Either way, you need a paper trail with the individual’s signature.
When a patient wants a covered entity (CE) to disclose his protected health information (PHI) to a third party, HIPAA regulations cover this situation in two separate ways. In one way, this is a required disclosure under HIPAA’s right of access. In another way, this is a permitted disclosure with a valid HIPAA authorization.
If you find this overlap of the HIPAA rules confusing, here’s a handy table that illustrates the differences between the two:
Source: www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html.