Parties and Scope
Identify vendor and reseller legal names, authorized territories, permitted channels, and product or service categories covered by resale rights.
A clear reseller agreement reduces legal and operational risk by defining roles, PHI handling obligations (including Business Associate Agreement requirements), pricing mechanics, and audit access. It preserves patient privacy compliance, clarifies who answers customers’ technical and regulatory questions, and protects revenue and intellectual property interests across the channel.
Organizations and roles that commonly prepare, review, or sign these agreements include both vendor and reseller legal, sales, and compliance teams.
Each party should involve legal and compliance early to confirm HIPAA, state privacy, and contractual clauses match operational practices.
Identify vendor and reseller legal names, authorized territories, permitted channels, and product or service categories covered by resale rights.
Define list prices, reseller discounts, invoicing cycles, payment terms, chargebacks, and procedures for price changes or rebates.
Include HIPAA-specific obligations, a Business Associate Agreement (BAA) if PHI is exchanged, security controls, and breach notification duties.
Specify who provides technical support, warranty responsibilities, service levels, escalation paths, and customer-facing obligations.
Set audit rights, reporting cadence, sales reporting format, and consequences for inaccurate reporting or noncompliance.
Define termination for convenience and cause, post-termination sell-off, data return or destruction, and transition assistance obligations.
| Field | Configuration |
|---|---|
| Signing Order | Sequential routing: vendor → reseller → countersign if needed |
| Authentication | Email plus SMS code or higher for sensitive PHI access |
| Audit Trail | Capture IP, timestamp, and user agent for each action |
| Attachments | Include BAA and pricing exhibits as required documents |
Use an eSignature platform that supports necessary authentication, secure storage, and industry integrations for downstream workflows.
Confirm the chosen platform can provide audit trails, optional BAAs for HIPAA compliance, access controls, and export options for long-term archival and regulatory inspection.
Date when obligations begin; impacts retention and performance
Typically 30–90 days before automatic renewal, as specified
Net 30 or Net 60 per agreement section
Vendor may require advance notice, often 10–30 days
HIPAA breach obligations apply; follow regulatory notice timelines
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
A clinical services provider needed reliable integration and API support for reseller workflows
A services reseller sought enterprise-grade compliance and SOC 2 assurances