Permitted Uses
Specifies exactly which PHI uses and disclosures the business associate may perform and prohibits uses outside those purposes.
A precise HIPAA Compliance Agreement allocates responsibility for PHI safeguards, reduces legal exposure, and documents breach response responsibilities. It also establishes operational expectations and supports regulatory compliance for both covered entities and business associates.
Covered entities and business associates, including hospitals, clinics, billing companies, IT vendors, and cloud providers, use HIPAA Compliance Agreements to set PHI handling rules.
The agreement framework scales for vendors of all sizes; organizations should match obligations to the sensitivity of the PHI and the services performed.
Chief privacy or compliance officers typically review and approve HIPAA Compliance Agreements, ensuring contractual language meets regulatory requirements, documents administrative controls, and aligns with internal policies and incident response plans.
An authorized vendor representative or general counsel signs on behalf of the business associate and confirms operational controls, employee training commitments, and the vendor's ability to meet breach notification and mitigation obligations.
Specifies exactly which PHI uses and disclosures the business associate may perform and prohibits uses outside those purposes.
Requires implementation of administrative, physical, and technical safeguards consistent with HIPAA Security Rule standards.
Defines timing and process for notifying the covered entity of unauthorized PHI access or disclosure.
Requires the business associate to flow down equivalent obligations to subcontractors or agents handling PHI.
Describes the agreement term, termination rights for material breaches, and return or destruction of PHI on termination.
Grants rights to inspect, audit, or require evidence of compliance, including documentation and access to policies.
| Field | Configuration |
|---|---|
| Signer Order | Sequential or parallel as required |
| Authentication | Email link, SMS code, or stronger |
| Audit Options | Capture IP, timestamp, and event log |
| Document Retention | Automate archival and secure access |
Ensure the chosen eSignature provider supports HIPAA controls, audit trails, and a BAA before using it for PHI agreements.
Document these platform requirements in procurement records and include them in the agreement to align operational and contractual controls.
Date obligations begin; enter as MM/DD/YYYY
Notify covered entity promptly; internal SLA typically 72 hours
Annual security and policy reviews recommended
Follow contract-specified cure and notice periods
Retention calculated from creation or last effective date
| Document | HIPAA Agreement | Data Processing Agreement |
|---|---|---|
| Primary Purpose | phi protection | general personal data processing |
| Regulatory Basis | hipaa rules | gdpr/state privacy laws |
| Required Clauses | baa, breach notice | dpa, data subject rights |
| Typical Industries | healthcare | tech, marketing, cloud |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |