Permitted Uses
Specify exactly which purposes the recipient may use PHI for, any prohibited secondary uses, limitations on data aggregation, and whether deidentified data is permitted for secondary processing.
Using a Healthcare HIPAA Exhibit ensures contractual clarity on PHI handling, assigns compliance responsibilities, and documents required safeguards and breach procedures. It reduces regulatory exposure under HIPAA, simplifies audits, and supports enforceable obligations for business associates and downstream vendors.
Healthcare providers, health plans, clearinghouses, and their vendors use the Healthcare HIPAA Exhibit before exchanging protected health information.
Legal, privacy, and procurement teams commonly review and approve the exhibit to ensure contractual alignment with HIPAA and organizational risk thresholds.
Specify exactly which purposes the recipient may use PHI for, any prohibited secondary uses, limitations on data aggregation, and whether deidentified data is permitted for secondary processing.
Describe administrative, physical, and technical safeguards required, referencing applicable standards such as encryption at rest and in transit, access controls, and logging practices regularly tested and documented.
Define notification timelines, required contents of breach notices, investigation responsibilities, remediation steps, and obligations to notify affected individuals and regulators including forensic analysis and reporting.
Grant rights to audit, inspect, and request documentation; specify frequency, notice required, accepted audit mechanisms, and remediation for noncompliance discovered during reviews including remote and onsite options.
State procedures for return, destruction, or secure disposal of PHI at termination, acceptable proof of destruction, and timelines for secure data deletion including backups and residual copies.
Require written flow-down obligations to subcontractors and vendors, ensure BAAs where required, and mandate equivalent safeguards and oversight for downstream processors with right-to-audit provisions and breach reporting.
| Workflow Field and Configuration Options | Configuration settings for each field |
|---|---|
| Signer Authentication Method and Strength | Email link, SMS OTP, KBA, or ID analysis |
| Required Attachments and Supporting Documents | Attach executed BAA and identity proof |
| Conditional Logic and Visibility Rules | Show PHI fields only when applicable |
| Audit Trail Capture and Retention Settings | Store timestamps, IP, action log, and copies |
Choose an eSignature platform that supports HIPAA, BAAs, strong encryption, and configurable authentication for signers handling PHI.
No fixed federal deadline; execute before commencing services
HIPAA requires notification 'promptly' and no later than 60 days in certain contexts
BAA should be in place before PHI exchange begins
Retention period starts at creation or last effective date
Specify how often audits occur and notice period required
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card required | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |