Patient identity
Full legal name, date of birth, and a secondary identifier such as medical record number to avoid misattribution.
A clear consent form reduces legal risk, documents patient authorization, and supports HIPAA compliance where images contain protected health information. It also establishes expectations about use, duration, and revocation rights, which protects the provider and preserves patient trust.
Providers, clinical staff, researchers, and communications teams use this form to collect documented photo permission before capturing or publishing identifiable images.
The signer should be the patient or an authorized representative; when the patient lacks capacity, follow institutional capacity and surrogate decision-maker policies.
Full legal name, date of birth, and a secondary identifier such as medical record number to avoid misattribution.
Specific description of intended uses—clinical, educational, research, internal training, or external marketing—with checkboxes where practical.
Define distribution channels (internal file, intranet, website, social media, publications) and any geographic limits on use.
Note whether still photos, video, or derived images (cropping, anonymization) are covered and whether identifying features may be shown.
State how long images will be retained, who controls deletion, and whether backups or archives apply to the policy.
Include signer name, signature, date, relationship to patient (if applicable), and a space for witness or notary when required.
| Field | Configuration |
|---|---|
| Authentication Method | Email link, SMS code, or stronger MFA depending on PHI level |
| File Format | Use PDF/A or PDF with preserved metadata for record integrity |
| Conditional Fields | Show representative fields only when patient lacks capacity |
| Audit Trail | Enable timestamping and certificate of completion |
Choose a signing platform that supports secure storage, audit trails, and any required compliance addenda such as a HIPAA BAA.
Ensure the platform provides role-based permissions, access logging, encrypted storage, and an option to sign a BAA when processing identifiable health images.
Obtain signature at or before the time photos are taken
Store signed form in the record within 24–72 hours
Allow a review period before external publication, typically 7–14 days
Acknowledge revocation requests within 30 days
Fulfill patient access requests per HIPAA timelines
Clinician or staff opens the consent and explains purpose before capture.
Patient or authorized signer signs and dates the form prior to photography.
Signed form uploaded to the medical record and linked to image files.
Periodic review of stored images according to retention policy and deletion rules.
A dermatologist requests photos for treatment tracking
A research coordinator needs images for a case report
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |