A patient leaves your primary care office on Monday with a sinus complaint, an after-visit summary that includes nasal rinse instructions, and a referral to the ENT group three miles down the road. By Thursday, that ENT's intake coordinator is on the phone with your front desk asking for "everything you have." Nobody in that chain stops to ask whether an authorization is required. This post is for the person who has to know the answer — the administrator, privacy officer, or office manager who owns the referral packet, the fax line, and the vendor list behind both.

The clinical content here is incidental. What matters operationally is that a nasal rinse encounter is a high-volume, low-acuity visit that routinely generates a cross-organizational records transfer, and high-volume workflows are where sloppy habits calcify.

Do You Need Patient Authorization to Send Records to the ENT?

No. Under the HIPAA Privacy Rule, a covered entity may disclose protected health information to another covered entity — or to any health care provider — for that provider's treatment activities without a patient authorization. The provision is 45 CFR 164.506(c)(2). It does not require the receiving provider to have a prior relationship with the patient, and it does not require a signed release form.

Two follow-on points your staff routinely gets wrong:

  • Minimum necessary does not apply to disclosures to a provider for treatment. See 45 CFR 164.502(b)(2)(i). If the ENT wants the full chart, you may send the full chart.
  • Treatment disclosures are excluded from the accounting of disclosures requirement under 45 CFR 164.528. You are not obligated to log the referral packet in an accounting log — though you should still log it somewhere for your own operational reasons, which I'll get to.

HHS maintains a plain-language explainer of permitted uses and disclosures for treatment, payment, and health care operations. Print it. Put it in the front desk binder. It will end more arguments than any policy you write yourself.

Where Staff Invent Requirements That Don't Exist

The most common failure is not over-disclosure. It's under-disclosure — a front desk clerk who insists on a signed release before faxing a chart to a specialist, delaying the referral by four days and generating a patient complaint. That's a training problem, not a privacy problem, but it lands on your desk either way.

The mirror-image failure is treating "treatment disclosure" as a blanket authorization for anything. It isn't. Sending the chart to the ENT is permitted. Sending it to the patient's employer, a device manufacturer's rep, or a marketing partner is not, and none of those are treatment.

What Actually Lives in a Nasal Rinse Referral Packet

Pull one from last month and look at what your system assembled. A typical packet from a primary care visit that ends in a saline irrigation instruction and an ENT referral contains:

  1. The encounter note and problem list
  2. The after-visit summary, including any nasal rinse instruction handout generated from your patient-education content library
  3. Current medication and allergy lists
  4. Any imaging report or order
  5. Insurance and demographic data pulled from registration
  6. Sometimes — unintentionally — unrelated encounters, prior specialist notes from other organizations, and scanned documents whose provenance nobody remembers

Item six is where your exposure sits. Minimum necessary doesn't restrict what you send to the ENT for treatment, but your designated record set definition does determine what you owe the patient later, and your retention policy determines what you should have been holding at all.

The Patient Education Handout Is a Record

Once your system generates a nasal rinse instruction sheet, attaches it to the encounter, and stores it, it's part of that patient's record. If the patient later requests their chart, that handout goes with it. If your content vendor supplies the handout dynamically and your system stores only a pointer rather than the rendered document, you have a records-production problem you haven't discovered yet.

Test it. Ask your records clerk to produce a two-year-old after-visit summary in full, with attachments, and time how long it takes.

The Four Channels Your Referral Packet Travels — and How Each Fails

Fax and E-Fax

Fax remains the default for specialist referrals in most markets. Misdirected faxes are a durable, boring, entirely preventable category of breach. You can review the pattern yourself in the OCR breach portal for incidents affecting 500 or more individuals, and the small-breach log your own practice keeps almost certainly shows the same thing at smaller scale.

Controls that actually reduce misdirected faxes: a maintained, locked directory of specialist fax numbers that staff cannot free-type over; a confirmation page requirement; and a standing rule that any number entered manually gets a second set of eyes. If you use an e-fax service, that vendor transmits and stores PHI on your behalf and is a business associate. Get the agreement signed before the first transmission, not after the first incident.

Direct Secure Messaging and HIE

If your organization participates in a health information exchange or uses Direct messaging, the referral packet may move without touching a fax line at all. That's better, but it changes your obligations rather than removing them: you inherit the exchange's participation agreement, its identity-proofing requirements, and its rules about what you may query. ONC's overview of health information exchange is a reasonable orientation for a new privacy officer.

Patient Portal

Some practices route referral documentation to the patient and let the patient carry it. That's legitimate and often faster. It also shifts the transaction into right-of-access territory, with different timelines and fee rules.

Paper in the Patient's Hand

Still common for a nasal rinse instruction sheet. Low tech risk, high workflow risk — nothing is logged, and if the patient never reaches the ENT, nobody notices. Build a referral-closure check into your care coordination process regardless of privacy considerations.

The Vendor Map Behind One Routine Referral

Sit down and list every third party that touches a single sinus-complaint referral. For most practices the list runs longer than expected:

  • EHR or practice management host — business associate
  • Patient education content library — business associate if it receives patient identifiers or stores rendered documents; possibly not if it's a static licensed content pack that never sees PHI. Determine which, in writing.
  • E-fax or secure transmission service — business associate
  • Appointment reminder / SMS vendor — business associate
  • Transcription or ambient documentation service — business associate
  • Release-of-information contractor, if you outsource records requests — business associate
  • Print-and-mail vendor for referral letters — business associate
  • The receiving ENT practicenot a business associate. They are a separate covered entity receiving a permitted treatment disclosure. Do not sign a BAA with them; it confuses both parties' obligations.

That last distinction trips up more practices than any other item on the list. A specialist you refer to is a peer covered entity. A vendor who moves the referral on your behalf is a business associate. Different paperwork, different liability.

If you find a vendor on that list without an executed agreement — and you will — you can generate a signature-ready Business Associate Agreement and close the gap this week rather than adding it to a remediation list that never gets worked.

A Referral Workflow With Names Attached

Policies fail when nobody owns a step. Here's a workable assignment structure for a two-to-ten-provider practice. Adapt the titles; keep the ownership.

  1. Provider (at close of encounter): marks the referral order, specifies the receiving practice from the locked specialist directory, and flags whether the full chart or a defined subset goes out.
  2. Referral coordinator (same business day): assembles the packet, confirms the destination against the directory, transmits, and files the confirmation.
  3. Referral coordinator (within 24 hours): logs the transmission in the referral tracker — date, destination, method, document count, staff initials.
  4. Front desk (on inbound specialist request): verifies the caller against the directory or a callback number, never a number the caller supplies. Confirms the request is for treatment. Routes to the coordinator.
  5. Privacy officer (monthly): samples ten referral transmissions, checks destination accuracy, and reviews any manual-entry exceptions.
  6. Privacy officer (quarterly): reconciles the vendor list against executed agreements.

Step three is optional under 164.528 and mandatory under common sense. When a patient calls in eight months claiming the ENT never got the records, your tracker is the difference between a two-minute answer and an afternoon of archaeology.

When the Patient Asks You Directly

Different rule, different clock. A patient requesting their own records — including the nasal rinse instruction sheet and the referral letter — triggers the right of access under 45 CFR 164.524. You have 30 days, with one permitted 30-day extension if you notify the patient in writing of the reason and the new date. Fees are limited to a reasonable, cost-based amount, and you must provide the records in the form and format requested if you can readily produce them.

OCR has pursued right-of-access enforcement steadily since 2019, and the fact patterns are unglamorous: small practices that took months, charged a flat per-page rate that wasn't cost-based, or simply didn't respond. Review the HHS individuals' right of access guidance and set a calendar reminder discipline around every inbound request.

Patient-Directed Transmission

If the patient asks you to send the records to a third party of their choosing — a new specialist, a family member, an attorney — that's a written, signed, patient-directed request under the same section, not a treatment disclosure. It requires the patient's written direction identifying the recipient and where to send it. Keep the two paths separate in your procedure document, because staff will otherwise blend them.

Where This Turns Into a Risk Analysis Finding

A referral workflow touches transmission security, workforce training, vendor management, audit logging, and access controls — five Security Rule areas in a single Tuesday-afternoon task. HHS published a proposed overhaul of the Security Rule in January 2025 that, if finalized, would tighten documentation expectations across all of them. Whatever the final shape, the direction of travel is toward more written evidence, not less.

Most practices already do the work. What they lack is the paper: a current risk analysis that names the referral transmission path, policies that match what the front desk actually does, and a vendor inventory that's been reconciled this year. If that describes you, generating your risk analysis and policy set through an automated compliance workflow is a faster route than rebuilding templates from scratch — and it produces the documentation an investigator asks for first.

A Ten-Minute Self-Audit You Can Run This Week

  • Pull three referral packets sent in the last 60 days. Did each go to a verified destination? Is the confirmation retained?
  • Ask two front desk staff whether a signed release is needed to fax a chart to a referred specialist. If either says yes, schedule training.
  • Open your specialist fax directory. When was it last verified against the receiving practices?
  • List every vendor that touches referral data. Match each to an executed agreement with a date.
  • Time a full records production for a two-year-old encounter, attachments included.
  • Confirm your right-of-access log shows a response date for every request in the last six months.

Every one of those checks is cheap. Every one of them surfaces a problem you would otherwise discover during a complaint investigation.

Next Step

Pick the two weakest items from that self-audit and fix them before the end of the month — the fax directory and the vendor agreement list are usually the fastest wins. Then get your underlying documentation current, so the next records request, complaint, or vendor questionnaire is a retrieval task rather than a scramble. Build your risk analysis and compliance document set and stop treating the paperwork as the thing you'll get to after the busy season.