Scope of Work
Precise description of services and deliverables, including which activities will involve PHI and any excluded duties to prevent scope creep and liability disputes.
A combined Healthcare MSA BAA Form reduces contract fragmentation, ensures HIPAA obligations are tied to commercial responsibilities, and clarifies incident response and liability allocation for PHI handling.
Healthcare providers, health IT vendors, managed services firms, and legal or procurement teams commonly use this combined agreement to govern commercial and PHI-handling relationships.
Precise description of services and deliverables, including which activities will involve PHI and any excluded duties to prevent scope creep and liability disputes.
Permitted purposes and restrictions for PHI use, including downstream subcontractor rules, minimum necessary principles, and permitted disclosures under HIPAA.
Specific technical and administrative safeguards required (encryption, access controls, logging) and obligations to maintain those safeguards throughout the term.
Timelines and responsibilities for breach notifications, investigation cooperation, mitigation steps, and public communications tied to regulatory obligations.
Right to audit or request security evidence, reporting cadence for compliance attestations, and consequences for failing audits or remediation.
Procedures for return or destruction of PHI upon termination, transition assistance, and survival of confidentiality obligations.
| Field | Configuration |
|---|---|
| Authentication | Email + SMS code or stronger |
| Signature type | Audit-backed electronic signature |
| Routing order | Sequential signers with conditional steps |
| Retention policy | Secure storage, exportable audit trail |
Use an eSignature platform that supports secure authentication, audit trails, and a HIPAA Business Associate Agreement when handling PHI.
Date parties sign the agreement, use MM/DD/YYYY format.
When obligations commence; may differ from execution.
Contractual deadline for notifying covered entities.
Retention begins at record creation or last effective date.
Period required to terminate services or withdraw access.
Draft MSA terms and enumerate PHI categories to be exchanged.
Complete security questionnaires and evidence review before final signature.
Obtain authorized signatures and record the executed document.
Enable production access only after compliance checkpoints are satisfied.
| Criteria | MSA + BAA | Separate MSA & BAA |
|---|---|---|
| Single Document | ||
| Signature Count | one execution | multiple coordinated signatures |
| Negotiation Complexity | higher | lower per document |
| Operational Clarity | single reference | requires cross-referencing |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |