Establishing secure connection…Loading editor…Preparing document…

Facility User Account Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Facility User Account Agreement

Please print clearly

Section 1: Internet Data Submission (IDS) User Account Information (all information is required)

1. FACILITY NAME:

2. AHCA NUMBER:

3. NAME OF IDS USERS (FIRST, MIDDLE INITIAL, LAST):

A. USER 01:

B. USER 02:

C. USER 03:

D. USER 04:

4. FACILITY ADDRESS:

5. USER E-MAIL ADDRESS:

A. USER 01:

B. USER 02:

C. USER 03:

D. USER 04:

6. BUSINESS PHONE:

A. USER 01:

B. USER 02:

C. USER 03:

D. USER 04:

7. BUSINESS FAX:

I understand that as an IDS User, I can submit data and retrieve the status of the data on behalf of the above designated facility.

I understand that by signing this document I am authorizing the Agency to send users of this system emails from time to time as it deems necessary.

By signing this document I acknowledge reading, understanding, and agreeing to its contents.

I understand that as an appointed User Account Administrator on behalf of the facility, I have the responsibility to:

1. Create/add and delete user accounts for other IDS users within my facility. Creating a user account grants access for an individual to read, submit and correct my facility’s confidential data. Deleting user accounts revokes this access.

2. Modify the demographic information for my facility’s Primary, Secondary and Administrator Contacts. This will be the method that SCHS is notified of any changes in name, mailing address, phone number, and e-mail address for each contact. Modifying contact demographic information directly changes the information on the SCHS database.

3. Reset passwords for IDS users within my facility. In the event that a user misplaces or forgets their password, they will be directed to contact their User Account Administrator to have it reset. The User Account Administrator should authenticate the user prior to resetting the password and issuing a new password.

4. Unlock IDS user accounts. IDS will lock user accounts after three (3) unsuccessful log on attempts. When the account is locked, users will be required to contact their User Account Administrator to unlock their account.

8. USER SIGNATURES:

A. USER 01:

DATE:

B. USER 02:

C. USER 03:

D. USER 04:

The original of this completed form, for each user at a reporting facility having IDS on-line access, shall be provided to SCHS at the time it is prepared and signed.

Section 2: For SCHS use only

Date Received:

Date Authenticated/Enrolled:

By:

Please Note: The Facility Administrator or Primary Contact at each facility must complete and sign the Third Party Authorization Agreement form approving a Designated Agent if a third party will be submitting this data to AHCA on behalf of the reporting entity.

Facility User Account Agreement Instructions and Definitions

Make a copy of the completed forms for your records. Mail the original(s) to:

AHCA, Attn: Data Collection and Quality Assurance Unit,
2727 Mahan Drive, Bldg. 3 MS#16
Tallahassee, FL 32308

SECTION 1: IDS Designated Agent User Information (All fields must be completed) --

To be completed by IDS User requesting access to Internet Data Submission System.

1. Facility Name: Provide the name of the reporting entity or facility.

2. AHCA number: Enter the identification number of the ambulatory center/hospital as assigned by AHCA for reporting purposes.

3. Name of IDS User: Provide the full name of the IDS user.

4. Business Address (Mailing Address): Enter the business address where you can receive mail.

5. E-mail address: Provide an e-mail address where you can be contacted.

6. Business Phone: Provide a phone number where you can be contacted.

7. Business Fax: Provide a fax number where you can receive faxes.

8. User Signature and Date: If you understand and agree with the responsibilities and guidelines for maintaining IDS security, as detailed in the user agreement, provide your signature and the date this agreement was signed.

SECTION 2: SCHS Use Only

Florida Center for Health Information and Policy Analysis 1/18/2007

Enter text✕

What the Facility User Account Agreement Covers

A Facility User Account Agreement is a written contract that defines who may access a facility's systems and premises, what access levels are permitted, and the responsibilities tied to that access. It typically covers user identity verification, permitted activities, credential issuance and expiration, acceptable-use rules, data handling expectations, and consequences for misuse. Organizations use this agreement to document consent and evidence authorization for physical and logical access, to support audits, and to set retention expectations for access records and related documentation.

Why a Formal Agreement Matters for Facility Access

A formal Facility User Account Agreement reduces ambiguity about privileges, improves accountability by recording consent and identity, and supports compliance with laws and internal policies such as HIPAA or FERPA when protected data is involved.

Why a Formal Agreement Matters for Facility Access

Who typically completes and signs this agreement

Organizations rely on a mix of operational, IT, and external parties to request, approve, and accept facility access terms.

  • Facility managers and security teams who issue physical access badges and define building-level rules.
  • IT administrators and application owners who grant system credentials and set logical access levels.
  • Contractors, vendors, employees, and temporary staff who require site or system access for work.

Properly routing the agreement to the correct approvers—security, IT, and legal—helps prevent unauthorized access and supports audit trails.

Typical signatories and their roles

Facility Manager

Facility Managers authorize physical access and approve badge issuance. Their signature confirms compliance with site safety rules, access time windows, escort requirements, and any site-specific training prerequisites. They remain responsible for revoking access when conditions change.

IT Administrator

IT Administrators authorize logical access to building systems and software. Their signature confirms assigned roles, multi-factor authentication requirements, data handling rules, and audit logging. They also document deprovisioning triggers and escalation paths.

Core elements to include in the agreement

A professional Facility User Account Agreement is concise but comprehensive: it assigns parties, defines scope and duration, enumerates permitted use, specifies security controls, sets privacy expectations, and records signature and approval authority.

Parties

Clearly identify the organization and the account holder using full legal names and contact details to avoid ambiguity about obligations and notice delivery.

Access scope

Define the physical areas and system privileges granted, including role-based limitations, time-of-day restrictions, and any project-specific restrictions.

Duration

Specify start and end dates or event-based triggers for access, and describe automatic expiry, renewal, or review procedures.

Security controls

List required authentication methods (password, MFA), device rules, and endpoint protections, plus reporting procedures for lost credentials.

Data handling

State obligations for handling sensitive data, encryption expectations, and any HIPAA/FERPA confidentiality clauses if applicable.

Consequences

Describe disciplinary steps, revocation procedures, liability allocation, and any indemnities for misuse or breach.

Security and compliance checkpoints to record

Encryption: TLS 1.2/1.3 in transit
Data at rest: AES-256 encrypted storage
Audit trail: Detailed signing logs retained
HIPAA: BAA required for PHI
Authentication: MFA and strong passwords
Standards: SOC 2 Type II and ISO 27001

Step-by-step: filling and approving the agreement

A short sequential checklist helps ensure complete, compliant submissions and faster provisioning.

  • 01
    Prepare: Gather IDs, role details, and justification for access.
  • 02
    Complete fields: Enter names, dates, and scope exactly as required.
  • 03
    Route for approval: Send to facility manager and IT approver in order.
  • 04
    Provision access: IT or security provisions credentials and records the audit trail.

Typical online workflow settings for digital completion

Configure these workflow settings when publishing the agreement for e-signature to ensure consistent routing and authentication.

Field Configuration
Account Type Select Employee, Contractor, or Visitor
Access Approval Require Facility Manager + IT approval
Expiration Policy Auto-expire after specified date
Authentication Enable email link or SMS code

Where to send completed agreements and how they're processed

Routing and storage rules determine who receives executed copies and where records are retained for audits and compliance.

  • Security Team: Receives executed agreement and updates badge roster.
  • IT Systems: Creates or adjusts user accounts after approvals.
  • HR or Vendor Office: Stores personnel records and training confirmations.
  • Archival Repository: Saves signed copy and audit trail for retention.

Digital signing and integration considerations

Use an eSignature platform that captures audit trails, stores signed records securely, and integrates with identity systems for provisioning.

  • Authentication options: Email, SMS, KBA, SSO
  • Integrations: Salesforce, NetSuite, Microsoft 365
  • File formats: PDF, DOCX, HTML

Ensure the chosen platform supports required compliance controls (audit trail, encryption, and optional BAA) and can forward signed records to your access-control system for automated provisioning.

Typical timelines and processing expectations

Set clear internal SLAs for request review, approval, provisioning, and periodic revalidation to avoid unauthorized lingering access.

Request Submission:

User submits agreement and identity documents immediately before access.

Approval Window:

Facility and IT approvals expected within 3 business days.

Provisioning:

Credentials issued within 1 business day after approvals.

Access Review:

Periodic revalidation every 90 days is common.

Renewal:

Renew or reapply before expiration to maintain continuous access.

Common mistakes when preparing the agreement

  • Entering nicknames or initials instead of full legal names delays verification and may trigger repeated identity checks or rejection.
  • Failing to specify exact access areas or systems leads to overprovisioning and unnecessary security risk for the facility.
  • Skipping expiration dates or review schedules causes lingering active accounts and increases audit findings during compliance checks.
  • Not capturing consent for electronic records (where consumer-facing) can invalidate the e-signature under ESIGN if consumer disclosure is required.

Consequences of incorrect or unauthorized access

Access termination: Immediate revocation of credentials
Disciplinary action: Employment sanctions or contract termination
Data breach fines: Civil penalties and remediation costs
HIPAA risk: Possible HIPAA penalties if PHI exposed
Criminal liability: Unauthorized entry may carry criminal charges
Insurance impact: Claims denial or higher premiums

Representative eSignature vendor pricing and compliance snapshot

Compare starting prices, trial availability, bulk-send capability, audit trail presence, and HIPAA support to choose a deployment model for facility agreements.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Business Premium) Yes Yes Yes Limited
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes Yes No No

Real-world examples of how organizations use this agreement

These short case arcs illustrate common implementation scenarios for Facility User Account Agreements across sectors.

Optica Ventures LLC

Small real estate manager uses a standard access agreement to onboard contractors quickly and securely.

  • Implemented role-based access with badge expiry.
  • The agreement reduced provisioning time and improved audit readiness by documenting approvals and expiration triggers for every contract worker.

Fertility Centers of Illinois

Healthcare provider attaches HIPAA confidentiality language to facility access forms.

  • Required BAA for vendors with PHI access.
  • Combined electronic signing and retention policies ensured six-year auditability and reduced paper handling in clinical areas.

Frequently asked questions about completing and enforcing the agreement

Answers to common questions about field entry, eSignature validity, notarization, and record retention for facility access agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users