Permitted Uses
Explicitly state allowed PHI uses and disclosures, restricting any activity not listed and requiring prior written consent for new uses.
A properly drafted Healthcare Comprehensive BAA aligns contractual duties with regulatory requirements under HIPAA and the HITECH Act, clarifies liability for breaches, and documents administrative, physical, and technical safeguards. It also supports vendor oversight and auditability while enabling lawful PHI exchanges necessary for patient care and billing.
Covered entities and vendors that handle PHI must execute a BAA before sharing protected health information; the BAA is finalized by authorized representatives.
Maintain a signed BAA on file for oversight, audits, and evidence of compliance with HIPAA and organizational vendor management policies.
Chief Privacy Officer or equivalent often reviews and signs BAAs on behalf of a covered entity, ensuring contractual language maps to internal policies, HIPAA risk assessments, and breach response plans.
Senior operations or compliance officers at the business associate sign to accept obligations, confirm security controls are in place, and to commit to required notifications and return/destruction of PHI at termination.
| Field Placement and Locking | Place signature, date, and checkbox fields; lock critical clauses |
|---|---|
| Signer Order | Set covered entity first, then business associate signer |
| Authentication Method | Choose email, SMS code, or stronger ID verification |
| Conditional Fields | Show additional fields when specific PHI types are selected |
| Audit and Certificate | Enable automatic audit trail and completion report |
Choose secure channels and appropriate signer authentication for eSubmission to preserve legal enforceability and data protection.
Execute BAA before any PHI is shared or services commence
Notify covered entity promptly per contract and HIPAA requirements
Reassess BAAs annually or after material service changes
Retain BAAs per retention policy and applicable laws
Ensure signed copies are available for audits and OCR inquiries
Explicitly state allowed PHI uses and disclosures, restricting any activity not listed and requiring prior written consent for new uses.
Describe administrative, physical, and technical safeguards such as encryption, access controls, logging, and least-privilege access to PHI.
Require BAAs with subcontractors and obligate the business associate to oversee and flow down protections to vendors.
Set timelines, contact points, and required content for notifications of unauthorized PHI disclosure or suspected incidents.
Allow covered entity to conduct audits, request evidence of controls, and receive audit reports or corrective action plans.
Specify procedures to return or securely destroy PHI when services end, including certifications of destruction where appropriate.
| Criteria | Healthcare Comprehensive BAA | DPA |
|---|---|---|
| HIPAA Enforcement | ||
| PHI Coverage | ||
| Typical Parties | covered entity & ba | controller & processor |
| Legal Basis | 45 cfr requirements | gdpr article 28 |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes (Business Premium) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA required) | Check with vendor | Check with vendor | Check with vendor | Check with vendor |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies | Varies | Varies |