Parties and Purpose
Identify contracting entities and state the narrow purpose of the addendum so obligations are limited to the covered services and interactions.
A concise addendum reduces ambiguity about responsibilities, protects regulated data, limits vendor liability, and documents required security controls and notice procedures — improving enforceability and operational clarity between parties.
The Business Service Addendum is completed by procurement, legal, compliance, or operations teams when engaging third-party service providers.
Final execution should be performed by personnel with authority to bind each organization and who understand operational and compliance ramifications.
Identify contracting entities and state the narrow purpose of the addendum so obligations are limited to the covered services and interactions.
Define precise services, deliverables, service levels, reporting cadence, and escalation paths so expectations and remedies are measurable.
Specify security controls, encryption, incident response timelines, and data handling requirements; include HIPAA BAA language when PHI is involved.
Describe permitted subprocessors, notification procedures for changes, and the vendor’s responsibility for downstream compliance and contractual flow-downs.
Set termination triggers, data-return or deletion procedures, and obligations for transitional services to avoid service gaps on exit.
Limitations of liability, insurance requirements, and indemnity scope should be explicit to allocate financial risk between parties.
| Field | Configuration |
|---|---|
| Signer Order | Set sequential or parallel signing based on negotiation needs. |
| Authentication | Choose email link, SMS code, or stronger MFA as required. |
| Retention Settings | Enable automatic archiving and export of signed copies and audit logs. |
| Notifications | Configure reminders and completion alerts for stakeholders. |
Select e-signature platforms that meet your technical, security, and regulatory needs before sending the addendum.
Verify the platform provides tamper-evident signed PDFs, an auditable completion certificate, encryption in transit and at rest, and options for BAAs where PHI is involved.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Available (premium) | Available | Available | Available | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA available) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
Request that the addendum be signed within 15–30 calendar days of issuance.
Services typically begin on the Effective Date entered in the addendum.
Contractual notice periods for breach or termination often range from 10 to 60 days.
Set a window of 30–90 days for data return or secure deletion after termination.
Schedule annual reviews of security and compliance clauses to reflect changes in law or operations.