Establishing secure connection…Loading editor…Preparing document…

Healthcare LDMTS Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE LDMTS AGREEMENT

This Healthcare LDMTS Agreement ("Agreement") establishes the terms under which Long-Distance Medical Telehealth Services ("LDMTS") will be provided by the healthcare provider identified below to the patient identified below. By completing and signing this Agreement, Patient consents to telehealth evaluation, treatment, and related administrative activities as described herein, and acknowledges the limits, risks, and conditions of such services.

Parties and Effective Date

Effective Date:

Scope of LDMTS

Provider shall deliver telehealth services including live interactive audio and video consultation, remote monitoring, and store-and-forward transmission of medical data where appropriate. Telehealth services may include initial evaluation, follow-up care, medication management, and coordination with other healthcare professionals. Telehealth services do not replace emergency care; for urgent or emergency situations, Patient must seek immediate in-person emergency services.

Patient Information

Insurance Information

Medical History and Current Health Status

Consent to Telehealth Services

Patient authorizes Provider to provide LDMTS as described in this Agreement. Patient acknowledges that telehealth involves the use of electronic communications to enable Provider to deliver care at a distance. Patient understands that telehealth may include transmission of medical information, images, and other data necessary for diagnosis, treatment, follow-up and care coordination.

Risks and limitations include, but are not limited to: technical failures beyond Provider control; limited ability to perform physical examinations; reduced fidelity of transmitted images or data; and delays or interruptions. There is no guarantee that telehealth care will be equivalent to in-person care for all conditions. Patient accepts these limitations and agrees to follow Provider instructions regarding when in-person evaluation is required.

Patient has the right to withdraw consent at any time by providing written notice to Provider. Withdrawal of consent will not affect the lawfulness of care provided prior to receipt of revocation.

Privacy, Security and HIPAA Authorization

Provider will use reasonable administrative, technical, and physical safeguards to protect the privacy and security of protected health information exchanged in connection with telehealth. However, Patient acknowledges that no method of electronic communication is completely secure and that breaches may occur. Patient further authorizes Provider to disclose medical information to other treating providers, payers, or health information exchanges as necessary for treatment, payment, and healthcare operations.

Authorization Expiration Date:

Fees, Billing and Insurance

Patient is responsible for fees for telehealth services not covered by insurance. Provider will bill Patient or Patient's insurer as indicated below. Patient must verify benefits with their insurer and is responsible for co-payments, co-insurance, deductibles, and any services denied by insurance.

Technical Requirements and Patient Responsibilities

Patient is responsible for ensuring they have a compatible device, reliable internet connection, and a private environment suitable for clinical discussion. Patient agrees to inform Provider of any change in contact information, medical status, or technology access that may affect delivery of telehealth services.

Emergency Protocols

Telehealth is not appropriate for emergencies. If Patient experiences an emergency or life-threatening condition during or between telehealth visits, Patient must call emergency services or proceed to the nearest emergency facility. Provider will attempt to contact Patient's emergency contact as necessary.

Termination, Revocation, and Amendment

Either party may terminate this Agreement for any reason upon written notice. Patient may revoke any authorizations provided herein in writing; revocation will not affect disclosures or actions already taken in reliance on prior authorization. Provider may amend terms of telehealth services subject to notice to Patient as required by law.

Representations, Warranties and Liability

Patient represents that responses to clinical intake and medical history questions are accurate to the best of Patient's knowledge. Provider will exercise professional clinical judgment in the provision of LDMTS. To the extent permitted by law, Provider's liability for any claims arising from telehealth services is limited to direct damages and shall exclude punitive, consequential, and incidental damages.

Governing Law and Dispute Resolution

This Agreement shall be governed by the laws of the state in which Provider is licensed, except to the extent preempted by applicable federal law. Any dispute arising from this Agreement shall be resolved through negotiation and, if necessary, non-binding mediation prior to initiating litigation, unless emergency injunctive relief is required.

Acknowledgment and Certification

By signing below, Patient certifies that they have read and understand this Agreement, that all information provided is true and correct, that Patient consents to receive LDMTS as described, and that Patient has had the opportunity to ask questions and receive answers regarding the nature, benefits, and risks of telehealth services.

Patient Name:

Signature:

Relationship to Patient:

Date:

Enter text✕

What the Healthcare LDMTS Agreement Is and when it applies

A Healthcare LDMTS Agreement is a data use arrangement used when a covered entity or business associate discloses a limited data set of protected health information for research, public health, or health care operations. The agreement documents permitted uses and disclosures, required safeguards, and prohibits re-identification and further disclosure except as permitted. It complements HIPAA privacy and security obligations by defining recipient responsibilities, data elements allowed in a limited data set, and administrative controls used to protect patient privacy while enabling secondary uses of clinical data.

Why organizations use a Healthcare LDMTS Agreement

A clear LDMTS Agreement enables lawful sharing of de-identified-but-limited datasets while preserving research and public health value and reducing regulatory risk under HIPAA.

Why organizations use a Healthcare LDMTS Agreement

Typical parties and roles involved with an LDMTS Agreement

Lead organizations sign and manage LDMTS Agreements to permit secondary use of limited data sets while meeting HIPAA requirements.

