Third-Party Directive
A third-party directive is a request an individual makes to a covered entity, under HIPAA's individual right of access, asking that a copy of their protected health information (PHI) be sent to a person or organization they choose. Unlike a standard authorization, this type of directive is generally tied to the individual's own access right rather than being a separate consent for the covered entity's own uses of the data. Whether and how a covered entity must comply can depend on the format of the records and current regulatory guidance, which readers should verify.
Under the HIPAA Privacy Rule's individual right of access, a third-party directive is an individual's signed, written request directing a covered entity to transmit a copy of PHI held in a designated record set to a third party the individual designates. As described in the evidence, such a directive does not require a valid HIPAA authorization, and covered entities that insist an individual present a valid authorization instead of honoring the access-based directive may be applying an incorrect standard. The scope of the obligation has been shaped by litigation and modified guidance; in particular, covered entities are generally not obligated to transmit to third parties PHI that is not maintained in electronic form or is otherwise outside the modified requirements. This term is distinct from a Privacy Rule authorization, which may permit uses and disclosures by the covered entity or by a third party for purposes beyond the individual's right of access. Practitioners should confirm the current requirements, applicable formats, and any fee limitations against the current regulatory text and HHS OCR guidance, and note that state law may impose additional requirements.
Why it matters
The third-party directive sits at the intersection of two provisions that are easy to confuse: the individual right of access and the standard HIPAA authorization. When an individual exercises their access right to have a copy of their PHI sent to a person or organization they choose, covered entities generally may not demand a full HIPAA authorization as a precondition. Treating a third-party directive as if it were an authorization, or refusing to honor it, risks applying an incorrect standard and may expose the covered entity to complaints and enforcement scrutiny by HHS OCR. Because the access right is one of the most frequently exercised individual rights, getting the intake process right has practical, day-to-day consequences.
The scope of this obligation has been shaped by litigation and by modified guidance, which is why practitioners need to track the current state of the rules rather than relying on older summaries. In particular, covered entities are generally not obligated to transmit to third parties PHI that is not maintained in electronic form or is otherwise outside the modified requirements. This distinction between electronic and non-electronic records materially affects what a covered entity must do in response to a directive, and misjudging it can lead either to over-disclosure or to improper denial of a legitimate request.
Because fee limitations, applicable formats, and the precise boundaries of the obligation have shifted over time, readers should verify the current requirements against the current regulatory text and HHS OCR guidance. State law may also impose additional requirements beyond HIPAA, and a compliant response under federal rules does not necessarily satisfy every applicable state standard.
Who it's relevant to
Inside Third-Party Directive
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Directive.