It's 4:40 on a Tuesday. A cardiology office three miles away calls your front desk and asks for the last two office notes, the most recent echocardiogram report, and the current medication list for a patient your physician referred that morning with diastolic heart failure. Your receptionist tells them she'll need a signed authorization and offers to mail a form to the patient.

That answer is wrong, and it costs you twice: the referral stalls, and you've manufactured a records request you now have to track. This post walks the administrative path that referral takes through your practice — who touches the chart, what the Privacy Rule actually permits, which vendors in the path need agreements, and what your audit log has to show six months from now if someone complains.

Treatment Disclosures Between Providers Do Not Require Authorization

A covered entity may use and disclose protected health information for treatment, payment, and health care operations without patient authorization. For treatment specifically, that includes disclosure to another provider — the cardiologist, the imaging center, the home health agency — for that provider's treatment of the patient. The rule is at 45 CFR 164.506(c)(2), and HHS maintains plain-language guidance on permitted uses and disclosures that your privacy officer should keep bookmarked.

The second half of that rule matters just as much for referral workflow: the minimum necessary standard does not apply to disclosures to a health care provider for treatment purposes. HHS says so directly in its minimum necessary guidance. If the receiving cardiologist wants the full problem list, the full med list, and three years of notes to manage a diastolic heart failure workup, your staff is not obligated to trim the packet down.

What trips practices up is that "not required" gets read as "not allowed." Front-desk staff hear "minimum necessary" in annual training, apply it to a treatment disclosure, and start redacting or refusing. Write the treatment exception into your release-of-information procedure in one sentence, in bold, and use it in training.

Do You Need a Patient Authorization to Send Records to a Cardiologist?

No. Under 45 CFR 164.506, a covered entity may disclose PHI to another covered health care provider for that provider's treatment of the patient without a patient authorization. Verbal consent, a signed HIPAA authorization form, and a referral form signature are all optional as a matter of federal law. Four conditions apply in practice:

  • Verify the requester. You must reasonably verify the identity and authority of the person asking. A callback to a published office number satisfies this; a fax cover sheet alone does not.
  • Check for special categories. Psychotherapy notes, substance use disorder records covered by 42 CFR Part 2, and certain state-protected categories follow different rules.
  • Check state law. Some states impose consent requirements stricter than HIPAA. Stricter state law wins.
  • Log it. Treatment disclosures are excluded from the accounting-of-disclosures requirement, but your own audit trail is what defends you later.

The Diastolic Heart Failure Referral Packet: Who Assembles What

Diastolic heart failure — commonly documented as heart failure with preserved ejection fraction — is a condition where records reliably cross organizational boundaries. There's usually an echocardiogram, often prior imaging, frequently labs from an outside reference lab, and typically ongoing co-management between primary care and cardiology. That means your records travel, come back, and travel again. Build the workflow once instead of improvising per patient.

Role assignments that actually hold up

Referring provider: names the receiving practice and the clinical question in the order. Not "cardiology consult" — the specific practice, the specific provider if known. Ambiguity at this step is what produces the 4:40 phone call.

Referral coordinator or MA: assembles the packet within one business day. Standing content: last two office notes, current medication and allergy list, problem list, relevant imaging reports and the underlying study if the receiving practice can accept images, relevant labs, insurance face sheet.

Release-of-information staff: executes the transmission through an approved channel and records it. Approved channels are a short, written list — not "whatever works."

Privacy officer: owns the channel list, the vendor agreements behind each channel, and the quarterly spot-check of the log.

A worked timeline

  1. Day 0, 10:15 a.m. Provider places the referral order with the receiving practice named and the reason documented.
  2. Day 0, by close. Coordinator assembles the packet and queues it for transmission. If images are involved, she confirms whether the receiving practice uses the same image exchange network or needs a link.
  3. Day 1. Packet transmitted. Log entry created: date, time, sender, recipient organization, recipient contact verified how, contents, channel, purpose (treatment).
  4. Day 1–3. Receiving practice calls for something not in the packet. Staff sends it under the same treatment authority, appends the log entry — no new authorization, no delay.
  5. Day 10–30. Consult note comes back inbound. It gets matched to the correct chart, routed to the referring provider for review, and filed. Unmatched inbound records go to a named person, not a shared folder nobody owns.

Five steps. Most practices have three of them written down and two of them living in one long-tenured employee's head. The two undocumented ones are where your exposure sits.

Where the Exceptions Live

The treatment exception is broad but not universal. Three carve-outs deserve a named owner in your practice.

