Establishing secure connection…Loading editor…Preparing document…

Healthcare CCA Addendum

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE CCA ADDENDUM

This Healthcare Care Coordination Agreement Addendum (Addendum) modifies the terms of the existing Care Coordination Agreement between Patient Name: and Provider Name: . Addendum Effective Date: Addendum Number:

Patient Information

Insurance Information

Medical History Summary

Addendum Terms and Modifications

Purpose: This Addendum documents agreed modifications to the existing Care Coordination Agreement limited to the scope, duration, and responsibilities set forth below. All terms of the underlying agreement remain in effect except as expressly modified by this Addendum.

Confidentiality and PHI Disclosure: The parties acknowledge that the performance of care coordination services requires the use and limited disclosure of protected health information (PHI). Provider shall use, disclose, and safeguard PHI in accordance with applicable privacy laws. Provider is authorized to disclose PHI to the individuals and entities engaged in care coordination as reasonably necessary to perform the services described in this Addendum.

By checking the box below, Patient authorizes Provider and its authorized agents to use and disclose PHI for care coordination, treatment planning, billing, and quality assurance as described above.

Legal Provisions

Integration: This Addendum and the underlying Care Coordination Agreement constitute the entire agreement with respect to the subject matter herein. All other terms of the underlying agreement not expressly modified remain binding and in full force.

Indemnification and Limitation of Liability: Each party agrees to indemnify the other for claims arising from its negligent or willful acts in the performance of obligations under this Addendum. Except as required by law, Provider's aggregate liability under this Addendum shall be limited to direct damages and shall exclude consequential or punitive damages.

Termination: Either party may terminate this Addendum in accordance with the termination provisions of the underlying Care Coordination Agreement. Termination shall not affect obligations incurred prior to the effective date of termination, including billing and recordkeeping obligations.

Amendment: Any amendment to this Addendum must be in writing and signed by the Patient and an authorized representative of the Provider.

Governing Law and Dispute Resolution: This Addendum will be governed by the laws applicable to the underlying Care Coordination Agreement. The parties agree to first seek resolution through good-faith negotiation and, if unresolved, through mediation before pursuing other remedies.

Acknowledgement and Certification

The undersigned certifies that they are the patient named above or the patient's legally authorized representative, have read and understand this Addendum, have had an opportunity to ask questions, and voluntarily agree to the modifications set forth herein. The patient understands the right to revoke this authorization in writing, except to the extent that action has already been taken in reliance on this authorization.

Patient Printed Name:

Signature:

Date:

Enter text✕

What the Healthcare CCA Addendum Is and When it Applies

The Healthcare CCA Addendum is a supplemental agreement that clarifies how a Covered Clinical Agreement (CCA) or similar healthcare contract will handle protected health information, compliance obligations, and responsibilities between parties. It typically supplements a primary contract to specify permitted uses and disclosures of PHI, security controls, breach notification steps, and the requirement for a Business Associate Agreement (BAA) when a vendor will create, receive, maintain, or transmit PHI on behalf of a covered entity. The addendum helps align contractual obligations with HIPAA privacy and security expectations and documents whether electronic execution is acceptable under applicable law.

Why a Healthcare CCA Addendum Matters for Compliance

A clear addendum limits ambiguity about PHI handling, assigns breach response duties, and documents safeguards that support HIPAA obligations.

Why a Healthcare CCA Addendum Matters for Compliance

Organizations and Individuals Who Typically Use This Addendum

The Healthcare CCA Addendum is used by entities that exchange or process PHI and need to document roles, limits, and security obligations.

  • Health systems and hospitals that contract with third-party service providers for clinical or IT services.
  • Managed care organizations and group practices that share PHI with vendors, consultants, or subcontractors.
  • Vendors, software-as-a-service providers, and business associates that access or store patient information.

Parties should complete the addendum before PHI is shared and include it alongside a BAA when required by HIPAA.

Step-by-Step: Completing the Healthcare CCA Addendum

Follow this sequential checklist to prepare, review, and execute the addendum so obligations are clear before PHI exchange.

  • 01
    Prepare: Gather entity details and existing BAA terms for alignment.
  • 02
    Define Scope: Specify permitted PHI uses, recipients, and retention limits.
  • 03
    Security Clauses: List technical and administrative safeguards required.
  • 04
    Execute: Obtain authorized signatures and record the effective date.

How to Configure an Online Workflow for This Addendum

A consistent digital workflow reduces execution friction and preserves an auditable record of consent and signature events.

Document Upload PDF or DOCX accepted; include the primary agreement as reference.
Field Placement Add signature, date, and initials fields in required spots.
Signer Order Set role-based signing (covered entity first, then business associate).
Authentication Require email + SMS code or SSO for higher-assurance signers.
Audit Capture Enable full audit trail: timestamps, IP, and action log.

Typical eSigning Flow for a Healthcare CCA Addendum

A reliable eSignature flow supports intent, attribution, consent, and retention — the four components of legal validity under ESIGN and UETA.

  • Upload: Sender uploads the addendum and attaches related BAA or agreement extract.
  • Place Fields: Add signature, date, and checkbox fields for consent and acknowledgments.
  • Authenticate: Signers authenticate (email link, SMS code, or SSO) before signing.
  • Complete & Store: Signed copies and audit trails are archived for retention and reproduction.

Platform Considerations for Secure Execution

Choose a platform that meets encryption and compliance needs and captures a verifiable audit trail.

  • Integrations: Salesforce, NetSuite, Google Workspace support automated storage and routing.
  • File Formats: PDF and DOCX support preserves formatting and embedded signatures.
  • Authentication: Options should include email, SMS, SSO, and advanced signer verification.

Verify the platform supports HIPAA (BAA available), AES-256 at rest, TLS 1.2/1.3 in transit, and captures a tamper-evident audit trail.

Security and Compliance Elements to Include

Encryption: AES-256 at rest
Transport: TLS 1.2/1.3
Audit Trail: Timestamps and IP logs
BAA: Available when PHI is handled
21 CFR Support: 21 CFR Part 11 compatible
Certifications: SOC 2 Type II; ISO 27001

Key Risks and Consequences of an Incorrect Addendum

HIPAA Violations: Civil and criminal penalties
Breach Costs: Notification and remediation expenses
Contract Liability: Indemnity and damages exposure
Operational Delays: Suspension of PHI exchanges
Regulatory Scrutiny: OCR investigations and audits
Reputational Harm: Loss of patient or partner trust

Common Preparation Errors to Avoid

  • Using vague scope language that allows unintended PHI uses and complicates oversight.
  • Failing to attach or reference the primary agreement or existing BAA, which creates conflicting obligations.
  • Omitting technical security specifications (encryption standards, access controls) that vendors must meet.
  • Relying on informal initials or text approvals without an auditable signature event and retention plan.

Timelines and Time-Sensitive Requirements

Key timing elements to track when preparing, executing, and operationalizing a Healthcare CCA Addendum.

Execution Timing:

Execute before any PHI exchange.

Breach Notification Window:

Specify timing (commonly within 72 hours of discovery).

Record Retention Start:

Effective date triggers retention obligations.

Periodic Reviews:

Reassess safeguards annually or upon material change.

Termination Notice:

Specify notice period for contract termination.

eSignature Pricing and Feature Comparison for Healthcare Use

Low-level pricing and core compliance features for commonly evaluated eSignature vendors; signNow is shown first per platform comparison guidance.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (premium tiers) Yes Yes Yes Varies
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions About the Healthcare CCA Addendum

Answers to common execution, enforceability, and compliance questions when preparing or signing a Healthcare CCA Addendum.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users