Scope Description
Specify exactly which procedures, tests, or data sets the patient is authorizing, using plain language and itemized lists to avoid ambiguity and overbroad permissions.
The form clarifies patient choices, documents informed consent for narrowly scoped actions, and reduces legal uncertainty. It creates a clear audit record of who authorized which use of protected health information, supports compliance with HIPAA privacy rules, and helps providers manage third-party data requests and research approvals without relying on informal permissions.
The form is completed whenever a provider needs explicit, documented patient permission that is not covered by a standing consent.
Use this form when the additional activity changes the scope of care or data use beyond the original consent document.
Specify exactly which procedures, tests, or data sets the patient is authorizing, using plain language and itemized lists to avoid ambiguity and overbroad permissions.
State who will use the data, for what purpose (treatment, research, billing), and whether de‑identified data may be created or shared with third parties.
Name external organizations or roles that may receive information, including labs, registries, insurers, and research partners, and describe limits on redistribution.
Explain how to withdraw consent, the effective date of revocation, and any actions that cannot be undone after revocation is processed.
Include a clear signature line to affirm that the signer understands the scope, with fields for relationship and authority if signed by an agent.
Record signer IP, timestamp, identity verification method, and document version so the consent can be authenticated and audited later.
| Field | Configuration |
|---|---|
| Authentication Method | Email link | SMS code | KBA optional |
| Conditional Fields | Show additional fields based on selected options |
| Template Library | Store standard consent text for reuse |
| Audit Trail | Enable automatic log and PDF attachment |
Confirm the platform supports secure PDF/DOCX handling, audit trails, and the authentication methods you require.
Integrations with EHRs and secure cloud storage reduce manual filing, ensure consistent retention policies, and simplify retrieval during audits or patient record requests.
HIPAA allows up to 30 days to respond to access requests (45 CFR §164.524)
Breach notifications typically issued within 60 days of discovery under HHS guidance
Specified on the form; governs when authorized actions may begin
Process revocations promptly; document the effective date and actions taken
Maintain signed consent consistent with HIPAA and applicable state law
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
Optica adopted a web-based supplemental consent for optional testing
A fertility center standardized supplemental consent for sample storage