Authorisation For Disclosure Of Protected Health Information Form Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Authorisation For Disclosure Of Protected Health Information Form?

The Authorisation For Disclosure Of Protected Health Information Form is essential in healthcare settings across England and Wales where patient confidentiality must be maintained while facilitating necessary information sharing. This document is required when medical records or health information needs to be shared with third parties, whether for continued care, legal proceedings, insurance purposes, or research. It ensures compliance with UK data protection laws and healthcare regulations while providing a clear audit trail of consent. The form includes specific details about what information can be shared, with whom, for what purpose, and for how long.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Authorisation For Disclosure Of Protected Health Information Form

When you need to share your medical records or health information with third parties in England and Wales, you must complete an Authorisation For Disclosure Of Protected Health Information Form. This legal document protects your privacy rights while enabling healthcare providers to lawfully share your confidential medical data with specified recipients for legitimate purposes.

When do you need this document?

You need this form whenever your healthcare provider must share your medical information with parties outside their direct care team. Common situations include transferring records to a new GP practice or specialist, providing medical evidence for insurance claims or legal proceedings, sharing information with employers for occupational health purposes, or releasing data to family members or legal representatives. The form is also required when healthcare providers need to disclose information to regulatory bodies, for medical research studies, or when changing healthcare systems such as moving from NHS to private care.

Key legal considerations

The form must clearly specify what information can be disclosed, who will receive it, and for what purpose. You have the right to limit the scope of disclosure and can specify certain information to be withheld. The authorisation must include a clear expiry date or event that terminates the permission. Healthcare providers cannot disclose more information than specified in your authorisation, and recipients must use the information only for the stated purpose. You retain the right to withdraw your consent at any time before disclosure occurs. The form should include safeguards ensuring that recipients will protect your information and not share it further without additional authorisation.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, healthcare providers must obtain your explicit consent before disclosing personal health data, except in specific circumstances such as legal obligations or vital interests. The Mental Capacity Act 2005 governs authorisations for patients lacking capacity, requiring decisions to be made in their best interests. The Access to Health Records Act 1990 provides additional rights regarding deceased patients' records. Healthcare providers have a common law duty of confidentiality that can only be breached with valid consent or legal authority. The Health and Social Care Act 2012 sets information governance requirements for NHS organisations, mandating proper consent procedures for data sharing. Your authorisation must meet these legal standards to be valid, and healthcare providers must maintain records of all disclosures made under your consent.

GOVERNING LAW

Applicable law

This Authorisation For Disclosure Of Protected Health Information Form is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: UK General Data Protection Regulation - Primary legislation governing personal data processing and protection in the UK post-Brexit

Data Protection Act 2018: UK's implementation of data protection standards, working alongside UK GDPR to regulate personal data processing

Access to Health Records Act 1990: Legislation providing rights of access to health records of deceased patients and regulating health records management

Mental Capacity Act 2005: Framework for making decisions on behalf of individuals who lack mental capacity to make specific decisions

Health and Social Care Act 2012: Legislation governing the structure and function of the NHS, including information governance requirements

Common Law Duty of Confidentiality: Legal obligation requiring healthcare professionals to protect patient confidentiality and only disclose information with consent or legal justification

Caldicott Principles: Set of principles governing how patient information should be used in healthcare settings and shared with other organizations

NHS Act 2006: Primary legislation establishing the framework for NHS services, including provisions for information handling

GMC Guidance on Confidentiality: Professional guidelines from the General Medical Council on managing patient confidentiality and information disclosure

BMA Guidelines: British Medical Association's professional guidance on medical ethics and information handling

NHS Digital Guidelines: Specific guidance on information governance within the NHS, including technical standards for data protection

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it