Business Associate Duties
Specify permitted uses and disclosures of PHI, scope of processing, subcontractor flow-down requirements, and obligations to implement safeguards and report incidents in defined timeframes.
A Healthcare Appendix clarifies HIPAA obligations, assigns business associate responsibilities, and documents required safeguards and breach procedures. It reduces ambiguity about permitted uses of PHI, supports audit readiness, and helps demonstrate due diligence during compliance reviews.
Parties who prepare or sign a Healthcare Appendix vary by role and responsibility within the health data lifecycle.
These stakeholders should confirm legal authority to bind the organization and ensure required technical or contractual attachments are included.
Specify permitted uses and disclosures of PHI, scope of processing, subcontractor flow-down requirements, and obligations to implement safeguards and report incidents in defined timeframes.
Describe privacy obligations including minimum necessary principles, de-identification standards, patient rights support, and procedures for responding to access or amendment requests.
List technical and administrative controls required (encryption, access controls, logging, vulnerability management), encryption expectations in transit and at rest, and authentication methods.
Define notification timelines, required content of breach notices, responsibilities for investigation and mitigation, and coordination for notices to affected individuals and regulators.
State retention periods, archival procedures, secure disposal methods, and obligations to return or destroy PHI at contract termination.
Include rights to audit, required documentation, remediation steps for deficiencies, and obligations to provide evidence for compliance testing or regulatory requests.
| Field | Configuration |
|---|---|
| Authentication | Email link with optional SMS code or higher assurance KBA |
| Signature Type | Allow standard e-signatures; require PKI-based signatures when regulation or policy demands |
| Audit Trail | Enable comprehensive logs capturing IP, timestamp, and action history |
| Document Retention | Store final signed PDF/A with certificate and export capabilities |
Use secure, auditable channels for distribution to preserve confidentiality and support later evidence collection.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8 per user per month billed annually | $15 per user per month billed annually | $14 per user per month billed annually | $19 per user per month billed annually | $15 per user per month billed annually |
| Free Trial | 7-day free trial, no credit card required | Varies by vendor and promotion | Varies by vendor and promotion | Varies by vendor and promotion | Varies by vendor and promotion |
| Bulk Send | Available in higher tiers | Available depending on plan | Available depending on plan | Available depending on plan | Available depending on plan |
| Audit Trail | Yes, comprehensive audit trail | Yes, audit trail provided | Yes, audit trail provided | Yes, audit trail provided | Yes, audit trail provided |
| HIPAA Compliant | Yes (BAA available) | Yes (BAA available) | Yes (BAA available) | No BAA typically available | No BAA typically available |
A midsize clinic attached a Healthcare Appendix to vendor contracts to centralize PHI handling rules and breach obligations.
A hospital system used an appendix to define data exchange with third-party analytics vendors.