Establishing secure connection…Loading editor…Preparing document…

Authorization for Use and Disclosure of Protected Health Information

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Authorization for Use and Disclosure of Protected Health Information
under HIPAA RULE 164.508

You May Refuse to Sign This Authorization

I, authorize to use and disclose in any form or format a copy of records concerning Individual but only as follows, to: for the purpose(s) of (state specific purposes)

I specifically authorize you to use and disclose the following types of super-confidential information (initial where appropriate):

HIV records (including HIV test results) and sexually transmissible diseases

Alcohol and substance abuse diagnosis and treatment records

Psychotherapy records

Tuberculosis

All hospital records

All of the above

I specifically authorize you to use and disclose the following Protected Health Information. Please initial one or more of the following, if applicable:

Written Medical Records:

X-rays/MRI/CT

Billing records

Prescription records

Other (specify in detail):

All of the above

I understand that my records may be subject to re-disclosure by recipient(s) and unprotected by federal or state law; that this Authorization remains effective until the following date: ; the following event:

or until you actually receive a signed revocation or until the records retention period required under federal and law has expired, whichever first occurs; that I have been given an opportunity to ask questions; that I have received a copy of the signed Authorization; that I may inspect a copy of my protected health information to be used or disclosed under this Authorization; that you have not conditioned provision of services to or treatment of me upon receipt of this signed Authorization; and that I may refuse to sign this Authorization. My refusal to sign will not affect my eligibility for benefits or enrollment, payment for or coverage of services, or ability to obtain treatment, except as provided on this form. If the purpose of this Authorization is for the use and/or disclosure of health information for a research study, and I refuse to sign this Authorization, you reserve the right to deny treatment associated with such research. If the purpose of this Authorization is to disclose health information to another party based on health care that is provided solely to obtain such information, and I refuse to sign this Authorization, you reserve the right to deny that health care. I understand that I may inspect or copy the information that is used or disclosed. I understand that I may revoke this Authorization at any time by notifying you in writing, except to the extent that action has been taken in reliance on this Authorization; or if this Authorization is obtained as a condition of obtaining insurance coverage, other law provides the insurer with the right to contest a claim under the policy or the policy itself.

(A copy of this signed form will be provided the individual).

Witness my signature this (date).

In the presence of:

Enter text

What this Authorization Is and When it Applies

An Authorization for Use and Disclosure of Protected Health Information is a written, dated document that gives a covered entity permission to use or disclose an individual’s protected health information (PHI) for specific purposes beyond treatment, payment, or health care operations. Under HIPAA an authorization must meet the content and signature requirements in 45 CFR §164.508; it should state what PHI is covered, who may disclose it, who may receive it, the purpose, an expiration, and the signature and date. Properly completed authorizations allow lawful data sharing while preserving patient rights.

Why a Clear Authorization Matters

A valid authorization protects patient privacy, documents consent for data sharing, and establishes legal authority for disclosure under HIPAA. It reduces ambiguity about permitted uses of PHI and protects providers and recipients from wrongful disclosure claims.

Why a Clear Authorization Matters

Who Typically Prepares or Signs This Authorization

The form is used by individuals, clinicians, organizations, and payers whenever PHI must be shared for purposes not otherwise permitted by HIPAA.

  • Patients and personal representatives who authorize release of medical records for referrals, legal matters, or personal use.
  • Health care providers and medical records departments when responding to records requests or coordinating care with specialists.
  • Insurers, attorneys, and third-party administrators that receive PHI for claims adjudication, legal proceedings, or benefits management.

Ensure the signer has capacity and that the document records identity, purpose, expiration, and signature to meet regulatory standards.

Core Elements Every Professional Authorization Should Include

A compliant authorization contains a defined set of elements that satisfy HIPAA and practical audit needs; include them verbatim to avoid invalidation.

Patient Identity

Full legal name, date of birth, and other identifiers to precisely identify the individual whose PHI is authorized for disclosure.

Description of PHI

A specific description of the information to be released (dates of service, types of records, test results) rather than a blanket or vague statement.

Recipient / Purpose

Name of the recipient(s) and the purpose for disclosure; narrow purposes reduce risk and are required by 45 CFR §164.508(c).

Expiration

A clear expiration date or event (MM/DD/YYYY or 'upon completion of claim') that limits ongoing access to PHI beyond the stated timeframe.

Redisclosure Notice

A statement that once disclosed the information may be subject to re-disclosure by the recipient and may no longer be protected under HIPAA.

Signature & Date

Signature of the patient or authorized representative, relationship to patient if applicable, and the date signed to validate consent.

Step-by-Step: Completing the Authorization

Follow these steps to create a complete, compliant authorization ready for signature and distribution.

  • 01
    Prepare the form: Populate patient identifiers and specific PHI description.
  • 02
    Name recipient and purpose: List recipients precisely and state the intended use.
  • 03
    Set expiration: Enter a clear date or event to terminate authorization.
  • 04
    Sign and date: Signer or representative signs; include relationship if applicable.

Where to Send or File the Completed Authorization

After execution, route copies to every party that needs lawful access; document distribution and retention to support compliance.

  • Originating Provider: Keep a signed copy in the patient’s medical record.
  • Receiving Organization: Send encrypted electronic copy or secure fax as requested by recipient.
  • Billing/Claims Department: Provide copy for claims processing where PHI relates to payment.
  • Patient or Representative: Give the signer a dated copy for their records.

Digital Signing and File Formats to Support Compliance

Use platforms that preserve an audit trail, support common document formats, and meet applicable authentication standards.

  • Accepted Formats: PDF, DOCX
  • Authentication Options: Email, SMS, KBA
  • Integrations: EHR, CRM, cloud storage

Ensure any e-signature provider supports HIPAA (BAA available), secure transport and storage (TLS/AES), and produces an auditable certificate of completion for legal defensibility.

How to Configure an Online Authorization Workflow

Set up fields, authentication, and retention controls before sending to ensure compliant capture and storage.

Field | Configuration Label | Behavior
Signature Method eSign overlay or digital signature
Authentication Email link, SMS code, or multi-factor
Expiration Setting Set explicit date or duration
Audit Trail Capture IP, timestamp, and actions

Key Timeframes and Processing Expectations

Certain operational timelines affect validity and revocation; note processing windows and the legal effect of revocation.

Processing Time:

Records may be produced within 7–30 business days depending on provider policy.

Effective Date:

The date signed is the authorization’s effective start date for disclosures.

Expiration:

Authorization expires on the stated date or event; unspecified expirations create legal risk.

Revocation Timing:

Revocation is effective upon receipt but does not undo disclosures already made in reliance on the authorization.

Retention Requirement:

Maintain copies and audit logs to meet HIPAA retention guidance.

Typical Processing Milestones

A simple timeline clarifies responsibilities from creation through long-term retention.

01

Drafting

Create authorization with precise PHI scope and purpose.

02

Execution

Signer completes signature and date fields; verify identity.

03

Distribution

Provide copies to recipient, patient, and records office.

04

Retention

Store signed copy and audit data per legal retention periods.

Essential Fields Required on the Form

Patient Name: Full legal name
Date of Birth: MM/DD/YYYY
PHI Description: Specific records & dates
Recipient: Name and contact
Expiration: Date or event
Signature: Signature and date

Consequences and Legal Risks of Improper Authorization

Invalid Authorization: Disclosure may be unlawful
HIPAA Enforcement: Civil fines and corrective actions
Civil Liability: Private claims for improper disclosure
Criminal Risk: Willful misuse may trigger penalties
Data Breach Exposure: Unauthorized re-disclosure increases breach risk
Operational Delay: Incomplete forms slow care or claims

Common Mistakes That Invalidate or Delay Authorizations

  • Using vague PHI descriptions such as 'all records' without dates or categories, which makes the request overbroad and risks rejection.
  • Failing to name the recipient precisely or omitting contact details, leading to misrouting and delays in fulfilling the request.
  • Omitting an expiration or using open-ended language, which can create legal uncertainty and may lead to refusal by the releasing entity.
  • Not documenting representative authority when a guardian or agent signs, which can require additional proof and slow processing.

Real-World Uses and Outcomes

Practical examples illustrate how organizations capture and act on authorized PHI disclosures while maintaining compliance.

Fertility Centers of Illinois

A clinic standardized patient authorizations for third-party lab sharing to speed results transfers by eliminating fax cycles.

  • Staff reduced manual follow-up by centralizing completed authorizations.
  • The organization retains signed copies in the EHR and documents each disclosure event for auditing and patient inquiries.

Xerox (NetSuite integration)

An operations team integrated authorization capture into workflow to attach signed consent to billing records.

  • This linked payment and clinical data for claims.
  • The integration ensured that only authorized PHI flowed to finance, with audit logs recorded for compliance reviews.

eSignature Platform Pricing & Compliance Snapshot

Common vendor pricing and feature differences relevant when choosing an eSignature solution for PHI authorizations; signNow is listed first per comparison convention.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Free trial available Free trial available Free trial available Free trial available
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions and Troubleshooting

Answers to common questions about validity, electronic signing, revocation, witnesses, and storage for PHI authorizations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users