This sample outlines a set of policies and procedures regarding covered entities obtaining authorization to use or disclose protected health information (PHI). HIPAA requires a covered entity to obtain authorization to use or disclose protected health information for all purposes not explicitly permitted under the regulations (45 CFR §164.508(b)(4); §164.508(c); §164.508(d)).