Establishing secure connection…Loading editor…Preparing document…

Healthcare TPR Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Healthcare Third-Party Release Authorization (TPR)

Patient Name:   Date of Birth:   Gender:

Third-Party Recipient

Recipient Phone:   Recipient Fax:   Recipient Email:

Information To Be Released

I authorize the health care provider named above to release the following protected health information to the recipient indicated:

Format of disclosure (select one or more):

Purpose of Release

Authorization Period and Revocation

This authorization will expire on:   If no date specified, authorization expires one year from signature unless state law provides otherwise.

I understand that I may revoke this authorization at any time by submitting a written notice to the health care provider, except to the extent that action has already been taken in reliance on this authorization. To revoke, provide revocation to the medical records office at the treating facility.

Redisclosure and Fees

I understand that once my information is disclosed pursuant to this authorization, the recipient may redisclose the information and it may no longer be protected by federal privacy regulations. The provider will make reasonable efforts to limit disclosure as requested but cannot control recipient redisclosure.

I understand that fees for copying and postage, if any, may be charged in accordance with state law and provider policy. I agree to pay routine copying fees when applicable.

Special Authorizations

Release of psychotherapy notes requires specific authorization. By initialing below I expressly authorize release of psychotherapy notes:   

Release of substance abuse treatment records protected under applicable federal or state law may require additional signature or acknowledgement. By signing below I acknowledge I have been advised if special protections apply.

Patient Rights and Certification

I certify that I am the patient or am authorized to act on behalf of the patient as the patient's personal representative. I understand that signing this form is voluntary and that I may refuse to sign without affecting my ability to obtain treatment, payment, enrollment, or eligibility for benefits.

By signing below I authorize the disclosure described in this document. I understand the nature and purpose of this release and that I may request a copy of this authorization after signing.

Signature

Patient Printed Name:

Signature:

Date:

Witness or staff (print name):   Title/Role:

Office use only — Record requested by:   Date processed:

Enter text✕

What the Healthcare TPR Document Is and when it’s used

A Healthcare TPR Document (Third-Party Release or Third-Party Request form) is an authorization that permits a covered entity or business associate to disclose protected health information (PHI) to a named third party or to respond to a third-party request for records. It defines the patient or authorized representative, the scope of information to be released, the purpose, and the duration of the authorization. Properly completed, signed, and retained releases satisfy HIPAA authorization requirements and create an auditable record of consent and disclosure decisions.

Why a clear TPR matters for patient privacy and compliance

A precise Healthcare TPR Document reduces legal risk, documents patient consent under HIPAA, and clarifies the recipient and scope of disclosure. It protects patient rights while providing auditable evidence of authorization for providers, payers, and auditors.

Why a clear TPR matters for patient privacy and compliance

Who typically completes or signs a TPR

The Healthcare TPR Document is completed by different parties depending on the request context; the form and signer vary by scenario.

  • Patients and authorized representatives completing authorizations for release to family, attorneys, or insurers.
  • Medical records staff or release coordinators preparing and tracking requests for legal, payer, or continuity-of-care transfers.
  • Attorneys, third-party requestors, or external organizations submitting formal requests for PHI with patient authorization.

Each signer’s role determines required fields, identity verification, and whether notarization or witness signatures are needed.

Primary signer roles and responsibilities

Patient / Representative

An individual patient or a lawfully authorized representative (executor, guardian, durable power of attorney) who must provide a valid name, relationship, signature, and date. Accuracy affects consent validity and potential liability for improper disclosure.

Records Custodian

Designated medical records staff or privacy officer who verifies identity, documents the request, records the disclosure details in the audit log, and ensures retention per HIPAA and institutional policy.

Core parts of a compliant Healthcare TPR Document

A professional TPR contains clearly labeled sections so requestors, patients, and auditors can verify scope, authority, and retention.

Patient Identity

Full legal name, date of birth, medical record number, and contact details to match records and verify the signer.

Recipient Details

Full name and contact information of the person or entity receiving PHI, including organization, address, fax, or secure transmission channel.

Scope of PHI

Specific categories or date ranges of records to be disclosed, e.g., lab reports, imaging, mental health notes, or entire medical record.

Purpose

Plain-language reason for disclosure such as insurance claim, legal matter, continuity of care, or patient request to obtain copies.

Duration & Expiration

Effective date and clear expiry or event-based termination (e.g., 90 days or upon revocation) so disclosures remain time-limited.

Signature & Attestation

Signature, printed name, date, and witness or notary sections when required; revocation instructions and statements about rights to refuse or withdraw consent.

Stepwise process to complete and process a TPR

Follow a consistent sequence to collect, verify, and document authorization before releasing any PHI.

  • 01
    Prepare Form: Select the correct TPR template and prefill known patient identifiers.
  • 02
    Verify Identity: Confirm signer identity using ID, KBA, or institutional verification policy.
  • 03
    Obtain Signature: Collect handwritten, witnessed, or valid e-signature with intent evidence.
  • 04
    Document Release: Log disclosure details and store the signed form in the record and audit trail.

Recommended digital workflow settings for TPR processing

Configure digital workflows to enforce identity checks, consent disclosures, and secure delivery channels.

Field Configuration
Authentication Email link + SMS code or KBA for sensitive disclosures
Consent Disclosure Present ESIGN consumer disclosure for patient access and paper-option opt-out
HIPAA BAA Require signed BAA for any third-party eSignature provider
Audit Trail Capture timestamp, IP, and signer actions for every transaction

Digital release flow from request to delivery

A controlled digital flow reduces manual errors and preserves an auditable record of every disclosure step.

  • Request Intake: Requestor submits form or request with patient authorization details.
  • Verification: Records team confirms identity and authorization scope.
  • Secure Transmission: Send PHI via encrypted channel or approved secure fax/email.
  • Recordkeeping: Store signed authorization and disclosure log in the patient record.

Technical and compliance capabilities to require in an e-sign platform

Select a platform that supports HIPAA obligations, strong authentication, and secure storage for TPR workflows.

  • Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
  • Audit Trail: Comprehensive timestamps and signer metadata
  • BAA Availability: Business Associate Agreement for HIPAA compliance

Ensure integrations with your EHR and document storage preserve metadata, access logs, and retention controls required for audits.

Common timelines and legal response deadlines

Timelines govern both patient access requests and provider response obligations; missed deadlines can create regulatory risk.

Access Request Response Time:

HIPAA generally requires a response within 30 days (45 CFR §164.524).

Expedited Requests:

Certain urgent requests may require faster handling; follow internal escalation procedures.

Retention Start Date:

Retention typically begins on creation or last effective date of the record.

Revocation Effective Date:

Revocations take effect on receipt and do not retroactively undo prior disclosures.

Notary or Witness Scheduling:

Allow extra time for in-person notarization or witness coordination when required.

Key processing milestones for a single TPR request

Track distinct stages so each milestone is auditable and responsibilities are clear.

01

Request Received

Record the request and assign a processing owner.

02

Identity Verified

Complete required identity proofing before release.

03

Authorization Obtained

Ensure signed authorization is valid and complete.

04

PHI Released

Transmit records and log the disclosure details.

Common mistakes that delay or invalidate TPRs

  • Incomplete recipient details that prevent secure delivery and cause repeated follow-up from records staff.
  • Mismatched patient identifiers (name or DOB) that lead to incorrect record retrieval or disclosure of another person's PHI.
  • Vague scope language such as 'all records' without date ranges, triggering additional verification and potential legal review.
  • Failing to include representative documentation when signed by an agent, producing avoidable processing delays and denied requests.

Consequences of incorrect authorizations or improper disclosures

HIPAA Civil Penalties: Per-incident fines and corrective action plans
Criminal Exposure: Willful disclosures can lead to criminal penalties
Invalid Release: Clinical or administrative requests may be denied
Patient Harm: Misrouted PHI can cause privacy breaches and harm
Reputational Damage: Loss of trust and public scrutiny
Regulatory Audit: Increased oversight and required remediation

Security and compliance controls to include with a TPR workflow

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3 in transit
Access Logging: Detailed audit trail entries
BAA Requirement: Signed Business Associate Agreement
Authentication: Multi-factor or KBA where appropriate
Retention Controls: Policy-driven retention and disposition

eSignature vendor comparison for Healthcare TPR workflows

Simple vendor comparison focused on pricing and essential compliance features relevant to handling healthcare authorizations; signNow appears first for parity.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently asked questions about Healthcare TPR Documents

Answers to common operational, legal, and technical questions encountered when preparing or processing TPRs.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users