Scope of Access
Precisely describe what categories of protected health information may be accessed, processed, or transmitted and for what limited business purposes.
A concise Healthcare Exhibit reduces ambiguity about PHI handling, aligns contracting parties on HIPAA obligations, and documents steps for breach response and record retention under applicable law.
Combining these perspectives helps the exhibit balance regulatory safeguards, operational feasibility, and enforceable contract terms.
A hospital administrator or director who signs on behalf of a covered entity should have delegated contracting authority and familiarity with HIPAA operational requirements; their signature binds the institution to data handling, breach notification, and access obligations.
A vendor executive or authorized representative signing the exhibit must be empowered to accept business associate duties, implement technical safeguards, and commit to contractual indemnities and reporting timelines.
Precisely describe what categories of protected health information may be accessed, processed, or transmitted and for what limited business purposes.
List allowed processing activities, any prohibition on re‑disclosure, and circumstances that require prior written consent or a separate authorization.
Specify required administrative, physical, and technical safeguards, including encryption in transit and at rest and access control standards.
Define the breach notification timeline, required contents of notices, forensic responsibilities, and cost allocation for remediation.
State retention periods, return or destruction procedures for PHI at termination, and any exceptions required by law.
Identify authorized signatories, effective dates, countersignature order if needed, and whether notarization is required for specific attachments.
| Field | Configuration |
|---|---|
| Signature Authentication | Email link plus optional SMS code |
| Conditional Fields | Show data-access details only when vendor checkbox selected |
| Attachment Upload | Allow supporting certificates and BAA documents |
| Audit Trail | Enable timestamped activity log |
Maintain consistent log records across systems and ensure integrations support exportable audit trails for compliance reviews.
Date when all required parties have signed and the exhibit becomes binding.
Date obligations begin; use MM/DD/YYYY format consistently.
Follow contract and HIPAA timelines for prompt notification.
Retention typically measured from creation or last effective date.
Patient access requests generally processed within statutory timelines.
Exhibit content finalized and ready for legal review.
Privacy and security teams confirm controls and BAA needs.
Authorized signers execute in agreed order.
Executed copy stored in records management system.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
A fertility center added a HIPAA addendum to vendor contracts to standardize PHI handling across clinics
A health system required a standardized exhibit for all new software vendors handling ePHI