Identification
Identify the covered entity and business associate using legal names, addresses, and DUNS or EIN where applicable so responsibilities are contractually anchored and unambiguous.
A signed attestation plus BAA creates contractual obligations that map to HIPAA requirements, documents risk allocation, and supports auditability.
The Healthcare Attestation BAA is completed by the covered entity, the business associate, and their legal or compliance contacts before PHI exchange.
Keep an executed copy with operational contracts and grant access to privacy and security teams for ongoing compliance checks.
A C‑level or authorized officer signs for the business associate, confirming corporate authority and commitment to contractual safeguards; include title and signature date to document authority.
An authorized representative of the covered entity (privacy officer, contract manager, or general counsel) signs to accept terms and to trigger operational onboarding and audits.
Identify the covered entity and business associate using legal names, addresses, and DUNS or EIN where applicable so responsibilities are contractually anchored and unambiguous.
Define the types of PHI, systems, and projects covered; narrow scope where possible to limit exposure and simplify audits and access controls.
Specify technical and administrative safeguards such as encryption, MFA, vulnerability management, and logging to allow verification during audits.
Set timelines and content for breach notifications, including whom to notify, required information, and coordination during mitigation and for regulatory filings.
Require prior notice or approval for subcontractors handling PHI and mandate flow-down of BAA terms to any subprocessor.
Describe termination rights, data return or destruction obligations, and survival of confidentiality and liability clauses after contract end.
Execute the BAA before any PHI is transferred or processed.
Review attestations and controls at least annually or after major changes.
Maintain related records for 6 years (45 CFR §164.530(j)).
Schedule periodic audits per BAA terms and operational risk posture.
Follow return or destruction obligations immediately upon contract end.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (plan dependent) | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |