Skip to main content
Category: Individual Rights

Third-Party Directive

Also known as: Third-Party Access Direction, Third-Party Access Direction for HIPAA Record Copies
Simply put

A third-party directive is a request an individual makes to a covered entity, under HIPAA's individual right of access, asking that a copy of their protected health information (PHI) be sent to a person or organization they choose. Unlike a standard authorization, this type of directive is generally tied to the individual's own access right rather than being a separate consent for the covered entity's own uses of the data. Whether and how a covered entity must comply can depend on the format of the records and current regulatory guidance, which readers should verify.

Formal definition

Under the HIPAA Privacy Rule's individual right of access, a third-party directive is an individual's signed, written request directing a covered entity to transmit a copy of PHI held in a designated record set to a third party the individual designates. As described in the evidence, such a directive does not require a valid HIPAA authorization, and covered entities that insist an individual present a valid authorization instead of honoring the access-based directive may be applying an incorrect standard. The scope of the obligation has been shaped by litigation and modified guidance; in particular, covered entities are generally not obligated to transmit to third parties PHI that is not maintained in electronic form or is otherwise outside the modified requirements. This term is distinct from a Privacy Rule authorization, which may permit uses and disclosures by the covered entity or by a third party for purposes beyond the individual's right of access. Practitioners should confirm the current requirements, applicable formats, and any fee limitations against the current regulatory text and HHS OCR guidance, and note that state law may impose additional requirements.

Why it matters

The third-party directive sits at the intersection of two provisions that are easy to confuse: the individual right of access and the standard HIPAA authorization. When an individual exercises their access right to have a copy of their PHI sent to a person or organization they choose, covered entities generally may not demand a full HIPAA authorization as a precondition. Treating a third-party directive as if it were an authorization, or refusing to honor it, risks applying an incorrect standard and may expose the covered entity to complaints and enforcement scrutiny by HHS OCR. Because the access right is one of the most frequently exercised individual rights, getting the intake process right has practical, day-to-day consequences.

The scope of this obligation has been shaped by litigation and by modified guidance, which is why practitioners need to track the current state of the rules rather than relying on older summaries. In particular, covered entities are generally not obligated to transmit to third parties PHI that is not maintained in electronic form or is otherwise outside the modified requirements. This distinction between electronic and non-electronic records materially affects what a covered entity must do in response to a directive, and misjudging it can lead either to over-disclosure or to improper denial of a legitimate request.

Because fee limitations, applicable formats, and the precise boundaries of the obligation have shifted over time, readers should verify the current requirements against the current regulatory text and HHS OCR guidance. State law may also impose additional requirements beyond HIPAA, and a compliant response under federal rules does not necessarily satisfy every applicable state standard.

Who it's relevant to

Privacy Officers and HIM Professionals
Those managing release-of-information and records request workflows need to distinguish an access-based third-party directive from a standard HIPAA authorization, since demanding an authorization when a directive suffices can misapply the standard. They should also account for whether the requested PHI is maintained in electronic form, because that affects the obligation to transmit to third parties.
Compliance and Legal Teams
Because the scope of the third-party directive obligation has been shaped by litigation and modified guidance, compliance and legal staff should monitor the current requirements, applicable formats, and any fee limitations against the current regulatory text and HHS OCR guidance, and consider whether state law imposes additional requirements beyond HIPAA.
Individuals Exercising Their Right of Access
Patients and their representatives can direct a covered entity to send a copy of their PHI to a person or organization they choose without providing a separate HIPAA authorization. However, the covered entity is generally not obligated to transmit records that are not maintained in electronic form or are otherwise outside the modified requirements.
Covered Entity Intake and Training Staff
Front-line staff who receive record requests should be trained to recognize a third-party directive so they do not improperly reject it or require an authorization. Because rules and fee limitations change over time, training materials should be checked against current HHS OCR guidance.

Inside Third-Party Directive

Individual's Right Basis
A third-party directive arises under the HIPAA Privacy Rule's individual access right, which generally permits an individual to direct a covered entity to transmit a copy of their protected health information (PHI) to a designated third party rather than to the individual directly.
Written and Signed Request
The directive typically must be in writing, signed by the individual, and clearly identify the designated recipient and the location or method for sending the PHI. Covered entities generally rely on this documentation to verify the individual's intent.
Designated Recipient
The third party named by the individual to receive the PHI, which may be another person or an entity that is not itself a covered entity or business associate. The directive channels disclosure to that recipient at the individual's instruction.
Scope Limited to Designated Record Set
The directive generally applies to PHI maintained in the covered entity's designated record set, consistent with the underlying access right, rather than to all information the entity may hold.
Distinction from Authorization
A third-party directive is grounded in the access right and differs from a HIPAA authorization for disclosure, though the two can overlap. The specific requirements, permitted fees, and applicability have been subject to regulatory and judicial developments, and readers should verify current HHS OCR guidance and the applicable regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Directive.

