{"@context":"https://schema.org","@type":"Article","headline":"Release of information","description":"Learn how a release of information differs from treatment consent, what a HIPAA authorization contains, how revocation works, and key safeguards.","url":"https://finnihealth.com/resources/glossary/release-of-information","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Release of information","item":"https://finnihealth.com/resources/glossary/release-of-information"}]}}
Glossary term

Release of information

Learn how a release of information differs from treatment consent, what a HIPAA authorization contains, how revocation works, and key safeguards.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

authorization to release records ROI

What does Release of information (ROI) mean for a family's rights and ethical care? A release of information, often called an ROI, is a request or permission process for sending specified records or health information to a named recipient for a defined purpose. Under HIPAA, many releases use a valid authorization, while other disclosures rely on a different permitted route. Treatment consent, record access, and an ROI are separate decisions.

An ROI names the disclosure

A useful ROI states what information may be sent, who may send it, who receives it, why it is needed, how long permission lasts, and who signed. Broad phrases such as “all records to anyone involved” make it hard to understand the actual disclosure.

The HHS Privacy Rule overview explains that covered entities may use or disclose PHI through several routes. Practices should record the route used for each disclosure rather than treating every exchange as identical.

HIPAA authorization has required elements

The HHS consent-versus-authorization FAQ describes an authorization as a detailed permission for specified PHI uses or disclosures when the Privacy Rule requires it. Core elements include a meaningful description of the information, who may disclose it, the recipient, purpose in applicable cases, expiration, signature, and date.

The HHS authorization decision tool also summarizes required elements. A valid form needs the rule’s required statements, including information about revocation and possible redisclosure. Current legal review should confirm the full form.

Some disclosures use another route

HIPAA permits certain disclosures without authorization, including defined treatment, payment, healthcare operations, public-health, required-by-law, family-involvement, and emergency routes when their conditions are met. Other federal or state laws may demand more protection.

Using the correct route matters. Asking for a blanket ROI when a narrower permitted route applies can create unnecessary delay and confusion. Sending information without a required authorization creates a different risk.

Verify who may sign

A parent, caregiver, emergency contact, personal representative, and involved person can have different authority. The HHS personal-representative guidance explains that applicable law determines representative status and scope, with special considerations for minors and possible abuse, neglect, or endangerment.

Verify identity, legal authority, limits, and expiration for the disclosure. A person may have authority over one record type or decision without authority over another.

Expiration and revocation need clear handling

An authorization must include an expiration date or event. Practices should track the version, effective period, covered records, recipient, and revocation status. At expiration, pause future disclosures that depend on that authorization and request a new decision when appropriate.

An individual can generally revoke a HIPAA authorization in writing, subject to the rule’s limits for actions already taken in reliance on it. Record when the revocation arrived, which workflows were stopped, which recipients were notified when applicable, and which disclosures rely on another lawful route.

Send only the authorized information

Match the actual packet to the authorization or permitted route. Check client, date range, record types, exclusions, recipient, destination, and delivery method. A correct form attached to the wrong person’s records does not protect privacy.

Use an approved secure channel, verify the address, log transmission, and confirm failure handling. For records with special protections, route the request to the privacy or legal owner before release.

A fictional school-coordination example

Jules is a fictional student whose family authorizes a covered ABA provider to send a two-page progress summary to a named school speech-language pathologist through the school’s secure portal. The authorization covers six months and excludes psychotherapy and unrelated billing records.

During one audit, staff review eight planned disclosures that depend on authorizations. Five packets match the named recipient, record type, date range, and current authorization, or 5 of 8. After adding a pre-send check, the next nine match in 9 of 9 cases. This measures packet readiness, not whether the authorization or disclosure was legally valid.

Record access and ROI differ

A person’s HIPAA right to access their own designated record set has its own scope, deadlines, fees, and denial rules. An authorization to disclose records to another person follows a different legal pathway in many situations.

When a family says “release my records,” ask whether they want their own copy, direct transmission under the access right, or a third-party disclosure under an authorization. Route the request without making the family select legal terminology.

Questions families can ask

Ask exactly which records, dates, recipient, destination, purpose, and expiration the ROI covers. Request a copy. Ask how to revoke it, which disclosures have already occurred, and whether another law protects a particular record type.

Confirm whether care or coverage depends on signing. HIPAA generally limits conditioning treatment or coverage on authorization, with defined exceptions. Ask the privacy contact to explain any claimed exception.

Before transmission, require a second check of identity, signer authority, current authorization, recipient, destination, record scope, date range, exclusions, expiration, and secure method. Log the exact packet and any failed delivery so the disclosure can be reconstructed.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Find ABA care near you