Accounting of Disclosures
An accounting of disclosures is a written list that a patient can request showing certain instances where their protected health information (PHI) was shared by a healthcare organization or its business associates. It is one of the individual rights granted under HIPAA, allowing people to learn how some of their health information has been used or released. Not every disclosure is included in this list; only certain categories of disclosures are generally required to be tracked and reported.
Under the HIPAA Privacy Rule, individuals generally have the right to receive, upon request, an accounting of certain disclosures of their protected health information made by a covered entity or its business associates. The accounting is typically a log documenting qualifying disclosures and includes information about those disclosures (such as, in most cases, the date, recipient, and purpose). The right applies to PHI in all forms covered by the Privacy Rule and is distinct from the Security Rule, which governs only ePHI. Notably, the Privacy Rule excludes several categories of disclosures from the accounting requirement, for example, certain disclosures for treatment, payment, and healthcare operations are generally not required to be included, so this term has a specific regulatory scope that differs from a literal 'accounting of all disclosures.' Practitioners should confirm the precise scope, exceptions, applicable time period, and any HITECH Act provisions affecting disclosures against the current regulatory text, and should note that state law may impose additional requirements.
Why it matters
The accounting of disclosures is one of the individual rights that gives HIPAA meaning from the patient's perspective. It provides a mechanism for people to learn how certain instances of their protected health information were shared beyond the routine flow of care, billing, and internal operations. For covered entities and business associates, honoring this right is a compliance obligation under the HIPAA Privacy Rule, and failing to produce a required accounting upon request can expose an organization to scrutiny from HHS OCR.
The practical challenge is that the accounting is not a record of every disclosure. The Privacy Rule carves out several categories, including certain disclosures for treatment, payment, and healthcare operations, that are generally not required to be included. This means organizations must be able to distinguish accountable disclosures from excluded ones and maintain records accordingly. Because patient expectations often differ from the regulatory scope (many assume they will receive a list of every place their data went), clear communication and accurate logging are both important to avoid disputes and to satisfy a request within the applicable time frame.
The requirement also intersects with evolving law. The HITECH Act contemplated changes to disclosure accounting, and state law may impose additional or stricter tracking obligations. Practitioners should confirm the precise scope, exceptions, applicable look-back period, and any HITECH-related provisions against the current regulatory text rather than relying on a general understanding, since these details determine what an organization is actually required to track and produce.
Who it's relevant to
Inside Accounting of Disclosures
Common questions
Answers to the questions practitioners most commonly ask about Accounting of Disclosures.