Patient Identification
Full legal name, date of birth, and at least one identifier (medical record number, SSN last four, or address) to ensure accurate retrieval of records.
A complete, correctly executed request accelerates care coordination, supports claims and legal processes, and reduces administrative rejections. It creates an auditable record that documents patient consent and the scope of information released under HIPAA (45 CFR §164.508).
Ensure the signer has legal authority and, when required, include documentation that demonstrates that authority with the request.
The patient signs when authorizing release of their own records. Include government‑issued name, date of birth, and a matching signature; mismatches can delay processing or trigger re-verification under provider identity procedures.
A guardian, parent, attorney-in-fact, or executor signs when legally empowered. Attach proof of authority such as a durable POA, guardianship order, or court appointment to avoid denials.
Full legal name, date of birth, and at least one identifier (medical record number, SSN last four, or address) to ensure accurate retrieval of records.
Name, organization, mailing address, phone, and email of the person or entity authorized to receive the records; specify whether paper, fax, or secure electronic delivery is requested.
Precise description of requested records (e.g., “ER visits 01/01/2023–12/31/2023,” lab reports, imaging, operative notes) to limit overbroad disclosures.
Reason for release (continuity of care, legal, insurance claim) where required by the custodian or state law; avoid vague descriptions when specific use affects release decisions.
Specify an expiration date for the authorization or state that it is valid for a defined number of days; include revocation instructions and how the patient withdraws consent.
Original signature of patient or authorized representative and date; include printed name and relationship if signed by a representative.
| Field | Configuration |
|---|---|
| Consent Disclosure | Display ESIGN consumer disclosure and obtain affirmative consent |
| Authentication | Use email + SMS code or identity proofing for representative signers |
| Delivery Method | Offer secure email, portal upload, or encrypted PDF with delivery receipt |
| Audit Trail | Retain timestamp, IP, signer email, and copy of signed record |
When using electronic platforms, confirm HIPAA compliance and BAA availability with the vendor and the records custodian before transmitting protected health information.
30 calendar days is common; some states or facilities require a shorter period
May be available for urgent care or legal deadlines; fee structures vary
Maintain signed request and audit trail for at least 6 years per HIPAA (45 CFR §164.530(j))
Revocation takes effect on receipt; records already released are not recoverable
If no response, contact records office within 7–14 days to confirm receipt
Requester sends signed authorization and any authority documentation
Records office confirms identity and representative authority
Medical records and related documents are located and collected
Records are transmitted and a release entry is recorded
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | BAA available | Varies by plan | Varies by plan | Varies | Varies |