Establishing secure connection…Loading editor…Preparing document…

Healthcare D&A Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE DISCLOSURE AND AUTHORIZATION AGREEMENT

Patient Information

Patient Name:    Date of Birth:    Gender:

Medical Record Number:    Emergency Contact:    Emergency Contact Phone:

Recipient of Information

Recipient Phone:    Recipient Fax:

Information To Be Disclosed (select all that apply)

Full medical record

History and physical    Progress notes

Laboratory results    Imaging/radiology reports

Pathology reports    Billing / insurance records

Mental health records (excluding psychotherapy notes)    Psychotherapy notes (requires specific authorization)

Substance use disorder treatment records (42 CFR Part 2)    HIV-related information

Purpose of Disclosure

Continuity of care / treatment    Insurance / claims / benefits

Legal / litigation    Personal use

Method of Disclosure

Mail    Patient pickup    Fax

Secure electronic transmission    Email for electronic transmission:

Expiration, Revocation & Fees

This authorization will expire on: . If no date is provided, this authorization expires one year from the date of signature.

Revocation: You may revoke this authorization at any time by delivering a written, dated and signed notice to the Medical Records Department or Privacy Officer of the releasing provider, except to the extent that the provider has already acted in reliance on this authorization. Revocation will not affect disclosures made prior to receipt of the revocation.

Fees: I understand that fees for copying and postage may apply. Agreed fee arrangement (if any):

Acknowledgments and Legal Notices

I understand that: (a) signing this authorization is voluntary and my treatment, payment, enrollment, or eligibility for benefits will not be conditioned on signing unless the disclosure is for payment, healthcare operations, or enrollment/eligibility and such conditioning is permitted by law; (b) information disclosed pursuant to this authorization may be subject to re-disclosure by the recipient and no longer protected by federal privacy regulations; (c) certain types of information, including psychotherapy notes, substance use disorder records, and HIV-related information, require special authorization and I have indicated consent for each specific category above.

I further acknowledge that I have the right to inspect and obtain a copy of the health information described on this form, and that this authorization is subject to any applicable legal restrictions on disclosure.

I certify that I am the patient or am authorized to act on behalf of the patient. If signing as a personal representative, I certify that I have legal authority to execute this authorization and must provide documentation of such authority upon request.

Acknowledgement

I have read and understand the terms of this authorization and I authorize the release of the specified information as described above.

Patient Name:

Signature:

Date:

If signed by a representative, attach documentation verifying authority (guardianship papers, power of attorney, court order, etc.).

Enter text✕

What the Healthcare D&A Agreement Is and when it applies

A Healthcare D&A Agreement (Disclosure and Authorization) is a written authorization that allows a patient or their representative to permit disclosure of protected health information (PHI) to specified recipients for defined purposes. It identifies the patient, the authorized recipient(s), the categories of information to be released, the purpose of the disclosure, an expiration or event-based end date, and signature and witness or notarization fields where required. When executed properly it documents patient consent for uses and disclosures not otherwise permitted by HIPAA and forms the legal basis for transferring PHI between covered entities and third parties.

Why a clear Healthcare D&A Agreement matters

A complete, accurate authorization ensures legal compliance under HIPAA, documents patient consent, and reduces disputes about permitted disclosures. It protects patient privacy while enabling necessary care coordination and administrative processing.

Why a clear Healthcare D&A Agreement matters

Who typically completes and relies on this authorization

Common users include providers and administrative staff who must obtain patient consent for PHI release before sharing records or billing information.

  • Physician offices and clinics that need to send records to specialists or insurers.
  • Health systems and hospitals sharing records for care coordination or legal requests.
  • Patients or authorized representatives requesting third-party access to medical records.

Proper role assignment and training reduce errors and ensure the authorization is valid for its intended purpose.

Typical signers and their roles

Privacy Officer

The healthcare organization privacy officer reviews form language for compliance, ensures necessary notice and BAA requirements are met, and maintains audit logs for all disclosures. They coordinate retention and response to patient requests and regulatory inquiries.

Patient or Representative

The patient (or legally authorized representative) must understand the purpose, recipient, and scope of PHI released. The signer must demonstrate intent and consent; mismatches in name or missing signature may invalidate the authorization.

Core elements to include in a professional Healthcare D&A Agreement

A compliant authorization is concise but complete: it identifies parties, scope, purpose, duration, revocation options, and signature blocks plus authentication measures when e-signed.

Patient Identity

Full legal name, date of birth, and an identifying number (medical record or patient ID) to avoid misattribution. Include the patient address or other identifier when available.

Recipient Details

Name and contact information of the individual or organization authorized to receive PHI. Be specific — vague recipients increase legal risk and may limit permissibility.

Scope of Information

List categories (e.g., lab results, mental health, substance use, imaging) or attach a records schedule. Broad phrases like 'all medical records' should be used knowingly and documented.

Purpose of Use

Specify purpose (e.g., continuity of care, insurance claim, legal review). Stated purpose narrows permissible uses and helps auditors evaluate compliance.

Effective Period

Include an expiration date or event triggering termination. Authorizations without expiration or that are unconditional increase compliance risk.

Revocation & Signature

Explain how to revoke the authorization, include signature and date lines, and specify witness or notarization if state law requires it.

Step-by-step: completing a Healthcare D&A Agreement

Follow these steps to prepare, get valid consent, and distribute disclosures while maintaining compliance.

  • 01
    Prepare the form: Pre-fill organization and recipient details.
  • 02
    Confirm identity: Verify patient identity with ID or medical record.
  • 03
    Specify scope: Select exact records and purpose.
  • 04
    Sign and record: Collect signature, record audit trail, store securely.

Configuring a compliant digital workflow

Set up the document fields, signer authentication, retention, and notifications to maintain a defensible electronic record.

Field Configuration
Authentication method Email + SMS code or stronger KBA for high-risk disclosures
Retention setting Retain signed PDF and audit trail for minimum regulatory period
Audit trail details Capture IP, timestamp, and signer actions
BAA requirement Sign Business Associate Agreement when storing PHI

Technical and format requirements for e-submission

Choose a platform that produces tamper-evident signed PDFs, supports required authentication, and can provide an audit trail.

  • File formats: PDF, DOCX supported
  • Integrations: Salesforce, NetSuite, Google Workspace
  • Accessibility: WCAG 2.0 Level AA support

Ensure the vendor can sign a BAA for HIPAA-covered workflows and produce exportable audit logs for compliance and legal review.

How electronic submission and delivery typically work

The e-submission process follows a standard sender-to-signer-to-recipient flow with authentication and automated distribution.

  • Upload document: Sender uploads template and configures fields.
  • Invite signer: Email or secure link sent to patient or representative.
  • Authenticate signer: Sign-in or SMS code confirms identity.
  • Deliver signed copy: System emails completed PDF with audit trail.

Timelines, deadlines, and processing expectations

Plan for timely execution and disclosure: processing times and statutory retention windows affect access and auditability.

Request response timeframe:

HIPAA requires giving access within 30 days in most cases

Processing time:

Allow 3–10 business days to retrieve and transmit records

Effective date:

Authorization effective on the signer date unless specified otherwise

Revocation notice period:

Revocation effective upon receipt; processing varies by policy

Audit availability:

Provide signed copy and audit trail upon request promptly

Key processing stages after an authorization is requested

Track each milestone to ensure timely disclosure, revocation handling, and record retention for compliance and reporting.

01

Request Received

Intake and identity verification start the process.

02

Authorization Completed

Signed authorization is recorded and audited.

03

Records Retrieved

PHI located and prepared according to scope.

04

Disclosure Delivered

Records transmitted and delivery logged in audit trail.

Common mistakes to avoid when preparing an authorization

  • Using vague recipient descriptions such as 'any provider' which can make it unclear what disclosures are permitted and create audit risk.
  • Failing to specify sensitive categories (mental health, substance use) or using inadequate language where state law requires distinct consent.
  • Accepting unsigned or undated forms, or failing to verify signer identity; these errors commonly lead to rework and legal challenges.
  • Omitting clear revocation instructions or expiration, which may result in indefinite PHI access and regulatory scrutiny.

Penalties and legal risks of an incorrect authorization

HIPAA Civil Penalties: Monetary fines and corrective action
Criminal Penalties: Possible imprisonment for knowing disclosures
State Enforcement: Licensing sanctions and fines
Civil Liability: Damages from privacy breach claims
Contract Risk: Invalidated releases and indemnity exposure
Operational Impact: Audits, remediation, and reputational harm

Vendor pricing snapshot for Healthcare eSignature use (signNow first)

Selected pricing and feature indicators for common eSignature vendors. Confirm current plan details with each vendor before procurement.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Security and compliance controls to look for

Encryption — In transit: TLS 1.2 / TLS 1.3
Encryption — At rest: AES-256 encrypted storage
HIPAA Support: BAA available upon request
Certifications: SOC 2 Type II, ISO 27001
Audit Trail: Tamper-evident, exportable logs
Regulated Records: 21 CFR Part 11 support available

Real-world examples of authorized disclosure workflows

These condensed examples show how organizations use authorizations to expedite care and maintain compliance.

John Butler — Fertility Centers of Illinois

Clinic standardized e-authorizations to reduce processing time

  • Implementation used API integrations to autofill patient identifiers
  • The team retained full audit trails and reported fewer retrieval errors, improving compliance and patient satisfaction while enabling remote access when needed.

Kodi-Marie Evans — Xerox

Enterprise operations integrated authorizations into NetSuite workflows

  • Bulk send templates reduced manual tasks
  • This reduced turnaround time for third-party requests and ensured consistent language and retention for audit readiness across subsidiaries.

Practical tips for accurate and efficient completion

Apply consistent practices to reduce rework, protect privacy, and maintain a clear legal record.

Use standardized templates
Create approved templates with mandatory fields, dropdowns for common recipients, and conditional fields for sensitive categories to minimize omissions and ensure consistent language.
Require identity verification
For remote signatures, use multi-factor authentication or knowledge-based verification when releasing sensitive PHI to reduce fraud and ensure signer attribution.
Attach scope exhibits
When releasing large or complex records, attach an itemized exhibit listing specific documents or date ranges to avoid ambiguity and simplify fulfillment.
Log revocations promptly
Track and process revocations immediately; retain revocation records with original authorizations and maintain audit logs for compliance reviews.

FAQs and troubleshooting for Healthcare D&A Agreements

Answers to common questions about validity, revocation, notarization, and electronic execution of authorizations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users