Permitted Uses
Clear description of allowed PHI uses and disclosures, limiting processing to functions the business associate performs on behalf of the covered entity and prohibiting unrelated uses.
A properly completed Healthcare BAA Form documents legal duties for PHI protection, supports HIPAA compliance, clarifies breach responsibilities, and provides contractual proof for regulators and auditors.
The BAA is used when a covered entity delegates PHI handling to a vendor or partner.
All parties should ensure authorized signatories and effective dates are recorded to create an enforceable agreement.
A chief privacy officer, general counsel, or authorized executive signs on behalf of the covered entity and confirms the organization will only disclose PHI as permitted and will require the business associate to implement required safeguards.
A chief compliance officer, general counsel, or authorized company officer signs for the vendor, accepting obligations to implement administrative, physical, and technical safeguards and to notify the covered entity of breaches.
Clear description of allowed PHI uses and disclosures, limiting processing to functions the business associate performs on behalf of the covered entity and prohibiting unrelated uses.
Specific technical, administrative, and physical safeguards the business associate must maintain, including encryption, access controls, logging, and incident response procedures.
Breach reporting timeframe and required content, specifying who notifies affected individuals, regulatory bodies, and steps for mitigation and investigation.
Requirement that the business associate obtain written agreements from all subcontractors imposing the same BAA obligations and permitting audits.
Covered entity rights to audit, inspect security policies, and require corrective actions, including cooperation for HIPAA compliance reviews and investigations.
Procedures for termination, return or destruction of PHI, and steps to address residual copies or legal retention obligations.
Record clearly as MM/DD/YYYY when obligations begin.
Report breaches promptly per internal SLAs and regulatory expectations.
Review BAAs annually or upon material service changes.
Maintain execution evidence for regulatory retention periods.
Define reasonable notice for audits and inspection access.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (Business Premium) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA required) | Yes | Yes | No | No |
| Field | Configuration |
|---|---|
| Upload Document | Use final PDF or DOCX format. |
| Place Signature Fields | Add signature, date, and checkbox fields. |
| Signer Authentication | Email + optional SMS or ID verification. |
| Audit Settings | Enable full event logging and certificate of completion. |
Ensure the eSignature platform supports HIPAA BAAs, robust audit trails, and integrations your organization requires.
Confirm contractual terms for data residency, BAA availability, and support levels before selecting a provider for PHI workflows.