{"@context":"https://schema.org","@type":"Article","headline":"Accounting of disclosures","description":"Learn what a HIPAA accounting of disclosures covers, which disclosures are excluded, the six-year period, response timing, required fields, and fees.","url":"https://finnihealth.com/resources/glossary/accounting-of-disclosures","datePublished":"2026-08-16T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Accounting of disclosures","item":"https://finnihealth.com/resources/glossary/accounting-of-disclosures"}]}}
Glossary term

Accounting of disclosures

Learn what a HIPAA accounting of disclosures covers, which disclosures are excluded, the six-year period, response timing, required fields, and fees.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

HIPAA disclosure accounting disclosure history

An accounting of disclosures is a written HIPAA report of certain PHI disclosures made by a covered entity or its business associates during the requested period. The current rule generally reaches up to six years before the request and excludes several categories, including many treatment, payment, operations, authorized, and individual-directed disclosures. It is a defined privacy right, rather than a complete portal, workforce-access, or audit-log history.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

The rule includes and excludes named categories

45 CFR 164.528 gives an individual a right to an accounting for covered disclosures in the preceding six years or a shorter requested period. The rule excludes disclosures for treatment, payment, and health-care operations; disclosures to the individual; certain incidental disclosures; disclosures made under authorization; and other listed categories.

The first task is classifying each disclosure against the rule, not exporting every row from a security log.

Each covered entry needs defined information

For each included disclosure, the accounting generally provides the date, recipient name and known address, a brief description of the PHI, and a brief statement of purpose or qualifying written request. The rule allows specialized treatment of repeated disclosures and certain research disclosures.

Keep disclosure-event evidence separate from transmission-system evidence. One report may need both, but the legal accounting fields come from the operative section.

Timing and fees are specific

A covered entity generally acts within 60 days. One extension of up to 30 days is available when the entity sends a timely written delay statement and expected completion date. The first accounting in a 12-month period is free. A reasonable cost-based fee may apply to a later request in that period after advance notice and an opportunity to withdraw or narrow it.

The Notice of Privacy Practices rule requires the notice to describe this individual right.

The term should stay narrow

A security audit trail records technical access events. An access report may show who opened a portal record. An accounting covers the disclosure events specified by the Privacy Rule. These artifacts can overlap without becoming interchangeable.

A fictional practice reviews 18 disclosure events for one request. Eleven fall within an exclusion, five require accounting entries, and two remain unclassified. Completion is 16 of 18 classified. The two unresolved events stay visible until the privacy owner decides their treatment.

Owner control

The HIPAA Privacy Rule overview provides the broader federal framework. An ABA practice should name the office receiving requests, disclosure sources, business-associate evidence, response clock, extension approval, fee rule, and final review. State law may offer additional rights or shorter timelines.

Build the disclosure inventory before a request

Map every route that can disclose PHI: clinical records, email, fax, portal exchange, claims, payer files, legal responses, public-health reporting, health oversight, law enforcement, research, vendors, and paper delivery. For each route, name the system owner, disclosure evidence, business associate, retention period, and method for retrieving older events.

The inventory should distinguish a disclosure to an outside recipient from internal workforce access. It should also record the legal or authorized purpose when the event occurs. Reconstructing purpose years later from a recipient name is unreliable. Preserve the qualifying request, authorization, report, transmission evidence, and correction history with the event.

Business associates must return the disclosure information needed for the covered entity's accounting. Test that obligation with sample dates and terminated vendors. A contract clause is insufficient when the vendor cannot produce recipient, date, information, and purpose fields within the response clock.

Classify events with a consistent rule

Create one row per disclosure event or permitted repeated-disclosure series. Record individual, date, recipient, known address, PHI description, purpose or authority, source system, inclusion decision, exclusion category, classifier, evidence, and unresolved question. Keep excluded events in the working file so a reviewer can see the classification denominator.

Some health-oversight or law-enforcement disclosures can be temporarily suspended from an accounting after the required agency or official statement. Store the scope, start, end, authority, and release trigger. Suspension postpones the relevant entry; it should not erase the underlying disclosure record.

For repeated disclosures to the same recipient for one purpose, follow the rule's permitted summary method only when its conditions are met. The report should remain understandable to the individual and traceable to event-level evidence.

Use a request checklist

  • verify the requester and authority without collecting unnecessary information
  • lock the requested period, which may be shorter than six years
  • query every covered-entity and business-associate source due for search
  • classify each event against the current inclusion and exclusion rules
  • investigate missing, duplicate, or conflicting records
  • produce every required field in plain language
  • apply the first-free and later-request fee rules correctly
  • send, extend, or suspend only through the rule's documented route
  • preserve the report, evidence, notices, and completion date

Track sources searched divided by sources due, events classified divided by events found, and requests completed by deadline divided by requests due. An on-time report with an unqueried vendor remains incomplete even if the visible entries are accurate.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni