HIPAA Authorization Form Generator

An incomplete authorization is not a weak authorization. It is not an authorization.

HIPAA spells out exactly what a release form has to contain: six core elements, three required statements, and extra language for psychotherapy notes, marketing, sales, and research. Miss one and the form is defective, which makes the release an impermissible disclosure. Answer a few questions and this tool drafts the form, flags every blank required element with its citation, and switches to a 42 CFR part 2 consent when the records are substance use disorder records. Free, private, no account.

9required elements and statements
6 yearsretention for the signed form
0data leaves your browser

The generator

Answer a few questions, get a form you can take to counsel

Everything runs in your browser. Start with the purpose and the record type, because those two answers decide which statutory statements the document has to carry and whether you are writing a HIPAA authorization at all.
1. What kind of release is this

These two answers change the whole document. The purpose decides which extra statutory statements the form has to carry, and the record type decides whether you are writing a HIPAA authorization at all.

The everyday case. An individual asks you to send records to an attorney, an employer, a school, a family member, an insurer, or another provider. Governed by the base requirements of 45 CFR 164.508.

Records held by a HIPAA covered entity. The form is built to 45 CFR 164.508.

2. The parties

Name the recipient, or a class of recipients, specifically enough that the person pulling the record knows exactly where it is going.

3. What, why, and for how long

This is the field that decides whether the form survives review. The description has to identify the information in a specific and meaningful fashion. Dates of service, record types, and the condition involved beat "any and all records" every time.

An expiration date or an expiration event that relates to the individual or to the purpose. An authorization with no end point at all is not valid outside research.

4. Options

The revocation statement, the conditioning statement, and the redisclosure warning are required by 45 CFR 164.508(c)(2) and are written into every draft.

6 required elements are still blank

45 CFR 164.508(b)(2)(ii) says an authorization that has not been filled out completely, with respect to a required element, is not a valid authorization. Acting on an invalid authorization is an impermissible disclosure, whatever the individual meant to agree to.

  • BlankDescription of the information45 CFR 164.508(c)(1)(i)

    The information has to be identified in a specific and meaningful fashion. A blanket phrase such as 'any and all records' is the most common reason an authorization is rejected as too broad.

  • BlankWho is authorized to disclose45 CFR 164.508(c)(1)(ii)

    The name or other specific identification of the person or class of persons authorized to make the use or disclosure. This is your organization.

  • BlankWho may receive it45 CFR 164.508(c)(1)(iii)

    The name or other specific identification of the person or class of persons who may receive the information.

  • BlankPurpose of the use or disclosure45 CFR 164.508(c)(1)(iv)

    A description of each purpose. When the individual initiates the authorization and elects not to state a purpose, 'at the request of the individual' is a sufficient description.

  • BlankExpiration date or event45 CFR 164.508(c)(1)(v)

    An expiration date, or an expiration event that relates to the individual or to the purpose. For research, 'none' or 'end of the research study' is sufficient.

  • BlankThe individual is identifiedPractical requirement

    45 CFR 164.508(c)(1) does not list the individual's name as a separate core element, because the signature block carries it. Every workable form names the individual anyway, clearly enough that staff pull the right record.

  • Check this

    This authorization is not finished. Under 45 CFR 164.508(b)(2)(ii) an authorization that has not been filled out completely with respect to a required element is not valid, and acting on it is an impermissible use or disclosure.

  • Check this

    If the individual is asking for a copy of their own records, the right of access at 45 CFR 164.524 is usually the faster and cheaper path, with a 30 day response deadline and a limit on what you may charge. An authorization is the right instrument when a third party is requesting the records or when the release falls outside the access right.

Most invalid authorizations are not drafting failures. They are staffing failures: the form was fine and the person at the desk released more than it covered, accepted one that had already expired, or never checked who was signing. That is a training problem, and it is fixable.

This draft is built from 45 CFR 164.508, 45 CFR 164.501, 45 CFR 164.502, and 42 CFR part 2. Nothing you enter is sent anywhere and nothing is stored. The draft is educational, is not legal advice, and using it does not make an organization HIPAA compliant. State law often imposes stricter rules than HIPAA on releasing information about HIV status, substance use disorder treatment, mental health care, genetic testing, and the records of minors. Have this form reviewed and adapted by qualified counsel before you put it into use.

What it covers

Six things this draft gets right

The draft is built from the regulation text and published HHS guidance. It is a starting point for counsel review, not a compliance determination and not legal advice.

Nine required parts

Every core element and required statement, checked live

45 CFR 164.508(c)(1) lists six core elements and (c)(2) lists three required statements. The tool tracks each one as you type and tells you which citation the blank field belongs to.

The invalidity rule

Incomplete is the same as invalid

Under 164.508(b)(2)(ii) an authorization that has not been filled out completely with respect to a required element is not a valid authorization. Releasing records on one is an impermissible disclosure.

Five purposes

Psychotherapy notes, marketing, sale, research, and everyday releases

Each carries different statutory conditions. Psychotherapy notes must stand alone, a sale must say it pays you, paid marketing must disclose the payment, and research is the one place conditioning is allowed.

Part 2 aware

Substance use disorder records get a Part 2 consent instead

Records held by a federally assisted Part 2 program are governed by 42 CFR 2.31, not by 164.508. Switch the record type and the document changes, including the redisclosure notice at 42 CFR 2.32.

State law prompts

Separate initial lines for specially protected categories

HIV status, substance use disorder treatment, mental health care, genetic testing, and reproductive health information are frequently governed by stricter state rules. The form gives each its own line.

Private by design

Nothing leaves your browser

The form is assembled entirely on your device. No account, no email, and none of the names, dates, or record details you type are sent anywhere or stored.

The full picture

Why the release of information desk is where compliance programs actually fail

A researched walk through what a valid authorization contains, the five defects that void one, the four purposes with extra conditions attached, where state law and 42 CFR part 2 take over, and the operational habits that keep a good form from being used badly.

The authorization is an exception, not the default

Start with the structure, because the structure explains why the form is written the way it is. The Privacy Rule is built as a general prohibition with holes cut in it. 45 CFR 164.502(a) says a covered entity may not use or disclose protected health information except as the subpart permits or requires. Treatment, payment, and health care operations are permitted without any signature. So are a long list of public interest disclosures at 164.512: required by law, public health, abuse reporting, health oversight, judicial proceedings, law enforcement in specified circumstances, and several more.

The authorization exists for everything else. It is the instrument that lets an individual open a door the rule otherwise keeps shut, and that is why the requirements are so specific. A permitted disclosure under 164.512 has a regulatory justification behind it. An authorized disclosure has only the individual's informed agreement, so the regulation spends most of its length making sure that agreement is real, is bounded, and can be withdrawn.

One consequence of that design is worth stating early, because it surprises people. The minimum necessary standard at 45 CFR 164.502(b) does not apply to a disclosure made pursuant to a valid authorization. The form itself is the limit. If the authorization says "any and all records" then nothing in the rule stops the entire chart from going out. That is precisely why the specificity requirement in the first core element carries so much weight, and why narrowing a vague form before you act on it is a protective act rather than an obstructive one.

Six core elements, three required statements

45 CFR 164.508(c) is unusually mechanical for a privacy regulation. It reads like a checklist because it is one.

The six core elements in (c)(1) are: a description of the information to be used or disclosed that identifies the information in a specific and meaningful fashion; the name or other specific identification of the person or class of persons authorized to make the requested use or disclosure; the name or other specific identification of the person or class of persons to whom the covered entity may make the requested use or disclosure; a description of each purpose of the requested use or disclosure; an expiration date or an expiration event that relates to the individual or the purpose; and the signature of the individual and the date, plus a description of a personal representative's authority when a representative signs.

Two of those have built-in shortcuts that are easy to miss. On purpose, the rule says the statement "at the request of the individual" is a sufficient description when the individual initiates the authorization and does not, or elects not to, provide a statement of the purpose. On expiration, the rule says "end of the research study," "none," or similar language is sufficient if the authorization is for research, including for the creation and maintenance of a research database or repository. Outside research, an authorization with no end point at all is missing a core element.

The three required statements in (c)(2) are about informed choice rather than mechanics. The first is the right to revoke in writing, together with the exceptions to that right and a description of how to exercise it, which may be done by reference to the entity's notice of privacy practices. The second is the conditioning statement, which takes one of two forms depending on whether 164.508(b)(4) permits conditioning in your situation. The third is the redisclosure warning: that information disclosed under the authorization may be redisclosed by the recipient and may no longer be protected.

That third statement is not boilerplate. It is the single most important sentence on the page for the individual signing it. An employer, an attorney, a school, a life insurer, and a disability carrier are typically not covered entities. Once records reach them, HIPAA is finished, and whatever those organizations do next is governed by their own contracts and by other law. People sign releases without understanding that, and a form that buries the warning is technically compliant and practically misleading. Paragraph (c)(3) requires plain language for exactly this reason.

The five defects, and the one that causes most of the damage

45 CFR 164.508(b)(2) says an authorization is not valid if the document has any of five defects: the expiration date has passed or the expiration event is known to have occurred; the authorization has not been filled out completely with respect to a required element; the authorization is known to have been revoked; the authorization violates the compound authorization rules in (b)(3) or the conditioning prohibition in (b)(4); or material information in the authorization is known by the covered entity to be false.

The second defect deserves its own paragraph because of what follows from it. There is no partial credit. An authorization missing an expiration date is not a slightly weaker authorization that a reasonable person would honor. It is not an authorization, which means the disclosure made in reliance on it was not permitted, which means it was an impermissible use or disclosure of protected health information, which means the breach presumption at 45 CFR 164.402 applies and you now owe a documented four factor risk assessment to decide whether notification is required. A blank line on a form has walked you into the breach analysis.

This is why the generator surfaces missing elements with their citations rather than silently producing a document that looks finished. The completeness check is not a drafting nicety, it is the difference between a permitted disclosure and a reportable one.

The third defect, known revocation, is an operational problem rather than a drafting problem. Under 164.508(b)(5) an individual may revoke an authorization at any time in writing, with two exceptions: to the extent the covered entity has already acted in reliance on it, and where the authorization was obtained as a condition of obtaining insurance coverage and other law gives the insurer the right to contest a claim under the policy or the policy itself. A revocation that arrives at the front desk and sits in someone's inbox for a week while records go out under the original form is a defect the file cannot fix afterward. Whoever handles releases needs a place to record revocations that the person pulling records actually checks.

Four purposes that carry extra conditions

Most authorizations are ordinary: send these records to that person. Four categories are not, and each has its own paragraph in the regulation.

Psychotherapy notes. 45 CFR 164.508(a)(2) requires an authorization for any use or disclosure of psychotherapy notes, including for treatment, payment, or operations, with narrow exceptions for the originator's own use in treatment, the entity's own training programs, and defending itself in a legal action brought by the individual. Paragraph (b)(3)(ii) then requires the authorization to stand alone: it may only be combined with another psychotherapy notes authorization. The definitional question is where most of the errors live. Under 45 CFR 164.501, psychotherapy notes are notes recorded by a mental health professional documenting or analyzing the contents of a private, group, joint, or family counseling session, kept separate from the rest of the individual's record. The definition excludes medication prescription and monitoring, counseling session start and stop times, modalities and frequencies of treatment furnished, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. A therapist who keeps everything in one file has, as a practical matter, no psychotherapy notes to protect under this rule, because separateness is part of the definition.

Marketing. 45 CFR 164.508(a)(3) requires an authorization for any use or disclosure for marketing, other than a face-to-face communication made by the covered entity to the individual and a promotional gift of nominal value provided by the covered entity. If the marketing involves financial remuneration to the covered entity from a third party, the authorization must state that. The 2013 Omnibus Rule tightened this considerably, and the practical trap is that communications an organization thinks of as patient education can meet the marketing definition when a product manufacturer is paying for them.

Sale of protected health information. 45 CFR 164.508(a)(4) requires an authorization for any disclosure that is a sale, and requires the authorization to state that the disclosure will result in remuneration to the covered entity. The definition at 45 CFR 164.502(a)(5)(ii) is broader than a cash purchase and excludes several ordinary transfers, including public health disclosures, research disclosures where the payment is a reasonable cost-based fee to prepare and transmit the data, treatment and payment disclosures, and disclosures for the entity's own due diligence in a sale, transfer, merger, or consolidation. Read the exclusions before you conclude you need this form.

Research. Research is the flexible one. 164.508(b)(3)(i) allows a research authorization to be combined with any other written permission for the same study, including a consent to participate. 164.508(c)(1)(v) allows an open expiration. And 164.508(b)(4)(i) is the one place a provider may condition treatment on the authorization, and only for research-related treatment, never for the ordinary clinical care the person would receive regardless of the study.

Substance use disorder records are a different regime

A HIPAA authorization does not release records held by a federally assisted substance use disorder program. Those records live under 42 CFR part 2, and consent runs on 42 CFR 2.31. The protection is broader than most people expect: Part 2 protects the fact that a person applied for or received services from a Part 2 program, so even confirming that someone is your patient requires consent.

The 2024 Part 2 final rule, with a compliance date of February 16, 2026, moved Part 2 substantially closer to HIPAA. The headline change is that a patient may now sign a single consent covering all future uses and disclosures for treatment, payment, and health care operations, with recipients described by a general designation rather than named individually. Where a HIPAA covered entity or business associate receives Part 2 records for treatment, payment, or health care operations under that consent, it may redisclose them in line with the HIPAA rules rather than under the stricter Part 2 redisclosure prohibition. What did not change is the prohibition on using Part 2 records in a civil, criminal, administrative, or legislative proceeding against the patient without specific written consent or a court order, and consent for that purpose may not be combined with a consent for other purposes.

The disclosure still has to carry the notice at 42 CFR 2.32, and the phrase in that notice that matters operationally is the one stating that a general authorization for the release of medical or other information is not sufficient. If a request for Part 2 records arrives on a standard HIPAA release form, the answer is a Part 2 consent, not a judgment call.

Authorization is not the same as access, and the difference is expensive

The most consequential everyday error at a release of information desk is routing a patient who wants their own records through the authorization process.

The individual right of access at 45 CFR 164.524 gives a person the right to inspect and obtain a copy of protected health information about them held in a designated record set. It carries a 30 day response deadline with one 30 day extension available, a requirement to provide the copy in the form and format requested where readily producible, and a limit on fees to a reasonable cost-based fee covering labor for copying, supplies, postage, and preparing an explanation or summary if the individual agreed to one in advance. It also requires you to honor a request to send the copy by unencrypted email once you have warned the individual of the risk and they still want it.

An authorization carries none of those protections. It has no deadline, no fee cap, and no format guarantee. OCR's Right of Access Initiative has produced a long series of enforcement actions against entities that failed to provide timely access, and the typical fact pattern is not malice. It is a records process built entirely around third party requests, with patients funneled into it because that is the only workflow that exists. Build the two paths separately, train the desk on which is which, and the most common access failure disappears.

The related trap is the third party directive: an individual using the access right to direct a copy to someone else. That path was narrowed by litigation in 2020, and the current HHS access guidance carries a notice about it. The safe operational rule is that a request from the individual for their own copy is an access request, a request from a third party is an authorization, and a request from the individual to send records to a third party should be checked against your counsel's current reading before you apply access fee limits to it.

State law sits on top, and it is where templates break

HIPAA sets a floor. 45 CFR 160.203 preserves state laws that are more stringent, which means a form that satisfies 164.508 perfectly can still be inadequate in your state.

The categories that most often carry extra state requirements are HIV and AIDS status, substance use disorder treatment, mental and behavioral health records, genetic testing results, sexually transmitted infection information, and reproductive health care. Many states require a specific, separate authorization for these rather than allowing them to ride along on a general release, which is why the generator offers individual initial lines for each. Minors are the other recurring complication: state law decides when a minor may consent to their own care, and where a minor lawfully consented, the parent is generally not the personal representative for those records under 45 CFR 164.502(g).

A few states also impose their own content requirements or duration limits on authorizations. This is not a place to guess. The generator ends every draft with the instruction to have counsel confirm your state rules, and that instruction is doing real work.

The form is the easy part

Here is the uncomfortable truth about release of information: most improper disclosures involving authorizations are not caused by a bad form. They are caused by a good form used badly.

The recurring failures are all human. Records go out that exceed what the authorization described, because the person pulling them read the patient name and not the scope. An expired authorization is honored because nobody checked the date. A revocation sits unprocessed. Identity is not verified, and records go to someone impersonating an attorney's office. A personal representative signs with no documentation of authority and no one asks for it. A stack of records for the wrong patient with a similar name goes into the envelope. Each of those is a training and process problem, and each of them produces the same downstream consequence: an impermissible disclosure, a breach presumption under 164.402, a four factor risk assessment, and possibly notification within 60 days under 164.404.

The controls that prevent them are unglamorous. Verify the identity of the requester before you release anything, which 45 CFR 164.514(h) requires. Read the scope line and pull to it, not around it. Check the expiration on the day of release, not the day of receipt. Keep revocations in one place the release desk checks every time. Log every disclosure, because the accounting of disclosures right at 45 CFR 164.528 and any future complaint both depend on that log. Give the individual their copy when you were the one who asked them to sign, as 164.508(c)(4) requires. And retain the signed form for six years from creation or from the date it was last in effect, whichever is later, under 164.508(b)(6) and 164.530(j)(2).

None of that is complicated. All of it depends on the person at the desk knowing why it matters, which is what training buys. Completing a course does not make an organization compliant, and nobody can certify that it does. What it produces is dated, verifiable evidence that named people were taught the rules on specific dates, which is exactly the evidence that sits next to a signed authorization in a well kept file.

Authorization FAQ

Common questions about HIPAA authorization forms

What has to be on a HIPAA authorization form for it to be valid?

Nine things, and they are itemized in the regulation. 45 CFR 164.508(c)(1) lists six core elements: a description of the information to be used or disclosed that identifies it in a specific and meaningful fashion; the name or other specific identification of the person or class of persons authorized to make the use or disclosure; the name or other specific identification of the person or class of persons to whom the covered entity may make the disclosure; a description of each purpose; an expiration date or an expiration event that relates to the individual or the purpose; and the signature of the individual with the date. 45 CFR 164.508(c)(2) then adds three required statements: the individual's right to revoke in writing with the exceptions to that right and how to exercise it, whether treatment or payment or enrollment or eligibility for benefits can be conditioned on signing, and the potential for the information to be redisclosed by the recipient and no longer be protected. Paragraph (c)(3) requires plain language, and paragraph (c)(4) requires the covered entity to give the individual a copy when the covered entity is the one seeking the authorization.

What makes a HIPAA authorization invalid?

45 CFR 164.508(b)(2) lists five defects. The expiration date has passed or the expiration event is known to have occurred. The authorization has not been filled out completely with respect to a required element. It is known to have been revoked. It violates the compound authorization rules in (b)(3) or the conditioning prohibition in (b)(4). Or material information in it is known to be false. The second one is the one that catches people, because it converts a paperwork oversight into a legal problem: an incomplete authorization is not a slightly weaker authorization, it is not an authorization, and releasing records on it is an impermissible disclosure that starts a breach analysis under 45 CFR 164.402.

Can we accept an authorization that says 'any and all medical records'?

It is risky, and it is the single most common weakness in the forms that arrive at a release of information desk. The regulation requires a description that identifies the information in a specific and meaningful fashion. A blanket phrase arguably fails that test, and it also puts you in the position of deciding how much to send with no guidance from the individual. The practical fix is to narrow it in writing: dates of service, record types, and the condition or episode involved. If a requester sends you a blanket form, going back for a specific one is not obstruction. It protects the individual and it protects you, because an over-broad release that sends a psychiatric history to an employer who asked about a knee injury is the kind of disclosure that generates a complaint.

Do we need an authorization if the patient just wants their own records?

Usually not, and treating an access request as an authorization request is a common and expensive mistake. The individual right of access at 45 CFR 164.524 gives a person the right to inspect and obtain a copy of protected health information about them in a designated record set. It comes with a 30 day deadline, a single 30 day extension, and a limit on fees to a reasonable cost-based fee. An authorization has none of those protections attached. If you route a patient asking for their own chart through an authorization form and a records vendor charging a per-page fee, you have converted a right into a transaction, and OCR has enforced against exactly that pattern in its Right of Access Initiative. Use an authorization when a third party is the one requesting records, or when the disclosure sits outside the access right.

Why do psychotherapy notes need their own form?

Because the regulation says the authorization for them may not be combined with anything else. 45 CFR 164.508(b)(3)(ii) permits an authorization for the use or disclosure of psychotherapy notes to be combined only with another authorization for psychotherapy notes. Stapling one to a general records release makes both of them defective under (b)(2)(iv). The definition matters as much as the form. Under 45 CFR 164.501 psychotherapy notes are notes recorded by a mental health professional documenting or analyzing the contents of a private, group, joint, or family counseling session, kept separate from the rest of the record. The definition explicitly excludes medication prescription and monitoring, session start and stop times, the modalities and frequencies of treatment furnished, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. Those excluded items are ordinary record content and travel on an ordinary authorization.

When does an authorization have to say we are being paid?

