Patient details
List full legal name, date of birth, address, and any identifiers (medical record number) to ensure the authorization is attributable and matches health records accurately in system records.
A precise HIPAA Authorization documents informed consent, limits the scope of permitted PHI disclosures, and helps covered entities demonstrate compliance. Clear authorizations reduce ambiguity about permitted recipients and uses, support accurate recordkeeping, and reduce the risk of improper redisclosures under HIPAA rules.
Typical users include healthcare providers, health plans, and authorized patient representatives who request or release protected health information.
List full legal name, date of birth, address, and any identifiers (medical record number) to ensure the authorization is attributable and matches health records accurately in system records.
Describe the types of information authorized for disclosure with specificity—e.g., dates of service, labs, imaging, or entire record—so recipients and auditors can determine scope precisely.
State the exact purpose of the disclosure (for example, payment, continuity of care, legal review, or research with IRB approval) to limit permissible use and improve enforceability.
Identify the individual or organization permitted to receive PHI, including name, department, and contact details, to limit redisclosure and enable downstream auditing.
Provide a specific end date or event (for example, 'one year from signature' or 'upon claim resolution') so the authorization remains time-limited and revocable.
Include the individual's signature, printed name, date, and relationship for representatives; add a statement about revocation rights and the possibility of redisclosure as required by 45 CFR §164.508.
| Form Field and Configuration Settings | Configuration |
|---|---|
| Authentication and signer verification options | Email link, SMS code, optional KBA or MFA |
| Conditional visibility and required logic rules | Show PHI fields only when recipient specified |
| Document format and file attachment preferences | PDF preferred; allow supporting attachments as needed |
| Audit trail retention and encryption settings | Retain logs six years; TLS and AES-256 encryption |
Electronic collection requires secure transport, strong authentication, and audit logging to support HIPAA compliance and traceability.
30 days to respond to access requests (45 CFR §164.524)
Specified expiration date or event defined on form
Revocation is effective upon receipt by covered entity
Keep authorization records for applicable retention period
Routine processing often completes within 7–30 business days
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |