California Authorization for Use or Disclosure of Health
What this California health authorization does and when it applies
Why a clear authorization matters for patients and providers
A properly completed authorization clarifies consent, allocates responsibility, and documents the lawful basis to share PHI. It reduces delays in care coordination and supports compliance with HIPAA and applicable California privacy rules while preserving the patient’s control over disclosure.
Who typically completes or receives this authorization
Use the correct form version and retain a copy in the medical record to show consent and handling instructions.
- Patients or authorized representatives who want records sent to another provider, insurer, or third party.
- Healthcare providers and medical records offices responding to requests for record transfer or care coordination.
- Insurers, legal counsel, or third-party requestors when documentation of consent is required.
Common signer roles and what they need to know
Patient
The patient signs to authorize disclosure. If a minor or incapacitated, a parent, legal guardian, or authorized surrogate must sign and should attach proof of authority.
Authorized Representative
A person signing on behalf of the patient must present a power of attorney, guardianship order, or other documentation showing legal authority; photocopies should be kept with the authorization.
Step-by-step: completing the authorization form
-
011. Identify: Enter the patient’s legal name and DOB exactly as on ID.
-
022. Specify: Describe PHI clearly, including date ranges and document types.
-
033. Designate: Name the recipient with full contact information.
-
044. Sign: Signer must date and sign; include relationship if signing for patient.
Digital workflow settings when sending electronically
| Field | Configuration |
|---|---|
| Authentication Level | Email link | SMS code | ID check |
| Document Retention | Secure storage | Audit trail enabled |
| Signer Role | Patient | Representative |
| Auto-routing | Send to EHR | Records department |
Technical considerations for e-signatures and electronic exchange
Confirm a Business Associate Agreement if PHI will be processed or stored by the e-signature provider.
- Formats Supported: PDF, DOCX, PDF/A
- Integrations: EHRs, Google Workspace, NetSuite
- Security: AES-256 at rest, TLS 1.2/1.3
Where completed authorizations are sent and retained
-
Send to Provider: Records office uploads to EHR or chart.
-
Send to Recipient: Mail, secure email, or direct EHR transfer.
-
Retain Copy: Provider keeps signed authorization in medical record.
-
Audit Log: System stores timestamp, IP, and signer details.
Timing considerations and typical processing expectations
Processing Time:
Providers often process requests within 5–30 business days.
Revocation Effect:
Revocation is effective upon receipt; prior lawful disclosures are not retroactively invalidated.
Access Requests:
HIPAA access requests should be honored within timelines set by covered entities.
Expiration Date:
Use a clear expiration date; otherwise default limitations may apply.
Third-Party Delivery:
Courier or mail adds additional transit time.
Common preparation mistakes that delay disclosure
- Incomplete recipient contact details that prevent successful delivery and require resubmission.
- Vague PHI descriptions that lead providers to deny or limit the release scope.
- Missing signature, date, or representative authority documentation causing form rejection.
- Using noncompliant transmission channels for PHI which creates privacy and security risks.
Legal and privacy risks from incorrect authorizations
eSignature vendor pricing and feature snapshot for PHI authorizations
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Real-world examples of streamlined authorizations
Optica Ventures LLC
The interface is simple and easy-to-use for our team; more importantly, it is just as easy for our customers.
- Focus on user-friendly forms reduced back-and-forth.
- As COO Brian Fitzgibbons reports, clearer authorizations cut processing time and improved customer satisfaction while maintaining compliance.
Fertility Centers of Illinois
The team praised responsive support and reliable API integration for record transfers.
- Integration with existing systems was key.
- The founder John Butler notes the platform enabled secure, auditable sharing of sensitive health records without adding manual steps.
Tips to complete authorizations accurately and efficiently
Frequently asked questions about California health authorizations
-
Can this authorization be signed electronically?
Yes. Electronic signatures are generally valid under the ESIGN Act (15 U.S.C. §7001) and UETA when the signer demonstrates intent, consent, attribution, and the record is retained. Ensure the e-signature vendor supports required authentication and that a BAA is in place if PHI is processed.
-
What happens if a required field is missing?
A missing essential field such as recipient, PHI description, signature, or expiration can cause the request to be denied or delayed. Resubmit a complete form and retain the original as part of the patient record.
-
How can a patient revoke an authorization?
Patients may revoke authorizations in writing. Revocation takes effect when received but does not undo disclosures made in reliance on the earlier authorization; record revocation and update internal routing accordingly.
-
Do providers need a BAA with the e-sign vendor?
If the vendor handles PHI as a service on behalf of a covered entity, a Business Associate Agreement is required under HIPAA. Confirm contractual and technical safeguards before transmitting PHI.
-
Are there special rules for sensitive records?
Certain records—such as mental health notes, substance use treatment, or HIV-related information—may require additional consent language or stricter state protections; check California statutes and facility policy.
-
How long should the signed form be retained?
Retain signed authorizations at least six years to satisfy HIPAA documentation requirements (45 CFR §164.530(j)); state law may require longer retention for some record types.