Establishing secure connection…Loading editor…Preparing document…

Healthcare AAQ-2

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Healthcare AAQ-2: Authorization & Assessment Questionnaire

Patient Information

Date of Birth:

Medical Record / ID #:

Gender:

Phone:

Email:

Relationship:

Phone:

Insurance Information

Policy Number:

Group Number:

Subscriber Name:

Medical History

Presenting Complaint / Planned Services

Risks, benefits, and alternatives associated with the proposed assessment, treatment or release of records have been explained to me. I understand significant risks may exist depending on the specific procedure or disclosure requested, including but not limited to allergic reaction, infection, or inadvertent disclosure of sensitive information. I acknowledge I have the right to ask questions, to seek additional information, and to decline or withdraw consent at any time as described below.

Authorization to Disclose Protected Health Information (PHI)

I authorize the release of my protected health information as described below. This authorization is voluntary and the information released may include records created by this facility and those obtained from other providers.

I understand that I may revoke this authorization at any time by delivering a written revocation to the releasing provider, except to the extent that action has already been taken in reliance on this authorization. I understand that information disclosed pursuant to this authorization may be subject to redisclosure by the recipient and may no longer be protected by federal privacy regulations.

Fees for copying records may be charged in accordance with applicable law. I understand that refusal to sign this authorization will not condition treatment, payment, enrollment, or eligibility for benefits, unless the information is necessary to determine eligibility for a specific service.

HIPAA Privacy Acknowledgment

By checking the box below I acknowledge that I have been offered or provided a copy of the Notice of Privacy Practices that explains how my health information may be used and disclosed and how I can access this information.

Certification: I certify that the information provided on this form is accurate to the best of my knowledge. I authorize the use and disclosure of my protected health information as specified above. I understand the contents of this form and my rights as described herein.

Patient Printed Name:

Relationship (if not patient):

Signature:

Date:

Enter text✕

What the Healthcare AAQ-2 Is and where it fits

The Healthcare AAQ-2 is a standardized administrative and assurance questionnaire used by healthcare organizations to collect vendor, contractor, or internal unit information about privacy, security, and operational controls. It captures HIPAA-related safeguards, business associate status, clinical process descriptions, and evidence of technical controls to support vendor management, risk assessments, contract reviews, and audit readiness. Organizations commonly use the AAQ-2 during onboarding, periodic revalidation, and procurement reviews to document compliance posture and to create an auditable record for internal governance or regulator inquiries.

Why a consistent Healthcare AAQ-2 matters

A consistent AAQ-2 aligns vendor information with HIPAA, privacy, and contractual obligations, reduces gaps during procurement and audits, and provides auditable evidence of controls and decision rationale for legal, clinical, and procurement stakeholders.

Why a consistent Healthcare AAQ-2 matters

Typical users and stakeholders

Common users and stakeholders who complete, review, or request the Healthcare AAQ-2 within healthcare organizations and vendor networks.

  • Vendor management teams conducting security and privacy assessments during onboarding and annual reviews.
  • Compliance and privacy officers validating HIPAA safeguards, BAA status, and risk mitigation controls.
  • Procurement and contracting staff using AAQ-2 responses to inform contract terms and service obligations.

AAQ-2 responses feed decisions by compliance, contracting, and clinical leadership and are retained for audit, contract enforcement, and regulatory review.

Who signs or certifies AAQ-2 responses

Compliance Officer

Primary reviewer who assesses AAQ-2 responses, confirms PHI handling, and ensures a Business Associate Agreement is in place when required. Coordinates remediation, documents risk acceptance decisions, and liaises with legal and IT security to validate technical safeguards and policies meet HIPAA obligations.

Vendor Manager

Manages vendor onboarding, aggregates AAQ-2 data for procurement decisions, and ensures contract clauses reflect disclosed security controls. Tracks reassessment schedules, follows up on missing documentation, and records corrective action plans and completion dates in vendor records.

Essential sections to include in a professional AAQ-2

Core sections and professional elements to include in a complete Healthcare AAQ-2, ensuring consistent responses, auditable evidence, and alignment with regulatory obligations.

Identification

Unique document ID, responder name, organization legal name, point of contact, and effective and submission dates to tie responses to a specific evaluation instance.

Privacy & HIPAA

Questions that confirm whether PHI is accessed or processed, current HIPAA policies, breach history, and whether a Business Associate Agreement (BAA) exists or is required.

Security Controls

Technical safeguards including encryption, access controls, vulnerability management, incident response, and evidence of SOC 2 or ISO 27001 where applicable.

Business Associate

Declaration of business associate status, scope of services affecting PHI, subcontractor use, and any regulatory exceptions or limitations to data handling.

Operational Practices

Operational items such as continuity plans, staff training, background checks, change management, and physical security measures tied to service delivery.

Certifications & Sign-off

Authorized signatory block, role/title, signature date, and an attestation statement certifying the accuracy and completeness of the responses under penalty of contract or law.

Step-by-step completion checklist

Follow these steps to complete the Healthcare AAQ-2 accurately and ensure required approvals and records are captured in your compliance system.

  • 01
    Prepare Document: Gather contracts, BAAs, and security evidence before starting.
  • 02
    Complete Sections: Answer all fields fully; attach requested documents.
  • 03
    Attach Supporting Docs: Include SOC 2, ISO certificates, policies, and incident reports.
  • 04
    Review & Approve: Obtain sign-off from compliance, legal, and vendor representatives.

Frequently asked questions and common issues

Answers to common questions about completing, signing, and retaining the Healthcare AAQ-2, including compliance, e-signature, and document storage considerations.


Need help? Contact support

Security and compliance data points to verify

Encryption: TLS 1.2/1.3; AES-256 at rest
Audit Trail: Timestamps, IP addresses, action history retained
BAA Availability: Business Associate Agreement option required
Access Controls: Role-based access and SSO support
Authentication: Two‑factor and advanced signer authentication
Certifications: SOC 2 Type II; ISO 27001; PCI DSS

Key penalties and compliance risks

HIPAA Enforcement: Civil penalties under HIPAA
Breach Notification: Mandatory reporting and remediation obligations
Contract Liability: Termination, indemnity, and financial exposure
Regulatory Audit: OCR or CMS findings and corrective actions
Data Misrepresentation: False answers can void agreements
Operational Impact: Service disruption or delayed onboarding

Common preparation mistakes to avoid

  • Submitting incomplete fields or placeholder text, which delays review and creates follow-up cycles with procurement and compliance teams.
  • Failing to attach evidence such as SOC 2 reports or policy documents, leaving assertions unverified and increasing audit risk.
  • Using inconsistent entity names or outdated signatory details, which can cause contract execution and payment mismatches.
  • Not executing a BAA before sharing PHI or failing to list subprocessors, exposing parties to regulatory and contractual violations.

Typical e-submission and routing flow

Standard workflow from form preparation to archival and audit trail capture when the Healthcare AAQ-2 is completed electronically.

  • Upload Document: Sender uploads questionnaire and attachments
  • Place Fields: Add signature, date, and evidence upload fields
  • Authenticate Signer: Use email, SMS, or stronger methods
  • Archive & Audit: Store signed copy with audit trail

Recommended digital workflow settings

Example configuration to collect, validate, and retain AAQ-2 responses in an electronic workflow.

Field Configuration
Signature Authentication Email + SMS code; optional KBA for high-risk vendors
Conditional Sections Show PHI questions only if PHI indicated
Document Attachments Require SOC 2 or ISO certificate uploads
Retention Setting Preserve signed record plus audit trail

Technical requirements and supported formats

Ensure your e-signature platform supports secure storage, audit trails, and common document formats before e-submitting the AAQ-2.

  • Integrations: Salesforce, NetSuite, Microsoft 365 support
  • Formats: PDF, DOCX, and structured data exports
  • Accessibility: WCAG 2.0 Level AA compliance

Typical timelines and processing expectations

Suggested timing expectations for requests, responses, and periodic reassessments tied to vendor lifecycle events.

Request Response Window:

Respond within 10 business days for initial onboarding

Initial Onboarding Review:

Allow 5–10 business days for validation and approvals

Annual Reassessment:

Revalidate AAQ-2 responses at least annually

BAA Execution:

Execute prior to any PHI exchange

RON Session Record:

Retain per state RON retention requirements

Key processing milestones

Sequential milestones that mark the AAQ-2 lifecycle from submission through final archival.

01

Submission

Vendor or internal unit submits completed AAQ-2 with attachments

02

Compliance Review

Compliance team evaluates answers and supporting evidence

03

Remediation

Vendor provides corrective actions or additional evidence

04

Approval & Archive

Authorized sign-off recorded; signed document and audit trail archived

How the AAQ-2 compares with related documents

A concise comparison showing when to use an AAQ-2 versus other vendor or security assessments.

Criteria Healthcare AAQ-2 Vendor Risk Assessment
Purpose operational and hipaa disclosures broader security posture
PHI Focus yes — phi specific usually not phi centric
Legal Weight contractary evidence informational assessment
Typical Use onboarding and baas periodic security audits

eSignature vendor pricing and feature comparison

A high-level comparison of common eSignature plans and features relevant for Healthcare AAQ-2 workflows; signNow is listed first per vendor order requirements.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Real-world examples of AAQ-2 use

Two illustrative scenarios showing how organizations apply AAQ-2 responses to vendor decisions and compliance workflows.

Optica Ventures

Optica required standardized AAQ-2 responses during onboarding to reduce follow-ups.

  • The AAQ-2 automated evidence collection.
  • This reduced validation cycles and provided a single record for audits and procurement decisions.

Fertility Centers of Illinois

The center integrated AAQ-2 with vendor records to verify BAAs and encryption controls.

  • The result was faster approvals.
  • Documentation supported HIPAA audits and streamlined annual reassessments across clinical systems.

Practical tips for accurate and efficient completion

Adopt these best practices to reduce errors, speed reviews, and maintain defensible records for the AAQ-2.

Standardize Templates
Use a single AAQ-2 template and version control to ensure consistent questions and evidence requirements across vendors.
Require Evidence
Mandate uploads of SOC 2 reports, policies, and training records rather than accepting unsubstantiated assertions.
Automate Reminders
Use workflow tools to enforce timelines, send reminders, and escalate overdue responses to owners.
Preserve Audit Trails
Keep signed PDF copies and detailed audit logs showing signer identity, timestamps, and IP addresses for compliance.
be ready to get more
Join over 28 million airSlate SignNow users