Iowa Admin. Code r. 191-90.18

Current through Register Vol. 46, No. 21, April 17, 2024
Rule 191-90.18 - Authorizations
(1) A valid authorization to disclose nonpublic personal health information pursuant to the health information rules as required under subrule 90.17(1) shall be in written or electronic form and shall contain all of the following:
a. The identity of the consumer or customer who is the subject of the nonpublic personal health information;
b. A general description of the types of nonpublic personal health information to be disclosed;
c. General descriptions of the parties to whom the licensee discloses nonpublic personal health information, the purpose of the disclosure and how the information will be used;
d. The signature of the consumer or customer who is the subject of the nonpublic personal health information or the individual who is legally empowered to grant authority and the date signed; and
e. Notice of the length of time for which the authorization is valid, the fact that the consumer or customer may revoke the authorization at any time, and the procedure for making a revocation.
(2) An authorization for the purposes of these health information rules shall specify a length of time for which the authorization shall remain valid, which in no event shall be for more than 24 months.
(3) A consumer or customer who is the subject of nonpublic personal health information may revoke an authorization provided pursuant to these health information rules at any time, subject to the rights of an individual who acted in reliance on the authorization prior to notice of the revocation.
(4) A licensee shall retain the authorization or a copy in the record of the individual who is the subject of nonpublic personal health information.

Iowa Admin. Code r. 191-90.18

Adopted by IAB March 20, 2024/Volume XLVI, Number 19, effective 4/24/2024