Does a third-party directive mean a covered entity has to disclose PHI to any vendor a patient names, no questions asked?
Not exactly. Under the HIPAA Privacy Rule's access right, an individual may direct a covered entity to transmit a copy of PHI in a designated record set to a third party the individual chooses. However, the directive must generally be in writing, signed by the individual, and clearly identify the designated person or entity and where to send the information. The covered entity is still permitted to take reasonable steps to verify the identity of the requesting individual and to confirm that the request meets these requirements. This is a distinct mechanism from a HIPAA authorization, which serves broader disclosure purposes. Readers should verify the specific procedural requirements against the current regulatory text.
If a patient directs PHI to an app or vendor, does that make the vendor a business associate subject to HIPAA?
Generally, no. When an individual exercises the right to direct their PHI to a third party of their choosing, the recipient does not automatically become a business associate simply by receiving the information at the individual's request. HIPAA obligations attach through defined relationships, typically a business associate relationship formed to perform functions on behalf of a covered entity. An app or vendor selected by the individual, acting at the individual's direction rather than on behalf of the covered entity, may fall outside HIPAA's direct reach, though other laws such as state privacy statutes or other federal frameworks may still apply. Each arrangement should be assessed against its specific facts and current guidance.
What information should a covered entity require in a valid third-party directive?
In most cases, a directive should be in writing, signed by the individual, clearly identify the PHI or records requested from the designated record set, and specifically name the third-party recipient along with a delivery destination such as an address or secure transmission method. Establishing a standard form or intake process can help staff confirm that these elements are present. Because specific requirements can be nuanced, covered entities should confirm the elements against the current Privacy Rule access provisions and any applicable OCR guidance.
How should a covered entity verify the identity of the individual submitting a directive?
The Privacy Rule generally permits a covered entity to apply reasonable verification procedures before acting on a request, provided those procedures do not create unreasonable barriers to the individual exercising their access right. Typical approaches include confirming identifying details on file or requiring a signature that can be checked against records. The verification should be proportionate and should not be used to unduly delay or obstruct a legitimate directive. Organizations should document their verification process and align it with current regulatory expectations.
Are there limits on what a covered entity may charge when fulfilling a third-party directive?
The Privacy Rule addresses permissible fees in connection with providing individuals access to their PHI, and fee limitations have been the subject of regulatory guidance and litigation over time. Because the treatment of fees for directing copies to third parties has evolved, covered entities should not assume a fixed permissible amount and should confirm the current fee rules and any applicable OCR guidance before charging. Overcharging can raise compliance concerns, so consulting current authority is advisable.
How does a third-party directive interact with the transmission and delivery of PHI once it leaves the covered entity?
When PHI is transmitted to a third party at the individual's direction, the covered entity should still apply appropriate safeguards during transmission consistent with the Security Rule for any ePHI, such as reasonable and appropriate protection while the information is under its control. Once the information has been delivered to the individual's chosen recipient as directed, the covered entity's HIPAA obligations for that data generally do not extend to how the recipient subsequently handles it, unless a separate covered relationship applies. Organizations should document delivery and confirm transmission safeguards against the applicable Security Rule requirements.

Common misconceptions

A third-party directive is the same thing as a HIPAA authorization.
While both can result in disclosure to a third party, a directive is generally exercised under the individual's right of access, whereas an authorization is a separate mechanism with its own required elements. The requirements, permitted fees, and enforceability of directives have been affected by regulatory and judicial developments, so practitioners should confirm the current framework against HHS OCR guidance.
The designated third-party recipient becomes bound by HIPAA once it receives the PHI.
HIPAA obligations attach through defined relationships such as covered entity and business associate status. A third party designated by an individual is not automatically a covered entity or business associate merely by receiving PHI at the individual's direction, though other laws may apply to that recipient's handling of the data.
A covered entity may deny a third-party directive if it disagrees with sending PHI to that recipient.
The directive reflects the individual's choice under their access right. Covered entities generally must honor a valid directive, subject to the same limited grounds for denial and verification steps that apply to the access right itself, and should reference current regulatory text for permissible exceptions.

Best practices

Require third-party directives in writing, signed by the individual, and clearly identifying the designated recipient and delivery method before transmitting PHI.
Verify the identity of the requesting individual using reasonable procedures consistent with the access right, while avoiding imposing barriers that unreasonably delay the disclosure.
Establish internal policies distinguishing a right-of-access third-party directive from a HIPAA authorization so staff apply the correct process and fee limitations.
Limit the disclosure to the PHI within the designated record set that the individual has directed, and document the request and the resulting disclosure.
Monitor current HHS OCR guidance and applicable regulatory text, since directive requirements, permitted fees, and scope have been subject to regulatory and judicial change.
Confirm whether state law or other frameworks impose additional requirements on directing or transmitting PHI to third parties beyond the HIPAA baseline.