Parties
Identify the covered entity and business associate by full legal name, address, and contact information so responsibilities are unambiguous.
A Healthcare BAA Document records commitments to protect PHI, clarifies each party’s duties, and demonstrates contractual safeguards required by HIPAA. It reduces regulatory risk, sets breach-response expectations, and supports audit readiness for covered entities and business associates.
Identify the organizations and roles that typically prepare, review, and execute a Healthcare BAA Document before PHI is shared with a third party.
Confirm signatory authority and operational contacts up front to prevent delays and ensure PHI exchanges occur only after the BAA is fully executed.
| Field | Configuration |
|---|---|
| Signature Type | Typed, drawn, or PKI-based |
| Authentication | Email link, SMS code, or KBA per risk |
| Audit Trail | Store timestamps, IPs, and action logs |
| Routing Order | Sequential or parallel signer order |
Confirm the eSignature provider supports strong transport and storage encryption, a signed HIPAA BAA, and reliable audit trails before executing Healthcare BAAs.
Determines when HIPAA obligations and reporting windows begin.
Follow HIPAA timelines for notification to affected parties and HHS as required.
Reassess security controls and update contractual terms on material change.
Specify timeframes to return or securely destroy PHI after termination.
Retention often begins on creation or last effective date per law.
Legal and security teams complete the initial BAA draft and risk assessment.
Authorized approver reviews and signs off on terms and liabilities.
Parties execute electronically or in writing and record the effective date.
Store executed agreement and certificate of completion for audits.
| Document | Healthcare BAA | DPA |
|---|---|---|
| Primary purpose | protect phi | process data |
| HIPAA focus | ||
| Signatories | covered entity & ba | vendor & controller |
| Required clauses | breach notice, safeguards | security, liability |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes (Business Premium) | Yes | Yes | Yes | Yes |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Identify the covered entity and business associate by full legal name, address, and contact information so responsibilities are unambiguous.
Define PHI, permitted disclosures, subcontractor, and breach to ensure consistent interpretation and reduce disputes.
Specify exactly what PHI uses are allowed, any permitted disclosures, and limitations to prevent unauthorized processing.
List administrative, physical, and technical safeguards required, including encryption, access controls, and incident response expectations.
Require prompt notification timelines, content of notices, remediation obligations, and cooperation for investigations.
Set termination triggers, data return or destruction processes, and surviving obligations for auditing and liability.