Two Distinct Concepts
Consent and authorization are related but legally distinct concepts that HIM professionals must be able to differentiate. Consent generally refers to a patient's agreement to receive treatment, while authorization under HIPAA refers to a patient's permission for a covered entity to use or disclose protected health information for purposes not otherwise permitted by the Privacy Rule.
Consent for Treatment
General consent for treatment is typically obtained at admission or registration and covers routine care activities. Informed consent, a higher standard, is required for specific procedures and involves a detailed discussion of risks, benefits, and alternatives so the patient can make a knowledgeable decision. Informed consent documentation should reflect that this discussion occurred and that the patient voluntarily agreed to proceed.
HIPAA Authorization
HIPAA does not require patient authorization for treatment, payment, or healthcare operations, but it does require a valid authorization for many other disclosures, such as releasing information to a life insurance company or for marketing purposes. A valid authorization must include a description of the information to be disclosed, the person authorized to make the disclosure, the recipient, an expiration date or event, and the patient's signature, among other core elements.
Research Consent
Research involving human subjects requires informed consent that meets both HIPAA and Common Rule requirements. In many cases, a combined form addresses both the research consent elements and the HIPAA authorization for use of health information in the study, though some institutions maintain separate documents. Institutional Review Boards oversee the consent process to protect research participant rights.
State Consent Laws
State laws often impose consent requirements that are more stringent than HIPAA, particularly for sensitive information categories such as HIV status, mental health records, and substance use disorder treatment records. When state law is more protective of patient privacy than HIPAA, the more stringent state provision generally governs.
Revocation
Patients have the right to revoke a HIPAA authorization at any time, provided the revocation is in writing, except to the extent the covered entity has already acted in reliance on it. HIM policies should clearly define the revocation process and ensure staff understand that revocation is not retroactive to disclosures already made.