Identifying Parties
Full legal names of certifying entity and contracting covered entity, including DBA names and corporate identifiers where applicable.
Sub-certifications create a documented chain of responsibility for regulated activities, reduce ambiguity about vendor obligations, and support audit readiness. They make it easier to verify compliance during procurement, contracting, and regulatory reviews while clarifying who is accountable for protected health information handling.
Organizations use sub-certifications to manage vendor risk and demonstrate compliance across clinical, IT, and administrative relationships.
The document is intended for both internal risk teams and external parties; it helps speed onboarding while preserving audit evidence.
Full legal names of certifying entity and contracting covered entity, including DBA names and corporate identifiers where applicable.
A short, specific description of the services, systems, or datasets the subcontractor will access or manage under the primary agreement.
List of regulatory or contractual standards (for example HIPAA, state privacy laws, or payer requirements) that the subcontractor certifies it meets.
Start and end dates for the certification and a statement about ongoing obligations after termination if applicable.
References to supporting documents such as audit reports, security policies, training logs, or certificates of insurance attached or available on request.
Printed name, job title, signature, and date from an individual with authority to bind the subcontractor contractually.
| Field | Configuration |
|---|---|
| Signer Order | Define sequence for vendor then covered entity |
| Authentication | Use email + access code or higher assurance as needed |
| Attachments | Include evidence files or links to audit reports |
| Retention | Set retention policy to meet HIPAA and contract terms |
Ensure the platform supports audit trails, export into PDF/A if needed, and integrations such as Salesforce or Google Workspace for streamlined recordkeeping.
Often required before system access or contract performance begins
Common practice to renew attestations yearly to reflect control changes
Trigger re-certification after major security incidents or scope changes
Align certification expiration with contract renewal or amendment
Preserve executed documents for the full retention term after audits
Create certificate and attach supporting evidence
Legal and privacy validate language and claims
Authorized representative signs and dates
Store executed copy and update contract index
A clinical director or equivalent with delegated authority may sign clinical-scope attestations when explicitly authorized by corporate resolution or internal policy; include job title and contact details for verification.
A named compliance officer or corporate officer typically signs corporate-level certifications; the signer should be able to bind the organization contractually and respond to audit inquiries.
Moved consent and administrative forms online to centralize records and speed onboarding
Implemented sub-certifications for outsourced billing partners to confirm PHI handling controls
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |