The organization must obtain a valid, plain-language written authorization from an individual before using or disclosing PHI for purposes not otherwise permitted by HIPAA, such as marketing, most research, or sharing with third parties. The authorization must clearly identify the disclosing covered entity and each recipient, and the individual must receive a copy of the signed authorization.
The authorization must contain these core elements:
- A description of the information to be used or disclosed
- The purpose of the use or disclosure
- The name (or other specific identification) of each disclosure recipient
- The name of the covered entity disclosing the information
- An expiration date or event
- The individual’s signature and date
It must also inform individuals of their right to revoke the authorization in writing at any time, and state that revocation will not affect actions taken in reliance on the authorization before receipt of the revocation.