← All tools
🩹 HIPAA Authorization

Need your medical records sent to you, a family member, a new doctor, or an insurer or lawyer? This is the form that lets it happen — a HIPAA authorization that tells your doctor, hospital or health plan they have your permission to release your protected health information. You (the patient — or a parent or guardian signing for someone) stay in control of exactly what goes out. Pick the scope and PaperKit builds the right release: your COMPLETE medical record; only SPECIFIC records you describe (and nothing else); or just the records from a DATE RANGE you set. Then choose why you're releasing it — for your OWN use, to share with a CAREGIVER or family member, for a LEGAL, disability or INSURANCE matter, or so ANOTHER PROVIDER can continue your care — and PaperKit reshapes the purpose language to match. It names the covered entity that may release the records and the recipient who may receive them, and it handles the parts people miss: the specially-protected categories the law makes you opt into one by one — mental-health, substance-use-disorder (42 CFR Part 2), HIV/AIDS and genetic information — plus the HIPAA-required expiration date or event, your right to revoke in writing, and the redisclosure warning. It's self-drafted and NOT notarized: you review and e-sign online (a personal representative can sign for a minor or someone who can't sign), then print the clean PDF and hand it to whoever holds your records. (What's protected and how records are released can vary by provider and state; consider an attorney for complex situations.)

What records are you releasing?

The big lever — your whole record, only specific records, or just a date range.

Release your complete medical record. Everything the provider holds may be disclosed, except any sensitive categories you switch off below.

Why are you releasing it?

This reframes the purpose language HIPAA asks you to state.

A caregiver or family member is helping with your care and needs access to your information.

You (the individual — you e-sign)

The patient whose records these are. You draft and e-sign; a HIPAA authorization is NOT notarized.

Who may release the records (covered entity)

The doctor, hospital, clinic or health plan that holds your records.

Who may receive the records (recipient)

The person or organization your records are released to.

Sensitive information (opt in or out)

The law protects these categories separately — each needs its own permission. Uncheck any you want withheld.

Expiration & your rights

HIPAA requires an expiration — set a date OR an event. Leave both blank to default to one year from signing.

Governing law & extras
Live preview

A real, section-by-section HIPAA authorization. The scope drives what's released; the purpose reframes why. Publish to get a hosted link you can e-sign online.

Enter your name…
✨ PaperKit Pro

$9/mo — remove the DRAFT watermark + “Made with PaperKit” badge, unlimited clean-PDF authorizations, and Pro across every tool.

A HIPAA authorization is a template for convenience, not legal or medical advice. It directs a covered entity — a doctor, hospital or health plan — to disclose your protected health information to someone you name. To be valid under the HIPAA Privacy Rule it must identify the information, who may disclose it and who may receive it, the purpose, an EXPIRATION date or event, and your dated signature (a personal representative may sign for a minor or an incapacitated individual). Specially-protected records — psychotherapy notes, substance-use-disorder records under 42 CFR Part 2, HIV/AIDS and genetic information — generally require your specific, separate authorization, and 42 CFR Part 2 records may not be redisclosed without further consent. A provider cannot condition your treatment or benefits on signing, and you may revoke this authorization in writing except as already acted upon. Notarization is NOT required. PaperKit is not a law firm; consult a qualified attorney for complex situations.