A medical authorization form is a written release that lets a healthcare provider use or disclose a patient's protected health information for a specific stated purpose — and under HIPAA it is only valid if it contains six core elements plus several required statements, including the patient's right to revoke. Below is a plain-language breakdown of every element, plus a copy-pasteable sample template you can adapt with your compliance team.
This article is educational, not legal advice. Confirm any form you actually use with your own counsel or HIPAA compliance officer before you deploy it.
What a medical authorization form actually is
A medical authorization form is how a patient gives written permission for their health information to be used or shared beyond routine care. HIPAA (the Health Insurance Portability and Accountability Act — the federal law that governs patient health data) lets providers use protected health information, or PHI — anything that identifies a patient and relates to their health — for treatment, payment, and normal operations without a signed release.
Almost everything outside that lane needs an authorization: sending records to a lawyer, a school, an employer, or a life insurer; releasing files to a new provider at the patient's request; using a photo in marketing; releasing psychotherapy notes. The general rule that separates "no authorization needed" from "authorization required" lives in 45 CFR 164.502, and the form's contents are dictated by section 164.508.
The HIPAA-required elements every valid authorization must contain
A HIPAA authorization is only valid if it carries six core elements and three required statements — miss one and the release can be treated as defective. Per 45 CFR 164.508, here is what each one means in plain language:
| Required element | What it means |
|---|---|
| Specific description of the information | Identify the PHI in a "specific and meaningful" way — not "all my records," but which records, dates, or types. |
| Who may disclose | The person or class of persons authorized to release the information (your practice, or a named provider). |
| Who receives it | The person or class of persons the information may be sent to. |
| Purpose of the disclosure | A description of each purpose. "At the patient's request" is acceptable when the patient initiates it. |
| Expiration date or event | A date or an event that ends the authorization (for example, "one year from signing" or "end of treatment"). |
| Signature and date | The patient's signature and the date. If a personal representative signs, their authority must be described. |
| Required statements | The right to revoke in writing; whether treatment can be conditioned on signing; and that re-disclosed information may lose HIPAA protection. |
A sample medical authorization form template
Use the skeleton below as a starting point only — the bracketed placeholders are generic, and every one should be reviewed by your compliance team before a patient signs. It is a plain sample, not a real person or practice presented as real.
Authorization for Use or Disclosure of Health Information
Patient name: [Patient name] Date of birth: [date of birth]
I authorize [Provider or practice name] to disclose the following information: [records requested — e.g., visit notes from a date range].
To: [name of the person or organization receiving the information].
For the purpose of: [purpose — e.g., continued care, or at the patient's request].
This authorization expires on: [expiration date or event].
I understand I may revoke this authorization in writing at any time by contacting [revocation contact], except where action has already been taken in reliance on it.
I understand that treatment, payment, enrollment, or eligibility [is / is not] conditioned on signing, and that information disclosed may be re-disclosed by the recipient and no longer protected by HIPAA.
Signature: [signature] Date: [date]
Paper form vs a secure digital form: never collect PHI through a generic web form
A standard "contact us" web form is not a safe place to collect an authorization. It usually emails submissions in plain text and stores them somewhere with no business associate agreement in place — exactly the kind of PHI handling HIPAA penalizes. A paper form handed over at the front desk is safe by default; a web form is only safe if it was built specifically to carry PHI.
A dental analogy from my own data: in my audit of 6,554 dental practice websites, 94% had three or more fixable issues site-wide — and a generic contact form doing double duty as intake is one I see constantly. That lesson crosses straight over to medical practices. For the full picture on where clinic forms go wrong, I walk through it in HIPAA compliance for clinic websites, and I cover the platform side in the best HIPAA-compliant website builders in 2026.
How to put a compliant authorization form on your website
The safe pattern is to route PHI into a HIPAA-eligible intake tool, never your generic form handler. Here is the order I use when I build intake for a practice:
- Confirm the vendor will sign a business associate agreement (BAA); no BAA, no PHI.
- List every field that touches PHI and separate it from marketing-only fields.
- Rebuild the authorization form so it carries all six core elements and three required statements above.
- Serve every form page over HTTPS and turn off plain-text email of submissions.
- Route submissions into an encrypted, access-controlled system — not a shared inbox.
- Give patients a clear revocation path and log who accessed each record.
- Have counsel or your compliance officer sign off before the form goes live.
This is the same discipline behind a proper medical clinic website design: forms are load-bearing, not decoration. The same care applies to a dental insurance verification form template or a dental referral form — anything carrying patient data belongs behind the same guardrails.
Getting it right
An authorization form is a legal instrument first and a web element second. Get the six core elements and the three statements right, keep PHI off any form that was not built for it, and confirm the final wording with your compliance team before you publish. If you want a second set of eyes on how your intake and authorization forms are set up, send me your site and I'll take a look.

