Clear Disclosure
Plain-language statement of risks from unencrypted email and alternatives such as a secure patient portal or encrypted messaging.
A written consent clarifies permission to transmit protected health information (PHI) by email, documents patient choice under HIPAA privacy rules, and provides a reproducible record for compliance and audit purposes.
Maintaining a signed consent reduces ambiguity about communication channels and supports HIPAA recordkeeping obligations.
The patient (or authorized representative) signs to indicate informed consent for email delivery of specific categories of PHI, acknowledging risks and the right to revoke consent in writing or via documented request.
A clinician or administrative staff member documents who explained the risks and recorded the consent; their signature verifies that required disclosures and technical limitations were communicated to the patient.
| Field | Configuration |
|---|---|
| Authentication | Email code or SMS OTP for signer verification |
| Document Storage | Encrypted archive with access controls |
| Audit Trail | Capture timestamp, IP, and signer actions |
| BAA | Execute business associate agreement for PHI handling |
Choose systems that offer auditable e-signatures, a BAA where PHI is processed, and integration with your record retention workflows.
Effective immediately upon valid signature
Process revocation promptly on receipt
60 days for large breaches (45 CFR §164.400 et seq.)
Retain from effective date per retention rules
Keep records available for regulatory review
Form completed and signed, identity verified.
Confirm email via test message or code.
Authorized email communications begin per scope.
Periodic review or renewal of consent as policy requires.
Plain-language statement of risks from unencrypted email and alternatives such as a secure patient portal or encrypted messaging.
Explicit list of message types permitted (e.g., appointment reminders, test results, billing) to avoid overbroad authorization.
Information on how long the consent will be retained and how the patient can obtain a copy for their records.
Simple instructions for how to withdraw consent, including contact method and effective date of revocation.
Permit wet or electronic signature, ensuring electronic execution meets ESIGN (15 U.S.C. §7001) requirements for intent and attribution.
Indicate whether a Business Associate Agreement governs vendor processing of PHI and where to obtain a copy.
PDF or PDF/A copy of the signed form stored in the EHR and in a secure document archive for auditability.
Record of verification message or OTP showing the address was validated before PHI transmission.
Executed Business Associate Agreement for any third party involved in storage or transmission of PHI.
Provider privacy practices summary and instructions on revocation and alternatives to emailing PHI.
| Criteria | Direct Email Consent | Secure Patient Portal |
|---|---|---|
| Security Level | lower | higher |
| Patient Convenience | high | moderate |
| Auditability | ||
| PHI Scope Controls | manual | granular automated |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |