HIPAA Training for Foundation Officers: What to Do Before Sharing Patient Stories at Fundraising Galas

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Training for Foundation Officers: What to Do Before Sharing Patient Stories at Fundraising Galas

Kevin Henry

HIPAA

August 21, 2026

8 minutes read
Share this article
HIPAA Training for Foundation Officers: What to Do Before Sharing Patient Stories at Fundraising Galas

Patient stories can ignite generosity, but they also touch Protected Health Information (PHI). This guide equips foundation officers to translate HIPAA into event-ready practice, reduce PHI disclosure limitations, and strengthen fundraising privacy compliance before a single script, video, or invitation leaves your desk.

HIPAA Training Requirements for Foundation Officers

Foundation officers who access or use PHI for development activity are part of the covered entity’s workforce for privacy purposes. They must receive role-based HIPAA training that is “necessary and appropriate” for their duties before working with patient information and whenever responsibilities change.

Core topics your training should cover

  • What counts as PHI and typical fundraising touchpoints where it appears (stories, photos, donor spotlights, videos, programs).
  • Fundraising allowances and PHI disclosure limitations, including opt-out obligations for solicitations.
  • De-Identification Standards: Safe Harbor vs. Expert Determination, with practical examples for narratives and media.
  • The Minimum Necessary Rule, role-based access, and content scoping for campaigns.
  • HIPAA Authorization basics, when it is required, and how to verify validity.
  • Incident reporting, vendor management (BAAs where appropriate), and secure handling of files and devices.

Timing and documentation

  • Provide training at onboarding, upon role change, and periodically as policy requires; refresh promptly when procedures or laws change.
  • Record attendance, date, curriculum, and trainer. Retain records according to your retention policy.

Evaluating Patient Story Identifiers

Before drafting a testimonial, identify whether the narrative contains PHI. PHI includes any information that relates to an individual’s health, care, or payment and can reasonably identify the person. Names, faces, specific dates, unique circumstances, and small-population facts can all re-identify a patient.

Red flags in patient narratives and media

  • Direct identifiers: name, photo or recognizable video, voice recordings, contact details, or medical record numbers.
  • Quasi-identifiers: precise dates of admission/discharge, rare conditions, exact age if over 89, detailed geography, or a very distinctive care path.
  • Context clues: mentions of a school, employer, community event, or caregiver that make a case uniquely identifiable.

Using De-Identification Standards

  • Safe Harbor: remove the enumerated identifier categories so the story cannot reasonably identify the individual.
  • Expert Determination: have a qualified expert document that the risk of re-identification is very small given your intended audience and distribution.

Practical de-identification tips for stories

  • Combine or generalize facts: use age bands, broader time frames (e.g., “last spring”), and larger geographic areas.
  • Avoid naming specific clinicians unless permitted by the fundraising allowance or covered by HIPAA Authorization.
  • Use staged or stock visuals not tied to the patient; blur or crop identifiable features when necessary.
  • Test your draft: could a neighbor, coworker, or small community recognize the patient from the details? If yes, pursue authorization.

Understanding Authorization Requirements

When a story includes PHI that goes beyond what HIPAA permits for fundraising communications, you need a HIPAA Authorization. This is common for gala videos, stage interviews, and feature articles that mention diagnoses, treatment details, or show a patient’s image or voice.

Scenarios that require HIPAA Authorization

  • Using names, faces, direct quotes, diagnosis or treatment details in any medium.
  • Disclosing a story to event vendors, the press, public websites, or social media.
  • Reusing a previous story for a new campaign when the original authorization doesn’t cover the new purpose, audience, or duration.

Elements of a valid HIPAA Authorization

  • Specific description of the information to be disclosed (e.g., name, photo, diagnosis, treatment timeline).
  • Who may disclose and who may receive the information (hospital, related foundation, named vendors, media).
  • Purpose of disclosure (e.g., “to share the patient’s story at the 2026 fundraising gala and related promotions”).
  • Expiration date or event, stated clearly (e.g., “end of the 2026 gala campaign”).
  • Statements about the right to revoke, the consequences of not signing (no effect on care), and the potential for redisclosure.
  • Signature and date of the individual or personal representative, with authority documented when applicable.

Special considerations

  • Minors or incapacitated adults: obtain authorization from the legal representative; plan for transitions when minors reach the age of majority.
  • Language access: provide plain-language forms and interpreter support as needed.
  • Scope control: disclose only what the authorization permits, for the channels and timeframe it specifies.

Coordinating Fundraising Communications

Development and privacy teams should align early so solicitations and gala content follow fundraising rules and honor opt-outs. Maintain a clear separation between permissible fundraising communications and any story that requires authorization.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What HIPAA permits for fundraising without authorization

  • Demographic information and contact details to send fundraising appeals.
  • Dates of health care provided, department of service, treating physician, outcome information, and insurance status for segmentation.
  • Each solicitation must provide a clear, simple way to opt out; choices must be honored across future fundraising efforts.

Operational controls for gala campaigns

  • Use scripts that stay within permitted categories unless a signed HIPAA Authorization expands the scope.
  • Coordinate with IT and analytics so only the minimum fields authorized for fundraising are shared with the foundation or vendors.
  • Execute Business Associate Agreements when vendors create, receive, maintain, or transmit PHI on your behalf.
  • Remember: event signage or ticket language does not replace a HIPAA Authorization for patient stories.

Applying the Minimum Necessary Standard

The Minimum Necessary Rule limits internal uses and routine disclosures of PHI to what is needed to accomplish the task. For permitted fundraising uses, share the smallest dataset that still meets the campaign’s purpose.

Disclosures made pursuant to a HIPAA Authorization are not subject to the Minimum Necessary Rule; however, you must still confine disclosures to the exact scope described in the signed authorization and avoid unnecessary spillover.

Practical application

  • Role-based access: grant development staff only the PHI elements they need for segmentation or stewardship.
  • Story scoping: if a diagnosis adds little to donor understanding, omit it—even with authorization.
  • Media review: strip metadata from images and redact nonessential details in captions and lower-thirds.

Routing Stories for Privacy Review

A predictable Privacy Review Workflow reduces risk and speeds approvals. Treat every patient story as a mini-project with documented checkpoints before production begins.

Privacy Review Workflow

  • Intake: use a standard form capturing proposed content, media, audiences, and distribution channels.
  • Screen: determine if the story can be de-identified; if not, initiate the HIPAA Authorization process.
  • Draft review: privacy reviews the script, visuals, captions, and run-of-show for PHI and Minimum Necessary Rule alignment.
  • Vendor alignment: confirm BAAs where needed and provide only approved assets.
  • Final approval: lock the version used at the gala; store it with the signed authorization and review notes.
  • Event controls: brief emcees and speakers to avoid ad-libbed PHI; manage Q&A to prevent unscripted disclosures.
  • Post-event audit: document where and when the story appeared; schedule takedowns per the authorization’s expiration.

Documenting Authorization and Compliance

Strong records prove compliance and streamline future campaigns. Keep a central repository that ties each asset to its legal basis (de-identified, permitted fundraising data, or HIPAA Authorization) and its approval path.

Compliance artifacts to retain

  • Signed HIPAA Authorizations (or expert determinations for de-identification) with versioned scripts and final media.
  • Revocations and the date you stopped further use or disclosure.
  • Opt-out logs for solicitations and suppression lists applied to all fundraising channels.
  • Approval emails, privacy review checklists, and vendor agreements.
  • Access logs and audit trails for who viewed or handled PHI throughout the campaign.

Retention and reuse

  • Retain required documents for at least six years from the date created or last in effect, whichever is later.
  • Before reusing a story, confirm that the authorization still covers the new channel, audience, and timeframe; if not, obtain a new one.

Conclusion

By pairing role-based HIPAA training with disciplined story vetting, precise HIPAA Authorizations, and a documented Privacy Review Workflow, you can showcase powerful patient stories at fundraising galas while honoring the Minimum Necessary Rule and maintaining rigorous fundraising privacy compliance.

FAQs.

When is HIPAA training required for foundation officers?

Provide training before officers access or handle PHI and whenever roles, systems, or procedures change. Most organizations also schedule periodic refreshers by policy to reinforce responsibilities tied to fundraising and event workflows.

How can patient stories be shared without violating HIPAA?

Use one of three paths: de-identify the story under recognized De-Identification Standards; rely only on PHI elements permitted for fundraising with clear opt-outs; or obtain a signed HIPAA Authorization that specifically covers the information, audiences, and timeframe for gala use.

What constitutes valid HIPAA authorization for fundraising?

A valid authorization clearly describes the information to be shared, who may disclose and receive it, the fundraising purpose, and an expiration date or event. It includes statements about the right to revoke, that care is not conditioned on signing, and potential redisclosure, and it must be signed and dated by the individual or authorized representative.

How should organizations document patient authorization for story sharing?

Store signed forms (including any translations), approved scripts, final media, and distribution records in a central repository. Track revocations, apply suppression to all channels, and retain records for at least six years. Verify authorization scope before any reuse or reposting.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles