Permitted Uses
Define exactly how PHI may be used or disclosed, including any limited purposes and prohibitions on further disclosure beyond the contract.
A precise contract clarifies responsibilities, limits liability, and sets minimum security and reporting standards between parties.
Who completes this contract depends on organizational role and whether PHI or other regulated data is exchanged.
Use the contract as a standard template for vendors handling data, then customize per service, risk, and jurisdiction.
Typically a senior officer or compliance lead at the covered entity with authority to bind the organization. This signer certifies that the organization requires the vendor to meet privacy and security obligations and can approve termination for material breaches.
An executive or authorized representative of the vendor who can commit the company to required safeguards, subcontractor flow-downs, and breach notification timelines. Signing binds the vendor to contractual and regulatory duties.
Define exactly how PHI may be used or disclosed, including any limited purposes and prohibitions on further disclosure beyond the contract.
Specify minimum administrative, physical, and technical safeguards required of the business associate to protect PHI and other regulated data.
Detail the timeline, required content, and escalation path for reporting suspected breaches to the covered entity and regulators.
Require flow-down obligations so subcontractors meet the same privacy and security standards and allow for vendor attestations or audits.
Obligate the business associate to return or securely destroy PHI at contract end, and specify exceptions for retention.
Include termination for material breach, cure periods, and post-termination obligations such as data return and transition assistance.
| Authentication method | Email link with optional SMS OTP for added assurance |
|---|---|
| Field types and placement | Signature, printed name, date, and checkbox for BAAs |
| Conditional logic | Show additional clauses when vendor stores PHI offsite |
| Bulk send options | Use bulk send for standard vendor onboards |
| Audit trail retention | Retain full certificate with signed PDF |
Prefer platforms that provide tamper-evident signed PDFs, detailed audit trails, and enterprise integrations to automate retention and access controls.
Contract takes effect on the agreed MM/DD/YYYY execution date
Allow typically 30–60 days to cure a material breach
Require prompt reporting; many programs use a 60-day target
Retention runs from creation or last effective date
Specify 30–90 days unless immediate termination is warranted
A healthcare provider needed consistent vendor agreements to protect patient records and meet audits.
A property management firm required vendor access to sensitive tenant records and medical accommodation forms.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |