Parties
Identify each internal unit or office by its full legal name and organizational role; include campus address and primary contact for notices.
A clear internal agreement reduces ambiguity about custody of records, protects student and patient data under FERPA or HIPAA as applicable, sets accountability for internal workflows, and documents authority for approvals. This reduces operational delays and helps demonstrate compliance to auditors and regulators.
These agreements are completed by operational or administrative staff who manage campus services, records, or research activities and by institutional counsel or compliance officers who review legal and privacy terms.
In practice, signers include an authorized representative for each internal party plus the institution's compliance or legal representative when privacy, financial, or research obligations exist.
| Field | Configuration |
|---|---|
| Signer Authentication | SSO or SMS code for institutional accounts |
| Document Visibility | Restrict access to named recipients only |
| Audit Trail Options | Enable full action logs and certificate generation |
| Retention Settings | Automate archival to records management system |
Choose platform features that match institutional security policies and compliance needs for FERPA, HIPAA, and research records.
Ensure the selected platform supports required attestations and can deliver signed PDFs plus verifiable audit logs for institutional recordkeeping and audits.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Identify each internal unit or office by its full legal name and organizational role; include campus address and primary contact for notices.
Define permitted activities, data types exchanged, geographic or program limits, and any excluded uses to reduce ambiguity in operations and audits.
State the effective date, renewal terms, notice periods for termination, and obligations that survive termination such as confidentiality and data return.
Specify protections for education records under FERPA and any internal safeguards; describe permitted redisclosures and consent requirements.
Describe technical and administrative controls, breach notification responsibilities, and whether HIPAA applies to health‑related records.
Require signatures from authorized representatives, include title blocks, and note whether electronic signatures are permitted under ESIGN/UETA.