Purpose of PHI
Explain why PHI is collected and typical uses, including treatment, payment, and health care operations, so patients understand routine disclosures and data handling practices.
A clear HIPAA Notice documents legal obligations, informs patients about PHI handling, and supports risk management by setting expectations on disclosures and complaints.
Explain why PHI is collected and typical uses, including treatment, payment, and health care operations, so patients understand routine disclosures and data handling practices.
List categories of permitted disclosures such as public health reporting, law enforcement, and disclosures to business associates; clarify any disclosures that require separate authorization.
State rights to inspect, obtain copies, request amendments, restrict disclosures, and receive an accounting of disclosures, including how to submit such requests and expected timelines.
Affirm the entity’s legal duty to maintain privacy and security, to provide a copy of the notice, and to notify patients following a breach of unsecured PHI as required by law.
Describe internal complaint channels and the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if privacy rights are believed to be violated.
Provide a contact name, phone, and email for privacy questions and indicate whether business associate agreements are used when third parties handle PHI.
| Field | Configuration |
|---|---|
| Signature Requirement | Require signed acknowledgment and date field. |
| Authentication Level | Use email plus SMS code for patient identity verification. |
| BAA Attachment | Attach executed business associate agreement where third parties sign. |
| Retention Policy | Auto-archive signed copies to secure storage for retention period. |
Digital distribution should preserve content, audit trails, and access controls while enabling patient receipt and signature.
Ensure the chosen platform supports encryption in transit and at rest, audit logging, and BAA execution where required to maintain HIPAA compliance.
A licensed clinician or designated privacy officer may sign to attest the notice is in effect and accurately reflects the entity’s practices; signatures should be recorded with title and date for audit purposes.
The patient or an authorized personal representative (per legal designation) signs to acknowledge receipt; documentation must show the representative’s authority and relationship to the patient.
Several organizational roles and third parties are involved in creating, reviewing, and distributing HIPAA Notices.
Each party has distinct responsibilities: legal review, operational deployment, and recordkeeping to demonstrate distribution and patient acknowledgment.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial, no credit card | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |