Metformin for Prediabetes: Records Sharing Workflow
It is 8:40 on a Tuesday. Your medical assistant has a stack of six referral packets to send out before lunch, and one of them is a shared-care handoff for a patient whose primary care visit involved a discussion of metformin for prediabetes. The receiving endocrinology group wants labs, the medication list, the last two progress notes, and the problem list. Your MA is holding a fax cover sheet and asking whether she needs a signed release.
This article answers that question and the twelve that follow it. It is a records and privacy workflow piece for practice administrators, privacy officers, and release-of-information staff. It does not tell you anything about how the medication is used clinically, and it should not inform any clinical decision. It tells you which disclosures the Privacy Rule permits without authorization, where the minimum necessary standard does and does not apply, which transmission channels drag a vendor contract behind them, and what your audit trail needs to show eighteen months from now.
Why a Metformin for Prediabetes Referral Needs No Authorization
Encounters that involve metformin for prediabetes tend to generate cross-organizational traffic: a primary care visit, a lab draw at an outside facility, sometimes a specialist consult, sometimes enrollment in a structured lifestyle change program. That is the only clinical fact this article relies on — these encounters move records between organizations, which is exactly the fact pattern the Privacy Rule's treatment provisions were written for.
Under 45 CFR 164.506(c)(2), a covered entity may disclose protected health information to another covered entity or to a health care provider for that provider's treatment activities. No authorization. No signed release. No patient consent form, unless your state law or your own policy imposes one. HHS states this plainly in its guidance on uses and disclosures for treatment, payment, and health care operations.
The practical consequence: if your release-of-information staff are chasing signatures for routine provider-to-provider referrals, they are burning hours on a step the regulation does not require, and they are delaying care while they do it. That delay is not a HIPAA violation, but it is an operational defect that shows up in patient complaints and in referral leakage reports.
Do You Need Patient Authorization to Send Records to a Specialist?
No. HIPAA permits a covered entity to disclose PHI to another health care provider for that provider's treatment of the patient without patient authorization. This includes referral packets, consult requests, lab results, medication lists, and progress notes. Three qualifications:
- State law may be stricter. Several states require written consent before releasing certain record categories, and stricter state law preempts HIPAA. Your privacy officer should maintain a one-page state-law overlay, not a memory.
- Specially protected categories have their own rules. Records from a federally assisted substance use disorder program fall under 42 CFR Part 2, and HIV, genetic, and behavioral health records carry state-specific restrictions. A medication list pulled straight from the chart can carry these categories along with everything else.
- A patient restriction request may be on file. If you agreed to a restriction under 164.522, honor it. Your EHR should flag it at the point of release, not in a binder.
The Minimum Necessary Carve-Out Your Staff Probably Doesn't Know About
Here is the detail that surprises even experienced release-of-information clerks: the minimum necessary standard does not apply to disclosures made to a health care provider for treatment purposes. That exception sits in 45 CFR 164.502(b)(2)(i), and HHS confirms it in its minimum necessary guidance.
The treating provider decides what they need. You are not required to redact a chart down to the referral question before sending it to the consulting endocrinologist.
Where Minimum Necessary Snaps Back Into Force
The exception is narrow, and your staff will over-apply it if you do not draw the line clearly:
- Payer requests. A prior authorization review is a payment disclosure. Minimum necessary applies. Send the clinical documentation the payer's criteria require, not the entire chart.
- Program vendors and care management platforms. If the recipient is performing a service for you rather than treating the patient, you are in business associate territory and minimum necessary applies.
- Employer wellness programs. A common and expensive failure point. An employer-sponsored program is almost never a treating provider.
- Internal access. Role-based access controls inside your own EHR are still governed by minimum necessary.
Write both halves into your policy in the same paragraph. Staff who learn only the exception will over-disclose; staff who learn only the rule will delay referrals.
The Channel Question: What Rides Along With Your Transmission Method
The disclosure may be permitted. The channel still has to satisfy the Security Rule.
Fax
Analog fax to a dedicated line remains permissible with reasonable safeguards: verified number, confirmation sheet retained, misdirected-fax procedure documented. If you use fax-over-IP or a cloud fax service, that service is storing and transmitting ePHI on your behalf and needs a signed business associate agreement. Check whether yours is on file. A surprising number of practices inherited a fax vendor during a phone system migration and never papered it.
Direct Secure Messaging and HIE
Direct messaging through a health information service provider, or query-based exchange through a regional HIE, is the cleaner path for provider-to-provider referrals. The HISP or HIE typically acts as a business associate, and participation agreements govern the rest. ONC maintains background on exchange models and interoperability at healthit.gov. Confirm two things before you rely on it: that your BAA or participation agreement is executed, and that your staff can produce a transmission receipt on demand.
Unencrypted email to another organization is where practices get themselves into trouble. Use an encrypted channel or your portal. If a patient asks you to send their records to a specialist by ordinary email and you warn them of the risk, that request is a patient-directed transmission and follows the access rules, not the referral rules — document the request and the warning.
The Specialist Is Not Your Business Associate — Stop Sending Them a BAA
A recurring time sink: your practice sends a BAA to the receiving endocrinology group before releasing the referral packet, and their compliance staff sends it back unsigned with a polite note. They are correct. A separate covered entity receiving PHI for its own treatment of the patient is not acting on your behalf and does not need a BAA with you.
The BAA belongs on the vendor layer, not the provider layer. The list that actually needs papering:
- Cloud fax and secure messaging vendors
- Release-of-information outsourcing firms
- Referral management and e-consult platforms
- Transcription services
- Care coordination or lifestyle-program platforms you contract with
- IT support with access to systems holding ePHI
If a referral partner or vendor turns up on that list without an executed agreement, you can generate a signature-ready business associate agreement and close the gap the same afternoon rather than waiting for a legal review cycle.
A Worked Twelve-Day Referral Loop, With Names on Each Step
Assign every step to a role. Steps without an owner become steps nobody did.
- Day 0 — Provider. Places the referral order in the EHR with a stated referral question. The question matters: it is what lets you defend the scope of what you sent.
- Day 0 — Referral coordinator. Checks for a patient restriction flag and for specially protected record categories. Confirms the recipient's Direct address or verified fax number against the master destination list, not against a sticky note.
- Day 1 — Referral coordinator. Transmits the packet through the approved channel. Saves the transmission receipt to the chart.
- Day 1 — EHR. Logs the disclosure automatically. Verify quarterly that it actually does.
- Days 2–5 — Referral coordinator. Confirms receipt and appointment scheduling. Unconfirmed referrals older than five business days go on a worklist.
- Days 6–12 — Front desk. Receives the consult note back. Files it, closes the referral loop, notifies the ordering provider.
- Monthly — Privacy officer. Samples ten closed referrals. Checks destination verification, receipt retention, and whether any packet went out through an unapproved channel.
What You Must Log, and What You Don't Owe the Patient
Treatment disclosures are excluded from the accounting of disclosures a patient can request under 164.528. That is not permission to skip logging. Your disclosure log is the evidence that a release was authorized, correctly scoped, and correctly addressed — and it is the first thing anyone asks for when a packet lands at the wrong practice.
Separately, when the patient asks for their own records, a different clock starts. You have 30 days, with one permitted 30-day extension and written notice of the reason. HHS's right of access guidance is worth handing to every staff member who touches records requests. Access enforcement has been one of OCR's most consistent priorities for years, and the failures are mundane: the request sat in a shared inbox, the fee was wrong, nobody logged the receipt date.
Five Failure Points an Audit Actually Finds
- Cloud fax vendor with no executed BAA.
- Destination fax numbers stored by individual staff rather than in a maintained master list.
- Referral packets sent from personal or unencrypted email during EHR downtime.
- Payer requests fulfilled with the entire chart because staff applied the treatment exception to a payment disclosure.
- Risk analysis that never mapped the referral pathway as a flow of ePHI leaving the organization.
Your Risk Analysis Has to Include the Referral Pathway
The last item is the one that costs the most and gets the least attention. If your risk analysis inventories servers and workstations but never traces where PHI physically leaves the building — the fax line, the HISP, the referral platform, the courier — it is incomplete. The Security Rule requires an accurate and thorough assessment of risks to all ePHI you create, receive, maintain, or transmit. Transmit is doing real work in that sentence. The Security Rule updates HHS proposed in January 2025 pointed even harder in this direction, with more explicit expectations around asset inventories and network mapping.
Practices with two clinicians and one referral coordinator rarely have staff hours for a documentation build of that size. If your risk analysis is a spreadsheet somebody started in 2022, using a platform that automates HIPAA risk analysis reports and the supporting policy set gets you a current, defensible document without a consulting engagement. No product is a government certification — HHS does not certify or endorse compliance tools — but a complete, dated risk analysis with named remediation owners is what OCR asks for first, and what most practices cannot produce.
Three Changes to Make This Week
First, put the treatment exception and the minimum necessary carve-out on a single laminated page at the release desk, with the payer-request exception in bold. Second, pull your vendor list and confirm every entity touching referral transmission has a signed BAA on file. Third, run the ten-referral sample audit described above and see what your logs can actually prove.
A referral packet built around metformin for prediabetes is not a hard privacy problem. It becomes one when nobody has written down which rule applies, who owns each step, and which vendor is sitting in the middle of the wire. Start with the risk analysis and the vendor inventory — build the documentation set once, then maintain it, and the rest of the workflow stops being a judgment call every Tuesday morning.