Establishing secure connection…Loading editor…Preparing document…

HIPAA Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!
HIPAA Form

What a HIPAA Form Is and when it applies

A HIPAA Form, commonly called a HIPAA authorization, is a written document that permits a covered entity or business associate to use or disclose an individual's protected health information (PHI) for specific purposes. It identifies the patient, the recipient of PHI, the information to be released, the purpose and an expiration date, and it documents the individual's signature and date. HIPAA authorizations must meet requirements in 45 CFR §164.508 and differ from HIPAA-compliant notices of privacy practices; they are required when disclosure is not otherwise permitted under the Privacy Rule.

Why a clear authorization matters for PHI disclosures

Use a HIPAA Form to obtain documented patient consent for specific PHI disclosures, reduce legal ambiguity, and create an auditable record that supports compliance with HIPAA requirements such as 45 CFR §164.508.

Why a clear authorization matters for PHI disclosures

Who typically completes or requests a HIPAA Form

Clinical providers, insurers, researchers, and third-party administrators commonly complete or request HIPAA Forms when accessing protected health information.

  • Healthcare providers: obtain patient authorization for sharing PHI outside permitted treatment, payment, or operations.
  • Insurers and payers: request authorizations for claims, eligibility verification, or subrogation investigations.
  • Researchers and public health: use authorizations when data cannot be de-identified under HIPAA Privacy Rule.

Roles that interact with HIPAA Forms

Medical Director

A Medical Director or treating physician may authorize release of patient records when the patient has signed a valid HIPAA authorization. They must confirm the scope, purpose, and limitations and document clinical necessity and any applicable institutional approvals before disclosure.

Privacy Officer

The Privacy Officer oversees policy compliance, verifies that authorizations meet 45 CFR §164.508 requirements, and manages business associate agreements. They track retention, handle revocations, and coordinate responses to breaches or requests for amendments to PHI disclosures.

Core elements every professional HIPAA Form should include

A professional HIPAA Form clearly identifies parties, describes PHI, states purpose and expiration, includes signature and authentication, and documents revocation and copy distribution procedures.

Patient Details

Include full legal name, date of birth, address, and any identifiers needed to locate records. Accurate demographics reduce search time and avoid mismatches that can delay disclosure.

Recipient Details

Provide recipient name, organization, contact information, and purpose. Specify whether copies, summaries, or entire records are requested and include recipient role and contact phone or secure portal address.

PHI Description

Clearly describe types of records, date ranges, and sections (for example lab results, imaging, notes). Avoid generic phrases like 'all records' unless necessary and justified.

Purpose & Expiration

Explain the specific reason for disclosure and select an expiration date or event. Use concrete dates or clearly defined conditions to limit authorization scope and legal exposure.

Signature Block

Include signer's printed name, signature, date, and relationship to patient if not the patient. For minors or incapacitated adults, include power of attorney or guardian documentation.

Revocation Terms

State how an individual can revoke authorization, any exceptions for actions taken in reliance, and where to send revocation notices. Include contact details and format requirements.

Step-by-step: completing and approving a HIPAA Form

Follow these steps to complete a HIPAA Form accurately and maintain a compliant audit trail.

  • 01
    Identify Parties: Enter patient and recipient full legal names
  • 02
    Specify PHI: List exact records and relevant date ranges
  • 03
    Purpose & Expiration: State purpose and MM/DD/YYYY expiration
  • 04
    Signature: Signer signs and dates; include witness if required

Where to send or file completed HIPAA Forms

Routing and submission depend on recipient and purpose; use secure channels and document retention procedures when transmitting PHI.

  • To Providers: Upload to EHR or send via secure portal
  • To Insurers: Attach to claim or insurer portal submission
  • To Researchers: Provide deidentified dataset or signed authorization
  • By Mail: Use certified mail marked as PHI with cover

Required information fields at a glance

Patient Name: Enter full legal name as on ID
Date of Birth: Use MM/DD/YYYY exact numeric format
Recipient: Name and organization receiving PHI
Description of PHI: Specify records, dates, and types
Purpose: State purpose for disclosure clearly
Expiration: Provide end date or event

Common pitfalls to avoid when preparing a HIPAA Form

  • Using overly broad language that does not describe PHI types or purpose, which can make an authorization noncompliant under 45 CFR §164.508 and risk unauthorized disclosure.
  • Missing an expiration date or clear event causes uncertainty about scope; include a specific date or describable event to limit disclosure duration.
  • Failing to exclude psychotherapy notes or certain substance abuse records when required; these categories often need separate, explicit authorizations.
  • Not obtaining a dated, handwritten or electronic signature linked to the signer; unsigned or improperly authenticated forms may be invalid.

Consequences of incomplete or improper authorizations

Invalid Authorization: Disclosure may be unlawful
Civil Penalties: Potential HIPAA fines per violation
Criminal Liability: Knowingly disclosing PHI risks charges
Contract Risk: BAA breaches trigger contractual remedies
Revocation: Individual can withdraw authorization
Operational Delays: Incomplete forms delay processing

Key dates and timing considerations

Timelines vary by use case: authorizations should include clear expiration and be retained per regulatory deadlines.

Expiration Date:

Specify MM/DD/YYYY or event-based expiration

Request Response Time:

Process requests within a reasonable business timeframe

Revocation Effective:

Revocations take effect on receipt except for prior reliance

Record Retention:

Retain for at least six years per 45 CFR §164.530(j)

Research Authorizations:

Comply with IRB and institution-specific timelines

Vendor pricing and core capability comparison relevant to HIPAA workflows

Compare baseline pricing and core features for common eSignature vendors relevant to HIPAA-form workflows and compliance needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Practical practices to reduce friction and risk

Adopt consistent templates and review procedures to ensure HIPAA Forms meet regulatory and organizational requirements before release.

Use a standardized, reviewed template
Maintain a versioned template that includes mandatory HIPAA language, handles sensitive categories separately, and is reviewed by privacy counsel. Store templates centrally and train staff on common exceptions.
Limit scope to minimally necessary PHI
Only request the specific categories and date ranges required for the stated purpose. Excessively broad authorizations increase compliance risk and complicate revocation or audit responses.
Confirm signer identity and authentication method
Verify signer identity using reasonable methods such as government ID, two-factor authentication, or in-person verification. Record the method in the file for audit and legal defensibility.
Retain records and audit trails
Keep signed authorizations and an audit trail showing who accessed PHI, when, and why. Retain records per HIPAA and applicable state retention rules to support compliance and incident response.

FAQs: signing, e-submission, revocation, and retention for HIPAA Forms

Answers to common questions about completing, signing, and storing HIPAA Forms, including electronic signature validity and retention considerations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users