Identification
Clear patient identifiers including full legal name, date of birth, and medical record number to avoid misdirected disclosures and ensure correct record retrieval.
A compliant ROI form creates a documented legal basis for sharing PHI, reduces processing delays, and helps protect patient privacy under HIPAA. It clarifies scope, limits redisclosure, and supports consistent handling across providers, payers, and third-party requestors.
Common participants include patients, clinical records staff, insurance representatives, and legal or research requestors.
Each role has distinct responsibilities: the signer grants consent; the provider verifies identity and documents the disclosure.
The patient or an agent with valid authorization signs to permit release. The signer must have capacity and provide identity evidence; mismatched names or missing authority can invalidate the release and delay disclosure.
Records staff verify identity, confirm the requested scope meets minimum-necessary rules, apply any state-specific constraints, and maintain an audit trail of disclosures and retention actions.
| Field | Configuration |
|---|---|
| Authentication Method | Email link, SMS code, or KBA |
| Required Fields | Name, DOB, MRN, recipient, purpose |
| Witness/Notary | Optional or state-dependent |
| Retention Setting | Retain signed record for 6 years |
Choose a platform that supports HIPAA controls, audit trails, and the file formats you use for medical records.
Ensure the vendor supports required compliance controls (BAA for HIPAA), secure storage (AES-256 at rest), and searchable audit logs to document consent and disclosure events.
Clear patient identifiers including full legal name, date of birth, and medical record number to avoid misdirected disclosures and ensure correct record retrieval.
Precise description of types of records or date ranges being released to limit disclosure to the minimum necessary information for the stated purpose.
Full name and contact information for the recipient, plus preferred transmission method to ensure secure and auditable delivery.
Explicit statement of why records are requested (e.g., continuity of care, insurance claims, legal proceeding) to document lawful use.
A specific expiration date and instructions for revocation must be included to limit ongoing access and define when authorization ends.
Language explaining that once disclosed the recipient may Redisclose PHI according to their policies, plus any state-specific re-release limits.
Plain-language directions for the signer about what to fill, acceptable formats for dates and IDs, and where to initial optional sections to avoid incomplete submissions.
Fields that appear only when relevant (e.g., substance-use records) narrow scope and reduce inadvertent disclosure of sensitive categories.
Capture IP address, timestamp, signer authentication method, and a certificate of completion to document consent and chain-of-custody for compliance reviews.
Include instructions and a clear revocation process that informs patients how to withdraw consent and the effective date of such withdrawal.
Record receipt and assign a tracking number for the request.
Complete identity proofing and agent authority checks.
Identify and assemble responsive records for review.
Transmit records and log delivery confirmation and audit details.
HIPAA requires a response within 30 days (45 CFR §164.524).
One 30-day extension allowed for complex requests with written notice.
Providers must act on record amendment requests within 60 days.
HIPAA accounting requests typically cover disclosures and must meet statutory response windows (45 CFR §164.528).
Maintain access logs and signed ROI copies per retention rules in this guide.
Check whether your state requires notarization or witnesses for this type of release.
Confirm the signer has legal capacity or valid power of attorney.
In-person notarization or Remote Online Notarization (RON) if permitted.
Accept government ID, credential analysis, or multi-factor verification per policy.
Add required witness signatures where state law or facility policy demands them.
Notary must complete and sign the acknowledgment or jurat as applicable.
Retain the required session recording if RON was used.
Log the notarization or witnessing event in the facility journal.
A primary care clinic needs to send cardiology records for consult
An insurer requests ER notes for a claim adjudication
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |