Permitted Uses
Specify exactly which operations or functions the business associate may perform with PHI and prohibit any other uses or disclosures not expressly permitted by the covered entity.
A properly drafted BAA allocates responsibility for PHI protection, clarifies incident reporting timelines, and preserves the covered entity’s ability to enforce HIPAA safeguards. It reduces regulatory risk and documents the parties’ intent to comply with 45 CFR §164.502(e) and §164.530.
Organizations that exchange PHI use BAAs to document obligations between covered entities and business associates before work begins.
Final signatures should be obtained from authorized representatives and documented prior to any PHI exchange.
Chief Information Security Officer or authorized executive typically signs on behalf of the covered entity. That signer confirms the entity’s expectations for PHI handling, audit rights, breach notification timing, and termination triggers under HIPAA and internal policies.
An officer or authorized contract signatory for the vendor signs to accept obligations including safeguards, subcontractor flow-downs, breach response, and cooperation with audits; signature confirms legal responsibility for PHI under the BAA terms.
Specify exactly which operations or functions the business associate may perform with PHI and prohibit any other uses or disclosures not expressly permitted by the covered entity.
Detail administrative, physical, and technical measures the business associate must implement, including access controls, encryption, logging, and vulnerability management practices.
Define breach reporting timelines, evidence required for the report, cooperative investigation responsibilities, and obligations for notifying affected individuals and regulators.
Require business associates to contractually bind subcontractors to the same BAA terms and to maintain oversight of their compliance and security practices.
Grant the covered entity the right to request documentation, security assessments, and access to records or to conduct audits consistent with HIPAA compliance needs.
Specify when PHI must be returned or securely destroyed at termination, including acceptable destruction methods and certification of destruction.
| Field | Configuration |
|---|---|
| Signature Type | Visible signature + audit trail |
| Authentication | Email plus SMS code where possible |
| Retention | Retain signed PDF and audit trail for minimum federal period |
| Access Controls | Role-based access and SSO for administrators |
Confirm technical and compliance features that matter for BAAs and PHI.
Retain audit trails, signed PDFs, and access logs to support audits and breach investigations.
Sign BAA before any PHI is shared; failure risks noncompliance
Prompt reporting as defined by the BAA and HIPAA rules
Retention begins on the effective date or creation of records
Maintain records for at least 6 years (45 CFR §164.530(j))
Reassess BAA terms annually or when services change
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes (Business Premium) | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |