Purpose and Scope
Define permitted types of PHI, departments involved, and whether the agreement covers only fax or additional transmission methods including secure gateways.
A written agreement reduces transmission errors and liability, sets security expectations for PHI, clarifies responsibilities when faxes are misdirected, and documents procedures needed for HIPAA compliance and incident response.
Common parties include healthcare providers, health systems, third‑party vendors, and business associates that exchange PHI by fax.
Identifying the correct contract signatories up front prevents ambiguity and supports compliance with HIPAA and vendor management requirements.
| Field | Configuration |
|---|---|
| Retention | Retain logs for 6 years (HIPAA) |
| Access Controls | Role-based access, unique accounts |
| Transmission Security | TLS 1.2/1.3 or secure fax gateway |
| Audit Trail | Capture IP, timestamp, and result |
Confirm integration and platform requirements before signing so the agreement aligns with existing systems.
Define permitted types of PHI, departments involved, and whether the agreement covers only fax or additional transmission methods including secure gateways.
Specify the minimum necessary standard, permitted data elements, redaction requirements, and procedures for de‑identification where appropriate.
Detail required technical controls such as encrypted fax gateways, TLS 1.2/1.3, access controls, and delivery confirmation procedures.
Require retention of transmission logs, delivery receipts, and access records sufficient to support incident investigations and compliance audits.
Assign breach reporting timelines, responsibilities and required content; include OCR notification obligations under HIPAA and contractual notice to affected parties.
Allocate responsibility for negligent transmissions, define limits on damages, and include indemnity for third‑party claims arising from PHI disclosures.
State when the agreement takes effect and renewal or termination notice period.
Provide at least 30 days' written notice for material changes to procedures or terms.
Report breaches to responsible parties and OCR within HIPAA-required timelines (OCR guidance expects prompt notification).
Maintain transmission and audit logs for HIPAA retention (see 45 CFR §164.530(j)).
Acknowledge and act on consent revocation within a defined operational window, typically 30 days.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Trial available | Trial available | Trial available | Trial available |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |