All resources
Core documents
2 min readReviewed July 2026

HIPAA Authorization

Why your healthcare agent may be stonewalled without one, and what a valid authorization must contain.

Key facts

  • The HIPAA Privacy Rule restricts what providers may disclose; a signed authorization (45 CFR § 164.508) unlocks it for named people.
  • A HIPAA authorization grants access to information only — it does not give anyone decision-making power.
  • It complements the healthcare directive: your agent needs records to make informed decisions.

The problem it solves

Federal privacy regulations under HIPAA limit what doctors, hospitals, and insurers may disclose about you. A cautious provider may refuse to share information even with your spouse or adult children. A standalone HIPAA authorization — governed by 45 CFR § 164.508 — instructs providers that the people you name may receive your protected health information.

What a valid authorization contains

The regulation requires specific core elements: a description of the information to be disclosed, who may disclose it, who may receive it, an expiration date or event, your signature and date, and notice of your right to revoke. Estate plans typically use a broad authorization naming the healthcare agent, alternates, and close family, with no early expiration.

Keep the distinction clear: the healthcare directive says who decides; the HIPAA authorization says who may be told. Your healthcare agent should appear in both, so they can get the information needed to exercise the authority they hold.

References

This guide is educational only and is not legal, tax, or investment advice. Laws vary by state and change over time; confirm current figures with the linked primary sources or a licensed professional in your state.

Related guides

Put it into practice

Elephant turns these documents into a guided, state-aware workflow — drafted, executed, and stored in one encrypted vault.

Get started