Examples
Worked examples
- Is an instance
An IRB grants a waiver of authorization under 45 CFR §164.512(i) so a hospital's clinical trials office can query the EHR to identify patients meeting a study's eligibility criteria for a retrospective chart review. Because the disclosure carries no individual authorization and fits no §164.528 exemption, it is accountable — though if the protocol involves 50 or more individuals' records, the covered entity may use the simplified per-protocol accounting at §164.528(b)(4) instead of listing each patient's disclosure separately.
- Is an instance
A hospital discloses a patient's records to a specialist for ongoing treatment. Because this is a treatment disclosure under §164.506, it is expressly exempt from accounting under §164.528(a)(1) and is never tracked for this purpose.
Counter-examples
Looks similar, but isn't
- Not an instance
A researcher obtains a signed HIPAA Authorization from each participant before pulling their records for a prospective clinical trial. Because the disclosure is made pursuant to a valid Authorization under §164.508, it is exempt from accounting under §164.528(a)(1) — it is still a real disclosure of PHI for research, but it does not count as one requiring an accounting entry.
Editorial commentary
HIPAA accounting of disclosures is an individual’s right, under the Privacy Rule at 45 CFR §164.528, to a written list of certain disclosures of their protected health information made in the prior six years. Routine treatment, payment, and operations disclosures are excluded; the right reaches unauthorized disclosures, including IRB-approved recruitment pulls and chart reviews under a waiver.
What counts as a disclosure requiring accounting
A disclosure is “accountable” under §164.528 when a covered entity discloses PHI to a person or entity outside itself and that disclosure does not fall into one of the Privacy Rule’s specifically enumerated exempt categories (see below). For each accountable disclosure, the covered entity must be able to produce:
- The date of the disclosure;
- The name (and address, if known) of the entity or person who received the PHI;
- A brief description of the PHI disclosed; and
- A brief statement of the purpose of the disclosure (or, where applicable, a copy of the individual’s written disclosure request).
The covered entity must act on a request — provide the accounting or deny it in specified circumstances — no later than 60 days after receiving it, with one permissible 30-day extension if the individual is given written notice of the delay and the reason for it. The first accounting an individual requests in any 12-month period must be provided free of charge; the covered entity may charge a reasonable, cost-based fee for additional requests within that same 12-month period, provided it first tells the individual the fee applies and gives them a chance to withdraw or modify the request. Covered entities must retain the accounting information itself, any written accounting actually provided, and the titles of the persons responsible for handling accounting requests, per the documentation requirements at 45 CFR §164.530(j).
Disclosures exempt from accounting
Most of what a covered entity discloses about a patient in the ordinary course of care never needs to be tracked for this purpose. Section 164.528(a)(1) exempts:
- Disclosures to carry out treatment, payment, and health care operations (45 CFR §164.506) — the largest category by volume, and the reason accounting logs don’t balloon to cover every clinical referral or billing transaction;
- Disclosures to the individual about their own PHI (45 CFR §164.502);
- Disclosures incident to an otherwise-permitted use or disclosure;
- Disclosures made pursuant to a valid Authorization the individual signed under 45 CFR §164.508 — this is the exemption research administrators run into constantly: a prospective study that obtains a signed HIPAA Authorization from each participant before pulling their records generates disclosures that are exempt from accounting, precisely because the individual already consented in writing to that specific use;
- Disclosures for a facility directory or to persons involved in the individual’s care (45 CFR §164.510);
- Disclosures for national security or intelligence purposes (45 CFR §164.512(k)(2));
- Disclosures to correctional institutions or law enforcement regarding an individual in custody (45 CFR §164.512(k)(5));
- Disclosures made as part of a limited data set under a Data Use Agreement (45 CFR §164.514(e)); and
- Disclosures made before the covered entity’s Privacy Rule compliance date (April 14, 2003 for most covered entities).
