Incident Command
Define command structure, decision authorities, alternates, and contact lists so leadership handoffs are clear during multi-day incidents.
A formal plan reduces uncertainty, preserves patient safety, and documents compliance steps required during emergencies. It clarifies roles, protects sensitive data, and creates a record that supports regulatory review and reimbursement decisions.
Healthcare providers, clinics, hospitals, long-term care facilities, and public-health agencies typically maintain crisis plans.
The plan also supports payers, suppliers, and affiliated community partners who need clear procedures for continuity and coordination.
Define command structure, decision authorities, alternates, and contact lists so leadership handoffs are clear during multi-day incidents.
Triage criteria, surge thresholds, cohorting rules, and protocols for resource allocation (ventilators, ICU beds, medications).
Templates for internal alerts, patient-family notifications, and public statements; designate spokespersons and approval workflow.
Procedures for protected health information handling, emergency disclosures, and HIPAA-limited authorizations; include BAA lists.
Inventory thresholds, alternate suppliers, reuse policies (if any), and conservation measures with responsible managers named.
Record-keeping standards, incident logs, after-action review checklist, and citations for applicable laws and reporting obligations.
| Field | Configuration |
|---|---|
| Activation Toggle | Auto-notify Incident Commander and admin team |
| Signature Fields | Require signer name, title, date for orders |
| Distribution List | Auto-send to compliance, legal, and supply teams |
| Audit Settings | Capture IP, timestamp, and completion certificate |
Choose platforms that support audit trails, HIPAA BAAs, and flexible signer authentication for emergency use.
Ensure any chosen vendor can provide a BAA, uses AES-256/TLS, and preserves a complete audit trail for post-incident review.
Annual review recommended; update after major incidents
Report certain public-health events to authorities within 24 hours
Retention begins on creation or last effective date
Respond within 30–60 days per HIPAA guidance
Complete and store within 90 days post-incident
Identify whether order needs witness or notarization
Choose in-person or remote online notarization
Use multi-factor or credential-proofing
Retain audio-video if RON is used
Include notary or witness affidavits with record
Preserve tamper-evident signed copy
Distribute authenticated record to relevant parties
Ensure timestamps and signer metadata captured
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
The center adopted an electronic signature workflow to manage patient consents during remote operations
Xerox integrated eSignature into enterprise workflows for approvals and vendor agreements
Typically signs clinical orders, triage protocols, and medical directives; should be explicitly named with backup designee and documented authority for emergency decisions.
Signs operational declarations, resource requests, and facility-level agreements; include title, delegation limits, and contact details in the plan.