When a study needs protected health information (PHI) but the covered entity does not have, or does not want to rely on, the individual’s signed HIPAA Authorization, the HIPAA Privacy Rule provides one narrow route around that requirement: an Institutional Review Board (IRB) or a separately constituted Privacy Board can approve a waiver, partial waiver, or alteration of the authorization requirement under 45 CFR 164.512(i)(1)(i). This guide walks through the three regulatory criteria the board must apply, the practical difference between a full and a partial waiver, the documentation the covered entity must obtain before disclosing any PHI, and how this HIPAA-specific mechanism differs from the separate Common Rule informed-consent waiver researchers often confuse it with.
What a waiver or alteration of authorization actually does
Ordinarily, a HIPAA-covered entity (a health care provider, health plan, or health care clearinghouse) may not use or disclose PHI for research unless the individual signs a valid Authorization meeting the core elements at 45 CFR 164.508. A waiver or alteration of authorization is the mechanism that lets the covered entity proceed without that signed document, or with a modified version of it, because an IRB or Privacy Board has independently determined the disclosure meets specific privacy-protective conditions. It is one of three distinct pathways under 45 CFR 164.512(i)(1) that permit PHI use for research without individual authorization — the other two are reviews preparatory to research (164.512(i)(1)(ii)), which never involves removing PHI from the covered entity, and research on decedents’ information (164.512(i)(1)(iii)). This guide covers the waiver/alteration pathway specifically; see 45 CFR 164.512(i) for how all three fit together.
The three regulatory criteria for approval
Under 45 CFR 164.512(i)(2)(ii), an IRB or Privacy Board may approve a waiver or alteration of authorization only if it determines, and documents, that all three of the following are satisfied:
1. The use or disclosure involves no more than minimal risk to privacy
This is not a single finding — the board must confirm three underlying elements:
- An adequate plan to protect identifiers from improper use or disclosure while the PHI is in the researcher’s hands.
- An adequate plan to destroy the identifiers at the earliest opportunity consistent with the research, unless there is a health or research justification for retaining them or a legal requirement to do so.
- Adequate written assurances that the PHI will not be reused or re-disclosed to any other person or entity, except as required by law, for authorized oversight of the research project, or for other research for which the use or disclosure of the PHI would itself be permitted.
2. The research could not practicably be conducted without the waiver or alteration
The board must find that requiring individual authorization would make the research impracticable — for example, because the population is too large to contact individually, contact information is only available in the records being reviewed, or the study design (a retrospective chart review, a registry-based cohort) is inherently incompatible with prospective authorization.
3. The research could not practicably be conducted without access to and use of the PHI
This is a separate finding from criterion 2: the board must confirm that a de-identified data set or a limited data set under a data use agreement would not suffice for the research question. If a de-identified or limited data set would work, a waiver of authorization for identifiable PHI is not the appropriate route — see Limited Data Set vs. De-Identified Data for how those narrower options compare.
Who approves it: IRB or Privacy Board
The Privacy Rule allows either an IRB, acting under its normal human-subjects review authority, or a Privacy Board — a body a covered entity may convene specifically for HIPAA research reviews — to make this determination. A Privacy Board is not optional window-dressing; the regulation requires it to have members with varying backgrounds and appropriate professional competence to review the effect of the research on privacy, at least one member who is not affiliated with the covered entity, the research sponsor, or any entity conducting or sponsoring the research, and no member with a conflicting interest in the specific research under review. In practice, most academic medical centers route HIPAA waiver requests through the same IRB that reviews the underlying human-subjects protocol rather than standing up a separate Privacy Board, but the regulation permits either.
Full waiver vs. partial waiver vs. alteration
These are three distinct outcomes an IRB or Privacy Board can approve, and the difference matters for what the research team is authorized to do:
- Full waiver: the requirement for individual authorization is waived entirely for the PHI uses and disclosures described in the protocol. This is typical for studies with no participant contact at all — a retrospective chart review or a registry analysis where no one is being recruited, enrolled, or re-contacted.
- Partial waiver: the requirement for authorization is waived only for a defined subset of PHI uses, most commonly to let study staff access identifiers and contact information before a signed authorization exists, in order to screen a patient population for eligibility and initiate recruitment. A partial waiver does not eliminate the authorization requirement for the study as a whole — once a prospective participant is identified and approached, the study team still needs a signed Authorization (or a separate full waiver covering the remaining research use of PHI) before further PHI is created, used, or disclosed for study procedures.
- Alteration of authorization: rather than removing the authorization requirement, the board modifies one or more of the core elements otherwise required at 164.508 — for example, permitting a shortened or modified authorization form for a specific limited use, while still requiring some form of documented individual permission. An alteration is evaluated against the same three criteria above; it is a middle path between a standard Authorization and a full waiver.
A partial waiver limited to recruitment is one of the most common uses of this provision in practice: it lets research staff query the electronic health record or an honest-broker system for eligibility criteria and contact information without first obtaining authorization from every patient in the searchable population, most of whom will never be approached. See Honest Broker: The De-Identified-Data Intermediary Role for a related mechanism institutions use to limit identifiable PHI exposure during that same recruitment-screening step.
Documentation the covered entity must obtain
A covered entity may not rely on a waiver or alteration until it has obtained documentation, signed by the chair or a designated member of the IRB or Privacy Board, that includes at minimum the following elements (45 CFR 164.512(i)(2)(ii)):
- Identification of the IRB or Privacy Board and the date the waiver or alteration was approved.
- A statement that the IRB or Privacy Board has determined the waiver or alteration satisfies the three criteria above — minimal privacy risk (with its three sub-elements), impracticability without the waiver, and impracticability without PHI access.
- A brief description of the PHI for which access has been determined to be necessary.
- A statement that the waiver or alteration was reviewed and approved under either normal review procedures or expedited review procedures, and if expedited, the criteria under which expedited review is permitted.
- The signature of the chair, or another member designated by the chair, of the IRB or Privacy Board.
This documentation is what a covered entity produces if HHS’s Office for Civil Rights or an institutional compliance audit later asks why PHI was used or disclosed without a signed patient authorization. It sits alongside — and is separate from — the accounting-of-disclosures obligation: waiver-based disclosures are not exempt from HIPAA’s accounting-of-disclosures requirement, so institutions running protocols involving 50 or more individuals’ records commonly rely on the simplified per-protocol accounting method available under 164.528(b)(4) rather than tracking each disclosure individually.
HIPAA authorization waiver vs. Common Rule informed-consent waiver
These are two separate legal mechanisms that are frequently confused because they often apply to the same study at the same time, and the same IRB commonly reviews both requests together — but they rest on different regulations, different reviewing-body requirements in some institutions, and different criteria:
- The Common Rule waiver of informed consent (45 CFR 46.116(f)) waives the requirement to obtain a participant’s consent to participate in the research itself. Its criteria are: minimal risk to subjects, the waiver will not adversely affect subjects’ rights and welfare, the research could not practicably be carried out without the waiver, and, if appropriate, subjects will be provided with additional pertinent information after participation. See Waiver of Informed Consent (45 CFR 46.116(f)) for the full criteria.
- The HIPAA waiver or alteration of authorization (45 CFR 164.512(i)) waives only the requirement to obtain permission to use or disclose PHI — it says nothing about whether someone may be enrolled as a research participant. Its criteria, covered above, are specifically about privacy risk to identifiers, not about risk to the subject from study participation.
A study can need one without the other: a retrospective chart review that never contacts or enrolls a living subject needs only the HIPAA waiver, not a Common Rule consent waiver, because there is no “participation” to consent to. Conversely, a purely behavioral study that never touches PHI held by a covered entity may need a Common Rule consent waiver with no HIPAA component at all. When a study does need both — commonly, a prospective study using patient records held by a covered entity — the two waivers are reviewed against their own separate criteria, even when the same IRB approves both in the same meeting and the outcomes are documented on the same protocol. For the full side-by-side comparison, including how the two waiver criteria differ point for point, see HIPAA Authorization vs. Informed Consent.
Where a waiver or alteration fits into a typical protocol
Two illustrative patterns show how the pieces above combine in practice; neither describes a specific real study, only the general shape of how these approvals are commonly structured:
- Retrospective chart review with no participant contact. A study team wants to analyze five years of clinical records to answer a research question, with no prospective enrollment. Because no one is contacted or asked to consent to anything, the team typically requests a full waiver of authorization (not a partial one) and, separately, may qualify for expedited or exempt Common Rule review depending on the risk profile and institutional policy — the HIPAA waiver and the Common Rule determination are still evaluated as two distinct questions.
- Prospective recruitment from clinical records. A study team needs to search the EHR for patients meeting eligibility criteria and contact eligible patients about enrolling. Here a partial waiver covering identifiers and contact information needed for screening and initial outreach is typical, paired with a standard signed HIPAA Authorization (and Common Rule informed consent) once a patient agrees to enroll and PHI beyond basic eligibility/contact data is used for study procedures.
Frequently asked questions
Can a waiver of authorization be approved without full IRB review?
Yes — the documentation requirement explicitly contemplates both normal and expedited review procedures, and the covered entity’s documentation must state which procedure applied. Whether a given waiver request is eligible for expedited review is governed by the reviewing board’s own procedures, not by 164.512(i) itself.
Does a partial waiver for recruitment mean the study never needs full authorization?
No. A partial waiver limited to recruitment only covers the specific PHI uses described in the approval — typically identifiers and contact information needed to screen and approach potential participants. Once someone is enrolled and additional PHI is created or used for study procedures, a signed Authorization (or a separate, broader waiver covering that use) is still required unless another 164.512(i) pathway applies.
Is a Privacy Board required, or can the IRB always handle this?
The Privacy Rule permits either. Most institutions route HIPAA waiver requests through the existing IRB rather than convening a separate Privacy Board, provided the IRB’s membership and conflict-of-interest handling can satisfy the same substantive requirements the regulation sets for a Privacy Board.
Does a HIPAA waiver of authorization also waive the requirement for informed consent?
No. They are governed by separate regulations with separate criteria. A HIPAA waiver only addresses permission to use or disclose PHI; it has no bearing on whether informed consent to participate in the research is required, waived, or altered under the Common Rule.
What happens if the covered entity discloses PHI under a waiver that doesn’t meet all three criteria?
A disclosure made without valid authorization and without a properly documented waiver, alteration, or other 164.512(i) pathway is a disclosure not permitted by the Privacy Rule, exposing the covered entity to HIPAA enforcement risk. This is why the documentation requirements — not just the underlying board determination — are treated as a compliance-critical record, not paperwork formality.
Related CASRAI pages
- 45 CFR 164.512(i) (HIPAA Uses and Disclosures for Research Purposes) — the full three-pathway overview this guide’s waiver/alteration pathway sits within.
- HIPAA Authorization vs. Informed Consent — side-by-side comparison of the two underlying regulations.
- Waiver of Informed Consent (45 CFR 46.116(f)) — the separate Common Rule mechanism.
- Limited Data Set (HIPAA) and Limited Data Set vs. De-Identified Data — narrower alternatives when full PHI access isn’t necessary.
- Honest Broker: The De-Identified-Data Intermediary Role — a complementary mechanism for limiting identifiable PHI exposure during recruitment.
- HIPAA Accounting of Disclosures — the related tracking obligation for waiver-based disclosures.
- HIPAA in Clinical Research and HIPAA Privacy Rule — broader framework context.
- IRB (Institutional Review Board) — the body most commonly reviewing these requests.
This guide summarizes the requirements of 45 CFR 164.512(i) as a general reference. It is not legal advice; institutional HIPAA and IRB policies may impose additional requirements beyond the federal minimum, and covered entities should confirm current requirements against 45 CFR 164.512 and their own Privacy Board/IRB procedures before relying on a waiver determination.







