When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting: Critical Disclosure Requirements Explained

When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting featuring HIPAA disclosure records, patient privacy rights, PHI, and compliance requirements.

Healthcare providers process significant volumes of personal patient information on a daily basis.Most of us have heard about HIPAA for its privacy reasons but may not be aware that patients have another right: requesting a log of specific releases of their protected health information (PHI).That is why many professionals and students search for when required, the information provided to the data subject in a HIPAA disclosure accounting.

Table of Contents

Why HIPAA Accounts are Needed In order to foster transparency, patients have a right to be able to learn when their health records have been shared in circumstances where HIPAA rules require organizations to account for all disclosures of health information. Unfortunately, not all disclosures of health information appear on a HIPAA accounting so it’s important to understand when an accounting is required and for what information it needs to include, for both employers in the healthcare industry, compliance officers, students seeking certification and also for the patients they serve. In this resource, we break down what a HIPAA disclosure accounting is, in addition to what requires a patient authorization under HIPAA rules.

What Is a HIPAA Disclosure Accounting?

A HIPAA disclosure accounting a formal written log specifying the particular disclosures a covered entity or its business associates have made concerning an individual’s Protected Health Information (PHI). A HIPAA disclosure accounting does not necessarily capture all internal times in which the medical records were accessed and used.

Its purpose is straightforward:

  • Promote transparency
  • Protect patient privacy
  • Increase organizational accountability
  • Allow patients to understand how their information has been shared

Patients have the legal right to request this information under the HIPAA Privacy Rule, provided the request falls within the applicable accounting period and understand their HIPAA patient privacy rights.

Why HIPAA Requires Disclosure Accounting

Medical records often move beyond the walls of a doctor’s office. Information may be disclosed to:

  • Public health agencies
  • Law enforcement
  • Government oversight agencies
  • Courts
  • Organ procurement organizations
  • Medical examiners
  • Researchers under qualifying circumstances

HIPAA recognizes that patients deserve visibility into many of these disclosures.

Disclosure accounting creates an official record that helps answer questions such as:

  • Who received my information?
  • Why was it disclosed?
  • When did it happen?
  • Was the disclosure permitted under HIPAA?

Greater transparency helps foster public confidence in healthcare organizations while supporting compliance with federal privacy laws.

When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting Must Include

One of the most common compliance questions is:

When required, the information provided to the data subject in a HIPAA disclosure accounting must include what?

Under the HIPAA Privacy Rule, an accounting generally includes enough detail for the individual to understand each reportable disclosure.

The information typically includes:

Required InformationPurpose
Date of disclosureShows when PHI was shared
Name of recipientIdentifies who received the information
Recipient’s address (if known)Provides additional identification
Brief description of PHI disclosedExplains what information was shared
Brief statement of purposeExplains why the disclosure occurred
Copy of written request (if applicable)Used when disclosure was requested in writing

These elements allow patients to evaluate whether disclosures were appropriate and consistent with HIPAA requirements.

Understanding Each Required Element

Date of the Disclosure

Each accounting must specify the exact date, and where such date cannot be determined with specificity, provide the approximate date on which the Protected health information was disclosed.By presenting disclosures in chronological order, the timeline helps individuals identify whether a disclosure took place within the requested accounting period.

Identity of the Recipient

The accounting identifies the individual or organization that received the protected health information.

Examples include:

  • State health departments
  • Federal agencies
  • Courts
  • Law enforcement agencies
  • Organ procurement organizations
  • Public health authorities

If available, the recipient’s address is also included to improve identification.

When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting covering HIPAA accounting, disclosure documentation, patient rights, PHI, and healthcare compliance.
Learn When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting by exploring disclosure tracking, patient rights, healthcare compliance, and privacy regulations.

Description of the Information Shared

HIPAA does not require every medical detail to be reproduced.

Instead, the accounting contains a brief description sufficient to explain what information was disclosed.

Examples include:

  • Laboratory test results
  • Immunization records
  • Hospital discharge summary
  • Surgical reports
  • Billing information
  • Demographic information

The description should be clear enough for the patient to understand the nature of the disclosure.

Purpose of the Disclosure

The accounting must also explain why the information was disclosed.

Typical purposes include:

  • Public health reporting
  • Compliance with court orders
  • Health oversight investigations
  • Organ donation coordination
  • Certain law enforcement activities
  • Research authorized under HIPAA

Where a written request initiated the disclosure, the accounting may reference that request instead of providing a detailed explanation.

Which Disclosures Must Be Included?

Not every disclosure of PHI appears in an accounting.

Generally, disclosures that must be tracked include those made for purposes such as:

Public Health Activities

Report Certain Health-Care Providers Certain categories of health care, conditions, injuries, and other public health events are commonly and routinely reported to public health departments, whether or not they are a part of regular treatment, payment, and operations. Such reports usually may be accounted because they fall out of the ordinary course of operations.

Health Oversight Activities

Government agencies responsible for licensing, audits, inspections, investigations, or regulatory oversight may receive protected health information as part of their official duties.

Examples include:

  • Compliance investigations
  • Medicare audits
  • Fraud investigations
  • Professional licensing reviews

Judicial and Administrative Proceedings

Certain disclosures made pursuant to court orders, subpoenas, or lawful administrative proceedings may appear in an accounting when required under HIPAA.

Law Enforcement Purposes

HIPAA permits certain disclosures to law enforcement officials under specific legal circumstances, including:

  • Locating suspects
  • Reporting crimes
  • Identifying deceased individuals
  • Responding to court orders

These disclosures are subject to strict legal standards and may be included in an accounting when applicable.

Research Disclosures

A research organization might obtainPHI under the same exceptions to the rules under HIPAA. Depending on how it’s provided, it may need to be included in the accounting given to an individual.

Organ Procurement and Tissue Donation

Medical information may be disclosed to organizations involved in:

  • Organ donation
  • Tissue donation
  • Eye donation
  • Transplant coordination

HIPAA allows these disclosures while still recognizing a patient’s right to know when qualifying disclosures occur.

Which Disclosures Are Not Included in a HIPAA Disclosure Accounting?

Knowing the exclusions is just as important to you as understanding which disclosures are reportable. One of the biggest misconceptions is that every access or disclosure of PHI will show up in accounting. This is a common misconception.

Treatment, Payment, and Healthcare Operations (TPO)

Perhaps the most significant exclusion involves disclosures made for:

  • Treatment
  • Payment
  • Healthcare operations

A good example of this, when your primary care doctor sends you to a specialist treating you, they don’t need to note this as a HIPAA “HIPAA Disclosure Accounting” document.

Disclosures Made Directly to the Patient

We have no responsibility and cannot be liable in any manner, to anyone in any way, to provide you with medical information which is or will be in your medical record and cannot have you provide medical records, or which I also may provide you with your medical information or any information considered and that also I use and also provide for care. We also do not account for disclosures that are to individual patients in whom they make use of them of information related to those individuals (including by providing them access to my patient records). The information here above will never hold me in any liability.

Disclosures Authorized by the Individual

HIPAA exception to accounting requirement – Covered entities have no duty to account for any “ HIPAA authorization signed in writing” that is valid and includes the protected health information for disclosure to a “third party”.

National Security and Certain Correctional Institution Disclosures

HIPAA also excludes certain disclosures related to:

  • National security activities
  • Intelligence functions
  • Protective services for government officials
  • Certain correctional institution operations

These exclusions recognize specialized legal and public safety considerations.

Limited Data Set Disclosures

Disclosures made when the limited data set has been created in a proper, organized, professional manner with an intended use as part of a research, public health or health care operations effort typically qualify for differing treatment under HIPAA and are usually not added to the general accounting of disclosures.

Special Rules for Multiple Disclosures to the Same Recipient

HIPAA acknowledges that a health care provider, for the same purpose and recipient, might disclose the same kind of data multiple times to the same party. The long accounting may become prohibitively long to read for both the patient and provider.

For recurring disclosures, the HIPAA Privacy Rule allows a simplified approach under specific circumstances. Instead of documenting every occurrence separately, the accounting may include:

  • The date of the initial disclosure made during the accounting period
  • The date of the most recent disclosure
  • The recipient’s name and address
  • A summary of the protected health information that was disclosed
  • The reason for the disclosures
  • The frequency or expected number of disclosures made during that period

This streamlined method keeps the accounting meaningful while reducing unnecessary administrative burden.

How Long Must Organizations Maintain Disclosure Accounting Records?

Retention HIPSAA Rules HIPAA compliance is a complicated and confusing area and HIPAA requirements for the retention of records is just one of the areas that people get wrong. Covered entities must in most cases retain documents concerning disclosures for six years from the date of creation or from the date on which it was last in effect – whichever is later.

