A disclosure accounting entry is the record of one disclosure that must appear in an individual's HIPAA accounting when the event is subject to the accounting right. The ordinary entry identifies the disclosure date, recipient and known address, a brief description of the protected health information disclosed, and a brief statement of purpose or an allowed copy of the underlying written request.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Four content fields make the entry understandable
Current 45 CFR 164.528 requires the date, recipient name and known address, a brief description of the PHI, and a purpose statement that reasonably informs the individual of the basis. A qualifying written request may replace the purpose statement. Internal ticket numbers alone cannot explain the disclosure.
Use the actual disclosure date, which may differ from the approval, request, batch, or log-entry date. Name the recipient at a level the individual can recognize and include the known address. Describe the PHI with enough specificity to communicate the record type and scope, such as an assessment and treatment-plan extract for a stated period. The purpose statement should identify why the disclosure occurred in plain language and connect it to the applicable basis without relying on an unexplained code.
When a qualifying written request is used instead of the purpose statement, keep the permitted copy attached to the entry and verify that it supplies the required explanation. A subpoena number, incident ID, or vendor label may help internal reconciliation, but it does not replace the individual-facing content.
Build from event evidence, not memory
Create the entry from the disclosure event and its source evidence. Relevant fields include the person, timestamp, sender or system, recipient, destination, records selected, transmission result, purpose or request, rule classification, and corrections. Pull events from manual logs, interfaces, secure messages, fax systems, health-information exchanges, vendors, and business associates. Preserve source identifiers so an auditor can trace the concise entry back to the actual transmission.
Normalize without erasing distinctions. Standard recipient names and addresses help deduplicate events, but two transmissions on the same date can still be separate disclosures. Conversely, retries of one failed transmission should not automatically become multiple completed entries. Define event rules and retain both raw and normalized values.
Source evidence should stay attached
Keep the disclosure event, system or person that released the information, recipient, legal or operational route, records sent, and correction history. The accounting shown to the individual can remain concise while the internal record preserves enough evidence to validate every field.
Apply inclusion and exclusion decisions after the event population is assembled. Store the classification, reviewer when needed, and reason. For repeated qualifying disclosures to the same person or entity for a single purpose, 45 CFR 164.528 permits a summary structure with the first disclosure information, frequency or number, and last date. Keep the underlying events so the practice can validate that the summary criteria and counts are correct.
Business-associate events require a dependable handoff. The contract and operating procedure should make relevant information available to the covered entity, or support a defined direct-response arrangement. Reconcile the associate's population, format, time zone, recipient fields, and corrections with internal events before producing the accounting.
Example with locked events
A monthly cohort contains 14 included disclosures. Twelve have all four required content fields; one lacks the PHI description and one lacks a usable purpose. Entry completeness is 12 of 14 disclosures, or 85.7%. Both incomplete events stay in the worklist.
Assume one complete entry reads: disclosure on May 6, 2026 to a named state agency at its known address; behavior-assessment report and service records dated January through April 2026; disclosed in response to the agency's identified oversight request. Internally, the entry links to the request, export manifest, secure-transmission receipt, and classification. The individual sees a concise explanation, while reviewers can reproduce its source.
Entry checklist
- Use the event's actual disclosure date.
- State the recipient name and known address in recognizable form.
- Describe the PHI type and scope with enough detail to be meaningful.
- Give a plain-language purpose or attach the qualifying written request.
- Link the entry to immutable or reproducible source evidence.
- Reconcile retries, duplicates, corrections, and repeated-disclosure summaries.
- Include relevant business-associate events and verify their field mapping.
- Review vague, missing, or internally inconsistent entries before delivery.
Owner controls
The HHS Audit Protocol checks the information included in accountings. Use required fields, recipient normalization, review for vague purpose text, immutable timestamps, and reconciliation across manual logs, vendors, and source systems. Measure field completeness before measuring delivery.
Monitor missing fields by source, events logged after long delays, recipient-address gaps, vague purpose text, duplicate rates, and corrections after delivery. Sample in both directions: trace source disclosures into the accounting and accounting entries back to transmissions. A delivered accounting is trustworthy only when its entry population and each required field are supported.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni