Parties
Full legal names and roles for each party, including business associate status and contact information for privacy/security officers.
The agreement reduces legal and operational risk by clarifying each party’s responsibilities for PHI, documenting consent and permitted disclosures, and establishing audit, breach-notification, and termination procedures required by HIPAA and HHS guidance.
Typical signatories include covered entities, business associates, subcontractors, contractors, and staff requiring access to PHI.
Assign signing authority and ensure each signer receives a dated copy; maintain an accessible log of executed agreements for compliance reviews.
Full legal names and roles for each party, including business associate status and contact information for privacy/security officers.
A detailed description of the categories of PHI to be accessed, whether limited data sets or full identifiers, and any exclusions.
Specific, narrow statements of purpose (treatment, payment, operations) and explicit prohibitions on secondary uses such as marketing.
Required administrative, physical, and technical controls (encryption, access controls, logging) and responsibility for implementing safeguards.
Effective date, term, and conditions for termination; obligations that survive termination such as return or destruction of PHI.
Notification timelines, investigation duties, mitigation steps, indemnification, and audit rights tied to regulatory obligations.
| Field | Configuration | Value |
|---|---|
| Primary authentication method and settings | Use email + SMS or enterprise SSO for stronger signer attribution. |
| Conditional fields and validations | Add required checks for dates, TIN formats, and conditional disclosures. |
| Signing order and parallel routing | Set sequential or parallel signing based on internal approval needs. |
| Retention and export settings | Enable PDF/A export, audit trail retention, and secure archival. |
Ensure the eSignature platform supports HIPAA-required safeguards and the authentication methods you need before digitizing the agreement.
Confirm the vendor will sign a Business Associate Agreement (BAA) where PHI is present and supports necessary retention and audit log exports.
Obtain signed agreement before granting access to PHI.
Review agreements annually or when services or systems change.
Retain relevant documentation for 6 years (45 CFR §164.530(j)).
Report breaches per policy; HHS notification for large breaches occurs within 60 days.
Specify deadlines for return/destruction of PHI after termination.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
A fertility clinic standardized confidentiality agreements for vendors and staff to centralize PHI protections and simplify audits.
A property management firm used confidentiality agreements when collecting tenant medical accommodation information for housing decisions.