Entity Identification
Full legal name, NPI or EIN, and primary business address so auditors and counterparties can match the certification to official registrations and contracts.
A clear, signed HIPAA Certification helps prove reasonable safeguards for PHI, supports contractual compliance with BAAs, and documents organizational controls that regulators review during audits or breach investigations under HIPAA rules.
Organizations complete this certification to document PHI protections and contractual commitments.
Signed certifications create an auditable record for contracts, audits, and incident response processes.
Full legal name, NPI or EIN, and primary business address so auditors and counterparties can match the certification to official registrations and contracts.
Description of PHI categories covered (e.g., treatment, billing, lab results) and any exclusions to clarify what data the certification governs.
Exact HIPAA/privacy policy name and effective date so reviewers know which controls and procedures were in force at the certification date.
Statement whether a Business Associate Agreement exists, its execution date, and any related contract identifiers that tie obligations together.
Name, title, and signature block for a person authorized to make binding compliance attestations on behalf of the organization.
Clear retention instructions, location of retained records, and responsible custodian so records can be produced during audits or investigations.
| Field | Configuration |
|---|---|
| Authentication | Email link or SMS code; use strong methods for high-risk exchanges |
| Audit Trail | Enable IP, timestamp, and action logging for each signer |
| Attachments | Require executed BAA and policy extract as PDF attachments |
| Retention | Set automated retention to at least six years |
Ensure the signing platform supports compliance features required for PHI exchange.
Choose a platform that offers a BAA, audit trail, encryption in transit and at rest, and integration with your record systems.
Set as MM/DD/YYYY and mirror policy effective date used in the assessment.
Recommend annual review; update sooner for material control changes.
HIPAA breach notifications required, generally within 60 days of discovery (see 45 CFR §§164.400–414).
Document updates when policies materially change; include new effective date.
Retain certification records at least six years (45 CFR §164.530(j)).
Collect BAAs, policy, and identifiers before drafting the certification.
Authorized signer signs and dates the certification with traceable evidence.
Recipient confirms signer authority and BAA status.
Store signed file with audit trail for required retention period.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
A clinic required vendor attestations before data integration
A software vendor needed partner compliance proof