The research-specific wrinkle: waiver-based disclosures are not exempt
This is the detail that makes §164.528 an operational issue for research administration rather than a purely legal one. Look back at the exemption list: it exempts authorized disclosures (§164.508) and limited-data-set disclosures (§164.514(e)) by name, but it does not exempt a disclosure made without authorization under an IRB- or Privacy Board-granted waiver of authorization under 45 CFR §164.512(i). That omission is deliberate, not an oversight — and it means every one of the following, common research workflows produces disclosures a covered entity must be able to account for:
- An IRB-approved waiver allowing a clinical trials office to query the EHR system for patients meeting a protocol’s eligibility criteria, for recruitment purposes;
- A waiver-based retrospective chart review pulling records across a patient population to study an outcome, without contacting or obtaining authorization from each individual;
- Reviews preparatory to research (45 CFR §164.512(i)(1)(ii)) — a researcher assessing feasibility by reviewing records before a protocol is finalized; and
- Research on a decedent’s PHI (45 CFR §164.512(i)(1)(iii)), where no living individual can grant authorization.
Full de-identification (45 CFR §164.514(a)–(b)) remains the one clean way to remove data from HIPAA’s scope, and therefore from the accounting requirement, entirely — see CASRAI’s De-identification entry. Short of that, if a waiver-based research disclosure identifies the individual (or the covered entity retains identifiers), the institution needs a way to produce an accounting of it.
The simplified accounting for research disclosures involving 50 or more individuals
HHS built a specific accommodation into §164.528(b)(4) precisely because waiver-based research disclosures would otherwise force a covered entity to log every individual record pull separately across a study that may touch thousands of records. Where a covered entity has made disclosures for a particular research protocol involving 50 or more individuals’ PHI — whether under a waiver of authorization, a preparatory-to-research review, or decedent research — it may provide a per-protocol accounting instead of a per-individual one, consisting of:
- The name of the protocol or research activity;
- A plain-language description of the research protocol, including its purpose and the criteria used to select records;
- A brief description of the type of PHI disclosed;
- The date, or period of time, over which the disclosures were made; and
- The name, address, and telephone number of the entity that sponsored the research and of the researcher who conducted it.
If, after seeing that protocol-level list, an individual asks whether their own record specifically was disclosed under a named protocol, the covered entity must make a reasonable effort to find out and tell them — the simplified accounting isn’t a way to avoid answering that question, only a way to avoid tracking every research disclosure at the individual level up front.
Why this is a genuine operational burden, not a paperwork formality
For a research administrator, §164.528 translates into real, ongoing infrastructure requirements rather than a one-time compliance checkbox:
- Disclosure logs must exist before a request arrives. The 60-day response clock starts on receipt of the request, which means the underlying tracking — which protocol, which waiver, what data elements, what date range — has to already be captured at the point of disclosure, not reconstructed afterward from study files scattered across departments.
- Coordination across the privacy office, the IRB, and the clinical trials/data-access office. The IRB approves the waiver; the privacy or HIM office typically owns the accounting-of-disclosures obligation institution-wide; the study team is the one who actually knows what was pulled and why. Without a defined process linking these, a request risks going unanswered within the deadline or being answered incompletely.
- Six years of retention. Because the lookback window is six years from the request date, disclosure records for a completed or even terminated study still have to be retrievable well after the study itself has closed out.
- Distinguishing waiver-based from authorized disclosures at the point of IRB submission. Because the accounting obligation turns on whether a disclosure was authorized or waiver-based, institutions benefit from making that distinction explicit and machine-trackable in IRB protocol records and data-request systems — not something to work out retroactively when a patient actually asks.
- The 50-record threshold is a design decision, not just a convenience. Structuring waiver-based data pulls at the protocol level (rather than as untracked ad hoc queries) is what makes the simplified accounting in §164.528(b)(4) usable when a request does come in.
Worked examples
Accountable research disclosure, simplified accounting applies. A hospital’s IRB grants a waiver of authorization under 45 CFR §164.512(i) so a clinical trials office can query the EHR to identify patients meeting a diabetes study’s eligibility criteria, ultimately reviewing 300 patients’ records. No authorization was obtained and no exemption applies, so this is an accountable disclosure — but because it involves 50 or more individuals under one protocol, the hospital may provide a per-protocol accounting (protocol name, purpose, PHI type, date range, sponsor/researcher contact) rather than 300 separate entries.
