Compound Authorization
A compound authorization refers to a HIPAA authorization form that is combined with another document, such as another consent or authorization. Under the HIPAA Privacy Rule, a covered entity generally may not combine an authorization to use or disclose protected health information (PHI) with other documents, subject to limited exceptions. This restriction is meant to keep the individual's permission clear and to protect the informed nature of their consent.
Under the HIPAA Privacy Rule (generally at 45 CFR 164.508(b)), an authorization for the use or disclosure of protected health information generally may not be combined with any other document to create a compound authorization. Certain limited exceptions apply, such as combining research-related authorizations with other permissions in specified circumstances; practitioners should verify the specific conditions and any prohibitions against the current regulatory text. The prohibition applies to covered entities' handling of PHI and is distinct from the required core elements of a valid authorization itself. Note that this term has a specific regulatory meaning under the Privacy Rule and that state law, the HITECH Act, or other frameworks may impose additional requirements beyond HIPAA; readers should confirm the exact scope and exceptions against the applicable CFR provisions.
Why it matters
The prohibition on compound authorizations exists to protect the informed and voluntary nature of an individual's consent to the use or disclosure of their protected health information (PHI). When an authorization is bundled with other documents, individuals may not fully understand what they are permitting or may feel that granting one permission is a condition of receiving another. By generally keeping the authorization as a standalone document, the HIPAA Privacy Rule aims to ensure the individual's decision is clear and deliberate.
For covered entities, getting this wrong can undermine the validity of an authorization entirely. If a covered entity improperly combines an authorization with another document outside the limited permitted circumstances, it risks relying on a defective authorization to use or disclose PHI, which can create compliance exposure under the Privacy Rule. Notably, some commentary, including a 2004 letter referenced in HHS materials, has argued that the compound authorization requirements can elevate form over substance and confuse subjects rather than clarify their consent, which illustrates that even well-intentioned form design must be reconciled with the specific regulatory conditions.
Because this is a specific regulatory concept, practitioners should not treat all bundled paperwork as prohibited or all separation as required; the exceptions matter. Readers should confirm the precise scope and applicable exceptions against the current regulatory text, and remember that state law, the HITECH Act, or other frameworks may impose additional requirements beyond HIPAA.
Who it's relevant to
Inside Compound Authorization
Common questions
Answers to the questions practitioners most commonly ask about Compound Authorization.