Maintaining these records serves several important purposes:

  • Demonstrates compliance during audits
  • Responds to patient requests
  • Supports internal privacy investigations
  • Documents regulatory compliance
  • Helps resolve disputes regarding information disclosures

Organizations that fail to maintain adequate documentation may face compliance issues during investigations by the U.S. Department of Health and Human Services (HHS), making HIPAA compliance requirements essential for healthcare providers.

How Patients Request a HIPAA Disclosure Accounting

Patients aren’t automatically mailed an accounting of disclosures. They have to request it from the healthcare provider or health plan (covered entity) that holds their PHI.

While organizations may have slightly different procedures, the process generally involves:

  1. Submitting a written request.
  2. Verifying the patient’s identity.
  3. Specifying the requested accounting period (within HIPAA limits).
  4. Allowing the covered entity time to prepare the report.

Under HIPAA, individuals are entitled to receive an accounting covering the applicable period permitted by law, subject to the rule’s exclusions and requirements.

When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting guide to HIPAA disclosure requirements, patient information access, privacy safeguards, and compliance.
When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting helps healthcare professionals and patients understand disclosure records, compliance rules, and privacy obligations.

Why Disclosure Accounting Matters for Healthcare Organizations

Disclosure accounting transcends simply being a regulatory requirement; it’s a hallmark of an organization’s dedication to patient privacy, data privacy, and a trusted framework for data handling. When the health and privacy organizations with vast data sets – patient and prescription histories, diagnostic reports, health conditions, imaging data, laboratory results – you are counting on it.

Accurate disclosure accounting helps organizations:

  • Demonstrate accountability
  • Improve transparency
  • Reduce privacy risks
  • Strengthen compliance programs
  • Build patient confidence
  • Prepare for regulatory audits

Organizations that establish clear documentation procedures are generally better equipped to respond quickly to patient requests and compliance reviews.

Common Compliance Mistakes

The disclosure accounting challenge – no facility is immune. It’s not rare for facilities, even seasoned providers to face disclosure accounting accounting difficulties. Some of the most frequent accounting pitfalls found:

Assuming Every Disclosure Must Be Reported

“One of the most frequent errors people make is believing that every instance of using PHI must be in the accounting,” says Brenda. “And yet, most standard uses – for example, uses made in treatment, uses made in payment, and uses made in health care operations – don’t get into the accounting at all.”

Poor Documentation Practices

It can be very difficult to reconstruct disclosure histories if the dates are absent or incomplete, or who the report was submitted to, or how vague the record of disclosure. That poses issues from a compliance point of view, should a patient submit a request for an accounting.

Confusing Access Logs with Disclosure Accountings

The health records will often maintain some sort of record the person who has accessed your patient. This does not take the place of a HIPAA accounting for disclosure. Your health records maintain system logs, while the accounting for disclosures document authorized uses and disclosures of PHI outside the organization that fit the HIPAA accounting requirement.

Overlooking Business Associate Responsibilities

Even though covered entities still need to ensure HIPAA compliance, business associates might still need to create and keep up to date records required for disclosure accounting. Because these parties may not create or handle these records regularly, thorough contracting agreements and consistent communication are critical to ensuring that when these records are required they will be present and available.

Failing to Train Staff

Employees who handle patient information should understand:

  • What constitutes a disclosure
  • Which disclosures require accounting
  • Documentation procedures
  • Response timelines
  • Privacy Rule requirements

Regular privacy training reduces the likelihood of errors and strengthens organizational compliance while supporting broader healthcare compliance and security practices.

Practical Example of a HIPAA Disclosure Accounting

Consider the following scenario:

The patient gets back with a request for an accounting of disclosures a couple of months later that it would be a reasonable time later. So this reportable disease incident then requires the patient’s hospital, because of regulation, to go ahead and report that communicable disease to the state Department of Public Health and the respective state department.

Because this disclosure falls within HIPAA’s accounting requirements, the hospital’s response may include:

Required ElementExample
Date of disclosureMarch 15, 2026
RecipientState Department of Public Health
AddressOfficial agency address, if known
Information disclosedLaboratory confirmation of reportable disease and related demographic information
PurposeMandatory public health reporting under applicable law

This example illustrates the type of information a patient can expect to receive. The accounting provides enough detail to explain what was shared, with whom, when, and for what reason, without reproducing the entire medical record.

Best Practices for Maintaining Accurate Disclosure Accountings

Organizations with effective privacy programs should establish few rules that facilitate more efficient and accurate disclosure accounting.

* Establish Written Privacy Policies. Develop comprehensive written policies identifying reportable disclosures requiring record-keeping, naming those responsible for documented these disclosures and defining procedures for fulfilling requests.

* Utilize Electronic Tracking Mechanisms. Health information technology (HIT) can track qualifying disclosure occurrences so the facility may accurately respond to patient request for an accounting of disclosures.

* Perform Periodic Audits. Conduct regularly audits to ascertain whether an organization is compliantly documenting qualifying disclosure events.

* Require business associate compliance with policies for disclosure record-keeping and dissemination of accounting of disclosure requests to patients in accordance with agreements.

* train all workforce members HIPAA requirements relative to the identification and document of qualified disclosures on an ongoing basis.

* Review and Update Organizational Policies Annually. Hipaa guidelines and best practices should be periodically reviewed, to ensure ongoing compliance on the part of the organizations workforcce.

Why This Requirement Matters Beyond Compliance

Disclosed accounting serves to enforce compliance to the law and build trusting relationships between patients and healthcare organizations. It helps ensure transparency by reassuring a patient about access to, control over, and transparency to personal health data given that they usually have very little insight into the extent to which their protected health information is shared.

Keeping diligent tabs on Disclosure Accounting allows healthcare organizations to go beyond compliance to encourage robust governance, reinforce healthy privacy practices and be ready for any patient or outside scrutiny of HIPAA and patient privacy protocols. Overall, accounting in HIPAA is consistent with another HIPAA aim – protecting individual rights around health data access while facilitating a productive flow of information among authorized organizations.

Conclusion

Understanding when required, the information provided to the data subject in a HIPAA disclosure accounting goes beyond preparing for a compliance exam or meeting a regulatory obligation. It reflects one of HIPAA’s most important principles: giving individuals greater transparency into how their protected health information is shared outside routine healthcare activities.

Accounting for Reportable Disclosures With A Proper Disclosure Accounting Done Well A properly prepared disclosure accounting helps an organization quickly and easily identify each qualified disclosure, what was disclosed, when, to whom, and why each was made, all while HIPAA delineates such reportable disclosures from those routine or permissible disclosures used for treatment, payment and operations a critical balance that allows the concept to be viable without compromising a patient’s rights.

A good practice of documenting these disclosures allows healthcare providers to strengthen their privacy programs and make demonstrating compliance and accountability, and providing some reassurance to their patients about data handling, feasible. And for all, in our world of electronic health records, data exchange and interconnected care, understanding the accounting of disclosures mandated by HIPAA is vital to both protecting patient privacy, and our own peace of mind that such processes support it.

When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting guide to HIPAA disclosure requirements, patient information access, privacy safeguards, and compliance.
When Required, the Information Provided to the Data Subject in a HIPAA Disclosure Accounting explains disclosure requirements, patient privacy rights, and HIPAA compliance responsibilities.

Frequently Asked Questions (FAQs)

1. What is a HIPAA disclosure accounting?

A HIPAA accounting of disclosures is a document that details some of the specific times and purposes for which a covered entity was authorized by the HIPAA Privacy Rule to disclose patient’s protected health information. It will help provide an idea of how and why patient’s protected health information was shared.

2. What information must be included in a HIPAA disclosure accounting?

A disclosure accounting generally includes the date of the disclosure, the recipient’s name (and address if known), a brief description of the PHI disclosed, and the purpose of the disclosure or a copy of the written request that authorized it when applicable.

3. Are disclosures for treatment, payment, and healthcare operations included?

No. Disclosures required to be included in the accounting statement are usually just what’s known as ‘disclosures required by HIPAA’, but usually not for TPO as the disclosures are necessary for the routine operation of the organization to provide care.

4. How long must healthcare organizations keep disclosure accounting records?

HIPAA generally requires covered entities to retain documentation related to disclosure accountings for at least six years from the date the records were created or were last in effect, whichever is later.

5. Can patients request a disclosure accounting at any time?

Yes. Patients have the right to request an accounting of qualifying disclosures by submitting a request to the covered entity. The organization must respond according to HIPAA’s requirements and applicable timeframes.

6. Does a HIPAA disclosure accounting include every time someone viewed my medical record?

No. A disclosure accounting is not the same as an electronic audit log. Audit logs record system access, while disclosure accountings report certain qualifying disclosures of protected health information outside routine internal uses.

7. Why is HIPAA disclosure accounting important?

“It builds trust with the patient, increases transparency and facilitates organizations’ compliance efforts with federal privacy regulations. This approach enables patients to be alerted in a simple yet meaningful way that their protected health information is being shared outside of the provider’s HIPAA Covered Entity, in a manner that is still operationally feasible,” the report explains.