Establishing secure connection…Loading editor…Preparing document…

Healthcare GSA Addendum

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE GSA ADDENDUM

This Addendum to the Master GSA Healthcare Services Agreement (the "Addendum") is entered into effective as of by and between:

RECITALS

WHEREAS, the Parties entered into the Master GSA Healthcare Services Agreement referenced above; and

WHEREAS, the Parties desire to amend certain terms and incorporate additional requirements related to the provision of healthcare services under that Agreement as set forth in this Addendum;

NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein, the Parties agree as follows.

1. SCOPE OF ADDENDUM

This Addendum modifies the Master Agreement only as expressly set forth. The specific services, locations, and population cohorts to which this Addendum applies are described below. Any services not expressly amended remain governed by the Master Agreement.

2. RATES, FEES, AND BILLING

Provider's rates, fees, and billing procedures for services furnished pursuant to this Addendum are set forth herein. Provider certifies that rates are consistent with rates charged to similarly situated government customers and that the Provider will maintain contemporaneous records to support billed charges.

3. PRIVACY, HIPAA, AND DATA SECURITY

Provider shall comply with all applicable federal and state privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA) and implementing regulations, with respect to any protected health information (PHI) created, received, maintained, or transmitted in connection with this Addendum. Provider shall implement administrative, physical, and technical safeguards appropriate to the size and complexity of its operations to protect PHI.

Provider affirms it has in place policies, procedures, and contracts necessary to meet HIPAA privacy and security obligations.

4. INSURANCE AND INDEMNIFICATION

Provider shall maintain insurance coverage as required by the Master Agreement and as set forth below. Provider shall indemnify, defend and hold harmless the Contracting Agency to the extent set forth in the Master Agreement and this Addendum.

5. AUDIT, RECORDS, AND REPORTING

Provider shall maintain books, records, and supporting documentation sufficient to verify compliance with this Addendum and the Master Agreement. Contracting Agency shall have audit and inspection rights as described below.

6. TERM, TERMINATION, AND TRANSITION

7. REPRESENTATIONS, WARRANTIES, AND CERTIFICATIONS

Provider represents and warrants that it is authorized to perform the services, holds all required licenses and certifications, and will comply with all applicable laws, rules and regulations.

8. PATIENT INFORMATION & AUTHORIZATION (IF APPLICABLE)

If the services affected by this Addendum relate to individually identifiable patients, the Provider warrants that it has obtained all required patient authorizations and consents as required by applicable law. Complete patient information below only for those patients subject to a specific authorization under this Addendum.

Patient information and authorization applicable for specific individuals under this Addendum

Male Female Other / Prefer not to say

INSURANCE & MEDICAL HISTORY (IF APPLICABLE)

9. GOVERNING LAW AND DISPUTE RESOLUTION

10. MISCELLANEOUS

In the event of any conflict between the terms of this Addendum and the Master Agreement, the terms of this Addendum shall control solely with respect to the subject matter herein; all other terms of the Master Agreement remain in full force and effect.

Each Party certifies that the person signing below is authorized to execute this Addendum on behalf of that Party and that the information and representations made herein are true and correct to the best of that Party's knowledge.

Contracting Agency - Printed Name:

By:

Date:

Title:

Healthcare Provider - Printed Name:

By:

Date:

Title:

Enter text✕

What the Healthcare GSA Addendum Is and When it Applies

The Healthcare GSA Addendum is a contract-level attachment used when healthcare providers, vendors, or contractors execute agreements that reference General Services Administration (GSA) procurement terms while also handling protected health information or other healthcare-specific obligations. It clarifies HIPAA-related responsibilities, data handling, breach notification, and any Health Insurance Portability and Accountability Act business associate agreement (BAA) elements that must be layered onto GSA-style terms. The addendum ensures healthcare-specific privacy, security, and recordkeeping obligations are explicit alongside standard procurement clauses.

Why a Healthcare GSA Addendum Matters for Contracts

A Healthcare GSA Addendum aligns procurement language with HIPAA obligations, clarifies who controls PHI, assigns breach response duties, and reduces ambiguity about audits, subcontracting, and retention. It helps both parties document legal responsibilities and lowers operational risk when federal purchasing language and healthcare privacy rules intersect.

Why a Healthcare GSA Addendum Matters for Contracts

Who Typically Completes a Healthcare GSA Addendum

Accurate completion requires input from contracting, legal counsel, and the privacy/security officer to ensure roles, BAA terms, and technical safeguards are correctly reflected.

  • Healthcare providers and health systems coordinating GSA-based purchases or federal contracts
  • Vendors and subcontractors supplying services that will access or process PHI
  • Government agencies or public health entities integrating HIPAA controls into procurement

Core Sections You’ll Find in a Healthcare GSA Addendum

A complete addendum groups obligations so reviewers can quickly find compliance, data handling, auditing, and liability terms. The following six components are typical and should be present or explicitly declined.

Definitions

Clear definitions of PHI, Covered Entity, Business Associate, and permitted uses.

Data Handling

Technical and administrative safeguards, encryption, and access controls.

Breach Notification

Notification timelines, responsibility allocation, and required content.

Audit Rights

Audit frequency, scope, and evidence production requirements.

Subcontracting

Flow-down obligations for subcontractors and approved subprocessors.

Liability & Indemnity

Allocation of risk, caps, and insurance expectations where permitted.

Essential Information to Include on the Addendum

Party Names: Legal entity names exactly as registered
TIN/EIN: Tax identification for invoicing and backup withholding
Authorised Signatory: Name and title of authorized signer
Effective Date: MM/DD/YYYY format for the agreement start
BAA Reference: Statement whether a BAA is attached or required
Data Scope: Types of PHI and permitted processing activities

Step-by-Step: Completing the Healthcare GSA Addendum

Follow this order to minimize omissions and get internal approvals before signatures.

  • 01
    Gather documents: Collect the base contract, BAA draft, and technical specs
  • 02
    Fill party details: Enter legal names, addresses, and signer titles
  • 03
    Define data scope: List PHI categories and permitted uses
  • 04
    Review & sign: Legal and privacy officer approve, then authorized signers execute

Configuring an Online Workflow for the Addendum

Set up fields, authentication, and retention before sending the addendum for signature to ensure compliance and evidence capture.

Field Configuration
Signature Type Electronic signature with date and printed name fields
Authentication Email link plus SMS code or organization SSO for higher assurance
BAA Required Attach executed BAA as a required document in workflow
Retention Settings Enable audit trail retention and export to secure storage

Where to Send and How Execution Typically Flows

A standardized path reduces review cycles and evidences consent steps for compliance audits.

  • Upload Base Contract: Attach the contract and addendum to the signing platform
  • Assign Reviewers: Add legal and privacy reviewers in parallel
  • Require BAA: Make BAA attachment mandatory for execution
  • Execute & Archive: Both parties sign; save signed copies and audit logs

Technical and Integration Considerations for eSigning

Ensure your platform can attach a signed BAA, provide a tamper-evident audit trail, and export signed records to your records system for retention and discovery needs.

  • Integrations: Salesforce, NetSuite, Google Workspace, Box
  • Formats: PDF, DOCX, and secure export to archival storage
  • Security: TLS in transit and AES-256 at rest

Key Dates and Timing You Should Track

Monitor execution windows, renewal triggers, and statutory retention start dates to avoid compliance failures or missed renewals.

Execution Before Start:

Sign before services begin to establish responsibilities

BAA Execution:

Execute BAA before any PHI is shared or processed

Contract Renewal:

Note renewal notice windows specified in the base contract

Breach Notification:

HIPAA often requires prompt notification; follow contract timelines

Record Retention:

Start retention clock from Effective Date per legal rules

Main Penalties and Risks from an Incorrect Addendum

1099 Filing Penalty: IRC §6721: $60–$330 per form for information return errors
HIPAA Enforcement: OCR civil penalties and corrective action for PHI breaches
Contract Termination: Breach of addendum obligations can trigger termination rights
Liability Exposure: Indemnity can shift costs for breach remediation
Operational Delay: Missing BAA halts PHI processing and project delivery
Reputational Harm: Public breach disclosure may affect trust and contracting ability

Real-World Examples of Contracting and Compliance

These customer experiences show how electronic execution and clear addenda reduce administrative friction and improve audit readiness.

Fertility Centers of Illinois

The interface is simple and easy-to-use for our team; more importantly, it is just as easy for our customers.

  • Platforms supported our API integration for automated document routing.
  • The result was faster signature turnaround, consistent audit logs, and a repeatable intake process that aligned legal and privacy reviews.

Optica Ventures LLC

The interface is simple and easy-to-use for our team; more importantly, it is just as easy for our customers.

  • Implementation reduced manual follow-ups and improved completion rates.
  • This streamlined approach allowed legal and compliance teams to focus on substantive review rather than chasing signatures, improving operational throughput.

Comparing eSignature Vendors for Healthcare Addendum Execution

Basic pricing and compliance attributes for common eSignature vendors. Confirm plan details with each vendor for enterprise features and BAAs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes (Business Premium) Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes Yes No No

Practical Tips for Accurate and Efficient Completion

Follow these practices to reduce execution time and preserve compliance evidence for audits and disputes.

Execute BAAs Early
Obtain a fully executed Business Associate Agreement before sharing any PHI; ensure the BAA is attached to the addendum and referenced clearly to avoid downstream processing delays and compliance gaps.
Verify Signer Authority
Confirm signers have corporate authority to bind the party; request a board resolution or delegation of authority for unfamiliar counterparties to prevent later invalidation or dispute over signature power.
Use Strong Authentication
Require at least email plus SMS or SSO for signers handling PHI to provide a stronger attribution trail and reduce repudiation risk during audits or breach investigations.
Keep Tamper-Evident Records
Preserve signed PDFs with embedded audit trails, timestamps, and event logs; store copies in secure archival systems with access controls to satisfy retention and e-discovery requirements.

Common Questions About Healthcare GSA Addenda

Answers to frequent issues that arise when preparing, signing, and storing a Healthcare GSA Addendum.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users