Authorisation To Use And Disclose Protected Health Information Form Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Authorisation To Use And Disclose Protected Health Information Form?

The Authorization To Use And Disclose Protected Health Information Form is a crucial document required under English and Welsh law when healthcare providers need to share patient information beyond direct care purposes. This form ensures compliance with the UK Data Protection Act 2018, UK GDPR, and healthcare-specific regulations. It should be used whenever protected health information needs to be shared with third parties, such as for research, insurance purposes, or with other healthcare providers outside the direct care team. The form includes specific details about what information can be shared, the duration of the authorization, and the intended recipients, while protecting patients' privacy rights.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Authorisation To Use And Disclose Protected Health Information Form

You need an Authorisation To Use And Disclose Protected Health Information Form when your healthcare provider must share your medical information with third parties beyond your direct care team. Under England and Wales law, this document serves as your formal consent mechanism, ensuring compliance with the UK Data Protection Act 2018 and UK GDPR while protecting your privacy rights and giving you control over how your sensitive health data is used.

When do you need this document?

You'll encounter this form in various healthcare scenarios where information sharing extends beyond routine care. Medical research participation requires your explicit authorization for researchers to access relevant health records. Insurance claims often need detailed medical information to process applications or assess coverage eligibility. When transferring care between different healthcare providers or trusts, your authorization enables seamless information sharing while maintaining legal compliance. Legal proceedings involving medical evidence may require this form to permit disclosure to solicitors or courts. Mental health services particularly rely on these authorizations when coordinating care between multiple specialists or social services.

Key legal considerations

Your authorization must be specific, informed, and freely given under UK GDPR principles. The form should clearly identify what specific health information can be disclosed, avoiding broad or blanket permissions that could compromise your privacy. You retain the right to withdraw your consent at any time, though this won't affect information already shared with your permission. The authorization should specify a reasonable duration rather than being open-ended, with most forms valid for 6-24 months depending on the purpose. Healthcare providers must ensure they only share the minimum necessary information required for the stated purpose, adhering to data minimization principles. If you lack mental capacity, decisions about information disclosure must follow Mental Capacity Act 2005 procedures, potentially involving appointed representatives or best interest assessments.

Legal requirements in England and Wales

Under the UK Data Protection Act 2018 and UK GDPR, healthcare providers must demonstrate lawful basis for processing your health information, with explicit consent being the most common basis for non-care related sharing. The Access to Health Records Act 1990 governs how your information can be accessed, particularly relevant for deceased patients' records. Mental Capacity Act 2005 provisions apply when you cannot provide informed consent, requiring healthcare providers to act in your best interests or follow valid lasting power of attorney arrangements. The Health and Social Care Act 2012 framework ensures information sharing supports integrated care delivery while maintaining appropriate safeguards. Your authorization must comply with NHS information governance standards and local trust policies, which often require additional approvals for certain types of disclosure. Healthcare providers must maintain audit trails of all information sharing activities and ensure recipient organizations have appropriate data protection measures in place.

GOVERNING LAW

Applicable law

This Authorisation To Use And Disclose Protected Health Information Form is drafted to comply with England and Wales law. Key legislation includes:

UK Data Protection Act 2018: Primary UK legislation governing the processing of personal data, including health information. Implements and supplements the UK GDPR.

UK GDPR: Post-Brexit version of the EU GDPR, setting out fundamental principles for data protection including lawfulness, fairness, transparency, purpose limitation, and data minimization.

Access to Health Records Act 1990: Legislation providing individuals with the right to access health records, particularly relevant for deceased patients' records.

Mental Capacity Act 2005: Legislation governing decision-making for individuals who lack capacity, including provisions for health information disclosure.

Health and Social Care Act 2012: Framework legislation for health service delivery in England, including provisions for information governance and sharing.

Common Law Duty of Confidentiality: Legal principle requiring healthcare professionals to keep patient information confidential unless there is a lawful basis for disclosure.

Caldicott Principles: Set of principles governing the handling of patient-identifiable information in the NHS, including justification for data use and minimum necessary access.

NHS Act 2006: Legislative framework for the NHS, including provisions for handling patient information and confidentiality.

GMC Guidance on Confidentiality: Professional guidelines from the General Medical Council on managing patient confidentiality and information disclosure.

BMA Guidelines: British Medical Association's professional guidance on handling patient information and consent for disclosure.

NHS Digital Data Security and Protection Toolkit: Framework of standards for handling health and care information, including requirements for security and protection of patient data.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it