Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

OCR Issues Guidance on the Use of HIPAA Authorizations for Research

By Dena M. Castricone on June 15, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

This week, the Department of Health and Human Services Office for Civil Rights (OCR) issued guidance on the use of HIPAA-compliant authorizations for research based on a mandate in the Cures Act for such guidance.  The guidance addresses authorizations and expiration language for future research as well as revocation of the authorization.  A copy of the guidance can be obtained here. 

OCR first clarifies that authorizations for future research do not need to specify each specific future study information would be used for, so long as those studies have not yet been determined.  Rather, the authorization must adequately describe the research purposes so that an individual reasonably could expect that his or her protected health information (PHI) could be used or disclosed for such future research.  Next, OCR explains that, if the purpose of the research is to create a research database or repository, the statements “end of the research study” or “none” are sufficient to meet the requirement that the authorization contain an expiration date or event that relates to the individual or the purpose of the use or disclosure.  It also is sufficient to state that the authorization will remain in effect unless and until the individual revokes it.

With respect to revocation, OCR reminds covered entities that they must explain how an individual can exercise his or her right to revoke.  The covered entity can do this in the authorization or it can refer the individual to the Notice of Privacy Practices if the process is detailed in that document.  Covered entities can establish reasonable procedures for revocation such as completing a revocation form, although OCR encourages covered entities to ensure that the process does not make it difficult for the individual to exercise his or her right to revoke.  Any revocation is not effective until the covered entity receives it or has knowledge of it.  While the right to revoke remains in effect at all times, OCR confirms that periodic reminders of a right to revoke are not necessary; however, nothing prevents a covered entity from providing periodic reminders.

OCR notes some exceptions to an individual’s right to revoke.  A covered entity is permitted to continue to use and disclose PHI it obtained prior to revocation if the covered entity acted in reliance on that authorization.  A covered entity may also continue to use or disclose for its research after the revocation if it is necessary to maintain the integrity of the research.  OCR provides the following examples:  “to account for a subject’s withdrawal from the research study, to conduct investigations of scientific misconduct, or to report adverse events.”  Finally, HIPAA permits certain uses and disclosures without an authorization such as the use of PHI for research purposes related to health care operations, such as quality assessment and improvement activities.

Photo of Dena M. Castricone Dena M. Castricone

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro…

Dena M. Castricone, CIPP/US is the chair of the Privacy and Cybersecurity group and a member of the Long Term Care and Health Care groups.  She also serves as Chair of the firm’s Women Expanding Business initiative and co-chair of the firm’s Pro Bono Committee.  Prior to joining Murtha Cullina, Dena served as a law clerk to the Chief Justice of the Rhode Island Supreme Court, Frank J. Williams.

As the Chair of the Privacy and Cybersecurity group and a Certified Information Privacy Professional (CIPP/US), Dena provides the full complement of data breach coaching services to business and health care clients including breach notification to individuals and various government entities.  Related to data breaches, she also counsels clients on the creation of information security, incident response plans and other proactive measures.  Additionally, Dena advises clients on compliance with state, federal and international privacy laws including the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) as well as many others. Dena has written extensively on privacy and cybersecurity issues and she is the Co-Editor of Privacy and Cybersecurity Perspectives.  Read More

Read more about Dena M. CastriconeEmailDena M.'s Linkedin Profile
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Privacy and Cybersecurity Perspectives
  • Organization:
    Murtha Cullina LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo