Definitions
Clear definitions for PHI, personal data, covered entity, business associate, and permitted processing to remove ambiguity and limit scope.
The Healthcare Information Security Agreement clarifies who controls PHI, specifies minimum technical and organizational safeguards, and defines breach response. Clear allocation of duties reduces compliance risk, supports regulatory audits, and documents each party’s obligations under HIPAA and related state laws.
Organizations and individuals involved with PHI use this agreement to define responsibilities and risk controls before data exchange.
Use parties’ roles to determine signature authority, required attestations, and any specialized security annexes for high-risk data flows.
The Privacy or HIPAA Security Officer signs on behalf of a covered entity to confirm organizational compliance programs, interpret security controls, request audit logs, and coordinate breach notifications with regulators and affected individuals.
The vendor or business associate’s security lead signs to certify implemented safeguards, provide technical contact points, agree to BAA terms where required, and accept responsibilities for incident response and remediation.
| Field | Configuration |
|---|---|
| Authentication Level | Email link, SMS code, or KBA as needed |
| Access Expiry | Set link expiration to limit exposure |
| Audit Trail | Record IP, timestamp, and actions |
| Template Library | Store reusable, versioned agreement templates |
Choose a platform that supports secure transmission, strong encryption, and retained audit logs for regulatory review.
Confirm the platform provides exportable signed copies, tamper-evident seals, and the ability to produce audit trails during an OCR or state regulator review.
Clear definitions for PHI, personal data, covered entity, business associate, and permitted processing to remove ambiguity and limit scope.
Specify encryption standards, access controls, multi-factor authentication, logging retention periods, and patching schedules with measurable targets.
Define notification timelines, required content, escalation contacts, and cooperation obligations for investigations and regulator reporting.
Grant covered entities the right to conduct or receive audit results and remediation plans within a defined timeframe.
Require vendor flow-down obligations, written agreements with subcontractors, and notification of changes in subcontracting.
Allocate responsibility for breaches, remediation costs, regulatory fines, and limits on damages where appropriate.
Notify HHS and affected individuals without unreasonable delay, no later than 60 days (45 CFR §§164.404–410).
Retain policies and agreements for 6 years from creation or last effective date (45 CFR §164.530(j)).
Make the agreement available to auditors or business partners upon request; no set federal filing deadline.
Maintain related employment verification records per 8 CFR §274a.2 timing rules.
Keep supporting financial records at least 3 years (IRC §6501(a)) where applicable.
Legal and security teams finalize clause language and controls.
Executive and procurement approvals confirm obligations and liability limits.
Authorized signers complete signatures and date the agreement.
Store signed agreement with audit trail and version history.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (Premium) | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |