BLOG

·

·

1 min read

Release of Information Form Template and the Six Elements That Make It Valid

Release of Information Form Template and the Six Elements That Make It Valid

A HIPAA release of information form template, the six core elements that make an authorization valid, and the five defects that void a signed one.

A HIPAA release of information form template, the six core elements that make an authorization valid, and the five defects that void a signed one.

Every page offering you a HIPAA release form gives you the form. Almost none of them mentions the rule that decides whether the signed copy is worth anything.

An authorization that has not been filled out completely, with respect to any required element, is not valid [1].

One blank field. Not "weaker," not "questionable." Not valid, which means disclosing on it is a disclosure without authorization.

So here is the template, the six elements the regulation requires, and the five specific defects that turn a signed form in your file into no authorization at all.

Key Takeaway: A release of information form, also called a HIPAA authorization or a medical release form, is a patient's written permission for a provider to disclose protected health information for a purpose HIPAA does not already permit. To be valid it must contain six core elements: a specific description of the information, who may disclose it, who may receive it, the purpose, an expiration date or event, and the individual's signature and date [1]. It must also carry three statements covering the right to revoke, whether treatment can be conditioned on signing, and the potential for redisclosure, and it must be in plain language with a copy given to the patient [1]. An authorization with any required element left blank is not valid [1]. No authorization is needed to use or disclose information for treatment, payment or health care operations [2]. Sully.ai's AI Scribe writes clinical documentation into the EHR so the record being released is complete and current.

What a Release of Information Form Is

It is written permission from a patient before you disclose their protected health information to someone, for a reason HIPAA does not already cover.

The regulation calls it an authorization. Everyone else calls it something else, which is the first problem.

Release of Information, HIPAA Authorization, and Medical Release Form

These are the same document.

release of information form, a HIPAA release form, a medical release form, a medical records release form, a HIPAA authorization form, and an authorization for release of information all describe one thing: the written permission defined in 45 CFR 164.508 [1].

Two US states also publish their own mandated forms, so a generic template is not automatically acceptable everywhere [3].

One document it is not: the medical history form a patient completes at intake. That collects information. This one releases it.

The naming matters only because it makes the form hard to find and easy to duplicate. Practices end up with three versions in circulation, and the oldest one is usually missing a required statement.

When You Actually Need One

Less often than most practices collect it.

A covered entity may use or disclose protected health information for its own treatment, payment or health care operations without any authorization [2]. Sending records to a treating specialist, billing a payer, running internal quality review: none of that needs a signed release.

What does need one is disclosure outside those permitted uses. An employer. An attorney. A life insurance underwriter. A school. A family member who wants to speak to the practice on the patient's behalf.

And one category runs the opposite way, covered at the end of this article: psychotherapy notes need an authorization even for treatment, payment or operations [1].

The Six Elements That Make an Authorization Valid

The regulation is specific about this, and it is worth reading closely rather than trusting a template you inherited.

The Six Core Elements

A valid authorization must contain at least the following [1]:

  1. A description of the informationto be used or disclosed, that identifies it "in a specific and meaningful fashion"

  2. Who may disclose it. The name or other specific identification of the person or class of persons authorised to make the disclosure

  3. Who may receive it. The name or other specific identification of the person or class of persons to whom the disclosure may be made

  4. The purpose of each requested use or disclosure. When the patient initiates the authorization, "at the request of the individual" is a sufficient description of the purpose

  5. An expiration date or an expiration event relating to the individual or to the purpose

  6. Signature of the individual, and the date. If a personal representative signs, the form must also describe that person's authority to act


Reference card listing the six core elements and three required statements that a valid HIPAA authorization must contain under 45 CFR 164.508, with the plain language, patient copy and six year retention requirements

Element four has a useful shortcut and element one has a common failure, both covered below.

The Three Required Statements

Beyond the six elements, the form has to carry statements adequate to put the patient on notice of three things [1]:

  • The right to revoke the authorization in writing, plus either the exceptions to that right and how to revoke, or a reference to those details in your notice of privacy practices

  • Whether treatment can be conditioned on signing. Either a statement that you may not condition treatment, payment, enrollment or eligibility on the patient signing, or, where you are permitted to condition it, the consequences of refusing

  • That the information may be re-disclosed by the recipient and may no longer be protected by the Privacy Rule

That last one is the statement most often missing from a homemade form.

Plain Language and the Copy Requirement

Two short rules that are easy to overlook.

The authorization must be written in plain language [1]. And if you sought the authorization, you have to give the patient a copy of the signed form [1].

There is also a retention obligation. A signed authorization is documentation that must be kept for six years from the date it was created or from the date it was last in effect, whichever is later [4].

The Release of Information Form Template

Copy this. Each line is labelled with the requirement it satisfies so you can see what is load-bearing and what is yours to adjust. If you also need the intake side, there is a separate medical history form template.

The Blank Template to Copy

AUTHORIZATION FOR RELEASE OF PROTECTED HEALTH INFORMATION

Patient name, date of birth, and identifier

1. Information to be disclosed (core element 1) Describe specifically. Record types and a date range. For example: "Office visit notes, laboratory results and imaging reports from 1 January 2025 to 30 June 2026."

2. Disclosed by (core element 2) Name of the practice, clinician or department authorised to release the information.

3. Disclosed to (core element 3) Name and address of the person or organisation receiving it.

4. Purpose (core element 4) State the purpose. If the patient is initiating this themselves, "at the request of the individual" is sufficient.

5. This authorization expires on (core element 5) A date, or an event such as "on conclusion of my disability claim."

6. Signature and date (core element 6) Signature of patient, or of personal representative with a description of their authority to act.

Required statements (all three) I may revoke this authorization in writing at any time, except to the extent that action has already been taken in reliance on it. Instructions for revoking are in the notice of privacy practices. Treatment, payment, enrollment and eligibility for benefits will not be conditioned on whether I sign this authorization. Information disclosed under this authorization may be redisclosed by the recipient and may then no longer be protected by federal privacy law.

A copy of this signed authorization has been provided to the patient.


Annotated example of a completed release of information form with each line tagged by the HIPAA core element it satisfies, and a note that leaving any required element blank voids the authorization

Getting the Description of Information Right

Element one is the field that fails most often, because "all records" is not a specific and meaningful description.

Too broad: "Any and all medical records. "Workable:" Office visit notes, imaging reports and operative reports relating to treatment of the lumbar spine, 1 March 2024 to present."

Too broad:"Everything in the chart. "Workable:" Complete record from 1 January 2026 to the date of signature, excluding psychotherapy notes."

Too broad:"Records for insurance. "Workable:" Discharge summary and cardiology consultation notes from the admission of 4 to 9 February 2026."

Being specific is not a favour to the disclosing party. A vague description is the reason a request comes back refused, which costs the requester weeks.

Where Sully.ai Fits in Records Release

The honest version of this is narrow, so here it is plainly.

A release moves the record. The record is the note. What actually reaches the attorney, the insurer or the next provider is only as good as what got documented at the time, and thin notes make thin disclosures that generate follow-up requests.

Sully.ai's AI Scribe captures the encounter and writes it into the chart during the visit, so the record being released is complete and current rather than reconstructed later. It runs on a single integration across Epic, Cerner, Meditech and Athenahealth.

Records requests also arrive by phone, in volume, and mostly from people who need a status update. The AI Receptionist answers those. Sully operates across 5,000+ providers and has delivered 50M+ hours of AI work [5].

To be clear about what Sully does not do: it does not complete, validate, track or store your authorizations. That is a records management and compliance function, and this article is not claiming otherwise. What we can speak to is whether an AI scribe is HIPAA compliant, which is a different question. Our security and compliance posture is a separate question from your authorization process.

Five Ways a Signed Form Becomes Invalid

This is the part worth putting in front of whoever processes disclosures. An authorization is not valid if the document submitted has any of these defects [1]:

  1. The expiration date has passed, or the expiration event is known to have occurred

  2. The authorization has not been filled out completely, with respect to any required element

  3. The authorization is known to have been revoked

  4. It violates the compound authorization or conditioning rules in the regulation

  5. Any material information in it is known to be false

Read that list again and notice where the risk actually sits. Numbers one, two and three are not legal failures. They are front-desk failures.

An expired form nobody re-checked. A blank field nobody caught. A revocation that arrived and never made it onto the record. Each one turns a form sitting in a file into no authorization at all, and a disclosure made on it into a disclosure made without permission.

A Release Is Not a Records Request

Here is the distinction that causes the most unnecessary friction, in both directions.

When a patient asks for a copy of their own records, that is not an authorization. It is the right of access, and it works differently.


Two column table comparing a HIPAA authorization with the individual right of access, showing that a records request by the patient triggers a thirty day deadline and a capped cost-based fee rather than requiring an authorization form

The Right of Access and Its Thirty Day Clock

An individual has a right of access to inspect and obtain a copy of their protected health information held in a designated record set [6].

The covered entity must act on that request no later than 30 days after receiving it, either by granting it and providing the access, or by providing a denial [6].

That is a request the patient makes, not permission the patient grants. It does not require a third-party authorization form, and routing it through one adds a step the regulation does not ask for.

What You Are Allowed to Charge

If the patient asks for a copy, you may impose a reasonable, cost-based fee. The regulation limits what that fee may include: labour for copying the information, whether on paper or electronically, supplies for the paper copy or portable media, and postage where the patient asked for it to be mailed [6].

One exception worth knowing in both directions: psychotherapy notes are excluded from the right of access [6].

Special Cases Worth Knowing

Two situations where the general rules above do not apply cleanly.

Psychotherapy Notes Need an Authorization Anyway

Everything in the first section said treatment, payment and operations need no authorization. Psychotherapy notes are the exception that runs the other way.

A covered entity must obtain an authorization for any use or disclosure of psychotherapy notes, including for treatment, payment or health care operations [1]. The narrow carve-outs are use by the originator of the notes for treatment, use in the entity's own training programmes, and use to defend itself in a legal action brought by the individual [1].

Authorizing a Family Member

This is the most common patient-facing version of the form, and the six elements are exactly the same.

The one wrinkle is signature authority. If someone other than the patient signs, the form must also describe that person's authority to act for them [1]. A spouse's name on the signature line, with nothing establishing why they may sign, leaves element six incomplete.

One caveat on scope. Some states impose stricter requirements than HIPAA, particularly for mental health, HIV status and substance use records, and substance use treatment records are governed separately under 42 CFR Part 2. Those rules are outside what is covered here, and they can change what your form has to say.

Book a demo and bring a records request you had to send back. The question worth asking is whether the note was thin or the form was.

FAQ

Q: What is a release of information form? It is a patient's written permission for a provider to disclose protected health information for a purpose HIPAA does not already permit. The regulation calls it an authorization, and it has six required elements plus three required statements [1].

Q: What makes a HIPAA authorization valid? Six core elements: a specific description of the information, who may disclose it, who may receive it, the purpose, an expiration date or event, and the patient's signature and date. Plus three statements covering the right to revoke, whether treatment can be conditioned on signing, and the possibility of redisclosure. It must be in plain language, and the patient must get a copy if the provider sought the authorization [1].

Q: Do I need an authorization to share records with another provider for treatment? No. A covered entity may use or disclose protected health information for treatment, payment or health care operations without an authorization [2]. Psychotherapy notes are the main exception, and those require an authorization even for those purposes [1].

Q: How long is a release of information form valid? Until the expiration date or expiration event written on it. There is no fixed statutory duration, and an authorization whose expiration date has passed is not valid [1]. Signed authorizations have to be retained for six years from creation or from when they were last in effect, whichever is later [4].

Q: Is a release form the same as asking for my own records? No, and the difference matters. Requesting your own records is the right of access, which obliges the provider to act within 30 days and limits the fee to a reasonable, cost-based amount covering labour, supplies and postage [6]. An authorization is for releasing information to someone else.

Sources

[1] U.S. Government Publishing Office — 45 CFR 164.508, Uses and Disclosures for Which an Authorization Is Required [2] U.S. Government Publishing Office — 45 CFR 164.506, Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations [3] HIPAA Journal— HIPAA Release Form[4] U.S. Government Publishing Office — 45 CFR 164.530, Administrative Requirements[5] Sully.ai — The AI Workforce for Healthcare [6] U.S. Government Publishing Office — 45 CFR 164.524, Access of Individuals to Protected Health Information

TABLE OF CONTENTS

Hire your

Medical AI Team

Take a look at our Medical AI Team

AI Receptionist

Manages patient scheduling, communications, and front-desk operations across all channels.

AI Scribe

Documents clinical encounters and maintains accurate EHR/EMR records in real-time.

AI Medical Coder

Assigns and validates medical codes to ensure accurate billing and regulatory compliance.

AI Nurse

Assesses patient urgency and coordinates appropriate care pathways based on clinical needs.

Ready for the

future of healthcare?

Ready for the

future of healthcare?

Ready for the

future of healthcare?