Release of information form

A release of information asks a patient to say who can see their records, what records, and why. This form is a REQUEST FORM only — it collects the patient's wishes and must be kept on file, but the provider still follows their own compliant process to verify the request, authenticate the recipient, and decide what actually gets released. A typed name is not a legal signature. Export the responses to keep with your records.

The form beside this text is live. Fill it in and submit it — it validates exactly as it would for a real respondent, and saves nothing.

Checkbox groups let patients restrict what is shared

A dropdown for "what records" would force choose-one. A checkbox group lets a patient say "medical history and medications only, not therapy notes". Specific choices prevent over-disclosure.

A typed name is an electronic acknowledgment, not a binding signature

The field is labeled "Type your full name" and the form says a typed name is not a signature. The typed name is proof the patient submitted the form, not proof of a legal signature. Your compliant process verifies it; the form collects it.

No card required.

Release of Information Form

Live preview

How to build this form

8 steps in the editor. Nothing here needs a paid plan.

  1. Add a text field for the patient's full legal name and a date field for date of birth for verification.
  2. Add fields for the recipient's full name, email and phone so your staff can verify and contact them about what records are being released.
  3. Add a checkbox group for what may be shared — medical history, test results, medications, imaging, therapy notes — so the patient can be specific about scope.
  4. Add a dropdown for purpose — treatment, insurance, legal, disability claim, other — so you know why the release was requested.
  5. Add a date field for expiry or duration so the release does not stay valid indefinitely.
  6. Add a required checkbox for consent — the patient must check it to confirm they understand and authorize.
  7. Add a text field for the patient's typed name as their acknowledgment. Label it clearly: "Type your name as an electronic authorization".
  8. Export to your records keeper. The patient keeps a copy if they need it; this is not a substitute for your own HIPAA-compliant authorization process.

Fields in this form

10 fields, using 6 of the 19 field types available.

QuestionField typeRequired
Patient's full legal nameShort textYes
Patient's date of birthDateYes
Recipient's full nameShort textYes
Recipient's emailEmailYes
Recipient's phonePhoneOptional
What records may be shared?CheckboxesYes
Purpose of this releaseDropdownYes
Release expires onDateYes
I authorize the release of my medical records as described aboveCheckboxesYes
Type your full nameShort textYes

What goes wrong with this form

Specific to a release of information form, not general advice about forms.

Treating the form as a legal document

This is a REQUEST form that you keep on file, not your official HIPAA-compliant release. You still use your provider's authorized release language, your own verification process, and your own retention schedule. The form captures what the patient is asking for; your process ensures it is done legally.

Not setting an expiry date

Add an expiry date or duration so the release does not stay valid forever. A date in the form prompts your staff to re-verify before releasing very old records. Many regulations limit how long a release is valid anyway.

Asking for too much detail upfront

Stick to legal name, date of birth, recipient, what records, purpose and expiry. Asking for notes, relationship to patient and reasons prolongs the form without information your compliant process will not use.

Questions about this form

Is a typed name on a form a legal signature for a release?

No. A typed name is an electronic acknowledgment that the patient submitted the form. It is not a legally binding signature. Your healthcare provider must use your own formal release-of-information process with proper verification, authentication and retention, because that process complies with your jurisdiction and your insurance. This form collects the patient's request; your provider verifies and acts on it.

Does this form satisfy HIPAA?

No. This is a general authorization form, not a covered HIPAA form. A HIPAA-compliant release has specific language and disclosures your provider's legal team approved. Use this form to collect the patient's wishes, then apply your provider's own authorized release process before actually sending records.

What should I do with the filled forms?

Store them with the patient's medical record in your secure records system for the retention period your regulations require. Export the responses as CSV, then file them according to your retention schedule.