Under HIPAA, when is a "disclosure accounting" required?
A disclosure accounting is required when an individual requests a list of certain non-routine disclosures of their PHI made by a covered entity. It covers up to the previous 6 years and excludes disclosures for treatment, payment, health care operations, and those the individual authorized. The entity must respond within 60 days.
The answer
Under HIPAA's Privacy Rule (45 CFR 164.528), a disclosure accounting is required when an individual requests a record of the disclosures of their protected health information (PHI) that a covered entity or its business associates have made. The individual has a right to receive an accounting of certain non-routine disclosures made in the six years prior to the request. The covered entity must act on the request within 60 days (with one 30-day extension permitted, and one free accounting per 12-month period).
Crucially, the accounting does not cover every disclosure. It focuses on disclosures the individual would not otherwise know about — such as disclosures for public health activities, to law enforcement, for research without authorization, to oversight agencies, in response to court orders, or those made in error (breaches).
What must NOT be accounted for
Several major categories are excluded from the accounting requirement. You do not have to account for disclosures:
- For treatment, payment, or health care operations (TPO) — these are routine and expected.
- Made pursuant to a valid authorization signed by the individual.
- To the individual themselves about their own PHI.
- Incidental to an otherwise permitted disclosure.
- For a facility directory or to persons involved in the individual's care.
- For national security or intelligence purposes, or to correctional institutions.
- Made as part of a limited data set.
Because TPO disclosures are the overwhelming majority of everyday PHI sharing, excluding them keeps the accounting focused on the unusual disclosures a patient could not otherwise track.
Why the tempting wrong answers fail
A common misconception is that an accounting must list every disclosure of PHI — it does not, because treatment, payment, operations, and authorized disclosures are all exempt. Another error is thinking it covers only the past year; the correct look-back period is six years (or a shorter period if the individual asks). A third mistake is believing the entity can take as long as it wants — the rule sets a firm 60-day response window with a single 30-day extension. Getting the excluded categories and the timeframes right is exactly what these exam questions test.
The bigger picture
The accounting-of-disclosures right is one of several patient rights under the Privacy Rule, alongside the right to access records, request amendments, and request restrictions. Its purpose is transparency: it lets patients see where their information went for non-routine reasons — such as reporting a communicable disease to a public health authority or complying with a subpoena — so they can detect and question uses they never authorized.
| Public health reporting | Yes | Non-routine disclosure the patient may not know about |
| Response to a subpoena or court order | Yes | Legal disclosure outside TPO |
| Research without patient authorization | Yes | Not covered by TPO or an authorization |
| Disclosures made in error / breaches | Yes | Unauthorized disclosures must be tracked |
| Treatment, payment, health care operations | No | Routine TPO disclosures are exempt |
| Made with the individual's authorization | No | The individual already consented |
| To the individual about their own PHI | No | Not counted as an accountable disclosure |
Frequently asked
What disclosures are exempt from HIPAA accounting?
Exempt disclosures include those for treatment, payment, and health care operations (TPO); disclosures made with the individual's authorization; disclosures to the individual about their own PHI; incidental disclosures; facility directory and care-involvement disclosures; national security and correctional disclosures; and limited data sets. These do not need to be listed in an accounting.
How far back does a HIPAA accounting of disclosures go?
An individual can request an accounting of accountable disclosures made in the six years prior to the date of the request. They may also ask for a shorter time period. Covered entities are not required to account for disclosures made before the compliance date.
How long does a covered entity have to respond to an accounting request?
A covered entity must provide the accounting within 60 days of receiving the request. It may take one 30-day extension if it gives the individual a written explanation of the delay and the new date. The first accounting in any 12-month period must be provided free of charge.
What must a HIPAA disclosure accounting include?
For each accountable disclosure, it must include the date, the name (and address, if known) of the recipient, a brief description of the PHI disclosed, and a brief statement of the purpose or a copy of the written request. For multiple similar disclosures to the same recipient, a summarized entry is allowed.