Establishing secure connection…Loading editor…Preparing document…

Healthcare Attestation BAA

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE ATTESTATION BUSINESS ASSOCIATE AGREEMENT (BAA)

Parties and Effective Date

This Business Associate Agreement (Agreement) is entered into by and between Covered Entity: and Business Associate: .

Effective Date:

Contact Information

Definitions

Capitalized terms used in this Agreement shall have the meanings given in the Health Insurance Portability and Accountability Act (HIPAA) and implementing regulations. For purposes of this Agreement, "Protected Health Information" or "PHI" shall mean individually identifiable health information transmitted or maintained by Business Associate on behalf of Covered Entity.

Permitted Uses and Disclosures

Business Associate may use and disclose PHI only as necessary to perform the services set forth in the underlying service agreement between the parties and as required by law. Business Associate shall not use or disclose PHI in any manner that would violate the Privacy Rule if done by Covered Entity, except as permitted by this Agreement.

Safeguards and Security Obligations

Business Associate shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI. These safeguards shall include, at a minimum, workforce training, access controls, encryption where feasible, and written policies and procedures for secure handling of PHI.

Breach Notification

Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, including breaches of unsecured PHI as required by the Breach Notification Rule, within forty-eight (48) hours of discovery or as otherwise required by law. Such notice shall include identification of the nature of the breach, affected PHI, corrective actions and mitigating steps taken.

Subcontractors

Business Associate shall ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions and conditions that apply to Business Associate with respect to such information.

Access, Amendment and Accounting

To the extent required by the Privacy Rule, Business Associate agrees to provide access to PHI maintained in designated records to Covered Entity, and to make amendments and provide accounting of disclosures of PHI as requested by Covered Entity in order to satisfy Covered Entity's obligations under the Privacy Rule.

Return or Destruction of PHI

Upon termination of the underlying services or this Agreement, Business Associate shall, at Covered Entity's election, return or securely destroy all PHI received from Covered Entity. If return or destruction is not feasible, Business Associate shall continue to safeguard the PHI and limit further uses and disclosures.

Indemnification and Liability

Each party shall indemnify, defend and hold harmless the other from and against any losses, liabilities or expenses resulting from a breach of this Agreement or violation of applicable law by the indemnifying party, subject to limitations agreed in the underlying service agreement and as permitted by law.

Term and Termination

This Agreement shall be effective as of the Effective Date and shall terminate when all PHI is returned or destroyed, or earlier if the underlying services agreement terminates. Covered Entity may terminate this Agreement for Business Associate's material breach if Business Associate fails to cure within thirty (30) days after written notice.

Miscellaneous

This Agreement constitutes the entire understanding between the parties with respect to the subject matter and may be amended only by a written instrument signed by both parties. This Agreement shall be governed by the laws of the state identified by Covered Entity for the underlying agreement.

Business Associate Attestation

The undersigned Business Associate hereby attests and certifies as follows (check all that apply and provide additional detail where indicated):

Business Associate maintains written security and privacy policies and has implemented reasonable administrative, physical and technical safeguards to protect PHI.

Business Associate provides periodic workforce training on HIPAA requirements and security policies.

Business Associate maintains an incident response plan and will notify Covered Entity of any unauthorized use or disclosure as required herein.

Business Associate has completed a risk assessment addressing confidentiality, integrity and availability of PHI within the last 24 months.

Authorized Representatives

Acknowledgment

By signing below, each party represents and warrants that the signer is authorized to execute this Agreement on behalf of the party, that the party will comply with all applicable provisions of HIPAA and implementing regulations with respect to PHI, and that the statements and attestations set forth in this document are true and correct.

Covered Entity:

By:

Date:

Business Associate:

By:

Date:

Enter text✕

What the Healthcare Attestation BAA Is and when it's used

A Healthcare Attestation BAA is a combined attestation statement and Business Associate Agreement that documents how a vendor, contractor, or service provider will handle protected health information (PHI). It confirms the party's responsibilities under HIPAA and HITECH, describes permitted uses and disclosures of PHI, and sets security, breach-reporting, and audit obligations. Organizations exchange this document before sharing PHI so covered entities can demonstrate contractual safeguards. The form is commonly used when a clinical system, billing processor, cloud host, or analytics provider will create, receive, maintain, or transmit PHI on behalf of a covered entity.

Step-by-step: Completing a Healthcare Attestation BAA

Follow these core steps in order to prepare, review, and execute the attestation and BAA so PHI sharing is contractually protected.

  • 01
    Prepare: Collect entity names, contact info, and scope of PHI exchange.
  • 02
    Draft: Specify permitted uses, security controls, and breach procedures clearly.
  • 03
    Review: Legal and compliance review for HIPAA alignment and operational feasibility.
  • 04
    Execute: Obtain authorized signatures before PHI transfer begins.

