Establishing secure connection…Loading editor…Preparing document…

Healthcare D&A Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE DISCLOSURE AND AUTHORIZATION (D&A)

Patient Name:   Date of Birth:   Gender:

Contact & Insurance

Medical Background (Optional)

Authorization

I hereby authorize the release of my protected health information as described below. Recipient Name:

Purpose of Disclosure (check all that apply):

Continuity of care / treatment    Billing / Claims    Legal / Court Proceeding    At patient request    Other:

Information to be disclosed (check all that apply):

Entire medical record (inclusive of all dates)   
Laboratory results    Imaging reports (X-ray, MRI, CT)    Mental health / psychotherapy notes    Substance use disorder treatment records    HIV-related information    Billing and payment records   

Method of disclosure requested (check all that apply):

Paper copy    Electronic copy (encrypted)    Fax    Fax number:    Secure patient portal   

Duration, Revocation & Redisclosure

This authorization will expire on: . If no expiration date is provided, this authorization expires one year from the date of signature.

I understand I may revoke this authorization at any time by delivering a written revocation to the health record custodian, except to the extent that action has already been taken in reliance on this authorization. Revocation will not affect disclosures already made in reliance on this authorization.

I understand that information disclosed pursuant to this authorization may be subject to re-disclosure by the recipient and may no longer be protected by federal privacy regulations. Additional protections may apply to mental health, substance use disorder, and HIV-related records; such records will be released only if I expressly authorize their release above.

Communications & Acknowledgments

I authorize the recipient named above to communicate with me at the contact information provided for purposes related to the use or disclosure of the records described in this authorization.

I acknowledge that I have been informed of my rights regarding protected health information, including the right to refuse to sign this authorization. I understand that treatment, payment, enrollment, or eligibility for benefits may not be conditioned on my signing this authorization, except as permitted by law.

I acknowledge that I have received or been offered a copy of the facility's Notice of Privacy Practices.

If this authorization is signed by a personal representative, documentation of legal authority (e.g., power of attorney, guardianship documents) must accompany this form.

Optional Instructions / Additional Limits

Signature

Printed Name:

Signature:

Date:

Relationship to Patient:

Enter text✕

What the Healthcare D&A Document Does

The Healthcare D&A Document is a patient authorization for disclosure and use of protected health information (PHI). It documents the patient's informed consent to release specified medical records or to permit access for designated recipients, purposes, and timeframes. Typical uses include sharing records with other providers, insurers, legal counsel, or third-party administrators. The authorization should identify the patient, describe the PHI to be disclosed, name recipients, state the purpose, include an expiration or event, and contain a dated signature or legally authorized representative signature.

Why a Clear Authorization Matters

A precise Healthcare D&A Document protects patient privacy, documents legal consent under HIPAA, and establishes the scope and duration of permitted disclosures. Properly completed forms reduce processing delays, support auditability, and limit downstream disputes about access to PHI.

Why a Clear Authorization Matters

Who Typically Completes and Relies on This Document

Covered entities, patients, and authorized representatives commonly use this authorization to manage PHI sharing.

  • Healthcare providers and clinics — Prepare and retain completed authorizations to satisfy release requests and to document lawful disclosure.
  • Patients and authorized representatives — Provide explicit instructions on recipients, purpose, and expiration; sign or initial required sections.
  • Insurance, legal, and administrative staff — Use the form to obtain records needed for claims, appeals, or legal matters while tracking consent.

Understanding the roles helps ensure signatures are collected correctly and responsibilities are clear.

Core Elements to Include in a Professional Authorization

A complete Healthcare D&A Document follows a standard structure so it is legally effective and operationally useful for requests and disclosures.

Patient ID

Full legal name, date of birth, and a government ID number or medical record number to uniquely identify the patient and avoid misdirected disclosures.

Recipient

Name and contact details of the organization or individual authorized to receive PHI, including mailing address, fax, or secure transfer instructions.

PHI Scope

Clear description of the records or categories of information to be disclosed — e.g., entire medical record, lab results, imaging, mental health notes.

Purpose

Specific purpose for disclosure such as continuity of care, insurance claim, legal representation, or research — avoid vague or unlimited language.

Expiration

A definite expiration date or event (for example, one year from signing or upon case closure) to limit authorization duration.

Signature

Patient or authorized representative signature with printed name, relationship if signed by a representative, and signed date to validate consent.

Step-by-Step: Completing the Authorization

Use this quick sequence to prepare, review, and finalize the Healthcare D&A Document accurately.

  • 01
    Gather IDs: Collect patient ID and medical record number.
  • 02
    Fill Fields: Complete recipient, PHI scope, purpose, and dates.
  • 03
    Verify Identity: Confirm signer identity per entity policy.
  • 04
    Sign and Date: Obtain dated signature and retain a copy.

Options for Digitizing and Automating the Form

Key platform settings to configure for secure online completion and e-submission of Healthcare D&A Documents.

Field Recommended Setting
Authentication Level Email plus SMS code or knowledge-based verification
Signature Type Audit-trail eSignature with timestamp
HIPAA BAA Execute BAA before transmitting PHI
Retention Policy Retain signed copy 6 years per HIPAA

Sharing and Technical Requirements for eSubmission

Choose secure delivery channels and compatible formats when collecting signed authorizations online.

  • Integrations: Connect to EHR or document storage
  • File Formats: Use PDF or PDF/A for permanence
  • Authentication: Email+SMS, KBA, or SSO

Typical Digital Exchange Flow

A secure, auditable workflow reduces errors and creates a retrievable record of consent and transfer.

  • Upload Form: Load blank authorization into the signing platform.
  • Place Fields: Insert name, date, signature, and witness fields.
  • Send to Signer: Deliver via secure link or authenticated email.
  • Archive Record: Store signed copy with audit trail.

Timeframes to Keep in Mind

Certain operational and regulatory deadlines affect processing, revocation, and records management; document timestamps are critical.

Expiration Specification:

Specify an exact date or event to limit consent duration.

Revocation Effective:

Revocation is effective upon receipt by the holder.

Provider Response Time:

Act on access requests within 30 days (45 CFR §164.524(b)).

Retention Requirement:

Keep authorizations for 6 years (45 CFR §164.530(j)).

Special Category Notices:

Psychotherapy notes require separate authorization under HIPAA.

Common Mistakes to Avoid

  • Incomplete recipient details leading to misdirected or refused disclosures and additional verification delays.
  • Vague PHI descriptions such as 'all records' without date ranges, causing processing back-and-forth and denials.
  • Missing or undated signatures, or signed by someone without legal authority to act as authorized representative.
  • Failure to document an expiration or event, creating unclear ongoing authorization and potential privacy risk.

Potential Consequences of Errors

HIPAA Penalties: Civil fines and corrective actions
Unauthorized Disclosure: Civil liability and breach notification costs
Invalid Authorization: Denied requests and administrative delays
Reputational Risk: Loss of patient trust and audits
Operational Cost: Time and resources to remediate errors
Criminal Exposure: Willful misuse may trigger criminal penalties

eSignature Vendor Comparison for Healthcare Authorizations

Basic pricing and capability differences between common eSignature providers; signNow is listed first per platform data and each vendor column shows typical starting price and common feature availability.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes (tiered) Yes Yes Yes Varies
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes Yes Varies Varies

Supporting Documents to Include with the Authorization

Attach identity and context documents to speed verification and ensure the correct records are released.

Photo ID

Copy of state ID or driver's license to confirm signer identity and prevent fraudulent requests.

Insurance Card

Front/back of insurer card or policy number to match claims and reduce retrieval time.

Prior Authorizations

Attach forms authorizing specific procedures if the disclosure relates to a prior consent or approval.

Power of Attorney

If signed by an agent, include a valid power of attorney or documentation establishing representative authority.

Who Can Legally Sign the Authorization

Patient — Signatory

The patient signs when they have capacity. If competent, the patient’s signature documents personal consent to disclose PHI and sets limits on scope and duration of release.

Authorized Representative — Signatory

An agent or legal guardian may sign when properly authorized. Include documentation of authority such as durable power of attorney or guardianship papers.

Notarization and Witnessing: Execution Steps

Follow these steps when a state or organization requires notarization or witnesses for the authorization.

01

Confirm Requirement

Verify whether state or organizational policy mandates a notary or witnesses.

02

Verify ID

Request government-issued ID to confirm signer identity.

03

Arrange Notary

Schedule an in-person notary or RON session if permitted by state law.

04

Execute in Presence

Signer must sign in the presence of the notary or required witnesses.

05

Notary Acknowledgement

Notary adds stamp/acknowledgement and records the act per state rules.

06

Record Journal Entry

Notary or staff record the event in the notary journal where required.

07

Store Secure Copy

Keep notarized signed copy with the patient's record.

08

Revocation Steps

Document any revocation received and distribute notices to prior recipients as needed.

Frequently Asked Questions About Healthcare D&A Documents

Answers to common operational and legal questions encountered when preparing or processing patient authorizations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users