Permitted Uses
Specify exact services and purposes for which the contractor may access PHI, and prohibit other uses such as marketing or resale without express consent.
A clear, signed BAA reduces regulatory exposure, documents required safeguards, and establishes breach response obligations. It creates enforceable contractual obligations that align with HIPAA duties and supports audits, risk assessments, and vendor oversight.
The agreement is used by covered entities and contractors who handle PHI; different stakeholders have distinct responsibilities before and after execution.
Each party should confirm authorized signatories, review technical safeguards, and document evidence of execution and distribution to relevant operational teams.
Specify exact services and purposes for which the contractor may access PHI, and prohibit other uses such as marketing or resale without express consent.
Mandate administrative, physical, and technical protections such as access controls, encryption at rest and in transit, and regular security assessments.
Require prompt notification to the covered entity upon discovery of a breach, investigate root cause, and cooperate with required notifications and mitigation.
Obligate the contractor to require compliant written agreements with subcontractors that mirror the BAA obligations and permit audits.
Define procedures for returning or securely destroying PHI upon termination, and exceptions for retained backups or legal holds.
Allocate responsibility for damages, regulatory fines, and costs for breach response, and state any limits on liability or insurance requirements.
| Field | Configuration |
|---|---|
| Authentication | Email plus optional SMS or KBA |
| Audit Trail | Enable full timestamps and IP logging |
| Template | Create reusable BAA template with locked clauses |
| Retention | Set automatic archival and export settings |
Choose a signing platform that supports audit trails, secure storage, and integrations needed for vendor management.
Ensure the provider offers HIPAA BAA support, configurable authentication (SMS, KBA, SSO), and preserves machine-readable audit logs for compliance reviews and incident investigations.
Execute BAA before contractor accesses PHI
Notify covered entity without unreasonable delay; no later than 60 days (HIPAA Breach Notification expectations)
Perform yearly contract and security control reviews
Obtain downstream agreements before subcontractor begins PHI work
Apply retention rules per written records policy
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day trial | Yes | Yes | Yes | Yes |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
Fertility Centers relied on digital execution to ensure compliance and speed.
Xerox integrated eSigning with enterprise systems to manage vendor agreements at scale.