Why a Healthcare Attestation BAA matters for compliance

A signed attestation plus BAA creates contractual obligations that map to HIPAA requirements, documents risk allocation, and supports auditability.

Why a Healthcare Attestation BAA matters for compliance

Who completes and signs this document

The Healthcare Attestation BAA is completed by the covered entity, the business associate, and their legal or compliance contacts before PHI exchange.

  • Covered entities — hospitals, clinics, health plans requesting vendor attestations and BAAs.
  • Business associates — vendors processing PHI such as cloud hosts or billing services.
  • Compliance teams — legal, privacy, and security reviewers approving contractual language.

Keep an executed copy with operational contracts and grant access to privacy and security teams for ongoing compliance checks.

Primary signers and their roles

Vendor Executive

A C‑level or authorized officer signs for the business associate, confirming corporate authority and commitment to contractual safeguards; include title and signature date to document authority.

Covered Entity Officer

An authorized representative of the covered entity (privacy officer, contract manager, or general counsel) signs to accept terms and to trigger operational onboarding and audits.

Essential fields to include in the attestation and BAA

Parties: Full legal names
Effective Date: MM/DD/YYYY
Covered PHI: PHI categories
Permitted Uses: Specific purposes
Security Controls: Technical safeguards
Breach Process: Notification terms

Core clauses every professional Healthcare Attestation BAA should include

A clear, enforceable BAA pairs an attestation of compliance with operational clauses that define responsibilities, limits, and verification mechanisms for PHI handling.

Identification

Identify the covered entity and business associate using legal names, addresses, and DUNS or EIN where applicable so responsibilities are contractually anchored and unambiguous.

Scope

Define the types of PHI, systems, and projects covered; narrow scope where possible to limit exposure and simplify audits and access controls.

Security Controls

Specify technical and administrative safeguards such as encryption, MFA, vulnerability management, and logging to allow verification during audits.

Breach Reporting

Set timelines and content for breach notifications, including whom to notify, required information, and coordination during mitigation and for regulatory filings.

Subprocessors

Require prior notice or approval for subcontractors handling PHI and mandate flow-down of BAA terms to any subprocessor.

Termination

Describe termination rights, data return or destruction obligations, and survival of confidentiality and liability clauses after contract end.

Typical flow for sending, signing, and storing the attestation and BAA

This compact workflow illustrates sender preparation, signer authentication, signature capture, and post-signature retention steps that preserve evidentiary detail.

  • Prepare Document: Populate party fields, scope, and security clauses before routing for signatures.
  • Configure Signing: Place signature blocks, dates, and optional authentication steps like SMS or KBA.
  • Signers Execute: Authorized signers authenticate and apply signatures; audit trail is created automatically.
  • Archive: Store signed PDF and audit trail in secure records with retention controls.

Practical tips to complete Healthcare Attestation BAAs accurately

Adopt these practices to reduce negotiation friction, speed onboarding, and improve audit defensibility.

Use clear, specific language
Avoid vague phrases like 'as needed' for PHI access. Define precise purposes, data categories, and technical controls to reduce later disputes and simplify compliance testing.
Align attestation to operations
Ensure the attestation reflects actual processes and security controls; mismatched statements can lead to failed audits or breach liabilities.
Document authorized signers
Record the name, title, and authority basis for each signer in the agreement; this reduces later challenges on signature validity and corporate authority.
Retain signed records securely
Store the signed BAA and its audit trail in encrypted storage with controlled access and retention aligned to HIPAA and organizational policy.

Key timing considerations and deadlines for execution and retention

Timing matters for enforceability and compliance; these common deadlines help you prioritize execution and recordkeeping.

Before PHI Exchange:

Execute the BAA before any PHI is transferred or processed.

Annual Review Recommended:

Review attestations and controls at least annually or after major changes.

HIPAA Retention:

Maintain related records for 6 years (45 CFR §164.530(j)).

Contract Audits:

Schedule periodic audits per BAA terms and operational risk posture.

Termination Actions:

Follow return or destruction obligations immediately upon contract end.

Common risks and potential penalties for incorrect BAAs or attestations

HIPAA Civil Penalties: Civil fines possible
Breach Liability: Statutory notification costs
Contractual Exposure: Indemnity obligations
Operational Disruption: Access suspensions
Regulatory Scrutiny: Enforcement audits
Reputational Harm: Loss of trust

Comparing eSignature providers for Healthcare Attestation BAAs

Key pricing and compliance points for common eSignature platforms; signNow is listed first for comparison and HIPAA availability.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes (plan dependent) Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently asked questions about Healthcare Attestation BAAs

Answers to common legal and practical questions about enforceability, signing, and recordkeeping for BAAs and attestations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users