regarding HIPAA regulations
Having been a hospital administrator for many years, and through the evolution of HIPAA and several JCAHO surveys I thought I would throw this in, since HIPAA was mentioned...
As far as I know, HIPAA regulations apply to health-care providers, insurance companies and other vendors that are in the reporting end of that business. If you aren't a health-care provider, insurance co., clearinghouse or a provider of equipment, then the very minimum requirement for you would be to get a 38USC7332 (speaks to information on HIV/Alcohol/Drugs/Sickle Cell) specific Authorization to release information signed AND dated; I don't think you have to worry about the rest of the HIPAA regs and standards.
...required when using individually identifiable healthcare information for a purpose other than treatment, payment, and/or health care operations.
...All authorizations MUST contain an expiration date, event or condition, and be signed by the patient and must be returned to the requestor.
USC7332 releases require that the purpose of needing the information and what it is to be used for be documented as well.
Keep in mind that if there is no specific expiration date on the release, it is not valid.
A sample USC7332 release can be found here:
http://www.va.gov/vaforms/medical/pd...-5345-fill.pdf
Just my opinion... I've also been a management consultant for behavioral health providers for a few years, and have had to deal with this type of issue since many of our clients' patients had Alcohol/drug issues...