Under the California Confidentiality of Medical Information Act (CMIA), patient medical records may not be disclosed without authorization unless disclosure is required for litigation or is required to communicate important medical information to other healthcare providers, insurers, and other interested parties.
Content for a valid authorization includes: The name of the person or entity authorized to make the request (usually the patient) The complete name of the person or entity to receive the protected health information (PHI) A specific description of the information to be used or disclosed, including the dates of service.
(a) Patients may authorize the release of their health care information by completing the CDCR 7385, Authorization for Release of Protected Health Information , to allow a family member or friend to request and receive an update when there is a significant change in the patient 's health care condition.
Release of Information Authorization Under the HIPAA Privacy Rule, when a release of information is intended for purposes other than medical treatment, healthcare operations, or payment, you'll need to sign an authorization for ROI.
(5) A person or entity who is not permitted to receive medical information pursuant to this part and who knowingly and willfully obtains, discloses, or uses medical information without written authorization from the patient shall be liable for a civil penalty not to exceed two hundred fifty thousand dollars ($250,000) ...