Risk Assessment
Executive summary of identified risks, likelihood, and mitigations tied to this system or process to support prioritization and tracking.
A consistent form centralizes security decisions, creates an auditable record, and helps demonstrate compliance with HIPAA and internal policies.
Typical users create, review, or sign the form at different stages of a project or process.
The form serves internal teams, external partners, and auditors as an authoritative record of security decisions and approvals.
A senior compliance officer who reviews risk findings, confirms policy alignment, and signs to attest that the form reflects organizational safeguards. This signer typically owns regulatory correspondence and certifies retention custodians for the record.
The technical lead who fills sections on access control, encryption, and logging. This person documents implemented controls, describes monitoring configurations, and signs to certify technical accuracy for auditors.
Choose a platform that supports secure e-signing, audit trails, and HIPAA-compliant workflows when PHI is involved.
Confirm the vendor can execute a Business Associate Agreement (BAA) for HIPAA, supports encryption in transit and at rest, and provides exportable audit logs for regulatory review.
Defines systems, locations, and PHI types covered by this record, plus the business justification and approved exceptions for access or retention.
Lists administrative, physical, and technical safeguards, including encryption, access control, logging, and patching schedules with implementation status.
Describes detection, escalation, notification timelines, and post-incident remediation steps tied to compliance requirements and forensic preservation.
Fields for required roles to attest accuracy, capture signature timestamps, and record the identity method used for each signer.
Executive summary of identified risks, likelihood, and mitigations tied to this system or process to support prioritization and tracking.
Detailed mapping of user roles to permissions, change history, and review cadence for least-privilege compliance.
Specify encryption in transit and at rest, key custody, and algorithms used to protect PHI and backups.
Retention windows, log types collected, and alerting thresholds to support breach detection and forensic needs.
Indicate whether a Business Associate Agreement exists, attach effective date, and list covered activities involving PHI.
Record whether relevant staff completed security and HIPAA training, including dates and training version identifiers.
Form drafted and supporting evidence attached for initial review.
IT validates controls and confirms evidence suffices for each control item.
Compliance signs off or requests remediation before final signature.
Final signed record exported and stored in the retention repository with metadata.
HIPAA requires prompt notification; affected individuals and HHS are typically notified without unreasonable delay and generally within 60 days.
If the form relates to employment verification, retain I-9s for three years after hire or one year after termination, whichever is later.
Maintain security documentation and policies for six years from creation or last effective date per HIPAA retention guidance.
Schedule annual reviews for high-risk systems and biennial reviews for lower-risk systems to ensure accuracy.
Ensure logs and exported evidence remain accessible for the first two years for quick audit response.
| Criteria | Electronic signature | Digital signature |
|---|---|---|
| Definition | any electronic mark | pki-based cryptographic signature |
| Legal basis | esign / ueta | esign / ueta (technology-specific) |
| Non-repudiation | audit trail evidence | strong cryptographic proof |
| Common use | general consent and approvals | high-assurance regulatory records |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
John Butler described using electronic workflows for compliance documentation to reduce turnaround times.
Tim Martin uses online forms to record site-level security measures for leased facilities.