Exempt disclosure, no accounting needed. The same hospital discloses a patient’s records to an outside cardiologist for ongoing treatment. Because this is a treatment disclosure under 45 CFR §164.506, it is exempt under §164.528(a)(1) and is never entered into an accounting log, regardless of how the request is later phrased.
Frequently asked questions
Does obtaining a signed HIPAA authorization avoid the accounting requirement?
Yes. A disclosure made pursuant to a valid Authorization under 45 CFR §164.508 is expressly exempt from accounting under §164.528(a)(1). This is one of the practical reasons some studies prefer to obtain individual authorization where feasible, over relying on an IRB waiver — though the waiver route remains the correct, permitted pathway when individual authorization is impracticable and the Rule’s minimal-risk criteria are met.
Does de-identifying the data avoid the requirement?
Yes, and more completely. Data that meets the Safe Harbor or Expert Determination de-identification standard at 45 CFR §164.514(a)–(b) is no longer PHI at all, so it falls outside HIPAA’s scope entirely — not just outside the accounting requirement. See CASRAI’s De-identification entry.
Is accounting of disclosures the same as the HIPAA right of access?
No. The right of access (45 CFR §164.524) lets an individual obtain a copy of their own PHI. Accounting of disclosures (§164.528) is a different right entirely: a list of who else the covered entity disclosed that PHI to, and why, for certain non-routine disclosures.
Does a limited data set disclosed under a Data Use Agreement need to be accounted for?
No. Disclosures made as part of a limited data set under 45 CFR §164.514(e), with a Data Use Agreement in place, are exempted from accounting by §164.528(a)(1) directly.
Related CASRAI resources
- HIPAA — the umbrella statute and its Privacy/Security/Breach Notification Rules
- HIPAA Privacy Rule — the Privacy Rule’s research-specific provisions in regulatory detail
- HIPAA in Clinical Research — the five permitted pathways for using PHI in a study, including the waiver of authorization this entry depends on
- De-identification
- Data Use Agreement (DUA)
- Informed consent
- IRB (Institutional Review Board)
- Common Rule (45 CFR 46)
- Exempt human subjects research
- Informed Consent in Research: What It Requires and How It Works
- Clinical Research Administration — cluster hub
References
- 45 CFR §164.528 — Accounting of disclosures of protected health information
- 45 CFR §164.508 — Uses and disclosures for which an authorization is required
- 45 CFR §164.512(i) — Uses and disclosures for research purposes
- 45 CFR §164.514(a)–(b) — De-identification of protected health information
- 45 CFR §164.514(e) — Limited data set
- 45 CFR §164.530(j) — Documentation requirements
- HHS Office for Civil Rights, “Right to an Accounting of Disclosures” FAQ guidance
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="HIPAA Accounting of Disclosures"
vocab-term-identifier="https://casrai.org/dictionary/term/hipaa-accounting-of-disclosures" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/hipaa-accounting-of-disclosures",
"name": "HIPAA Accounting of Disclosures",
"identifier": "https://casrai.org/dictionary/term/hipaa-accounting-of-disclosures",
"description": "A disclosure of protected health information (PHI) is subject to the HIPAA accounting-of-disclosures requirement at 45 CFR §164.528 when a covered entity makes it without the individual's authorization and it does not fall into one of the Privacy Rule's enumerated exempt categories (treatment/payment/health care operations, disclosures to the individual, incidental disclosures, authorized disclosures under §164.508, facility-directory/care-related disclosures, national-security/law-enforcement disclosures, limited-data-set disclosures under §164.514(e), or disclosures made before the covered entity's Privacy Rule compliance date). An individual has the right to request — and the covered entity must provide within 60 days, extendable once by 30 — a written accounting of every disclosure meeting that definition made in the six years preceding the request.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/hipaa-accounting-of-disclosures",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-30T05:47:01",
"inLanguage": "en"
}






