Patient Identifiers
Full legal name, date of birth, and any medical record number to ensure records are correctly matched and retrieved.
This authorization establishes lawful patient consent to disclose PHI and clarifies scope, duration, and recipients. It protects patient privacy, documents consent for third-party access, and enables providers and payers to exchange necessary records while meeting HIPAA requirements.
Common parties involved include patients, authorized representatives, healthcare providers, insurers, and legal counsel; each has distinct responsibilities when creating or receiving the form.
Ensure the person completing the form has authority to consent and that the receiving party is clearly identified to avoid unauthorized disclosure.
The patient is the primary signer when of legal capacity; the signature documents voluntary consent for specific PHI disclosures and should match the name on the medical record to avoid processing delays.
A legally appointed guardian, parent for minors, or person with durable power of attorney may sign when permitted by law; organizations should verify authority with documentation before releasing PHI.
| Field | Configuration |
|---|---|
| Patient ID Field | Required, text field, validation enabled |
| Recipient Email | Required, validated format |
| PHI Scope Field | Multi-line, required selection options |
| Signature Field | Required, capture timestamp and IP |
Confirm platform capabilities before accepting electronic authorizations to ensure legal validity and secure handling of PHI.
Choose a platform with HIPAA support (BAA available), robust audit trails, and integrations to your EHR or document management system for secure exchange.
Enter the date authorization begins.
Specify expiry date or event; default often 90 days.
Typical release within 7–30 days depending on volume.
Mark urgent; some providers expedite within 3 business days.
Revocation affects future disclosures only once received.
Patient submits signed authorization to provider.
Provider verifies identity and authority.
Staff locates and compiles relevant records.
Provider transmits records to recipient and logs activity.
Full legal name, date of birth, and any medical record number to ensure records are correctly matched and retrieved.
Full recipient name and organization plus secure contact details to reduce misrouting and support secure delivery methods.
Precise description of the records, types, and date ranges to avoid overly broad releases and protect unrelated information.
A narrowly tailored purpose (treatment, billing, legal) that informs the provider’s decision to release records under policy.
A clear expiration date or triggering event so the authorization does not permit indefinite access to PHI.
Patient or authorized representative signature, printed name, relationship, and date to document consent and legal authority.
A primary care clinic needs imaging and lab results sent to a cardiologist
An attorney requests records to support a personal injury claim
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA required) | Yes (BAA available) | Yes (BAA available) | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies | Varies | Varies |