Scope and inventory
Comprehensive list of covered systems, data stores, third‑party services, and physical locations to ensure no PHI repository is omitted from analysis.
A formal assessment documents vulnerabilities, supports HIPAA compliance, and reduces exposure to breaches and regulatory enforcement. It helps prioritize remediation, allocate resources, and demonstrate due diligence to auditors, payers, and legal counsel.
Final reviewers usually include senior leadership and legal counsel for approval and to align remediation with business priorities and contractual obligations.
Comprehensive list of covered systems, data stores, third‑party services, and physical locations to ensure no PHI repository is omitted from analysis.
Systematic identification of internal and external threats, paired with vulnerability evidence and exploitability assessment to quantify exposure accurately.
A documented, repeatable scoring rubric that combines likelihood and impact to produce ranked risks for consistent prioritization across assessment cycles.
Actionable tasks with owners, target dates, resources, and success criteria to track progress and demonstrate remediation to auditors.
Concise summary of top risks, residual risk posture, and budgetary or resource requests for leadership decision making and board reporting.
Evidence of control testing, patching status, and user training metrics to substantiate risk reduction claims after remediation.
| Field | Configuration |
|---|---|
| Authentication | Email link with optional SMS or MFA |
| Approval order | Sequential signer order or parallel reviewers |
| Retention policy | Automated archival and legal hold options |
| Notifications | Custom reminders and escalations |
Ensure the vendor can provide a Business Associate Agreement for HIPAA and demonstrates encryption, logging, and retention controls required by auditors.
Conduct promptly when systems go live or when HIPAA coverage begins
Perform at least once per year to track changes and progress
Reassess after major system, vendor, or clinical workflow changes
Set target dates and periodic status updates for owners
Maintain signed records and evidence for the audit lifecycle
Define objectives, in-scope systems, and team roles before data collection.
Gather inventories, logs, vendor contracts, and process maps for analysis.
Score and prioritize findings with rationale and evidence.
Assign owners, set deadlines, and report progress to leadership.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |