Scope
Define exactly which PHI types, treatments, or disclosures the addendum covers and any exclusions to avoid ambiguity.
A clear addendum reduces ambiguity about permitted uses of PHI, documents patient decisions for audits and disputes, and supports regulatory compliance such as HIPAA. It creates a signed record that can be relied on in clinical, billing, and legal workflows while preserving patient choice.
Clinics, hospitals, and individual practitioners attach this addendum when care or data handling differs from standard consent or when extra authorizations are required.
Use by these groups ensures the addendum is completed, stored, and enforced alongside the primary consent in the patient record.
Define exactly which PHI types, treatments, or disclosures the addendum covers and any exclusions to avoid ambiguity.
List the persons, organizations, or providers permitted to receive PHI or perform the specified procedures, including role descriptions.
State the reason for the additional consent (research, specialist referral, telehealth, third-party billing), linking action to the permitted purpose.
Set a clear effective date and expiration or event-based termination (e.g., end of treatment episode) to limit open-ended access.
Provide instructions for withdrawing consent and explain exceptions where revocation does not apply, such as actions already taken.
Include printed name, signature, date, and contact for the signer and, if applicable, space for witness or notary details.
| Field | Configuration |
|---|---|
| Authentication Level | Email link or SMS code; use stronger methods for sensitive disclosures. |
| Audit Trail | Capture IP, timestamp, and signer actions for legal evidence. |
| Document Retention | Apply record retention tags per HIPAA and organizational policy. |
| Access Controls | Limit view/edit rights to care team members and compliance staff. |
Use a platform that supports encryption, audit logs, and HIPAA-compliant handling when sending addenda electronically.
Confirm platform certifications and agreements before eSubmitting PHI-sensitive addenda to maintain HIPAA compliance and defensible records.
Sign the addendum prior to the relevant treatment or disclosure whenever possible.
Send to compliance or the EHR within 24–48 hours of signing.
Retain electronic evidence and metadata immediately for auditability.
Process revocations promptly and document the effective date of withdrawal.
Provide copies on request per HIPAA access timelines (typically 30 days).
Create and populate addendum fields before patient interaction.
Explain and obtain informed consent at the point of care.
Collect signatures, witness, or notary as required.
Attach to the medical record and index for retrieval.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
The clinic attached a focused consent addendum for embryo storage authorization and data sharing
A compliance group used addenda to document telehealth recording permissions for behavioral health sessions