How to Complete an Authorization to Release Information to a Third Party

An authorization to release information to a third party is a signed, dated document that lets a hospital, school, bank, employer, or government agency share your records with someone you name. To complete one so it actually gets honored, use the record holder’s own form when you can, fill in every required field (the records, the holder, the recipient, the purpose, an expiration, your signature and date), attach proof of your legal authority if you’re signing on someone else’s behalf, and submit it in a way that gives you proof of delivery. Most rejections come from missing one of those pieces, not from anything complicated.

Why the Form Is Required at All

Federal privacy laws block organizations from handing over your personal records without your written consent. Healthcare providers and insurers operate under HIPAA, which sets detailed rules for what a valid authorization must say.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required Schools that receive federal funding follow FERPA, which requires signed and dated consent naming the records, the purpose, and the recipient before releasing student information.2eCFR. 34 CFR 99.30 – Under What Conditions Is Prior Consent Required to Disclose Information Federal agencies operate under the Privacy Act of 1974, which prohibits disclosure of records about you without your prior written consent.3Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals Employers pulling a consumer report for a background check need a standalone written disclosure and your written authorization under the FCRA.4Office of the Law Revision Counsel. 15 USC 1681b – Permissible Purposes of Consumer Reports

The upshot for you: whichever kind of record you’re trying to move, the receiving organization can only act on a written authorization that satisfies the relevant law. Getting the form right the first time is the difference between records arriving in weeks and the request bouncing back with no explanation.

Start by Asking for Their Form

Most organizations have their own authorization template, and using it is almost always the safest approach. Hospitals and clinics post theirs on a medical records page or patient portal. Schools keep theirs with the registrar. Banks and financial institutions usually route the request through a privacy or compliance department. If you cannot find it online, call the administrative office and ask specifically for their authorization to release information form.

Some providers will only honor their own version and reject anything else. Even when an organization technically accepts outside forms, using theirs prevents formatting mismatches and guarantees every field the staff expects to see is present. Draft your own only when the record holder has no template, and if you do, make sure it contains everything in the checklist below.

What the Form Must Contain

HIPAA’s authorization requirements are the most detailed of the federal privacy laws, so they double as a practical checklist for almost any release. A valid HIPAA authorization must include all of the following:1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required

  • A specific description of the information to be released. “All records” is technically valid but often triggers extra scrutiny. You’ll get faster results naming dates of service, record types (lab results, imaging, visit notes), or account numbers.
  • The name of the person or organization currently holding the records.
  • The name and contact details of the person or company who should receive them.
  • The purpose of the disclosure. If you’re initiating the request yourself and prefer not to state a reason, writing “at the request of the individual” is enough under HIPAA.
  • An expiration date or event after which the authorization no longer works. A specific calendar date is clearest. You can also tie expiration to an event (“upon completion of the loan application”), but vague language like “during the life of the claim” invites rejection.
  • Your signature and the date you signed. A signature without a date, or a date without a signature, invalidates the form.

A HIPAA authorization must also include three notice statements: that you can revoke the authorization in writing, whether the organization can refuse to treat or enroll you if you decline to sign, and that the information may be re-disclosed by the recipient and no longer protected by HIPAA.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required Pre-printed forms build this language in. If you draft your own, leaving it out makes the authorization defective.

FERPA consent has to specify the records, the purpose of the disclosure, and the party or class of parties who will receive them.2eCFR. 34 CFR 99.30 – Under What Conditions Is Prior Consent Required to Disclose Information Other releases follow the same shape: name the records, name the recipient, state the purpose, sign and date.

Getting Your Identifying Details Right

Expect the form to ask for your date of birth, Social Security number, or other identifiers so the records staff can match you to the right file. Double-check every digit. A transposed number or a maiden name that no longer matches what the provider has on file is one of the most common reasons a request stalls.

Whether You Need a Notary

Most medical and educational release forms do not require notarization. A signature and date are enough. Some financial institutions and government agencies do require a notary’s seal, particularly for high-value transactions or when a representative is signing rather than the record holder. Read the form’s instructions before assuming. If notarization is required, bring valid photo ID and fill in every field before you sign. Notaries generally refuse to notarize documents with blank spaces because those blanks create a fraud risk.

Signing on Someone Else’s Behalf

You sign the form yourself in most cases. When the person whose records are at stake is a minor, incapacitated, or deceased, someone with legal authority has to sign instead, and the form needs to show what that authority is.

Children

For medical records, a parent, legal guardian, or person acting in a parental role generally has authority to sign for an unemancipated minor.5eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information, General Rules There are exceptions. If the minor lawfully consented to the treatment on their own — as many states allow for services like mental health or reproductive care — the parent may not have the right to authorize disclosure of those specific records. When someone other than the patient signs, the form must describe that person’s authority, for example “parent of minor child.”

For school records, FERPA gives parents the right to consent. That right transfers to the student at age 18 or when the student enrolls in a postsecondary institution, and from that point the school needs the student’s consent, not the parent’s.6Office of the Law Revision Counsel. 20 USC 1232g – Family Educational and Privacy Rights

Incapacitated Adults and Deceased Patients

If an adult cannot make their own healthcare decisions, anyone with legal authority under applicable law — a court-appointed guardian, a healthcare power of attorney holder — is treated as the individual’s personal representative under HIPAA.5eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information, General Rules When signing as a personal representative, attach a copy of the document that establishes your authority: a guardianship order, a power of attorney, or letters testamentary and a death certificate for a deceased person’s estate. Providers routinely deny authorizations from representatives who submit no proof.

Electronic Signatures and Portals

Under the federal E-SIGN Act, a signature or record cannot be denied legal effect just because it is in electronic form.7Office of the Law Revision Counsel. 15 USC 7001 – General Rule of Validity FERPA also recognizes electronic signatures on consent forms as long as the signature identifies and authenticates the signer and shows their approval of the content.2eCFR. 34 CFR 99.30 – Under What Conditions Is Prior Consent Required to Disclose Information In practice, many hospitals, insurers, and schools accept electronic authorizations through their patient or student portals. If you’re submitting a standalone document rather than going through a portal, ask first — some organizations still require a wet-ink signature on paper, and a rejected electronic form only costs you time.

Submitting the Form and Tracking It

Pick a submission method that gives you proof of receipt. A secure online portal is usually fastest and creates an automatic timestamp. Faxing to a dedicated records line is still standard at many healthcare facilities. If you mail the form, use certified mail with a return receipt.

Under HIPAA, a covered entity must act on a request for access to protected health information within 30 days of receiving it. The organization can extend that deadline once by another 30 days, but it must notify you in writing with the reason for the delay and the expected completion date.8eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information For non-medical records, response times vary by organization, so ask when you submit how long the wait typically runs.

Providers may charge a reasonable fee to cover copying and mailing. Electronic copies through a portal are often free. HIPAA limits paper-copy charges to the reasonable cost of labor, supplies, and postage, and state law frequently sets per-page caps. If a quoted fee looks high, ask the provider to explain how it was calculated.

After the expected processing window, call the receiving party to confirm the records arrived. If they haven’t, contact the records department at the disclosing organization to check status. A polite follow-up at the two-week mark often catches administrative snags before they turn into real delays.

Mistakes That Get Authorizations Rejected

Most rejections come from the same short list of preventable errors:

  • Missing or mismatched identity details. A wrong date of birth, a maiden name that no longer matches the file, or a transposed SSN digit will stop the request cold.
  • No signature or no date. Both are core elements, and missing either gives the records department grounds to reject the form immediately.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
  • Expired authorization. If the expiration date has passed or the event has already occurred, the form is dead on arrival. Pick a date far enough out to absorb processing time.
  • Vague or missing recipient. Listing the recipient on a cover letter but leaving the field blank on the authorization itself is a common cause of denial.
  • Wrong form. Some organizations only accept their own template. If a request is rejected on this ground, ask for the correct version and resubmit.
  • No proof of representative authority. When someone other than the patient or student signs, attach the guardianship order, power of attorney, or death certificate plus letters testamentary. Providers regularly deny third-party authorizations that arrive without proof.

When a form is rejected, the records department should tell you why. Fix the specific issue and resubmit rather than starting over with a fresh form — unless the problem is that you used the wrong template entirely.

Revoking an Authorization You Already Signed

You can withdraw an authorization at any time. Under HIPAA, the revocation must be in writing and takes effect as soon as the covered entity receives it.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required It does not undo disclosures the organization already made while the authorization was active; it only stops future releases.

To revoke, send a signed and dated letter, or fill out the organization’s revocation form if it has one, stating that you’re withdrawing the authorization. Identify the original by date and, if possible, reference number. Send it the same way you submitted the original — portal, fax, or certified mail — so you have a record of when the organization received it. Once processed, the organization must stop releasing your records under that authorization from that point forward.