Skip to main content
Category: Individual Rights

Accounting of Disclosures

Also known as: Accounting for Disclosures, HIPAA Disclosure Accounting, Right to an Accounting of Disclosures
Simply put

An accounting of disclosures is a written list that a patient can request showing certain instances where their protected health information (PHI) was shared by a healthcare organization or its business associates. It is one of the individual rights granted under HIPAA, allowing people to learn how some of their health information has been used or released. Not every disclosure is included in this list; only certain categories of disclosures are generally required to be tracked and reported.

Formal definition

Under the HIPAA Privacy Rule, individuals generally have the right to receive, upon request, an accounting of certain disclosures of their protected health information made by a covered entity or its business associates. The accounting is typically a log documenting qualifying disclosures and includes information about those disclosures (such as, in most cases, the date, recipient, and purpose). The right applies to PHI in all forms covered by the Privacy Rule and is distinct from the Security Rule, which governs only ePHI. Notably, the Privacy Rule excludes several categories of disclosures from the accounting requirement, for example, certain disclosures for treatment, payment, and healthcare operations are generally not required to be included, so this term has a specific regulatory scope that differs from a literal 'accounting of all disclosures.' Practitioners should confirm the precise scope, exceptions, applicable time period, and any HITECH Act provisions affecting disclosures against the current regulatory text, and should note that state law may impose additional requirements.

Why it matters

The accounting of disclosures is one of the individual rights that gives HIPAA meaning from the patient's perspective. It provides a mechanism for people to learn how certain instances of their protected health information were shared beyond the routine flow of care, billing, and internal operations. For covered entities and business associates, honoring this right is a compliance obligation under the HIPAA Privacy Rule, and failing to produce a required accounting upon request can expose an organization to scrutiny from HHS OCR.

The practical challenge is that the accounting is not a record of every disclosure. The Privacy Rule carves out several categories, including certain disclosures for treatment, payment, and healthcare operations, that are generally not required to be included. This means organizations must be able to distinguish accountable disclosures from excluded ones and maintain records accordingly. Because patient expectations often differ from the regulatory scope (many assume they will receive a list of every place their data went), clear communication and accurate logging are both important to avoid disputes and to satisfy a request within the applicable time frame.

The requirement also intersects with evolving law. The HITECH Act contemplated changes to disclosure accounting, and state law may impose additional or stricter tracking obligations. Practitioners should confirm the precise scope, exceptions, applicable look-back period, and any HITECH-related provisions against the current regulatory text rather than relying on a general understanding, since these details determine what an organization is actually required to track and produce.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers are typically responsible for establishing the processes that log accountable disclosures and for fulfilling accounting requests within the applicable time frame. They must ensure staff can distinguish disclosures that must be tracked from those that fall within Privacy Rule exceptions, and should confirm the current required data elements and look-back period against the regulatory text.
Covered Entities
Healthcare providers, health plans, and healthcare clearinghouses that are covered entities bear the direct obligation to provide an accounting upon an individual's request. They should maintain records sufficient to produce a compliant accounting for PHI in all covered forms, not only electronic records.
Business Associates and Subcontractors
Business associates that make disclosures of PHI on behalf of a covered entity may be required to track those disclosures and support the covered entity's accounting obligation. The specific responsibilities generally flow through the business associate agreement, so those terms should define how disclosure records are maintained and shared.
Health Information Management and IT Teams
HIM and IT staff often implement the logging systems and workflows used to capture accountable disclosures and to generate the written accounting. They should build classification and reporting capabilities that align with the current regulatory scope and applicable time period.
Research and IRB Personnel
Staff involved in research using PHI may need to track certain disclosures so that they can be included in an accounting when required, since research-related disclosures can fall within the accounting scope depending on the circumstances. They should confirm the applicable requirements against current guidance and any institutional or state-specific rules.

Inside Accounting of Disclosures

Individual Right of Access to an Accounting
The HIPAA Privacy Rule generally grants individuals the right to receive, upon request, an accounting of certain disclosures of their protected health information (PHI) made by a covered entity or, in many cases, its business associates. This right applies to PHI in all forms, consistent with the broader scope of the Privacy Rule.
Look-Back Period
An accounting typically covers disclosures made during a defined period preceding the date of the request. The specific length of this period is set by the regulation, and readers should verify the current time frame against the applicable regulatory text rather than relying on a fixed figure.
Content Elements of the Accounting
For each disclosure that must be accounted for, the accounting generally includes information such as the date of the disclosure, the name of the recipient entity or person, a brief description of the PHI disclosed, and the purpose of the disclosure. The precise required elements should be confirmed against the current regulation.
Disclosures Excluded from the Accounting
The Privacy Rule generally excludes certain categories of disclosures from the accounting requirement, such as disclosures made to carry out treatment, payment, and health care operations, disclosures made to the individual, and disclosures pursuant to an authorization. The complete list of exceptions should be verified against the applicable regulatory text.
Covered Entity and Business Associate Roles
The obligation to provide an accounting rests with the covered entity, but disclosures made by a business associate on the covered entity's behalf may need to be included. These responsibilities are typically allocated through the business associate agreement, which defines how the business associate supports the covered entity in fulfilling this right.
Timing and Fees for Responding
The Privacy Rule generally establishes a time frame within which a covered entity must respond to an accounting request and addresses whether and when a reasonable fee may be charged for additional requests within a given period. Specific deadlines and fee conditions should be confirmed against the current regulation.

Common questions

Answers to the questions practitioners most commonly ask about Accounting of Disclosures.

Does an accounting of disclosures require us to track every disclosure of a patient's PHI?
No. This is a common misconception. The accounting of disclosures right generally does not extend to every disclosure. Several categories are typically excluded, most notably disclosures made to carry out treatment, payment, and health care operations, as well as disclosures made to the individual themselves or pursuant to a valid authorization, among others. The right is designed to capture disclosures that fall outside these routine categories. Because the specific list of exclusions is defined in the Privacy Rule and has been affected by developments such as the HITECH Act, readers should verify the current scope against the applicable regulatory text.
Is the accounting of disclosures the same as giving a patient access to their own records?
No. These are two distinct rights under the HIPAA Privacy Rule and should not be conflated. The right of access generally allows an individual to inspect and obtain a copy of their own PHI held in a designated record set. The accounting of disclosures, by contrast, is a record of certain disclosures the covered entity or its business associates made of the individual's PHI to others. One provides the underlying information; the other provides a log of where that information went. Confirm the precise contours of each right against current guidance, as state law may impose additional requirements.
How far back does an accounting of disclosures generally need to cover?
The Privacy Rule establishes a lookback period during which an individual may request an accounting of covered disclosures. Rather than citing a specific number of years here, we note that a defined maximum period applies and that an individual's request may specify a shorter timeframe. Because this period and any related provisions can be affected by regulatory updates, you should confirm the current lookback requirement against the applicable regulatory text before setting your organization's retention and reporting practices.
What information should typically be captured for each accountable disclosure?
For disclosures subject to the accounting requirement, covered entities generally need to record enough detail to produce a meaningful accounting. This typically includes the date of the disclosure, the name or identity of the recipient (and address where known), a brief description of the PHI disclosed, and a brief statement of the purpose of the disclosure or a copy of the underlying request or authorization. The exact required elements are defined in the Privacy Rule, so verify the current specifications and consider whether state law adds further requirements.
How do business associates factor into our accounting of disclosures process?
Because business associates may make disclosures of PHI on behalf of a covered entity, the accounting obligation can implicate those disclosures as well. In practice, covered entities generally address this through their business associate agreements, ensuring the business associate will provide the information needed to respond to accounting requests. The obligation attaches through the defined covered entity-business associate relationship rather than to the vendor in isolation. Organizations should confirm how responsibilities are allocated in their agreements and against current regulatory guidance.
Can we charge a patient a fee for providing an accounting of disclosures?
The Privacy Rule generally addresses fees in the context of accounting requests, and in many cases an initial accounting within a given period is provided without charge, with the possibility of a reasonable cost-based fee for additional requests within that period, subject to notice. Because fee provisions and timeframes are set by the regulation and may be adjusted over time, and because state law may differ, you should confirm the current fee rules and notice requirements against the applicable regulatory text before establishing a fee practice.

Common misconceptions

The accounting of disclosures must list every disclosure of PHI a covered entity has ever made.
The accounting generally applies only to disclosures within a defined look-back period and excludes several categories of disclosures, such as those for treatment, payment, and health care operations, disclosures to the individual, and disclosures made pursuant to an authorization. The full set of exclusions should be verified against the applicable regulatory text.
This right is part of the HIPAA Security Rule and applies only to electronic PHI.
The accounting of disclosures is an individual right under the HIPAA Privacy Rule, which covers PHI in all forms, including oral and paper. The Security Rule, by contrast, governs only electronic PHI and addresses safeguards rather than individual access rights.
Only covered entities are involved, so business associates have no role in accounting for disclosures.
While the obligation to provide the accounting generally rests with the covered entity, disclosures made by a business associate on the covered entity's behalf may need to be captured. The business associate agreement typically defines how the business associate supports the covered entity in meeting this obligation.

Best practices

Maintain a reliable process and records for tracking disclosures that fall within the scope of the accounting requirement, capturing the date, recipient, PHI described, and purpose so responses can be assembled accurately.
Clearly distinguish accountable disclosures from those that are excluded, such as treatment, payment, and health care operations, and verify the current list of exclusions against the applicable regulatory text.
Address accounting responsibilities in business associate agreements, specifying how business associates will track and report disclosures they make on the covered entity's behalf.
Confirm the current look-back period, response deadlines, and any permissible fee conditions against the current Privacy Rule text, since these specifics are set by regulation and may change over time.
Train workforce members responsible for handling access and disclosure requests so they can recognize an accounting request and route it appropriately within the required time frame.
Check whether applicable state law or the HITECH Act imposes additional requirements beyond the baseline HIPAA accounting obligation, and adjust internal procedures accordingly.