Definitions
Clear definitions for PHI, covered entity, business associate, subcontractor, and permitted uses to avoid ambiguity in scope and obligations.
Use an addendum to document HIPAA-compliant handling of PHI, allocate liability, and establish operational controls such as access limits, audit logging, and breach response timelines to reduce regulatory and contractual exposure.
Organizations and vendors involved with PHI use this addendum to set expectations and meet regulatory obligations.
The document helps align technical, administrative, and contractual controls so both parties document duties and response procedures clearly.
A senior officer or delegated representative with authority to bind the organization (CFO, General Counsel, or VP of Operations). Their signature confirms agreement to contractual obligations and potential indemnities.
Compliance or IT security lead manages implementation details, coordinates technical controls, and serves as point of contact for audits and breach notifications.
Clear definitions for PHI, covered entity, business associate, subcontractor, and permitted uses to avoid ambiguity in scope and obligations.
Explicitly state how PHI may be accessed, used, or disclosed, including allowed de-identification processes and any prohibited activities.
Technical and administrative controls required (access controls, encryption, logging, vulnerability management) and any minimum security standards.
Timeframes and responsibilities for notifying the covered entity of suspected or confirmed breaches, including required content of notices.
Rules for engaging subcontractors or downstream processors, including flow-down obligations and verification requirements.
Post-termination handling of PHI: return, secure destruction, and certification procedures, plus remedies for noncompliance.
| Field | Configuration |
|---|---|
| Signer Order | Sequential routing: covered entity → business associate → compliance officer |
| Authentication | Email + SMS code or higher for access to PHI |
| Audit Trail | Capture IP, timestamps, and signer actions |
| Retention | Retain signed copy for minimum regulatory period specified |
Use a platform that supports secure eSignature, audit logs, and HIPAA-compliant workflows when PHI is involved.
Ensure the selected platform provides encryption in transit and at rest, audit logging, and the ability to export a tamper-evident signed record for compliance reviews.
Typically within 72 hours of discovery; confirm contract timeframe
Annual or more frequent assessments to verify controls
Retention period begins on creation or execution date
Require advance notice before onboarding subcontractors
Specify a reasonable window (for example, 30 days) to produce requested audit materials
A hospital required encryption and access logs from a backup vendor
A telehealth vendor subcontracted billing and needed flow-down protections
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year limit | Varies by plan | Varies by plan | Varies by plan |