Attestation Statement
A concise declaration that the signer completed specified HIPAA training and understood relevant obligations; written text should mirror organizational policy language where possible.
An explicit attestation documents that workforce members received required HIPAA training and helps meet the training obligation under 45 CFR §164.530(b). It creates a verifiable record for audits, incident response, and internal compliance reviews.
Organizations and individuals across health operations rely on attestations to document mandatory HIPAA training and to maintain compliance records.
Attestations are useful for any role that creates, accesses, or supports protected health information, and for third parties performing services under a Business Associate Agreement.
A concise declaration that the signer completed specified HIPAA training and understood relevant obligations; written text should mirror organizational policy language where possible.
Full legal name and employee or contractor ID; avoid nicknames and include the job title to link the attestation to access privileges.
Course title, curriculum outline or topics covered, provider name, and whether the training was classroom, online, or blended delivery.
Exact completion date and total instruction time in hours or minutes to show sufficiency of training time for policy requirements.
Method used to verify completion (certificate ID, LMS record, supervisor confirmation) and any audit-trail metadata such as timestamps.
Hand-signed or electronically signed block with printed name and date; for electronic signatures include authentication details and an audit certificate.
| Field | Configuration |
|---|---|
| Authentication | Email link or SMS code; use MFA for sensitive roles |
| Audit Trail | Enable timestamps, IP logging, and signer metadata |
| Record Linking | Attach LMS certificate ID or HR employee number |
| Retention Setting | Auto-archive signed records for required retention period |
Use a secure eSignature platform that supports audit trails, MFA, and HIPAA BAA execution when handling PHI.
Ensure the chosen platform can export signed PDFs with embedded audit certificates, meet your retention policy, and sign a BAA if ePHI is processed or stored.
Required under 45 CFR §164.530(b); commonly completed at hire
Frequency set by policy; often annually or upon material policy change
Triggered by incidents to address specific failures
Deliver when HIPAA or local privacy policies are revised
Maintain attestations per retention guidance and audits
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Trial available | Trial available | Trial available | Trial available |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |