Establishing secure connection…Loading editor…Preparing document…

Authorization for Use and Disclosure of Protected Health Information

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DEPARTMENT OF HEALTH SERVICES
COUNTY OF LOS ANGELES
AUTHORIZATION FOR USE AND DISCLOSURE OF PROTECTED HEALTH INFORMATION

Last Name / First / MI / Date of Birth / Medical Record Number

HEREBY AUTHORIZES:

To Release Protected Health Information To:

for the time period beginning , and ending

INFORMATION TO BE DISCLOSED

PLEASE CHECK ALL APPROPRIATE BOXES:

THE PURPOSE OF THE DISCLOSURE - PROVIDE A DESCRIPTION OF THE PURPOSE OF INTENDED USE AND DISCLOSURE

I understand that health information used or disclosed as a result of my signing this Authorization may not be further used or disclosed by the recipient unless another authorization is obtained from me or unless such use or disclosure is specifically required or permitted by law.

EXPIRATION DATE: This authorization is valid until the following date,

Page 2 - AUTHORIZATION FOR USE AND DISCLOSURE OF PROTECTED HEALTH INFORMATION

YOUR RIGHTS WITH RESPECT TO THIS AUTHORIZATION:

Right to Receive a Copy of This Authorization - I understand that if I agree to sign this authorization, which I am not required to do, I must be provided with a signed copy of the form.

Right to Revoke This Authorization - I understand that I have the right to revoke this Authorization at any time by telling DHS in writing. I may use the Revocation of Authorization at the bottom of this form. Mail or deliver the revocation to:

I also understand that a revocation will not affect the ability of DHS or any health care provider to use or disclose the health information for reasons related to the prior reliance on this Authorization.

CONDITIONS: I understand that I may refuse to sign this Authorization without affecting my ability to obtain treatment. However, DHS may condition the provision of research-related treatment on obtaining an authorization to use or disclose protected health information created for that research-related treatment. (In other words, if this authorization is related to research that includes treatment, you will not receive that treatment unless this authorization form is signed.)

I have had an opportunity to review and understand the content of this authorization form. By signing this authorization I am confirming that it accurately reflects my wishes.

Signature Of Patient/Legal Representative:

If signed by other than the patient, state relationship and authority to do so:

DATE:

WITNESS:

REVOCATION OF AUTHORIZATION

Signature Of Patient/Legal Representative:

If signed by other than the patient, state relationship and authority to do so:

DATE:
Enter text✕

What this Authorization for Use and Disclosure of Protected Health Information Is

An Authorization for Use and Disclosure of Protected Health Information is a written document by which an individual (or their personal representative) gives a covered entity permission to use or disclose specified protected health information (PHI) for purposes beyond treatment, payment, or health care operations. The form identifies the information to be disclosed, the authorized recipient, the purpose of disclosure, an expiration date or event, and the individual’s signature and date. It operates alongside HIPAA privacy rules and state privacy laws to document consent for specific disclosures.

Why a Clear Authorization Matters

A properly completed authorization documents patient consent, limits scope of disclosure, and reduces administrative delays when sharing PHI for research, legal matters, billing, or third-party requests. Clear authorizations also support compliance with HIPAA and applicable state privacy laws.

Why a Clear Authorization Matters

Who Completes and Signs This Authorization

Typical users include patients, authorized representatives, clinical staff, health information management teams, and legal counsel when PHI must be shared beyond routine care.

  • Patients and guardians who authorize release of their own medical records to insurers, attorneys, or third parties for specific purposes.
  • Healthcare release teams or HIM staff preparing records for transfer, billing, research, or case review under specified consent terms.
  • Legal or compliance professionals requesting PHI for claims, litigation, or regulatory review where documented patient authorization is required.

The form should be completed by the individual whose PHI is at issue or by a legally recognized representative, and signed and dated before any non-routine disclosure occurs.

Step-by-Step: Filling Out and Using the Authorization

Follow these practical steps to complete the authorization and ensure it is valid for disclosure.

  • 01
    1. Identify Parties: Enter patient and recipient details accurately.
  • 02
    2. Specify Records: Describe the exact records and date range to disclose.
  • 03
    3. Sign and Date: Signer must sign and date in the signature block.
  • 04
    4. Retain Copy: Keep a copy in the medical record as required.

Typical Workflow for Processing an Authorization

This sequence summarizes how an authorization moves from request to release in a typical health information workflow.

  • Request Received: Patient or requester submits a completed form.
  • Verify Identity: Staff confirms signer identity and authority.
  • Validate Content: Confirm records described are available and scope is clear.
  • Release Records: Provide records and document release in audit trail.

Digital Workflow Settings to Configure

If completing or routing the form electronically, configure these core settings for authentication, compliance, and recordkeeping.

Field Configuration
Authentication Email + optional SMS OTP or KBA
Signature Fields Require signature and signature date
HIPAA Addendum Attach BAA and privacy notice where required
Retention Settings Retain signed copy and audit trail

Technical Requirements for Secure eSubmission

Use a platform that supports secure transmission, audit trails, and HIPAA controls when collecting or sharing PHI electronically.

  • Encryption: TLS 1.2/1.3 in transit
  • Data at Rest: AES-256 encryption
  • Integrations: Salesforce, NetSuite, Google Workspace

Ensure the vendor offers a signed Business Associate Agreement (BAA) for HIPAA-covered activities and maintains detailed audit logs for each disclosure.

Key Timeframes to Note When Using an Authorization

Certain dates and response times affect validity, revocation, and processing of authorized disclosures; plan accordingly.

Expiration Date:

Specify MM/DD/YYYY or event; common durations are six to twelve months.

Revocation Effective:

Revocation is effective on receipt when provided in writing by the individual.

Provider Response Time:

HIPAA requires covered entities to respond to disclosures and access requests in a timely manner; access requests generally within 30 days (45 CFR §164.524).

Third-Party Use Period:

Recipients may hold PHI per their policies; include usage limits in the authorization.

Record Retention:

Retain the signed authorization consistent with HIPAA and state recordkeeping rules.

Milestones from Authorization to Release

Track these sequential stages so each milestone is documented and auditable during disclosure processing.

01

Form Completion

Accurate fields and signature completed by the patient or representative.

02

Identity Verification

Staff confirms identity and legal authority to sign.

03

Approval and Routing

HIM or privacy office approves scope and authorizes release.

04

Disclosure Logged

Record delivery, recipient, and audit details in the chart.

Common Mistakes to Avoid

  • Vague descriptions such as 'all medical records' that force manual review and delay release.
  • Unsigned or undated forms that are not valid for disclosure and lead to re-submission requests.
  • Failure to include a specific expiration date or event, creating uncertainty about the authorization’s scope.
  • Using incorrect recipient details that result in disclosure to the wrong party and potential privacy breaches.

Security and Compliance Essentials

Encryption: TLS 1.2/1.3; AES-256 at rest
Audit Trail: Timestamps, IP, action log
BAA Requirement: Business Associate Agreement required
Access Controls: Role-based permissions
Authentication: Email, SMS OTP, or KBA options
Certifications: SOC 2 Type II, ISO 27001

Penalties and Risks of Errors or Unauthorized Disclosure

HIPAA Fines: Civil and criminal penalties
Invalid Authorization: Denial of request; rework delays
Unauthorized Disclosure: Breach notification obligations
Legal Exposure: Litigation or regulatory review
Operational Delays: Claims and care coordination impact
Reputational Harm: Loss of patient trust

Real-World Examples of Authorization Use

These brief examples show how organizations use authorizations for discrete operational needs.

Fertility Centers of Illinois

A clinic needed consistent patient authorizations for third-party lab disclosures.

  • They standardized an authorization form across locations.
  • The standardized form reduced manual review, ensured HIPAA-compliant language, and improved processing times for diagnostic result transfers to outside laboratories and patients’ designated providers.

Optica Ventures LLC

A services firm required signed medical releases for employee leave cases.

  • The company used a single authorization template.
  • Centralizing the form simplified validation, minimized rework, and allowed occupational health teams to release only the narrowly specified records needed to assess leave eligibility.

Selected eSignature Vendor Pricing and Feature Overview

Compare typical entry-level pricing and key capabilities for platforms commonly used to collect authorizations and other PHI-related signatures.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Tips to Reduce Processing Time and Compliance Risk

Adopt consistent templates, include required elements, and use secure e-signature tools to make processing predictable and auditable.

Use a standard template
Standardize the authorization across departments with clearly labeled fields and required validations. Consistent templates reduce manual review, speed release, and help ensure every required HIPAA core element is present.
Limit the scope
Describe specific records and date ranges rather than blanket authorizations. Narrow scope minimizes unnecessary disclosure and simplifies privacy office review and approval for third-party requests.
Document revocations
Provide a clear revocation process and record revocations promptly. Maintain a revocation log so future requests are checked against active revocations before disclosure occurs.
Attach supporting ID
When identity verification is necessary, request a copy of government-issued photo ID or use multi-factor authentication during e-signing to reduce misidentification risks.

Frequently Asked Questions About Authorizations and PHI Disclosures

Answers address common legal, technical, and operational questions about valid authorizations, revocation, e-signing, and retention.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users