What Is Release of Information?
Release of information, commonly abbreviated ROI, is the process by which healthcare organizations disclose protected health information to patients, other providers, insurers, attorneys, and other authorized parties. ROI functions must balance timely access to information with strict privacy and security safeguards.
Elements of a Valid Authorization
Under the HIPAA Privacy Rule, a valid authorization for release of PHI must contain specific core elements, including:
- A specific and meaningful description of the information to be disclosed
- The name of the person or entity authorized to make the disclosure
- The name of the person or entity to whom the disclosure will be made
- A description of the purpose of the disclosure
- An expiration date or event
- The signature of the individual and the date signed
The authorization must also inform the individual of their right to revoke the authorization in writing and note any exceptions to that right.
Turnaround Time Requirements
Under HIPAA, covered entities generally must provide individuals access to their records within 30 days of the request, with a possible one-time 30-day extension if the individual is notified of the reason for delay. Many states impose shorter turnaround time requirements, and organizations must comply with whichever standard is more stringent or protective of patient rights.
Fees for Copies of Records
HIPAA permits covered entities to charge a reasonable, cost-based fee for providing copies of records to patients, which may include costs of labor, supplies, and postage. Fees charged to third parties, such as attorneys or insurance companies, are often governed by separate state fee schedules that may differ from patient access fees.
Accounting of Disclosures
Patients have the right to request an accounting of certain disclosures of their PHI made by a covered entity within the preceding six years. This accounting excludes disclosures made for treatment, payment, and healthcare operations, as well as disclosures made pursuant to a signed authorization.
Handling Third-Party Requests
Requests from attorneys, insurance companies, and other third parties must be verified for a valid authorization or applicable legal exception before information is released. HIM staff must confirm the requestor's identity and the scope of the request matches what was authorized.
Special Categories of Information
Certain categories of health information, such as substance use disorder treatment records, HIV status, and mental health records, are subject to additional federal or state protections requiring specific authorization language beyond standard HIPAA requirements.
Conclusion
Accurate and timely release of information processing requires strict adherence to authorization requirements, turnaround times, and special category protections to safeguard patient privacy while supporting continuity of care.