Scope
Define the specific systems, data types, locations, and services covered by the attestation so reviewers can determine applicability.
A signed attestation documents organizational commitments, clarifies responsibility for protected health information, and helps satisfy contractual or regulatory obligations. It creates a reproducible record that supports audits, vendor oversight, and due diligence without replacing required notices, policies, or incident reports.
Covered entities, business associates, vendors, and subcontractors use attestations to confirm compliance with HIPAA, contract terms, or payer rules.
Attestations also help compliance teams manage third-party risk and provide a consistent record for internal audits and external reviewers.
Define the specific systems, data types, locations, and services covered by the attestation so reviewers can determine applicability.
Identify the legal, regulatory, or contractual standards relied upon (for example, HIPAA policies, NIST controls, or payer requirements) to avoid ambiguity.
List the administrative, technical, and physical safeguards or specific activities being attested to, such as encryption, access controls, and workforce training.
State the date when the attested controls were in effect and whether the attestation covers a point-in-time or ongoing compliance period.
Name an authorized individual with authority to bind the organization and include job title, contact information, and signature date.
Note any exclusions, dependencies on third parties, or conditions that restrict the scope or strength of the attestation statement.
| Field | Configuration |
|---|---|
| Required Fields | Make name, entity, scope, and date mandatory |
| Authentication | Enable email or SMS codes for signer verification |
| Attachments | Allow PDF uploads for policies and training logs |
| Retention | Set record retention to meet HIPAA/contract terms |
Ensure your e-signature platform supports accepted formats, audit trails, and required integrations before sending attestations.
Choose a platform that provides tamper-evident signed PDFs, detailed audit logs, and, where applicable, a Business Associate Agreement for HIPAA compliance.
Provide attestation at or before contract execution.
Update attestations for annual compliance recertification.
Re-attest following major system or policy changes.
Report incidents per HIPAA breach rules, typically within 60 days.
Supply attestations on request during audits or oversight.
A clinical network standardized attestations for vendor PHI access
A property manager used attestations for tenant health screening vendors
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Trial available | Trial available | Trial available | Trial available |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |