Patient Identification
Full legal name, date of birth, and medical record number to remove ambiguity across systems and to match the shield to the correct patient record.
The document reduces disclosure risk, creates a clear audit trail for PHI handling, and helps demonstrate compliance with HIPAA privacy rules (45 CFR §164.502). It also clarifies who may access information and under what circumstances, reducing disputes and regulatory exposure.
Multiple stakeholders prepare, approve, or enforce Healthcare Shielding Documents depending on setting and scope.
Responsibilities vary: clinical staff collect patient details; privacy teams set controls; counsel reviews legal sufficiency.
Full legal name, date of birth, and medical record number to remove ambiguity across systems and to match the shield to the correct patient record.
Explicit categories or time ranges of information to be shielded (for example mental health notes, substance abuse records, or lab results for specific dates) to avoid over- or under-broad restrictions.
Named persons or classes (providers, insurers, third-party services) permitted to receive or view the shielded PHI, with role-based limitations where appropriate.
Effective start and end dates or event-based triggers (e.g., until revoked or end of treatment) so enforcement and retention obligations are time-bound.
Security and transmission requirements (encryption, access logs, minimum necessary rules) that receiving parties must follow when accessing shielded PHI.
Procedures for recording access, handling breach incidents, and the process for the patient or authorized party to revoke or amend the shielding instruction.
| Field | Configuration |
|---|---|
| Identity Check | SMS code or institutional SSO |
| Routing | Sequential signer order with role checks |
| Audit Trail | Capture IP, timestamp, and actions |
| Storage | Encrypted archive with access logs |
Choose tools and integrations that support secure upload, authenticated signing, encrypted storage, and robust audit trails.
Ensure the chosen platform supports HIPAA-required controls (BAA), secure transmission (TLS 1.2/1.3), AES-256 encryption at rest, and an immutable audit trail for access and signature events.
Takes effect on the date signed unless another date is specified.
Process revocation requests promptly; document receipt and action taken.
Typical processing window is 1–3 business days for updates.
Keep related records 6 years (45 CFR §164.530(j)).
Some states require additional steps for advance directives; check local rules.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no card | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
A clinic standardized shielding forms and added digital signatures to speed consent processing
A small practice used electronic forms to attach patient privacy instructions to tenant files