Establishing secure connection…Loading editor…Preparing document…

Healthcare Addendum Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE ADDENDUM AGREEMENT

Parties and Effective Date

This Healthcare Addendum Agreement (the Addendum) is entered into by and between the healthcare provider and the patient identified below to modify and supplement the terms of the existing Healthcare Service Agreement between the parties. Provider Name:

Patient Name:    Date of Birth:

Effective Date of Addendum:

Recitals

WHEREAS, the parties previously entered into a Healthcare Service Agreement governing the provision of medical care and related services; and

WHEREAS, the parties desire to amend certain terms of that agreement as set forth in this Addendum; and

NOW, THEREFORE, in consideration of the mutual covenants contained herein, the parties agree as follows.

Addendum Terms

1. Purpose and Scope

This Addendum clarifies, amends, or supplements the existing agreement solely as to the provisions set forth below. Except as expressly modified by this Addendum, all terms and provisions of the original Healthcare Service Agreement shall remain in full force and effect.

2. Modification of Services

The following services, care plans, or responsibilities are added, removed, or modified:

3. Patient Information and Communication

4. Insurance and Billing Adjustments

The following changes to billing, insurance submission, or patient financial responsibility are effective as of the Effective Date of this Addendum.

5. Protected Health Information and Privacy

The parties acknowledge that any use or disclosure of Protected Health Information (PHI) under this Addendum shall comply with applicable privacy laws and the notice of privacy practices previously provided by the Provider. The Provider shall implement administrative, physical, and technical safeguards appropriate to the sensitivity of the PHI to prevent unauthorized disclosure.

Patient grants the following specific authorizations (check applicable boxes):

  Authorization to provide and coordinate the services described in Section 2.
  Authorization for limited PHI disclosure to third-party payors or care coordinators as necessary for treatment and payment.
  Authorization to communicate health information to emergency contact listed above.

6. Limitations, Risks, and Right to Withdraw

Patient understands any modification to treatment or care protocols may carry benefits and risks. Patient retains the right to withdraw consent to any element of this Addendum at any time by providing written notice to Provider. Withdrawal will not affect disclosures or actions already taken in reliance upon this Addendum prior to receipt of withdrawal.

7. Term, Expiration, and Termination

This Addendum shall commence on the Effective Date and shall remain in effect until: Expiration Date: unless earlier terminated in accordance with the original agreement or by mutual written consent.

8. Indemnification and Liability

Each party shall indemnify, defend, and hold the other harmless from third-party claims arising out of the indemnifying party's breach of this Addendum, negligence, or willful misconduct, subject to any limitations of liability set forth in the underlying Healthcare Service Agreement.

9. Amendment; Severability; Governing Law

This Addendum may be amended only by a written instrument signed by both parties. If any provision of this Addendum is held invalid, the remaining provisions shall remain in full force. This Addendum shall be governed by the law specified in the underlying Healthcare Service Agreement; if none is specified, the law of the state in which the Provider maintains its principal place of business shall apply.

10. Notices

All notices required under this Addendum shall be in writing and delivered to the addresses on record for each party or to the addresses specified below.

11. Patient Acknowledgment and Consent

By signing below, Patient acknowledges receipt of a copy of this Addendum, represents that Patient has read and understands its terms, and consents to the modifications set forth herein. Patient affirms that all information provided on this form is true and complete to the best of Patient's knowledge.

Patient understands they may request a copy of this Addendum and any related amendments for their records.

12. Additional Notes / Special Instructions

Signature

Patient Printed Name:

Signature:

Date:

If signed by guardian or authorized representative, print name:

Relationship to Patient:

Enter text✕

What a Healthcare Addendum Agreement Is and When It Applies

A Healthcare Addendum Agreement is a supplemental contract attached to a primary services or vendor agreement that specifies how protected health information (PHI) is handled, shared, and secured. It clarifies permitted uses and disclosures, assigns responsibilities for safeguards and breach response, and documents obligations required by HIPAA and related privacy rules. The addendum commonly references required administrative, technical, and physical safeguards, reporting timelines, and any Business Associate Agreement (BAA) elements necessary when a vendor will create, receive, maintain, or transmit PHI.

Why a Healthcare Addendum Matters for Compliance and Risk Control

A clear addendum reduces regulatory risk, defines PHI handling limits, allocates breach-response duties, and supports auditability under HIPAA. It makes expectations explicit for both covered entities and vendors while preserving contract enforceability under U.S. e-signature laws.

Why a Healthcare Addendum Matters for Compliance and Risk Control

Who typically prepares and signs a Healthcare Addendum

Multiple parties usually sign: the covered entity (or authorized representative) and the vendor’s authorized signer, with legal and privacy teams retained for review when necessary.

  • Covered entities and provider organizations who must protect patient information.
  • Business associates and vendors that store, process, or transmit PHI.
  • Legal, privacy, or compliance teams that draft and review safeguard clauses.

Essential elements to include in a professional Healthcare Addendum Agreement

A robust addendum organizes responsibilities, defines PHI scope, sets security requirements, and prescribes breach procedures so both parties meet HIPAA obligations and maintain an evidentiary audit trail.

Parties

Full legal names and contact information for the covered entity and business associate, including mailing addresses and designated privacy contacts.

Scope

Precise description of services performed and the types of PHI exchanged, limiting access to the minimum necessary for the service.

Permitted Uses

Specific permitted uses and disclosures of PHI, including any prohibited activities and restrictions on redisclosure.

Safeguards

Required administrative, physical, and technical safeguards, encryption expectations, access controls, and incident detection practices.

Breach Response

Notification timelines, investigation responsibilities, remediation obligations, and cooperation with regulatory inquiries.

Termination

Procedures for return or destruction of PHI at contract end and conditions for retaining transitory copies for legal or operational reasons.

Step-by-step: complete and execute the Healthcare Addendum

Follow a simple review-and-sign sequence to ensure the addendum is complete, legally enforceable, and aligned with the primary contract.

  • 01
    Prepare: Attach addendum to the primary agreement and populate all required fields.
  • 02
    Review: Have legal/privacy review PHI scope and safeguards; confirm BAA elements.
  • 03
    Sign: Authorized parties sign using a compliant eSignature or wet signature as required.
  • 04
    Archive: Store executed copy with audit trail and retention metadata for future compliance.

Configuring a digital workflow for the addendum

Set up a consistent signing workflow that enforces authentication, captures an audit trail, and stores signed copies securely.

Field Configuration
Signer Authentication Email link, SMS code, or KBA per risk level
Document Fields Required signature, initials, dates, and designated contact fields
Audit Trail Capture IP, timestamp, and action log automatically
Retention Policy Set automated archival and access controls on completion

How to route and submit an executed Healthcare Addendum

Define a clear routing path so the executed addendum reaches all required parties and is archived with compliance metadata.

  • To Counterparty: Send executed copy to the vendor or covered entity contact.
  • Compliance Team: Provide a signed copy to privacy and security teams for records.
  • Legal Counsel: Deliver with the primary agreement for contract management files.
  • Secure Archive: Store final document in a controlled repository with audit logging.

Technical considerations for digital signing and archival

Ensure the chosen system can produce a tamper-evident signed record and export a copy for long-term retention.

  • File Formats: PDF and DOCX are standard for legal records
  • Integrations: Connectors for systems like Salesforce and NetSuite
  • Access Controls: Role-based permissions and MFA

Key deadlines and timing expectations for addendum execution

Track execution and notification deadlines to maintain regulatory alignment and to trigger retention schedules after termination.

Effective Date:

Date when addendum obligations begin; use MM/DD/YYYY format

Execution Deadline:

Complete signatures before services commence or as contract requires

Breach Notification:

Notify affected parties without unreasonable delay and within 60 days for reportable breaches

Periodic Reviews:

Schedule annual or biennial reviews of safeguards and scope

Retention Trigger:

Retention clocks start at effective date or creation of the record

Milestones from drafting to long-term retention

A sequential milestone view helps teams coordinate drafting, approval, execution, and archival tasks for each addendum.

01

Drafting

Define PHI scope and required safeguards with stakeholders.

02

Internal Review

Legal and privacy review for compliance with HIPAA and contract law.

03

Execution

Obtain authorized signatures, timestamp, and audit evidence.

04

Archival

Store executed copy with retention metadata and access controls.

Common preparation mistakes to avoid

  • Vague PHI descriptions that expand vendor access beyond necessary purposes and increase exposure.
  • Omitting a required Business Associate Agreement clause when a vendor will create or receive PHI.
  • Using unauthorized signers or not verifying signing authority before execution of the addendum.
  • Failing to capture an auditable signing record and retention metadata for compliance and audits.

Consequences of an incorrect or missing Healthcare Addendum

HIPAA Fines: Civil and criminal penalties; HHS enforcement
Regulatory Action: Corrective plans and audits imposed by regulators
Contractual Liability: Breach of contract claims and damages
Notification Costs: Expense of breach notification and remediation
Operational Disruption: Service interruptions and reputational harm
Evidence Gaps: Missing audit trail undermines defense in disputes

Security and compliance checklist for the addendum

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
BAA Required: Business Associate Agreement when handling PHI
Audit Trail: Timestamped logs, IP, signer attribution
Access Controls: Role-based permissions and least-privilege access
Authentication: Multi-factor or equivalent signer verification
Certifications: SOC 2 Type II, ISO 27001 available on request

Real-world examples of addenda in practice

Practice examples show common use patterns and how organizations address PHI handling and vendor responsibilities.

Fertility Centers of Illinois

Used digital addenda to consolidate PHI handling terms across clinics

  • Enabled signed BAAs for vendors
  • John Butler noted the team appreciated secure, auditable records for compliance and integration with existing systems.

Martin Properties

Added PHI-limited clauses for tenant screening vendors

  • Restricted data categories and retention
  • Tim Martin reported smoother vendor onboarding and clearer privacy obligations after centralizing addendum templates.

Who should sign and who should approve the addendum

Authorized Signer

Chief Privacy Officer or an executive with contract authority should sign for the covered entity; signature must be within delegated signing authority.

Secondary Approver

General counsel or privacy counsel should review and approve language addressing PHI, breach response, and regulatory obligations before execution.

Frequently asked questions about Healthcare Addendum Agreements

Answers to common questions about legality, signatures, BAAs, revocation, storage, and state differences to help you avoid common pitfalls.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users