Parties
Full legal names of the covered entity and downstream organization, including DBA entries where applicable.
A clear downstream attestation helps covered entities demonstrate due diligence, allocate responsibilities, and reduce exposure from third-party handling of PHI while supporting contractual and regulatory obligations.
Organizations across healthcare delivery, payer and vendor groups use downstream attestations when sharing PHI with third parties.
The attestation is signed by authorized representatives of the covered entity and the downstream vendor to create a clear, auditable record of responsibilities.
Chief compliance or privacy officer who reviews regulatory language, confirms the attestation aligns with the entity's BAA and organizational risk appetite, and signs on behalf of the covered entity when authorized.
Senior vendor or vendor compliance lead who documents the downstream controls in place, certifies adherence to required safeguards, and signs to accept contractual obligations and audit cooperation terms.
Full legal names of the covered entity and downstream organization, including DBA entries where applicable.
Precise description of the categories of PHI, purposes for access, and datasets involved.
Summary of administrative, physical, and technical safeguards the vendor maintains.
Whether the downstream vendor may subcontract and how subcontractors will be bound.
Notification timelines, cooperation obligations, and forensic support expectations.
Authorized signatory names, titles, dates, and any witness or notarization requirements.
| Field | Configuration |
|---|---|
| Authentication | Email link or SMS code; consider stronger 2FA for high-risk access |
| Signature Fields | Signature, printed name, title, date; mark required |
| Conditional Fields | Show subcontractor fields only if subcontracting is allowed |
| Retention Metadata | Capture document type, effective date, and contract ID for indexing |
Choose a platform that supports secure transmission, audit trails, and retention controls aligned with HIPAA.
Obtain before PHI transfer begins
Archive signed copy immediately after signing
Follow HHS OCR timelines (60 days when applicable)
Re-attest or revalidate controls annually
Reissue attestation alongside BAAs at renewal
Covered entity requests attestation and provides scope details
Compliance and legal review obligations and controls
Authorized vendor representative signs and dates
Signed document and audit trail stored for retention period
A regional fertility center required downstream attestations for cloud vendors storing PHI
A payer used attestations to document subcontractor analytics access
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Free trial varies | Free trial varies | Free trial varies | Free trial varies |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | Varies | Varies |