Revocation of Authorization
Revocation of authorization is the right of an individual to take back permission they previously gave for their protected health information to be used or shared. Under the HIPAA Privacy Rule, a person can generally do this at any time, but the revocation must be put in writing. Once revoked, the covered entity should stop the uses and disclosures that relied on that authorization, though certain actions already taken in reliance on it may not be reversible.
Under the HIPAA Privacy Rule, revocation of authorization refers to an individual's right to withdraw, in writing and generally at any time, an authorization they previously granted for specific uses or disclosures of protected health information (PHI). The revocation is subject to defined limitations: it is typically not effective to the extent that the covered entity has already acted in reliance on the authorization, and other exceptions may apply as set out in the applicable regulatory text. This right pertains to the Privacy Rule's authorization requirements and is a distinct concept from consent or the notice of privacy practices, though revocation language is commonly addressed within an entity's authorization and notice documentation. Practitioners should verify the precise conditions, exceptions, and any procedural requirements against the current regulation, and note that state law may impose additional requirements beyond HIPAA.
Why it matters
The right to revoke an authorization is a core expression of individual control over protected health information under the HIPAA Privacy Rule. When a person grants authorization for a specific use or disclosure of their PHI, that permission is not permanent; the Privacy Rule generally allows individuals to withdraw it at any time, provided the revocation is put in writing. For covered entities, honoring revocations promptly is both a compliance obligation and a trust matter, because failing to stop uses or disclosures that relied on a revoked authorization can expose the entity to complaints and enforcement scrutiny from HHS OCR.
The practical significance lies in the timing and the limits of revocation. A revocation does not undo actions a covered entity has already taken in reliance on the authorization before the revocation was received. This means the effectiveness of a revocation is forward-looking in most cases, and organizations need clear processes to identify when a valid written revocation has arrived and to halt further reliance on the authorization from that point. Ambiguity or delay in this process can lead to uses or disclosures that the individual no longer permits.
Revocation is also distinct from related concepts such as consent or the notice of privacy practices, and conflating them can create compliance gaps. Because state law may impose additional or more stringent requirements, and because the precise exceptions are set out in the regulatory text, entities should treat revocation handling as an area requiring documented procedures and periodic verification against current guidance rather than assuming a single generic workflow satisfies every obligation.
Who it's relevant to
Inside Revocation of Authorization
Common questions
Answers to the questions practitioners most commonly ask about Revocation of Authorization.