Instead of using a homegrown keyed hash function for signing unique records, use blake2b which features both custom digest lengths and signing keys. This will require regeneration of all the signed records in the database but we're not in production yet (5/4/21) so that should be OK.