42 CFR Part 2 records. The 2024 final rule aligning Part 2 more closely with HIPAA carried a compliance date of February 16, 2026 — already behind you. Substance use disorder treatment records from a Part 2 program still follow their own consent architecture even after alignment. If your chart contains records you received from a Part 2 program, forwarding them onward is not the same act as forwarding your own notes.

Psychotherapy notes. Separately maintained process notes from a mental health session require authorization for nearly every disclosure, including treatment disclosure to another provider. If your practice employs a behavioral health clinician, confirm those notes are actually stored separately — the protection depends on it.

State law. HIV status, genetic testing, and reproductive health records carry state-specific consent rules in many jurisdictions. Your privacy officer should maintain a one-page state overlay, dated and reviewed annually.

Every Vendor in the Transmission Path Needs an Agreement

Trace the packet's actual route. It likely passes through more hands than your policy manual admits: a cloud fax service, a release-of-information contractor, an image exchange network, a transcription service, a health information exchange, a document management platform, and whoever backs up all of the above.

Each of those that creates, receives, maintains, or transmits PHI on your behalf is a business associate and needs a signed agreement. The common failures are unglamorous: the fax vendor was signed by an office manager in 2019 and the file can't be located, the image exchange network was never papered because "the hospital set it up," or a subcontractor changed hands and nobody re-executed. If you're rebuilding that paperwork from scratch, a signature-ready business associate agreement is faster to generate than to draft, and it gets you a dated artifact you can actually produce.

Two questions to ask about every channel on your approved list: who else touches the data in transit, and what does the vendor's own log show. If the vendor can't answer the second question in writing, your incident response plan has a hole in it.

Information Blocking: The Other Rulebook Governing the Same Packet

HIPAA tells you what you may disclose. The information blocking regulations at 45 CFR Part 171 address practices that are likely to interfere with access, exchange, or use of electronic health information. Reflexively demanding an authorization for a treatment disclosure, imposing unnecessary delays, or refusing to use an available electronic channel can raise questions under that framework as well as slow patient care. ASTP/ONC maintains current material on information blocking, including the exceptions.

Practical translation for your front desk: "we don't do that" is not a defensible answer when a receiving provider requests records electronically for treatment. Train staff to escalate to the privacy officer instead of declining.

When the Patient Asks Instead of the Cardiologist

Different request, different clock. A patient exercising the right of access under 45 CFR 164.524 gets their records within 30 days, with one 30-day extension available if you notify them in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount — labor for copying, supplies, postage. Search and retrieval time is not chargeable.

Right-of-access enforcement has been one of OCR's most consistent activity areas, and the resolution agreements are public on the OCR portal. If a diastolic heart failure patient asks you to send their own records to a new cardiologist in another state, that's a patient-directed transmission under the access right, and the 30-day clock applies — not your referral SLA.

The Audit Trail You'll Wish You Had

Assume a complaint lands eighteen months from now: a patient alleges records went to the wrong cardiology practice. Your defense is the log entry, the verification note, and the policy that staff were trained on. If your log is a spiral notebook at the front desk or a spreadsheet three people edit, you don't have a defense — you have an argument.

The Security Rule requires audit controls and, upstream of that, an accurate and thorough risk analysis covering every system and channel where ePHI moves. NIST's SP 800-66 Revision 2 is the practical companion for scoping that work. Most small and mid-size practices know they need it and stall on the document production. If that's you, automating your risk analysis and policy set gets the paperwork current in days instead of quarters — including the release-of-information and disclosure-logging policies this workflow depends on.

Six Fixes to Make This Quarter

  • Add one bolded line to your ROI procedure: treatment disclosures to other providers require no authorization and are not subject to minimum necessary.
  • Publish a written list of approved transmission channels. Anything not on it requires privacy officer approval.
  • Reconcile that list against your signed BAAs. Every channel, every subcontractor, every date.
  • Standardize the referral packet contents so assembly isn't a judgment call at 4:40 p.m.
  • Assign a named owner for inbound unmatched records with a five-business-day resolution target.
  • Spot-check twenty disclosure log entries per quarter and document that you did.

None of this is clinical. All of it determines whether a diastolic heart failure referral moves in a day or sits in a queue while someone hunts for an authorization form nobody needed. If your risk analysis, policies, and vendor agreements are older than your current staff roster, generate a current compliance document set and start the next quarter with paperwork that matches how your practice actually moves records.