Scope
Clear listing of categories of PHI, systems, and datasets covered by the annex, limiting unintended access.
A Healthcare Annex Form isolates health-data obligations from general contract terms, reducing ambiguity over PHI handling, breach response, and permitted uses. It helps align contractual language with HIPAA requirements and state privacy laws while documenting technical and administrative safeguards.
Teams who prepare or review the annex usually include legal, compliance, and operational staff responsible for healthcare data handling.
The completed annex should be reviewed by counsel and the responsible privacy officer before signatures are collected.
The Privacy Officer reviews language on PHI handling, authorizations, breach notification timelines, and ensures the annex reflects HIPAA and state privacy obligations. They confirm technical safeguards and retention controls before approval.
A contracting officer or authorized executive at the vendor accepts obligations in the annex, confirms operational ability to comply with access and security requirements, and signs on behalf of the vendor organization.
| Field | Configuration |
|---|---|
| Routing Order | Sequential signer order with reviewer approvals |
| Authentication | Email + SMS code or enterprise SSO |
| Capture Evidence | Enable audit trail and completion certificate |
| Storage | Save signed PDF to secure cloud repository |
Ensure the chosen platform supports HIPAA, secure storage, and integration with existing systems.
Clear listing of categories of PHI, systems, and datasets covered by the annex, limiting unintended access.
Define the exact purposes (treatment, payment, operations) and restrictions on secondary uses like research or marketing.
State required technical controls (TLS 1.2/1.3, AES-256), access logging, and role-based access limits for PHI.
Specify timelines for detection, notice to the covered entity, and cooperation steps for investigation and reporting.
Allow audits or evidence production on request, including sample logs and compliance documentation.
Outline retention period, secure deletion or return procedures, and conditions triggering extended retention.
Determines when obligations and retention clocks begin.
Patient consents often expire per state or policy.
Prompt reporting timelines required by covered entities.
At least yearly compliance reassessment recommended.
Fulfill state/career-specific patient access timelines.
Optica attached a concise annex to limit PHI scope to de-identified claims
Fertility Centers used an annex to capture patient-consent language specific to reproductive health data
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |