Skip to main content
Category: Individual Rights

Revocation of Authorization

Also known as: Authorization Revocation, Withdrawal of Authorization
Simply put

Revocation of authorization is the right of an individual to take back permission they previously gave for their protected health information to be used or shared. Under the HIPAA Privacy Rule, a person can generally do this at any time, but the revocation must be put in writing. Once revoked, the covered entity should stop the uses and disclosures that relied on that authorization, though certain actions already taken in reliance on it may not be reversible.

Formal definition

Under the HIPAA Privacy Rule, revocation of authorization refers to an individual's right to withdraw, in writing and generally at any time, an authorization they previously granted for specific uses or disclosures of protected health information (PHI). The revocation is subject to defined limitations: it is typically not effective to the extent that the covered entity has already acted in reliance on the authorization, and other exceptions may apply as set out in the applicable regulatory text. This right pertains to the Privacy Rule's authorization requirements and is a distinct concept from consent or the notice of privacy practices, though revocation language is commonly addressed within an entity's authorization and notice documentation. Practitioners should verify the precise conditions, exceptions, and any procedural requirements against the current regulation, and note that state law may impose additional requirements beyond HIPAA.

Why it matters

The right to revoke an authorization is a core expression of individual control over protected health information under the HIPAA Privacy Rule. When a person grants authorization for a specific use or disclosure of their PHI, that permission is not permanent; the Privacy Rule generally allows individuals to withdraw it at any time, provided the revocation is put in writing. For covered entities, honoring revocations promptly is both a compliance obligation and a trust matter, because failing to stop uses or disclosures that relied on a revoked authorization can expose the entity to complaints and enforcement scrutiny from HHS OCR.

The practical significance lies in the timing and the limits of revocation. A revocation does not undo actions a covered entity has already taken in reliance on the authorization before the revocation was received. This means the effectiveness of a revocation is forward-looking in most cases, and organizations need clear processes to identify when a valid written revocation has arrived and to halt further reliance on the authorization from that point. Ambiguity or delay in this process can lead to uses or disclosures that the individual no longer permits.

Revocation is also distinct from related concepts such as consent or the notice of privacy practices, and conflating them can create compliance gaps. Because state law may impose additional or more stringent requirements, and because the precise exceptions are set out in the regulatory text, entities should treat revocation handling as an area requiring documented procedures and periodic verification against current guidance rather than assuming a single generic workflow satisfies every obligation.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for establishing and maintaining the processes that receive, validate, and act on written revocations. They should ensure that authorization and notice documentation clearly describes how individuals can revoke, that revocations are logged and honored promptly, and that staff understand the reliance limitation so that already-completed disclosures are handled appropriately. They should also confirm procedures against current regulatory text and applicable state law.
Compliance and Legal Teams
Compliance and legal professionals need to distinguish revocation of authorization from consent and from the notice of privacy practices, since these are separate concepts with separate obligations. They should confirm the precise exceptions and procedural requirements in the current regulation and assess whether state law imposes additional requirements beyond HIPAA when advising on revocation handling.
Health Information Management and Front-Line Staff
Staff who process disclosures and manage patient records are often the first to receive a written revocation. They need clear guidance on recognizing a valid revocation, stopping further reliance on the revoked authorization from the point of receipt, and understanding that actions already taken before the revocation may not be reversible.
Patients and Individuals
Individuals who have previously authorized uses or disclosures of their PHI benefit from understanding that they generally retain the right to revoke that authorization in writing at any time. They should also understand that revocation is forward-looking in most cases and typically does not reverse disclosures a covered entity already made in reliance on the authorization.

Inside Revocation of Authorization

Right to Revoke
Under the HIPAA Privacy Rule, an individual who has signed a valid authorization for the use or disclosure of their PHI generally has the right to revoke that authorization at any time. This right and the process for exercising it must be described in the authorization document itself.
Written Revocation Requirement
Revocation of an authorization must generally be made in writing. The specific mechanics of how a covered entity accepts and processes a written revocation should be defined in its policies; practitioners should verify format and submission requirements against the current regulatory text.
Exception for Prior Reliance
A revocation generally does not apply to the extent that a covered entity has already taken action in reliance on the authorization before the revocation was received. In other words, revocation is prospective and does not undo uses or disclosures already made in good-faith reliance.
Exception for Obtaining Coverage
Where an authorization was obtained as a condition of obtaining insurance coverage, other law may permit the insurer to contest a claim or the policy, which can limit the practical effect of a revocation. Readers should confirm the precise scope of this exception against current regulatory guidance and applicable state law.
Documentation of the Revocation
Covered entities are generally expected to retain revocation documentation consistent with the Privacy Rule's recordkeeping obligations, so that the change in authorization status is traceable and enforceable within their PHI handling processes.
Scope Limitation to Authorizations
Revocation applies to authorizations for uses and disclosures that require them. It does not govern uses and disclosures that the Privacy Rule permits without authorization, such as certain treatment, payment, and health care operations activities, which fall outside the revocation mechanism.

Common questions

Answers to the questions practitioners most commonly ask about Revocation of Authorization.

Does revoking a HIPAA authorization undo disclosures that already happened?
No. A revocation generally operates prospectively, meaning it stops future uses and disclosures that would have relied on the authorization. It does not reach back to invalidate or reverse disclosures a covered entity already made in reliance on the authorization before it received the revocation. This is a common point of confusion because individuals sometimes expect revocation to retract information that has already left the covered entity's control. The Privacy Rule recognizes an exception for actions taken in reliance on the authorization prior to revocation. You should verify the precise scope of these provisions against the current regulatory text.
Can a patient revoke an authorization at any time for any reason?
As a general matter, an individual has the right to revoke an authorization, but that right is subject to exceptions defined in the Privacy Rule. Notably, revocation typically does not apply to the extent the covered entity has already acted in reliance on the authorization, and there are limited situations, such as where the authorization was obtained as a condition of obtaining insurance coverage, where other law provides the insurer with a right to contest a claim. So while the right to revoke is broad, it is not absolute. Readers should confirm the current exceptions against the applicable regulatory text, as the specifics matter case by case.
How should an individual submit a revocation, and can we require it in writing?
The Privacy Rule generally requires that a revocation be in writing. The authorization form itself must describe the individual's right to revoke and how to exercise it, so your process should be consistent with what you stated on the form. Many covered entities designate a specific point of contact or method for submitting revocations to ensure they are received and acted upon promptly. Confirm the specific writing and process requirements against the current regulatory text, and note that state law may impose additional expectations.
What is the practical difference between the effective time of a revocation and prior reliance?
Operationally, the revocation takes effect when the covered entity receives it, and obligations to stop relying on the authorization attach from that point forward. Anything the entity already did in reliance before receipt generally remains permissible under the reliance exception. This makes documenting the date and time of receipt important, because that receipt point is what separates permissible prior reliance from uses that must now cease. Your internal procedures should capture receipt dates so staff can determine what was done before versus after.
How should we document a revocation once we receive it?
As a practical matter, covered entities typically retain the written revocation, record the date it was received, and link it to the original authorization and the individual's records so that staff can identify that the authorization is no longer a valid basis for further use or disclosure. Documentation supports demonstrating that the entity acted appropriately on the revocation. Because HIPAA imposes general documentation and retention obligations, and because these can interact with state law, confirm retention periods and formats against current guidance and applicable state requirements.
How do we make sure downstream recipients and systems stop relying on a revoked authorization?
In practice, once a valid revocation is received, the covered entity should update its internal systems and notify relevant workforce members or functions so that no further uses or disclosures are made in reliance on that authorization. Where information had been shared with others, keep in mind that HIPAA obligations attach through defined relationships, so any duty a business associate has to act on a revocation would generally flow through the business associate agreement rather than from HIPAA directly regulating every recipient. Coordinate with your privacy officer on how notifications propagate, and verify the boundaries of these obligations against the current regulatory text.

Common misconceptions

Revoking an authorization erases or reverses PHI that has already been disclosed.
Revocation is generally prospective. It does not affect uses or disclosures a covered entity already made in reliance on the authorization before the revocation was received; those actions stand.
An individual can revoke an authorization verbally, for example by a phone call.
Revocation must generally be in writing. A verbal statement typically does not constitute a valid revocation, though practitioners should confirm their organization's accepted process and the current regulatory text.
Once an authorization is revoked, the covered entity can no longer use or disclose any of the individual's PHI.
Revocation only affects the specific uses and disclosures that required the authorization. Uses and disclosures the Privacy Rule permits without authorization, such as certain treatment, payment, and operations activities, are not blocked by a revocation.

Best practices

Include a clear, plain-language statement of the individual's right to revoke and the process for doing so directly within the authorization form, as generally required by the Privacy Rule.
Establish a documented written-revocation intake process, specifying where revocations are submitted, who processes them, and how quickly they take effect, and verify these requirements against the current regulatory text.
Retain revocation documentation alongside the original authorization, consistent with the Privacy Rule's recordkeeping obligations, so authorization status remains traceable.
Train workforce members to recognize that revocation is prospective and does not undo prior good-faith reliance, so they do not attempt to reverse completed disclosures or misstate the effect to individuals.
Clearly distinguish authorization-based uses and disclosures from those the Privacy Rule permits without authorization, so revocations are applied to the correct scope and not over- or under-enforced.
Review the prior-reliance and insurance-coverage exceptions, and confirm whether applicable state law imposes additional revocation requirements beyond HIPAA before finalizing internal policies.