Revocation Statement
A clear sentence stating the exact rights being removed, naming the third party by full legal name and relationship, and specifying whether revocation applies to past disclosures, future disclosures, or both.
A concise, legally sound removal form reduces ambiguity about who may access PHI and documents the patient's intent.
Several roles interact with and complete the removal form depending on the situation and organizational workflow.
Clear assignment of responsibility speeds processing and reduces errors when revoking third-party access.
Oversees receipt and processing of removal requests, verifies identity documents, updates access controls in the electronic health record, and retains a copy for the organization’s audit log and HIPAA documentation.
Initiates the removal by identifying the third party to be revoked, providing proof of identity, and signing the form to confirm withdrawal of consent for disclosures or access to medical records.
A clear sentence stating the exact rights being removed, naming the third party by full legal name and relationship, and specifying whether revocation applies to past disclosures, future disclosures, or both.
Full legal name, date of birth, medical record number or other provider identifier, and contact details to avoid ambiguity and ensure the revocation is applied to the correct record.
Precise description of the categories of PHI and effective date of revocation; include any date ranges or specific documents to be excluded from prior authorizations.
Dated signature of the patient or authorized representative affirming intent; include printed name and relationship to the patient to support verification.
Record of identity verification steps taken (ID type checked, remote authentication used, notary or witness if required) and the staff member who completed verification.
A provider or records office section confirming receipt, processing date, staff initials, and any follow-up actions taken to remove access across systems.
| Field | Configuration |
|---|---|
| Authentication Method | Email plus SMS code or ID document upload |
| Conditional Fields | Show supporting-authority upload when signer is not the patient |
| Retention Policy | Auto-store for 6 years under HIPAA retention rules |
| Notification | Automated confirmation to patient and staff upon processing |
Confirm that your eSignature and records systems meet privacy and interoperability needs before enabling eSubmission.
Providers commonly acknowledge receipt within 3–5 business days
HIPAA-related requests typically processed within 30 days (see 45 CFR §164.524)
Processing and system updates frequently complete in 7–14 business days
Expedited handling may require proof of urgent need or legal order
Retain processed revocations per retention policy and HIPAA recordkeeping rules
Patient or agent completes and submits the removal form via accepted channel.
Records staff validates identity and supporting authority documents.
EHR and access controls are updated to remove third-party permissions.
Provider sends confirmation to patient and logs the action in the audit trail.
A patient ends a caregiver’s access to medical records after a relationship change.
A legal guardian’s authority expires and the guardian seeks removal from a minor’s account.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (plan dependent) | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |