Parties
Identify the covered entity, the business associate, and any subcontractors; include full legal names and addresses for contracting and notice purposes.
The GSA BAA clarifies responsibilities for PHI handling, reduces legal and contractual ambiguity, and documents required safeguards and breach procedures to meet HIPAA obligations while enabling federal procurement workflows.
Typical parties and users involved in preparing and signing a GSA BAA include procurement, legal, and privacy teams on both sides.
Final execution usually requires an authorized contracting officer or designated signatory for the government party and an officer or authorized representative for the vendor.
Identify the covered entity, the business associate, and any subcontractors; include full legal names and addresses for contracting and notice purposes.
Define types of PHI covered, sources of PHI, and the specific services that require access so responsibilities and limits are unambiguous.
List expressly permitted and prohibited uses and disclosures of PHI, including any uses required to perform GSA tasks or fulfill contractual obligations.
Specify administrative, physical, and technical safeguards required (encryption, access controls, audit logs) and any NIST or agency standards to follow.
State notification timing and content, investigation duties, cooperation with the covered entity, and reporting to HHS or other authorities as applicable.
Require BAAs or flow-down provisions with subcontractors and set audit/monitoring rights to ensure downstream compliance.
| Field | Configuration |
|---|---|
| Signer Authentication | Use email+SMS code or higher for vendor and contracting officer |
| Access Control | Limit document visibility to named signers and reviewers |
| Audit Trail | Enable full timestamp and IP logging |
| Retention Setting | Retain executed copy per agency recordkeeping rules |
Choose distribution channels that preserve audit trails and control access to PHI.
Execute BAA before starting PHI-related work
Notify covered entity without unreasonable delay; HHS reporting often within 60 days
Allow covered-entity audits per contract terms and reasonable notice
Retain executed BAA per agency and HIPAA retention rules
Require BAAs with subcontractors before subcontracted PHI processing
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day free trial | Yes | Yes | Yes | Yes |
| Bulk Send | Yes | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |