Establishing secure connection…Loading editor…Preparing document…

Healthcare RAC Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE RAC AUTHORIZATION TO RELEASE PROTECTED HEALTH INFORMATION

Patient Information

Patient Name:

Date of Birth:    Gender:

Insurance Information

Medical History Summary

RAC Authorization and Purpose

I hereby authorize release of my protected health information (PHI) as described below to the Recovery Audit Contractor, its designated agents, representatives, and any contractor performing auditing, claim review, or appeals-related activities on behalf of payors or governmental health programs. This authorization is limited to information reasonably necessary to conduct audits, adjudicate claims, identify overpayments, and pursue recovery or appeals related to such claims.

Scope of Records to be Disclosed (check all that apply):

Entire medical record for dates specified

Medical progress notes, history and physical, discharge summaries

Billing statements, itemized charges, claims and remittance advices

Imaging and radiology reports

Laboratory and pathology reports

Operative and surgical records

Time period for records: From to

This authorization includes disclosure of information relating to mental health treatment, substance use disorder treatment, and HIV-related information only if I affirmatively indicate consent below.

Include mental health records
Include substance use disorder treatment records
Include HIV-related information

Legal Notices, Rights, and Limitations

I understand that: the information disclosed under this authorization may be subject to redisclosure by the recipient and may no longer be protected by federal privacy laws; I may revoke this authorization at any time by providing written notice to the providing facility or entity, except to the extent that action has already been taken in reliance on this authorization; treatment, payment, enrollment, or eligibility for benefits will not be conditioned on my signing this authorization except where permitted by law.

Revocation must be submitted in writing to the Health Information Management or Privacy Office identified by the disclosing provider. Revocation will not affect disclosures made in reliance on this authorization prior to receipt of a valid written revocation.

By signing below I certify that I am the patient or authorized representative with legal authority to sign on behalf of the patient. I authorize the entities named above to release the specified records for the stated purpose. I understand that I will receive a copy of this signed authorization upon request.

HIPAA Acknowledgment

I acknowledge receipt of the applicable Notice of Privacy Practices and understand how my PHI will be used and disclosed pursuant to this authorization. I authorize disclosure as described above and accept that disclosures to some recipients may not be protected by federal law.

I acknowledge and consent to release of PHI as described

Additional Instructions / Limitations

Patient Name:

Signature:

Date:

Enter text✕

What the Healthcare RAC Document Is and when it matters

A Healthcare RAC Document is the packet prepared to respond to Recovery Audit Contractor (RAC) requests or other payer audits of clinical and billing records. It typically includes patient authorizations, copies of medical documentation, coding summaries, and a cover letter that ties clinical findings to billed items. Organizations assemble these packets to verify claim accuracy, document medical necessity, and either substantiate billed services or identify overpayments for repayment. Proper assembly and secure delivery are critical to preserve patient privacy and to establish a clear audit trail for later review or appeal.

Why a well‑prepared RAC packet reduces downstream risk

Preparing a complete Healthcare RAC Document clarifies documentation at the time of audit, helps demonstrate medical necessity, and shortens vendor review cycles. Accurate packets reduce the risk of repayment demands, improper denials, and extended appeals.

Why a well‑prepared RAC packet reduces downstream risk

Who normally prepares and signs RAC response packets

Typical teams that assemble and submit Healthcare RAC Documents within health systems and practices.

  • Health information management teams who gather records, verify redaction, and release documentation to payers.
  • Compliance and revenue integrity officers who validate coding, identify overpayments, and coordinate appeals.
  • Billing and clinical staff who confirm dates of service, providers of record, and clinical narratives.

These roles collaborate to ensure documentation accuracy, legal compliance, and timely submission.

Primary signers and internal stakeholders

Compliance Officer

A compliance officer typically reviews audit requests, confirms legal authority to release records, and signs attestations about internal review processes. They coordinate legal reviews, repayment calculations, and interaction with payer auditors to ensure the response meets regulatory obligations.

Health Information Manager

The HIM director or designee compiles and certifies medical records, manages redaction for PHI, documents chain of custody, and often signs record‑release attestations. They ensure the packet shows complete and accurate documentation tied to each claim line.

Essential security and compliance details to include

PHI handling: Limit access and log disclosures.
Encryption: TLS 1.2/1.3 in transit; AES-256 at rest.
Audit trail: Timestamps, IPs, and action logs.
BAA status: Business Associate Agreement required.
Regulatory scope: Comply with HIPAA and state privacy laws.
Signature law: ESIGN and UETA support eSign validity.

Step-by-step: assembling a Healthcare RAC Document

Follow a repeatable sequence to reduce errors, preserve PHI, and build a defensible audit trail.

  • 01
    Collect records: Gather all requested charts, imaging, orders, and notes.
  • 02
    Map to claims: Tie each document piece to the corresponding claim line.
  • 03
    Document review: Have coding and clinical reviewers confirm medical necessity.
  • 04
    Finalize packet: Insert cover letter, signatories, and fielded index.

Configuring an online RAC packet workflow

Set up fields and routing so reviewers, signers, and auditors see a consistent, auditable sequence when using an eSignature platform.

Field Configuration
Patient ID field Mandatory text field; auto-validate format
Signature field Require signer email and date stamp
Reviewer order Sequential routing: HIM → Coding → Compliance
Access controls Restrict by role and enable view-only links

Where to send the completed packet and common delivery channels

Choose the delivery channel required by the auditor; preserve a copy and the audit trail when you transmit.

  • Payer portal: Upload per payer instructions; preserve confirmation receipts.
  • Secure email: Use encrypted attachments and delivery receipt.
  • Certified mail: Use return receipt to document physical delivery.
  • Portal via vendor: Third-party submission portals accepted by some contractors.

Technical requirements for digital preparation and submission

Ensure your platform supports secure PDF, audit trails, role‑based routing, and HIPAA controls before eSubmitting a RAC packet.

  • File formats: PDF, DOCX, and scanned images supported.
  • Integrations: Connectors for EHRs and storage platforms.
  • Authentication: Email, SMS, or stronger signer verification.

Typical timelines and response expectations

Deadlines vary by payer and contractor; track the request date, internal review deadlines, and the submission deadline to avoid late responses.

Initial request window:

Often 30–45 days to produce records; verify payer notice.

Internal review target:

Allow 7–14 days for HIM and coding review.

Submission deadline:

Meet payer-specified cutoff to avoid default findings.

Appeal timeframe:

Varies by payer; often 30 days for first-level appeal.

Retention start:

Retain copies from the submission date forward.

Key milestones in the RAC response lifecycle

Track milestones from receipt to resolution so each stage has clear ownership and time expectations.

01

Request Received

Log receipt date and reference number immediately.

02

Records Assembled

Complete collection and redaction prior to review.

03

Internal Sign-off

Coding and compliance sign attestations before dispatch.

04

Submission & Confirmation

Transmit and retain delivery confirmation and audit trail.

Common preparation mistakes to avoid

  • Submitting incomplete charts or missing imaging that breaks the link between documentation and billed codes, causing rework and adverse findings.
  • Failing to obtain or record a valid patient authorization when the payer requests protected health information, risking denial of the response.
  • Using unsigned attestations or unsigned electronic forms without a clear audit trail, which can undermine the credibility of the packet.
  • Delivering documents via nonsecure channels that expose PHI and create reportable HIPAA incidents and potential contract breaches.

Consequences of an incorrect or late RAC response

Repayment obligations: Return overpaid amounts plus interest.
Civil liability: Exposure under False Claims Act possible.
Fewer allowances: Reduced opportunities for negotiated settlements.
Reputational harm: Payer trust and contract standing may suffer.
Increased audits: Higher audit frequency can follow errors.
HIPAA risk: Improper disclosures may trigger breach notifications.

Core components every Healthcare RAC Document should contain

Include these elements to create a self‑contained packet that links clinical documentation to coding and payer claims.

Cover Letter

A concise cover letter references the payer request, lists included records, and provides a point of contact for follow‑up; it frames the submission and helps the contractor index materials.

Patient Authorization

A valid signed release or authorization that permits release of PHI for audit purposes; document type and signer authority must meet state and federal requirements.

Medical Records

Complete clinical documentation including notes, orders, imaging reports, and lab results tied to dates of service and provider signatures to demonstrate medical necessity.

Coding Summary

A reconciled coding spreadsheet or summary that maps claim lines to supporting documentation and includes coder rationale for disputed items.

Signatory Attestation

A signed attestation from compliance or HIM confirming the packet is complete and accurate and identifying the person with authority to sign.

Audit Trail

Timestamped record of who accessed, modified, or sent the packet, including delivery receipts and eSignature metadata when used.

Real-world examples of electronic handling in healthcare workflows

These brief examples show how organizations standardized record responses and preserved auditability while protecting PHI.

Fertility Centers of Illinois

John Butler led a switch to electronic packet assembly to centralize responses and preserve signaling metadata.

  • The team used role-based routing to reduce sign-off time.
  • As a result, they reported fewer delayed responses and maintained a stronger audit trail while meeting payer deadlines consistently and safeguarding patient privacy.

Optica Ventures LLC

Brian Fitzgibbons described simplifying external document requests through consistent templates and signer roles.

  • Templates aligned records to claims quickly.
  • This reduced repetitive manual steps, improved internal reviewer clarity, and shortened turnaround time for external auditors while keeping access controls intact.

eSignature vendor pricing and compliance overview for RAC document workflows

Compare common vendors on starting price, trial availability, bulk-send capability, audit trail presence, and HIPAA compliance to select a platform that meets security and volume needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently asked questions about Healthcare RAC Documents and eSign

Answers to common questions about validity, PHI, signer authority, notarization, and reversing submissions for Healthcare RAC Documents.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users