  • Covered entities and health systems responsible for disclosing limited data sets for approved research or operations, and for ensuring a valid agreement is in place.
  • Business associates and analytics vendors receiving data to perform functions on behalf of a covered entity, bound by the agreement and any required BAA terms.
  • Researchers, public health agencies, and institutional review boards that receive limited data sets and must comply with permitted-use restrictions and security obligations.

Clear role definitions in the agreement reduce ambiguity about permitted processing, auditing responsibilities, and breach notification duties.

Core components to include in a professional Healthcare LDMTS Agreement

A compliant agreement balances permitted uses with privacy protections; include concise clauses for each functional area rather than ambiguous or open-ended provisions.

Permitted Uses

Specify allowed activities (research, public health, operations) and prohibit re-identification or further disclosure beyond the defined purposes.

Data Description

List the data elements included in the limited data set and confirm excluded direct identifiers per HIPAA limited data set rules.

Safeguards

Detail administrative, technical, and physical safeguards, including encryption, access controls, and minimum-security baselines for data recipients.

Reporting & Audit

Require periodic reporting, access logs, and audit rights that allow the disclosing party to verify permitted use and compliance.

Breach Response

Define notification timelines, investigative duties, and coordination procedures consistent with HIPAA breach notification expectations.

Liability & Indemnity

Allocate responsibility for misuse or re-identification and include indemnity provisions, insurance minimums, and limits on liability where appropriate.

Essential information fields to collect in the agreement

Disclosing Party: Organization name
Receiving Party: Organization name
Purpose: Permitted use description
Data Elements: Limited data set list
Effective Date: MM/DD/YYYY format
Signatory Authority: Name and title

Step-by-step: completing a Healthcare LDMTS Agreement

Follow a structured sequence to populate, review, sign, and retain the agreement to limit downstream compliance work and evidentiary gaps.

  • 01
    Prepare draft: Populate parties, purpose, and data elements.
  • 02
    Security review: Confirm safeguards and encryption requirements.
  • 03
    Legal review: Validate permitted uses, liability, and BAA alignment.
  • 04
    Execution: Obtain authorized signatures and record retention details.

How to configure an online completion workflow

Set up a reproducible digital workflow that assigns fields, enforces validation, and captures an auditable trail for each signing event.

Field validation rules Require MM/DD/YYYY for dates
Signer order Choose sequential or parallel routing
Authentication method Email link or SMS code
Document retention Enable secure copy storage
Audit capture Record IP and timestamp

Digital signing and technical considerations

Use a platform that supports audit trails, secure storage, and required authentication for sensitive healthcare agreements.

  • Integrations: Salesforce, NetSuite, Microsoft 365 supported
  • File formats: PDF and DOCX accepted
  • Security standards: TLS 1.2/1.3; AES-256 at rest

Ensure the chosen eSignature provider can sign a BAA, capture a complete audit trail, and export tamper-evident signed PDFs for long-term retention.

Where to send and how to route the executed agreement

Define a distribution pattern so copies reach legal, privacy, and the receiving party without manual handoffs and so retention begins immediately.

  • Copy to legal: Store signed copy in legal repository
  • Privacy office: Provide a copy to privacy/compliance team
  • Receiving party: Deliver executed agreement to recipient
  • Retention archive: Archive in secure long-term storage

Typical timelines, deadlines, and processing expectations

Timing expectations reduce project delays; set internal deadlines for review, signature, and secure transfer before any data disclosure occurs.

Internal review timeline:

7–14 business days for legal and security review

Signature turnaround:

Target 3–7 business days by parties

BAA execution:

Align with DUA before data release

Audit readiness:

Ensure logs retained immediately

Retention checkpoint:

Confirm storage within 30 days

Common mistakes that cause delay or compliance issues

  • Using broad-purpose language that permits undefined future uses increases re-identification and regulatory risk under HIPAA.
  • Failing to align the DUA with an executed Business Associate Agreement (BAA) when recipients are business associates creates contractual gaps.
  • Omitting specific technical safeguards such as encryption or logging leaves ambiguous obligations and complicates audits.
  • Relying on handwritten initials or incomplete signatory details that do not demonstrate authority can undermine enforceability.

Penalties and enforcement risks for incorrect or missing agreements

HIPAA enforcement: Civil monetary penalties possible
Breach liability: Recipient may face liability
Regulatory audit: Audit findings and corrective plans
Contract disputes: Damages and injunctive relief
Data misuse: Reputational harm
Operational delay: Project stoppage pending remedies

Real-world examples of LDMTS Agreement use

Sample use cases illustrate typical drafting choices and operational controls required to share limited datasets responsibly.

Fertility Centers of Illinois

The center needed de-identified data for outcomes research and partnered with an analytics vendor

  • The agreement restricted re-identification and required annual audits
  • They retained signed DUAs and a written security plan to meet HIPAA audit expectations and document who could access patient-level records.

Martin Properties

A health research lab requested limited clinical datasets for a population study

  • The lab agreed to logging, restricted access, and data destruction after study completion
  • The executed agreement defined permitted analyses, required quarterly reporting, and preserved audit rights for the disclosing hospital.

Typical eSignature vendor pricing and feature comparison for healthcare agreements

Compare entry-level pricing and core capabilities relevant to executing Healthcare LDMTS Agreements, including HIPAA support and envelope limits.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently asked questions about Healthcare LDMTS Agreements

Common questions and practical answers to help parties avoid execution mistakes and compliance gaps.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users