Identification
Unique document ID, responder name, organization legal name, point of contact, and effective and submission dates to tie responses to a specific evaluation instance.
A consistent AAQ-2 aligns vendor information with HIPAA, privacy, and contractual obligations, reduces gaps during procurement and audits, and provides auditable evidence of controls and decision rationale for legal, clinical, and procurement stakeholders.
Common users and stakeholders who complete, review, or request the Healthcare AAQ-2 within healthcare organizations and vendor networks.
AAQ-2 responses feed decisions by compliance, contracting, and clinical leadership and are retained for audit, contract enforcement, and regulatory review.
Primary reviewer who assesses AAQ-2 responses, confirms PHI handling, and ensures a Business Associate Agreement is in place when required. Coordinates remediation, documents risk acceptance decisions, and liaises with legal and IT security to validate technical safeguards and policies meet HIPAA obligations.
Manages vendor onboarding, aggregates AAQ-2 data for procurement decisions, and ensures contract clauses reflect disclosed security controls. Tracks reassessment schedules, follows up on missing documentation, and records corrective action plans and completion dates in vendor records.
Unique document ID, responder name, organization legal name, point of contact, and effective and submission dates to tie responses to a specific evaluation instance.
Questions that confirm whether PHI is accessed or processed, current HIPAA policies, breach history, and whether a Business Associate Agreement (BAA) exists or is required.
Technical safeguards including encryption, access controls, vulnerability management, incident response, and evidence of SOC 2 or ISO 27001 where applicable.
Declaration of business associate status, scope of services affecting PHI, subcontractor use, and any regulatory exceptions or limitations to data handling.
Operational items such as continuity plans, staff training, background checks, change management, and physical security measures tied to service delivery.
Authorized signatory block, role/title, signature date, and an attestation statement certifying the accuracy and completeness of the responses under penalty of contract or law.
| Field | Configuration |
|---|---|
| Signature Authentication | Email + SMS code; optional KBA for high-risk vendors |
| Conditional Sections | Show PHI questions only if PHI indicated |
| Document Attachments | Require SOC 2 or ISO certificate uploads |
| Retention Setting | Preserve signed record plus audit trail |
Ensure your e-signature platform supports secure storage, audit trails, and common document formats before e-submitting the AAQ-2.
Respond within 10 business days for initial onboarding
Allow 5–10 business days for validation and approvals
Revalidate AAQ-2 responses at least annually
Execute prior to any PHI exchange
Retain per state RON retention requirements
Vendor or internal unit submits completed AAQ-2 with attachments
Compliance team evaluates answers and supporting evidence
Vendor provides corrective actions or additional evidence
Authorized sign-off recorded; signed document and audit trail archived
| Criteria | Healthcare AAQ-2 | Vendor Risk Assessment |
|---|---|---|
| Purpose | operational and hipaa disclosures | broader security posture |
| PHI Focus | yes — phi specific | usually not phi centric |
| Legal Weight | contractary evidence | informational assessment |
| Typical Use | onboarding and baas | periodic security audits |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Optica required standardized AAQ-2 responses during onboarding to reduce follow-ups.
The center integrated AAQ-2 with vendor records to verify BAAs and encryption controls.