Who Ultimately Decides Whether a Medical Record Can Be Released?

In most situations, you are the person who decides whether a medical record can be released. The HIPAA Privacy Rule treats the patient as the default authority: a healthcare provider generally needs your signed authorization before sharing your protected health information with anyone outside the circle of people directly involved in your care or payment. HIPAA then names specific exceptions — a personal representative can authorize release on your behalf when you cannot, and certain disclosures are allowed or required by law without anyone’s consent. The provider’s job is to verify the request, apply the rule, and release only what the rule permits.

When Your Authorization Is Required

Your written authorization is required whenever someone outside the treatment, payment, or healthcare operations process wants your records. Life insurance underwriters evaluating an application, employers making non-workers’-compensation inquiries, attorneys in a private dispute, family members who are not your designated representative — none of them can obtain your records without your signature.

What catches people off guard is the treatment, payment, and healthcare operations carveout. Providers do not need your authorization to share records for those purposes. A hospital can send your chart to a specialist for a referral, a lab can send results back to the ordering physician, and a billing department can submit information to your health insurer, all without asking you first.1HHS.gov. Uses and Disclosures for Treatment, Payment, and Health Care Operations The exception exists because requiring authorization for every routine exchange between the people caring for you would halt the healthcare system.

Everything outside that carveout defaults back to you.

What Makes an Authorization Legally Valid

When your authorization is needed, a vague “I consent” is not enough. HIPAA lists specific elements an authorization must contain to be valid:2eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required

  • A specific description of the information being released, not just “all medical records.”
  • The person or entity authorized to make the disclosure.
  • The person or organization receiving the records.
  • The purpose of the disclosure. If you initiated the request and prefer not to explain, “at the request of the individual” is enough.
  • An expiration date or event.
  • Your signature and the date. If a personal representative signs for you, the form must describe their authority to do so.

The form also has to tell you that you can revoke the authorization in writing at any time, that the provider generally cannot condition your treatment on whether you sign, and that once your information reaches the recipient it may be re-disclosed and lose HIPAA protection.2eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required An authorization missing any of these elements is defective, and a provider should not act on it.

Who Else Can Authorize Release on Your Behalf

Several situations shift the decision away from the patient to another authorized person.

Parents Deciding for Minor Children

In most cases, a parent is treated as the personal representative of their unemancipated minor child and can authorize release of that child’s records.3Department of Health and Human Services. The HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records The parent stands in for the child for privacy purposes.

There are exceptions. State laws in many jurisdictions let minors consent on their own to certain kinds of care, such as reproductive health services, substance use treatment, and mental health care. When a minor legally consents to their own care under state law, the minor becomes “the individual” under HIPAA for that specific care, and the parent no longer controls release of those particular records. A parent who agreed to a confidentiality arrangement between their child and a provider also cannot override that agreement later to obtain the records.

Healthcare Agents for Incapacitated Adults

When an adult cannot make their own decisions, a person holding a healthcare power of attorney or healthcare proxy can authorize release on their behalf. The authority activates when a medical professional determines the patient lacks decision-making capacity. What the agent can actually do — including which records they may access — depends on how the underlying document is written. A broadly drafted power of attorney typically covers records access; a narrowly drafted one may not.

Executors After Death

The executor or administrator of a deceased person’s estate becomes the personal representative for HIPAA purposes and can authorize disclosures of the decedent’s health information.4HHS.gov. Guidance – Personal Representatives An estate executor’s authority is broader than a living patient’s healthcare agent, because settling an estate, pursuing insurance claims, and understanding hereditary health risks all require access to the records.

HIPAA protections for a deceased person’s records last 50 years from the date of death.5HHS.gov. Health Information of Deceased Individuals During that period, any disclosure not otherwise permitted by HIPAA requires written authorization from the personal representative, just as it would for a living patient.

When Records Can Be Released Without Anyone’s Consent

HIPAA identifies specific situations where a provider can, and sometimes must, disclose health information without authorization from you or a personal representative. These exceptions are narrow and defined.

Court Orders and Subpoenas

A court order directly compels a provider to release the records the order specifies, and only those records.6eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required A subpoena not backed by a court order is different. Before a provider responds to a standalone subpoena, the requesting party must show either that you were notified of the request or that they sought a qualified protective order. If you receive notice that someone has subpoenaed your records, you may have time to object before the provider releases anything.

Public Health Reporting

Providers can share information with public health authorities for disease tracking, injury reporting, vital statistics, and public health investigations without your authorization.6eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required Communicable disease surveillance and outbreak response run through this channel, often via automated electronic case reporting to state health departments or the CDC.

Law Enforcement

Police and other law enforcement officials can obtain limited health information under specific conditions. A provider may share enough to help identify or locate a suspect, fugitive, or missing person, but only certain data points, not your full chart. Providers can also disclose information they believe in good faith is evidence of a crime that occurred on their premises.6eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required

Workers’ Compensation

HIPAA permits providers to disclose health information to workers’ compensation insurers, state administrators, and employers involved in a workers’ compensation case, without your authorization, to the extent necessary to comply with workers’ compensation laws.7HHS.gov. Disclosures for Workers’ Compensation Purposes The disclosure must stay within the boundaries set by that law, but the provider does not need to wait for your sign-off before sharing relevant treatment records with the insurer handling your claim.

Emergencies

When you are in an emergency and cannot consent, providers can share information as needed for your immediate treatment. They can also disclose information to help identify a deceased person or determine cause of death. Saving a life or preventing serious harm takes priority over waiting for paperwork.

The Provider’s Role as Gatekeeper

Providers do not ultimately decide whether your records can be released. You do, or the law does. But providers carry the responsibility for making sure every disclosure follows the rules. They verify the identity and authority of whoever is requesting records, confirm that authorization forms contain the required elements, and check whether a legal exception applies before releasing anything without consent.

One of the provider’s most important obligations is the “minimum necessary” standard. When sharing your records, a provider must make reasonable efforts to limit the disclosure to only what is needed for the stated purpose. A workers’ comp insurer asking about a back injury does not get your full psychiatric history. The minimum necessary rule has notable exceptions: it does not apply to disclosures for treatment, disclosures you authorized, disclosures to you or your personal representative, or disclosures required by law.8HHS.gov. Summary of the HIPAA Privacy Rule

Providers must also give you a Notice of Privacy Practices, a written document explaining how they use and share your health information, what your rights are, and what their legal duties are. The notice must be provided no later than your first visit, and the provider must make a good-faith effort to get your written acknowledgment that you received it.9eCFR. 45 CFR 164.520 – Notice of Privacy Practices for Protected Health Information

State Laws Can Give You More Control

HIPAA sets a federal floor, not a ceiling. When a state law provides stronger privacy protections than HIPAA, the state law stands.10HHS.gov. Preemption of State Law Some states restrict disclosures HIPAA would otherwise allow, or add protections for sensitive categories like HIV status or mental health records. Your provider must follow whichever rule, federal or state, gives you more privacy.

If a Provider Releases Records It Should Not Have — or Refuses One It Should

If a provider releases your records to someone who was not authorized, or refuses a valid authorization you signed, you can file a complaint with the HHS Office for Civil Rights.11HHS.gov. Filing a Health Information Privacy Complaint Complaints can be submitted online through the OCR Complaint Portal or in writing. You do not need a lawyer to file, and anyone who believes a HIPAA violation occurred can submit one. OCR is the enforcement body providers answer to when they get the release decision wrong.