A patient asks a seemingly simple question: “Who’s received my health data?”

If you can easily answer this question, congratulations! You must be keeping a detailed and accurate accounting of disclosures. But if this question makes your heart race, then you’ve come to the right place.

Most people in HIM know what an accounting of disclosures is: it’s a “paper” trail documenting when protected health information (PHI) has been released or changed hands. In fact, it’s so simple that it can often be easy to forget.

When a patient asks who has received their information and why, you need documented records to back up your answer. Poor documentation can create compliance risks and make it harder to track disclosures accurately.

In this guide, we’ll break down what needs to be in an accounting of disclosures, what’s excluded and how healthcare organizations can build a process that makes tracking HIPAA accounting of disclosures easy and stands up to scrutiny without creating extra administrative headaches.

Keep reading to learn how you can answer this question quickly and confidently in the future.

What Is a HIPAA Accounting of Disclosures?

HIPAA gives patients the right to know how their information is being shared, and you need a reliable way to provide that information when requested.

An accounting of disclosures under HIPAA is essentially a record of certain disclosures of PHI. It gives patients the right to request a report showing when their information was disclosed during the previous six years under circumstances outlined by the HIPAA Privacy Rule.

Why Does HIPAA Require It?

Healthcare teams handle the most sensitive information that can be shared. Giving patients visibility into how that information is disclosed helps reinforce confidence that PHI is being handled responsibly.

HIPAA accounting of disclosures requirements serve several goals:

  • To promote patient trust and transparency
  • To help patients understand how their information is shared
  • To create accountability around disclosure activities
  • To support compliance and audit readiness

In many ways, it’s an extension of a fundamental HIPAA principle: patients should have meaningful visibility into the use and disclosure of their health information.

Which Disclosures Have to be Tracked?

The exact requirements depend on the nature of the disclosure and applicable HIPAA provisions, which is why HIM teams should avoid relying on assumptions or memory when determining what must be documented.

Common examples of PHI disclosures that must be tracked include:

  • Public health reporting activities
  • Disclosures required by law
  • Certain law enforcement requests
  • Health oversight activities, such as audits or investigations that are not within the definition of health care operations
  • Certain research-related disclosures
  • Other non-routine disclosures that occur outside standard operational workflows

Which Disclosures Are Generally Excluded?

Not every disclosure of PHI needs to appear on an accounting of disclosures. Routine disclosures that serve the purpose of treatment, payment and healthcare operations (TPO) are acceptable exclusions. The intent of these exclusions is to ensure that health data is able to move quickly in use cases that support patient treatment and outcomes.

Common exclusions from a HIPAA accounting of disclosures include:

  • Treatment-related disclosures
  • Payment-related disclosures
  • Healthcare operations-related disclosures
  • Disclosures made directly to the patient
  • Disclosures made with a valid patient authorization
  • Certain incidental disclosures
  • Certain limited data set disclosures

What Information Should a HIPAA Accounting of Disclosures Include?

Generally, a HIPAA accounting of disclosures should include:

  • The date of the disclosure
  • The recipient’s name (and address, if known)
  • A brief description of the information disclosed
  • The purpose of the disclosure and/or a copy of the written request for certain legally required disclosures

These details may seem straightforward in the moment, but the real challenge comes when someone needs to reconstruct a disclosure that occurred three years ago. Incomplete documentation can create significant headaches when patients request an accounting months (or years!) after the original disclosure occurred.

Moral of the story? Future-you will appreciate every detail documented today!

Keeping Track of Disclosures: Common Challenges

If a HIPAA accounting of disclosures sounds simple on paper, that’s because paper rarely reflects reality.

Disclosures Are Tracked in Multiple Places

In many organizations, disclosure information lives across numerous systems and departments, including:

  • EHR notes
  • Email chains
  • Department spreadsheets
  • Paper documentation

When information is spread across multiple locations, compiling an accurate accounting can become a time-consuming exercise.

Decentralized Processes

Disclosure-related activities often touch multiple teams, from HIM departments, compliance offices and legal teams to risk management and clinical departments. Without clear ownership, documentation practices can vary significantly across the organization.

Best Practices for Maintaining a Defensible Process

When it comes to HIPAA accounting of disclosures, the best process is a reliable one that serves as a foundation for your release of information documentation standards.

A defensible process is one that can withstand patient questions, compliance reviews and audits because it follows established procedures rather than relying on memory or individual interpretation.

1. Create Clear Policies

Create written policies that outline:

  1. Which disclosures require documentation
  2. What information must be recorded
  3. Who is responsible for tracking disclosures
  4. How requests for an accounting will be handled

The more ambiguity that exists, the more likely teams are to interpret requirements differently. Clear policies help ensure everyone is working from the same playbook, whether they’re in HIM, compliance, legal or clinical operations.

2. Centralize Documentation

Disclosures often leave breadcrumbs across multiple systems, like EHR notes, email chains, spreadsheets and paper records.

The more places information is stored, the harder it becomes to reconstruct an accurate accounting later. Whenever possible, maintain a centralized source of truth that captures disclosure activity in a consistent format.

A centralized approach can help:

  • Reduce duplicate recordkeeping
  • Minimize conflicting information
  • Improve reporting accuracy
  • Shorten response times when requests arise

3. Conduct Periodic Reviews

Even well-designed processes can crumble over time. Regular reviews help organizations verify that disclosures are being documented appropriately and that documentation remains complete and accurate. These reviews can also uncover process gaps before they become compliance concerns.

Consider periodically evaluating:

  • Whether disclosures are being tracked consistently
  • Documentation completeness
  • Process adherence across departments
  • Opportunities to improve efficiency or reduce manual steps

Think of it as preventive maintenance for your compliance program. It’s much easier to fix small issues during a routine review than during an audit or patient inquiry.

4. Train Staff Regularly

Policies are only effective if people understand them.

Because accounting of disclosures requirements can be nuanced, ongoing training is essential. Staff should know not only how to document disclosures, but also how to recognize when documentation is required in the first place.

Training should focus on:

  • Common disclosure scenarios
  • Documentation expectations
  • Department-specific responsibilities
  • Changes to processes or regulations

The goal is to create confidence and consistency across teams, reducing the likelihood that important disclosures fall through the cracks. And remember, most people need to hear information many times before they commit it to memory. So don’t just check the box once on training and call it good. Ensure you have a regular cadence of training refreshers backed by documentation that staff can use as a reference.

5. Don’t Rely on a Single Person

Every HIM team has a version of this: “Oh, documenting disclosures is this person’s job – they’ll handle it!” And that person probably does handle it, exceptionally, right up until they have a backlog or are out on a well-earned vacation. Suddenly no one can find the disclosures, and the only record is a color-coded spreadsheet that makes sense to exactly one person.

When your accounting of disclosures lives in a single person’s head (or hard drive), you don’t have a process. A defensible process doesn’t depend on any one individual being available, remembering the details or decoding their own shorthand.

To keep institutional knowledge from walking out the door, aim to:

  • Document the how, not just the what, so anyone can step in and pick up where the last person left off
  • Cross-train at least one backup on disclosure tracking and reporting
  • Store disclosure records in a shared, centralized system rather than a personal spreadsheet or inbox
  • Use consistent, plain-language labels so documentation makes sense to everyone

How Greater Visibility Supports HIPAA Compliance

Effective disclosure tracking is about creating a process that allows organizations to quickly understand:

  • What was disclosed
  • To whom
  • Why it was disclosed/under what authority
  • And when the disclosure occurred

Organizations that centralize release of information workflows often find it easier to maintain a complete and defensible accounting trail over time.

This focus on transparency is one of the reasons HealthMark’s MedRelease platform includes accounting of disclosures and reporting capabilities. The goal is to provide visibility into disclosure activity and make relevant information easier to access when needed, rather than requiring teams to piece together information from multiple systems.

The Solution? Easy, Transparent Processes

Accounting of disclosures may not be the most talked-about area of HIPAA compliance, but it’s an important one.

When healthcare organizations establish clear workflows, maintain thorough documentation and build transparency into everyday operations, responding to disclosure requests feels less like putting a puzzle together with pieces missing and more like opening a filing cabinet with everything in the right place.

The key is knowing what needs to be included and building a robust documentation process for disclosures, so the work is practically done for you as part of your existing workflows. Because when someone asks where and when their protected health information has been shared, the best answer is never: “Let me check six different spreadsheets and get back to you!”

Want more practical compliance insights? Subscribe to the HealthMark blog for expert guidance on HIPAA compliance and release of information best practices.

Sources:

  1. HIPAA Privacy Rule. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
  2. 45 C.F.R. § 164.528 – Accounting of Disclosures of Protected Health Information. Electronic Code of Federal Regulations (eCFR). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.528
  3. Right to an Accounting of Disclosures (FAQs). U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/faq/right-to-an-accounting-of-disclosures/index.html

Where do you want to start?

Tell us a little bit about yourself, and we’ll match you with the right expert to help you optimize your patient information.