Releases of information (ROI) are a core part of how health data moves between providers, payers, and patients. Under U.S. privacy rules, certain disclosures must be documented and reported to individuals who request an accounting of disclosures. This article explains when releases of information need to be accounted for, what must be included, and practical steps for compliance. It covers HIPAA requirements and touches on related contexts like public records laws.
HIPAA Accounting Of Disclosures: When It Is Required
Under the Health Insurance Portability and Accountability Act (HIPAA), covered entities and business associates must provide an accounting of disclosures of protected health information (PHI) upon request. The accounting is required for disclosures made after the effective date of HIPAA and within the prior six years. The rule applies to disclosures not incidental to a treatment, payment, or healthcare operations, and not to disclosures made to the patient themselves.
What Must Be Included In The Accounting
- Dates of each disclosure or the time period involved.
- Description of the PHI disclosed (type or specific data elements).
- Recipient or the name of the person or entity to whom the PHI was disclosed.
- Purpose of the disclosure (why the information was shared).
- Location or where the disclosure occurred, to the extent feasible.
Disclosures that are exempt from this accounting requirement include those made for treatment, payment, or healthcare operations; disclosures to the patient when they request their own PHI; disclosures to family or friends involved in the patient’s care when the patient has limited capacity or has consented; and disclosures made pursuant to an authorization that specifies the information release. In many cases, routine internal disclosures within a covered entity or between a covered entity and a business associate may not require an accounting if they are part of permissible uses and disclosures under HIPAA.
What Triggers An Accounting Request
Patients or their personal representatives can request an accounting of disclosures in writing. The request should specify the time period (up to six years) and, ideally, be precise about the PHI or disclosures of interest. The covered entity must respond within a set timeframe, typically within 60 days, with an accounting or a justification for denial. If the request is complex, an extension may be possible, with a notice to the requester explaining the delay.
Limitations And Practical Scope
- The accounting is not required for disclosures made without patient authorization that are otherwise permitted by HIPAA (e.g., for treatment, payment, or operations).
- Only disclosures of PHI are included; aggregated data or de-identified information falls outside the scope of an accounting.
- Disclosures made to law enforcement, necessary to avert serious threats, or required by other laws may be exempt or handled differently according to state and federal rules.
Beyond HIPAA: Other Contexts For Accounting Of Information Releases
While HIPAA focuses on health data, other laws and government programs require tracking and reporting certain information releases. Public records laws, state privacy statutes, and sector-specific regulations can impose their own accounting or auditing requirements for disclosures, though these are often distinct from HIPAA’s accounting of PHI disclosures.
Public Records And Freedom Of Information Act (FOIA) Context
FOIA requests typically involve access to government records, not an accounting of disclosures. Agencies may log disclosures of records under FOIA, but individuals requesting an accounting of disclosures of sensitive information may face different processes. In private sector contexts, similar accountability may be mandated by state transparency laws or industry regulations rather than HIPAA.
Practical Steps For Compliance
Organizations should implement a structured approach to ROI accounting to ensure timely and accurate responses to patient requests and to demonstrate compliance during audits. The following steps help align operations with HIPAA requirements and best practices.
- Establish a Disclosure Logging System: Maintain an auditable system that records each PHI disclosure, including date, recipient, purpose, and data scope.
- Automate Where Possible: Use electronic health record (EHR) features or privacy management software to capture disclosures automatically and generate standardized accounting reports.
- Define Exemption Rules: Clearly document which disclosures are exempt from accounting and ensure staff apply these rules consistently.
- Train Staff Regularly: Provide ongoing training on when disclosures require an accounting, how to respond to requests, and how to protect PHI.
- Retention Policy: Store accounting records for at least six years, or longer if required by state law or organizational policy, with secure access controls.
- Auditing And Oversight: Periodically review disclosure logs for accuracy, completeness, and potential gaps in data capture.
- Communicate Clearly With Patients: Use plain language in responses, explaining what is included in the accounting and any exemptions that apply.
Common Pitfalls And How To Avoid Them
Organizations often stumble on timing, scope, and data accuracy. Ensuring a robust process reduces risk of noncompliance and enhances patient trust.
- Under-Reporting: Ensure all eligible disclosures are captured, including indirect disclosures through intermediaries.
- Missing Data Points: Include all required elements, such as recipient details and purpose, to avoid incomplete accounts.
- Incorrect Time Frames: Limit the accounting to the prior six years, unless state or organizational policies require broader review.
- Delayed Responses: Establish internal service level expectations to respond within mandated timelines.
Frequently Asked Questions
How long must accounting records be kept? Typical practice is to retain for at least six years, matching the HIPAA window, though some jurisdictions require longer retention.
Are disclosures to law enforcement included? It depends on the context and legal basis. Some disclosures may be exempt or require separate documentation.
Can patients request an electronic accounting? Yes. Many entities provide electronic formats that simplify review and download for the patient.
Key Takeaways
- HIPAA requires an accounting of disclosures of PHI for disclosures within the past six years, with specified content in the report.
- Not all disclosures require an accounting; routine internal uses, certain care-related disclosures, and patient-authorized releases may be exempt.
- Effective control systems and clear policies help ensure timely responses, data accuracy, and regulatory compliance.
