The right to a copy. Patients are generally entitled to receive a copy of any authorization they sign.

The right to inspect and amend. Patients have broader rights under HIPAA to inspect and request amendments to their records. Authorization forms themselves, as part of those records, fall within these rights.

How to build a HIPAA authorization form digitally in Knack Health

A paper authorization form stored in a file folder satisfies the basic requirement. However, it creates real operational problems. Retrieving a specific form to verify it is still in effect takes manual effort. Auditing which disclosures occurred under a given authorization requires cross-referencing paper logs. Processing a revocation means manually locating and annotating the original form.

A digital HIPAA authorization form connected to a structured patient record in Knack Health solves all of these problems at once. Specifically, when a patient submits an authorization form, that authorization becomes a structured record in the database, linked to the patient’s existing records, timestamped, and accessible only by the roles your configuration permits. Record change logs capture every view and modification. Revocations update the record rather than requiring a separate paper trail.

Knack Health includes encryption at rest and in transit, role-based access controls at the page, record, and field level, and record change logs on every record. A signed BAA comes with every HIPAA plan. The platform is also SOC 2 Type II certified. For the full breakdown of how Knack Health handles the technical safeguards, the HIPAA-compliant forms guide covers each layer.

Here is the general approach to building a digital HIPAA authorization form in Knack Health. Exact steps and interface elements evolve as the product updates. Treat this as a process guide.

Step 1: Define the object structure. In Knack Health, a database object (a table) backs each form type. For the authorization form, create an object that includes fields for each of the six required elements plus the three required statements. At minimum, that means fields for: PHI description, disclosing party, recipient name and identification, purpose of disclosure, expiration date or event, patient signature, date signed, revocation status, and revocation date if applicable.

Step 2: Build the form. Use Knack Health’s form builder to create a patient-facing form from the object. Add conditional logic where useful. For example: if the authorization type is “psychotherapy notes,” display a notice that this authorization cannot be combined with any other authorization. If the patient indicates they want to revoke a prior authorization, route the submission to the revocation workflow rather than creating a new record.

Step 3: Connect the authorization to the patient record. Link the authorization object to the patient record object so every authorization a patient has signed appears in their record. This connection makes it possible for authorized staff to see at a glance whether a current, valid authorization exists for a specific disclosure before acting on a request.

Step 4: Configure role-based access. Not every staff member needs to see authorization forms. Use Knack Health’s role-based access controls to restrict who can view, edit, or process authorizations. Front-desk staff may need to see whether an authorization exists and whether it is still in effect. The privacy officer or compliance team may need full access to the record including revocation history. Clinical staff typically need read access only.

Step 5: Set up the revocation workflow. When a patient revokes an authorization, your staff must record the revocation in the patient’s record and flag it for the team member responsible for the associated disclosure. Knack Health’s workflow automation triggers a notification to the relevant team when it receives a revocation submission. It also automatically updates the authorization record’s status field from “active” to “revoked.”

For organizations building a broader authorization management system, rather than just a standalone form, the HIPAA-compliant patient registry guide covers how to structure connected patient records in Knack Health. The healthcare workflow automation guide covers how to connect form submissions to operational processes.

Knack Health’s HIPAA Forms plan starts at $159/mo.

FAQ

What is the difference between a HIPAA authorization form and a HIPAA release form?

They are the same legal document described by different names. A HIPAA release form, or release of information form, is an authorization form used specifically to authorize the release of medical records to a third party. Both must meet the same Privacy Rule requirements. The HIPAA release of information guide covers the release workflow and validation process specifically.

A HIPAA authorization form is invalid if it is missing any of the six required elements or any of the three required statements. Common defects include a missing expiration date, a vague description of the PHI covered, a missing recipient name, or an undated patient signature. A defective authorization cannot serve as a legal basis for disclosure. Any disclosure made on the basis of a defective authorization is an impermissible disclosure under the Privacy Rule.

Yes. A patient can revoke a HIPAA authorization at any time in writing. The revocation takes effect when the covered entity receives it. Disclosures your organization already completed before receiving the revocation remain valid. Your organization must have a documented process for receiving revocations, updating authorization records, and notifying the relevant staff.

Covered entities must retain authorization forms for at least six years from the date of creation or from the date the authorization was last in effect, whichever is later. This requirement covers signed authorizations and declined or revoked ones.

No. Authorization is not required for disclosures made for treatment, payment, or healthcare operations. Authorization is required for disclosures outside those categories, including disclosures to employers, life insurers, marketers, and researchers, as well as patient-initiated disclosures to third parties.

No. A general consent for treatment authorizes the provider to treat the patient and to use PHI for the purposes necessary to carry out that treatment, billing, and standard operations. It does not substitute for a HIPAA authorization form for non-routine disclosures. Authorization forms require specific elements, specific recipients, specific purposes, and expiration terms that a general consent form does not include.

Knack Health supports e-signature fields in its form builder. Confirm the specific signature functionality available on your plan with the Knack Health team, since feature availability varies by plan and product updates occur regularly.