Parties
Full legal names and contact information for the covered entity and business associate, including mailing addresses and designated privacy contacts.
A clear addendum reduces regulatory risk, defines PHI handling limits, allocates breach-response duties, and supports auditability under HIPAA. It makes expectations explicit for both covered entities and vendors while preserving contract enforceability under U.S. e-signature laws.
Multiple parties usually sign: the covered entity (or authorized representative) and the vendor’s authorized signer, with legal and privacy teams retained for review when necessary.
Full legal names and contact information for the covered entity and business associate, including mailing addresses and designated privacy contacts.
Precise description of services performed and the types of PHI exchanged, limiting access to the minimum necessary for the service.
Specific permitted uses and disclosures of PHI, including any prohibited activities and restrictions on redisclosure.
Required administrative, physical, and technical safeguards, encryption expectations, access controls, and incident detection practices.
Notification timelines, investigation responsibilities, remediation obligations, and cooperation with regulatory inquiries.
Procedures for return or destruction of PHI at contract end and conditions for retaining transitory copies for legal or operational reasons.
| Field | Configuration |
|---|---|
| Signer Authentication | Email link, SMS code, or KBA per risk level |
| Document Fields | Required signature, initials, dates, and designated contact fields |
| Audit Trail | Capture IP, timestamp, and action log automatically |
| Retention Policy | Set automated archival and access controls on completion |
Ensure the chosen system can produce a tamper-evident signed record and export a copy for long-term retention.
Date when addendum obligations begin; use MM/DD/YYYY format
Complete signatures before services commence or as contract requires
Notify affected parties without unreasonable delay and within 60 days for reportable breaches
Schedule annual or biennial reviews of safeguards and scope
Retention clocks start at effective date or creation of the record
Define PHI scope and required safeguards with stakeholders.
Legal and privacy review for compliance with HIPAA and contract law.
Obtain authorized signatures, timestamp, and audit evidence.
Store executed copy with retention metadata and access controls.
Used digital addenda to consolidate PHI handling terms across clinics
Added PHI-limited clauses for tenant screening vendors
Chief Privacy Officer or an executive with contract authority should sign for the covered entity; signature must be within delegated signing authority.
General counsel or privacy counsel should review and approve language addressing PHI, breach response, and regulatory obligations before execution.