Two situations, and they have separate citations. If the disclosure is a sale of protected health information, 45 CFR 164.508(a)(4) requires an authorization and requires that authorization to state that the disclosure will result in remuneration to the covered entity. If the use or disclosure is for marketing and the marketing involves financial remuneration to the covered entity from a third party, 45 CFR 164.508(a)(3)(ii) requires the authorization to state that such remuneration is involved. The definition of a sale at 45 CFR 164.502(a)(5)(ii) carries several exclusions, including disclosures for public health, for research where the payment is a reasonable cost-based fee to prepare and transmit the data, for treatment and payment, and for a covered entity's own due diligence in a sale or merger. Check the exclusions before you assume you need the form.

Can we refuse treatment to someone who will not sign?

Almost never. 45 CFR 164.508(b)(4) prohibits conditioning treatment, payment, enrollment in a health plan, or eligibility for benefits on whether the individual signs an authorization, and the form has to say so. There are three narrow exceptions. A health care provider may condition research-related treatment on an authorization for the use or disclosure of protected health information for that research. A health plan may condition enrollment or eligibility on an authorization sought before enrollment for underwriting or eligibility determinations, so long as it is not for psychotherapy notes. And a covered entity may condition the provision of health care that is solely for the purpose of creating protected health information for disclosure to a third party, such as a pre-employment physical, on an authorization for that disclosure. When one of those applies, the form states the consequences of refusing to sign rather than promising that nothing is conditioned.

Are substance use disorder records different?

Yes, and a HIPAA authorization does not release them. Records held by a federally assisted substance use disorder program are governed by 42 CFR part 2, and consent runs on 42 CFR 2.31 rather than 164.508. Part 2 protects even the fact that a person applied for or received services from a Part 2 program, so confirming that someone is your patient needs consent too. The 2024 Part 2 final rule, whose compliance date was February 16, 2026, aligned much of Part 2 with HIPAA and now allows a single consent covering all future uses and disclosures for treatment, payment, and health care operations, with the recipients described by a general designation. The disclosure still has to carry the notice required by 42 CFR 2.32, and Part 2 records still may not be used in a proceeding against the patient without specific written consent or a court order. Selecting the Part 2 record type in the generator switches the document to a consent built on those rules.

Does state law change what we need?

Frequently, and this is where a generic template does the most damage. HIPAA is a floor, not a ceiling, and 45 CFR 160.203 leaves more stringent state privacy laws in force. Many states require a separate, specific authorization to release HIV or AIDS information, genetic testing results, mental health records, or substance use disorder treatment information, and many treat the records of minors and of emancipated minors under rules that differ from the federal default about who counts as a personal representative. Some states set their own form content requirements or their own maximum authorization duration. That is why the generator offers separate initial lines for the specially protected categories, and why every draft ends by telling you to have counsel confirm your state's rules before you adopt it.

How long do we keep the signed form?

Six years, at minimum. 45 CFR 164.508(b)(6) requires a covered entity to document and retain any signed authorization as required by 45 CFR 164.530(j), and 164.530(j)(2) sets the retention period at six years from the date of creation or the date when the document was last in effect, whichever is later. Note the second half of that clause. An authorization with a three year expiration signed in 2026 is last in effect in 2029, so the six year clock runs from there, not from the signature date. Keep the disclosure log alongside it. If someone later exercises the accounting of disclosures right at 45 CFR 164.528, or if a complaint arrives, the signed form and the record of what was actually sent are the two documents you will be asked for.

Does using this form make our organization HIPAA compliant?

No. A valid authorization form covers one narrow requirement. Organizational compliance is a much larger program that includes a written risk analysis, administrative, physical, and technical safeguards, a notice of privacy practices, individual rights processes, business associate agreements, breach response, workforce training, and ongoing oversight. No document template and no training provider can certify an organization as HIPAA compliant, and the federal government does not accredit or endorse HIPAA training providers. What a good form and dated training records give you is evidence: proof that the release was authorized and that the people handling it had been taught the rules.

Once the form is right, the next question is whether the people using it know what it covers. Start with HIPAA certification or plan a team rollout for everyone who touches PHI.

The other half of the file

A perfect form does not help if the desk releases more than it covers.

Covered entities owe workforce training under the Privacy Rule and a security awareness program under the Security Rule. Business associates owe the security program too. Train the people who handle records with a course that produces dated, verifiable certificates, and keep those records next to your signed authorizations.