What Is Release of Information in Healthcare: Rules and Penalties

Release of information in healthcare is the formal process by which your medical records are shared with you or with someone else you or the law allows to receive them. The rules come mostly from the federal Health Insurance Portability and Accountability Act (HIPAA), which decides when your written permission is needed, when it isn’t, how quickly a provider has to respond, what they can charge, and when they can say no. Knowing how the process works is what lets you get your own records without being overcharged, send them where you want them to go, and recognize a privacy violation when it happens.

What Gets Shared and Who Has to Follow the Rules

The information HIPAA protects is called Protected Health Information, or PHI. That covers any health-related data tied to you as an identifiable person: diagnoses, lab results, treatment notes, billing records, insurance details, demographics, even appointment schedules. It applies to electronic files, paper charts, and spoken conversations alike.1eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information: General Rules

The rules bind “covered entities,” which means most healthcare providers, health plans, and healthcare clearinghouses that transmit health data electronically. If data can’t identify you, it falls outside HIPAA. Once your name, birthdate, Social Security number, or another identifier is attached to health data, every use and disclosure of that data has to follow the rules below.

When Your Written Authorization Is Required

Outside a set list of exceptions, a covered entity needs your signed authorization before releasing your records. A valid authorization is not a casual signature. It has to include a specific description of the information being shared, who is disclosing it, who is receiving it, the purpose of the disclosure, an expiration date or event, and your signature and date. If someone signs for you as a personal representative, the form must describe their authority to do so.2eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required

A vague reference to “my medical records” is not specific enough. The authorization also has to tell you that you can revoke it in writing, explain how, and state that the provider generally cannot condition your treatment, payment, or benefits on whether you sign. You are entitled to a copy of what you signed.

Revoking an Authorization

You can pull back an authorization at any time by sending a written revocation to the covered entity holding your records. It takes effect when the provider receives it, not when you send it, and it cannot undo disclosures the provider already made while it was valid. If a third party such as a law firm helped create the form, sending your revocation to that third party does not count. It has to reach the entity that actually holds the records.3HHS.gov. Can an Individual Revoke His or Her Authorization?

Sending Records to a Third Party

You can direct your provider to send your records straight to someone else, like another doctor, an attorney, or a family member. The instruction must be in writing, signed, and clear about who the recipient is and where the records should go.4HHS.gov. Can an Individual, Through the HIPAA Right of Access, Have His or Her Health Care Provider or Health Plan Send the Individual’s PHI to a Third Party?

Personal Representatives

HIPAA treats a personal representative the same as the patient. Parents are generally the personal representatives of their minor children unless state law says otherwise. Adults holding a healthcare power of attorney or serving as legal guardians also qualify. A provider may refuse to treat someone as a representative if it reasonably believes that person has subjected the patient to abuse or that access could endanger the patient.5HHS.gov. Personal Representatives and Minors

Extra Rules for Sensitive Records

Two categories of records get more protection than the baseline. Psychotherapy notes, the personal notes a mental health professional keeps separate from the rest of your record, require a specific authorization before disclosure for almost any reason, including sharing with another treating provider. The narrow exceptions are mandatory abuse reporting and situations involving a credible threat of serious, imminent harm. Psychotherapy notes do not include your diagnosis, treatment plan, session times, medications, or progress summaries.6HHS.gov. Does HIPAA Provide Extra Protections for Mental Health Information Compared with Other Health Information

Records from federally assisted substance use disorder treatment programs are covered by a separate federal rule, 42 CFR Part 2, that is stricter than HIPAA. A general medical release form is not enough to authorize disclosure of these records. The consent has to meet Part 2’s specific requirements, and any disclosure has to carry a written warning to the recipient that the information cannot be used in legal proceedings against the patient without a separate consent or a court order. Courts can authorize disclosure for criminal investigation of a patient only when the crime is extremely serious, such as one involving loss of life or serious bodily injury.7eCFR. 42 CFR Part 2 – Confidentiality of Substance Use Disorder Patient Records

When Providers Can Share Without Asking

The biggest exception is treatment, payment, and healthcare operations, often abbreviated TPO. Your primary care doctor can send records to a specialist, your hospital can share billing data with your insurer, and a health system can use your records for internal quality work, all without a separate signature from you.8eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry out Treatment, Payment, or Health Care Operations

HIPAA also permits disclosure without authorization in a range of public-interest situations, each with its own conditions: public health reporting such as communicable disease surveillance, reports to law enforcement under specific legal requirements, compliance with court orders and subpoenas, workers’ compensation claims, organ donation coordination, research approved by an institutional review board, and reports involving suspected abuse, neglect, or domestic violence.9eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required

Even when a disclosure is permitted, the “minimum necessary” standard limits it to the amount of PHI reasonably needed for the purpose at hand. A billing department answering an insurance claim for a broken arm has no business including your full psychiatric history. Minimum necessary does not apply when a provider shares records with another provider for treatment, when you request your own records, when disclosure is made under your written authorization, or when federal law requires the disclosure.10HHS.gov. Minimum Necessary Requirement

Getting Your Own Records: Format, Fees, and Timing

HIPAA’s Privacy Rule gives you a set of enforceable rights over your health information, and access to copies is the one most patients use.11U.S. Department of Health & Human Services (HHS). Your Rights Under HIPAA You can also request corrections to errors in your record, ask for an accounting of disclosures your provider made for reasons other than treatment, payment, or healthcare operations, and receive a written privacy notice explaining how your information is used.

Format

You can request your records in the format you want, as long as the provider can reasonably produce them that way. If your records are electronic, you can ask for an electronic copy, whether that is a PDF, a spreadsheet, or structured clinical data. The provider cannot push you toward a different format just because it prefers one. If it truly cannot produce the format you asked for, you and the provider have to agree on a readable alternative. Only if you turn down every electronic format the provider can produce may the provider default to paper.12U.S. Department of Health & Human Services (HHS). Individuals’ Right under HIPAA to Access their Health Information

Fees

When you request your own records, the fee has to be “reasonable and cost-based.” It can only cover the labor of copying, the cost of supplies like paper or a CD, and postage if you ask for mailed copies. Providers cannot pass along the cost of searching for or retrieving your records, maintaining their systems, or verifying your identity.13HHS.gov. May a Covered Entity Charge Individuals a Fee for Providing the Individuals with a Copy of Their PHI? If your records are available through a certified electronic health record patient portal, the provider generally cannot charge you at all, because there is no labor or supply cost involved.14HHS.gov. May a Covered Health Care Provider Charge a Fee under HIPAA for Individuals to Access the PHI That Is Available Through the Provider’s EHR Technology? You cannot be forced to buy a USB drive or CD; email or mail is your right.

One important boundary. These HIPAA fee caps apply only when you request your own records. When records are sent to a third party such as an attorney or insurance company at that party’s request, state law governs the fees, and state per-page charges and search fees vary widely.

Timing

A provider has 30 calendar days from receiving your request to act on it. It can take a one-time extension of up to 30 more days, but only if it notifies you in writing during the original 30-day window, explains the delay, and gives you a date. No second extension is allowed.12U.S. Department of Health & Human Services (HHS). Individuals’ Right under HIPAA to Access their Health Information If you are past 30 days without a written explanation, that alone is a potential HIPAA violation.

A request to amend a record, rather than copy it, gets 60 days, with the same possible one-time 30-day extension in writing.15eCFR. 45 CFR 164.526 – Amendment of Protected Health Information The provider can deny an amendment if it believes the record is accurate, but it has to respond.

When a Provider Can Legally Deny Access

A provider cannot refuse to release your records just because it prefers not to. HIPAA lists specific grounds, and they split into two groups.12U.S. Department of Health & Human Services (HHS). Individuals’ Right under HIPAA to Access their Health Information

Some denials are unreviewable, meaning you have no right to a second opinion. Psychotherapy notes are excluded from the right of access entirely. Information compiled in anticipation of legal proceedings can be withheld. A correctional institution can deny an inmate a copy if providing it would jeopardize safety or security, though the inmate still keeps the right to inspect the records in person. If you agreed to a temporary suspension of access as part of a clinical trial, the provider may deny access until the study ends. And if a non-provider source, such as a family member, gave information under a promise of confidentiality, the provider can withhold it to protect that source.

Other denials are reviewable, which means you can have a different licensed healthcare professional reconsider the decision. Those apply when a professional determines that access is reasonably likely to endanger your life or physical safety or someone else’s, or that giving records to a personal representative could cause substantial harm. Concern that you might be upset or confused by what the record says is not a valid reason to deny access.

If Your Rights Are Violated

You can file a complaint with the HHS Office for Civil Rights within 180 days of learning about the violation. OCR may extend that deadline for good cause. Complaints go through OCR’s online portal, by email to OCRComplaint@hhs.gov, or by mail, and should name the entity and describe what happened.16HHS.gov. How to File a Health Information Privacy or Security Complaint The most common complaints involve unauthorized uses and disclosures, inadequate safeguards, and failure to give patients timely access to their own records.

Providers that breach unsecured PHI have their own notification obligations. They must notify each affected person within 60 days of discovering the breach, and if more than 500 residents of a single state or jurisdiction are affected, prominent media in that area must also be notified within the same window.17HHS.gov. Breach Notification Rule

Civil Penalties

Civil penalties are tiered by culpability, and the figures below are the most recently published inflation-adjusted amounts.18Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Did not know, and could not have known through reasonable diligence: $145 to $73,011 per violation, up to $2,190,294 per calendar year.
  • Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, up to $2,190,294 per calendar year.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, up to $2,190,294 per calendar year.
  • Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, up to $2,190,294 per calendar year.

Criminal Penalties

Anyone who knowingly obtains or discloses PHI in violation of HIPAA can be prosecuted. A knowing violation carries up to $50,000 in fines and up to one year in prison. A violation under false pretenses carries up to $100,000 and up to five years. A violation committed with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm carries up to $250,000 and up to ten years.19Office of the Law Revision Counsel. 42 USC 1320d-6 Wrongful Disclosure of Individually Identifiable Health Information