Establishing secure connection…Loading editor…Preparing document…

Healthcare Services Addendum

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE SERVICES ADDENDUM

Parties and Recitals

This Healthcare Services Addendum (the Addendum) is entered into between Provider Name: and Patient Name: . This Addendum supplements and modifies the existing healthcare services agreement between the parties dated: and is effective as of Effective Date: .

Patient Information

Insurance Information

Medical History (Summary)

Addendum Scope of Services

Description of Additional Services to be added to the existing agreement:

Service Location(s):

Fees, Billing and Payment

Additional fees associated with the services described above: Amount: $. Payment responsibility: .

Provider authorized to bill insurance on Patient's behalf: Yes

Authorizations and Privacy

The Patient authorizes Provider to access and use relevant medical information for treatment and billing in connection with the additional services. The Patient acknowledges receipt of Provider's privacy practices and consents to allowable disclosures under applicable privacy law for treatment, payment, and healthcare operations.

Patient authorizes release of medical records necessary to effectuate billing and coordination of care: Yes

Expiration of Authorization (if different from effective term above):

Risks, Liability and Acknowledgments

The Patient acknowledges that the additional services may involve inherent risks. The Provider has explained the nature and purpose of the services, reasonably foreseeable material risks, and alternatives. Patient acknowledges understanding and consents to proceed.

Patient acknowledges and agrees to hold Provider harmless for ordinary risks of treatment, except for willful misconduct or gross negligence.

Term, Termination and Amendment

This Addendum shall commence on the Effective Date specified above and shall continue for the period described in the additional services description or until terminated in accordance with the underlying agreement. Either party may terminate this Addendum for material breach upon written notice as provided in the underlying agreement. Amendments to this Addendum must be in writing and signed by both parties.

Compliance with Law

Provider and Patient shall comply with all applicable federal and state laws, including laws governing privacy of medical information and billing practices. Any provision prohibited by law shall be deemed severed and the remaining provisions shall remain in full force and effect.

Acknowledgment and Certification

By signing below, the Patient certifies that the information provided in this Addendum is true and accurate to the best of the Patient's knowledge, that the Patient understands the scope and terms of the additional services, and that the Patient authorizes the Provider to deliver and bill for the services as described above.

Patient Printed Name:

Relationship to Patient (if signer is legal guardian):

Signature:

Date:

Provider Representative:

Enter text✕

What the Healthcare Services Addendum Is

A Healthcare Services Addendum is a contractual attachment that defines responsibilities, privacy safeguards, and data handling rules between a service provider and a covered entity or business associate. It clarifies HIPAA-related obligations, permitted uses and disclosures of protected health information (PHI), breach notification procedures, and supplementary security controls that supplement the underlying services agreement.

Why a Healthcare Services Addendum Matters

Use an addendum to document HIPAA-compliant handling of PHI, allocate liability, and establish operational controls such as access limits, audit logging, and breach response timelines to reduce regulatory and contractual exposure.

Why a Healthcare Services Addendum Matters

Who Typically Completes This Addendum

Organizations and vendors involved with PHI use this addendum to set expectations and meet regulatory obligations.

  • Covered entities (hospitals, clinics, health plans) formalizing vendor relationships and data flows
  • Business associates (cloud providers, billing firms, telehealth vendors) accepting responsibilities for PHI handling
  • Legal, compliance, or procurement teams negotiating contract clauses and liability limits

The document helps align technical, administrative, and contractual controls so both parties document duties and response procedures clearly.

Who Signs and Who Manages the Addendum

Authorized Signatory

A senior officer or delegated representative with authority to bind the organization (CFO, General Counsel, or VP of Operations). Their signature confirms agreement to contractual obligations and potential indemnities.

Contract Owner

Compliance or IT security lead manages implementation details, coordinates technical controls, and serves as point of contact for audits and breach notifications.

Core Elements to Include in a Healthcare Services Addendum

A compliant addendum spells out scope, PHI protections, incident procedures, and audit rights. Below are six essential components to include and tailor to the relationship.

Definitions

Clear definitions for PHI, covered entity, business associate, subcontractor, and permitted uses to avoid ambiguity in scope and obligations.

Permitted Uses

Explicitly state how PHI may be accessed, used, or disclosed, including allowed de-identification processes and any prohibited activities.

Security Safeguards

Technical and administrative controls required (access controls, encryption, logging, vulnerability management) and any minimum security standards.

Breach Notification

Timeframes and responsibilities for notifying the covered entity of suspected or confirmed breaches, including required content of notices.

Subcontractors

Rules for engaging subcontractors or downstream processors, including flow-down obligations and verification requirements.

Termination & Return

Post-termination handling of PHI: return, secure destruction, and certification procedures, plus remedies for noncompliance.

Step-by-Step: Completing the Addendum

Follow these sequential steps to review, complete, and finalize the Healthcare Services Addendum with minimal risk and clear accountability.

  • 01
    Review Contract: Confirm underlying services agreement terms to avoid conflicts.
  • 02
    Fill Core Fields: Enter legal names, effective date, and scope accurately.
  • 03
    Specify Controls: Detail security, logging, and breach response obligations.
  • 04
    Execute Signatures: Obtain authorized signatures and date the document.

How to Configure an Online Workflow for This Addendum

Set up an electronic workflow to collect signatures and maintain an audit trail; include authentication and document retention settings in the configuration.

Field Configuration
Signer Order Sequential routing: covered entity → business associate → compliance officer
Authentication Email + SMS code or higher for access to PHI
Audit Trail Capture IP, timestamps, and signer actions
Retention Retain signed copy for minimum regulatory period specified

Where to Send or File the Completed Addendum

After execution, route copies to legal, compliance, and IT security while storing a signed master in the contract repository with controlled access.

  • Legal Department: Keeps master agreement and monitors compliance obligations.
  • Compliance Team: Tracks regulatory deadlines and audit readiness.
  • IT Security: Implements and documents technical controls.
  • Contract Repository: Store signed PDF with tamper-evident audit trail.

Digital Signing and Delivery: Technical Requirements

Use a platform that supports secure eSignature, audit logs, and HIPAA-compliant workflows when PHI is involved.

  • Authentication: Multi-factor options (SMS, email code, KBA, SSO) for strong signer attribution
  • Document Formats: PDF and DOCX support with embedded audit trail
  • Integrations: Connectors to EHR, contract repository, and identity providers

Ensure the selected platform provides encryption in transit and at rest, audit logging, and the ability to export a tamper-evident signed record for compliance reviews.

Essential Data Elements to Include

Party Names: Legal entity identifiers
Effective Date: Start date of obligations
PHI Scope: Types of health data covered
Security Controls: Required safeguards
Breach Terms: Notification and remediation rules
Subcontractor Rules: Flow-down and verification

Key Risks and Potential Penalties

HIPAA Fines: Civil monetary penalties and corrective action plans
Contract Damages: Indemnities and liability exposure
Breach Costs: Notification, credit monitoring, and remediation expenses
Regulatory Enforcement: Civil investigations and mandatory audits
Reputation Harm: Loss of trust and referrals
Operational Disruption: Service interruptions and remediation workload

Common Mistakes to Avoid

  • Leaving PHI handling vague or undefined, which creates compliance gaps
  • Failing to require flow-down obligations for subcontractors that access PHI
  • Using weak signer authentication for documents authorizing PHI access
  • Neglecting to align retention and destruction clauses with HIPAA timelines

Practical Tips for Accurate and Efficient Completion

Adopt consistent templates, require minimal but sufficient data fields, and use electronic workflows that capture a robust audit trail to reduce errors and speed execution.

Use a Standard Template
Maintain a vetted addendum template to ensure consistent protections and reduce negotiation time.
Limit PHI Access
Specify least-privilege access and logging to help detect misuse.
Set Clear SLAs
Define response times for incidents and availability expectations to reduce disputes.
Document Evidence
Keep technical evidence of controls (logs, configuration snapshots) linked to the agreement.

Timelines and Processing Expectations

Identify the timing expectations for notification, review, and record retention so both parties know their responsibilities in routine and incident scenarios.

Breach Notification Deadline:

Typically within 72 hours of discovery; confirm contract timeframe

Security Review Cadence:

Annual or more frequent assessments to verify controls

Document Retention Start:

Retention period begins on creation or execution date

Subprocessor Notice:

Require advance notice before onboarding subcontractors

Audit Response Time:

Specify a reasonable window (for example, 30 days) to produce requested audit materials

Practical Examples of Use

Two representative scenarios show how organizations apply the addendum in practice.

Hospital and Cloud Backup Vendor

A hospital required encryption and access logs from a backup vendor

  • The vendor agreed to AES-256 at rest and TLS 1.2+
  • Implementation included quarterly access reviews and an incident response playbook to speed containment and notification.

Telehealth Provider and Payment Processor

A telehealth vendor subcontracted billing and needed flow-down protections

  • The addendum required subprocessors to sign identical PHI obligations
  • Resulting controls included restricted access roles and monthly reconciliation audits to verify compliance.

eSignature Vendor Comparison for Healthcare Addenda

A concise pricing and capability snapshot to help compare options for signing and storing Healthcare Services Addenda. signNow appears first in the comparison per platform ordering rules.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year limit Varies by plan Varies by plan Varies by plan

Frequently Asked Questions and Troubleshooting

Common questions and practical answers when preparing or executing a Healthcare Services Addendum.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users