Definitions
Define PHI, permitted disclosures, workforce, and terms used throughout the agreement so obligations are unambiguous and enforceable.
The agreement helps demonstrate workforce training and administrative safeguards required by HIPAA, documents employee obligations, and creates a contractual basis for enforcement and discipline. It reduces the risk of unauthorized disclosures, supports breach response, and aligns internal policy with federal requirements.
Use the agreement to document acknowledgment at hire and whenever responsibilities or systems that handle PHI change.
Responsible for distributing the agreement during onboarding, maintaining signed copies, and ensuring re‑acknowledgment after privacy policy changes. HR documents training completion and coordinates corrective action when violations occur.
Reads and signs to acknowledge understanding of HIPAA policies, required safeguards, and reporting duties. Signing indicates intent to comply and creates evidence of affirmative acknowledgment for audits and investigations.
Define PHI, permitted disclosures, workforce, and terms used throughout the agreement so obligations are unambiguous and enforceable.
Spell out permitted internal uses, minimum necessary standards, and prohibited external disclosures absent patient authorization.
Describe physical, technical, and administrative safeguards required of the employee, including device and password handling.
Require prompt reporting of suspected breaches or inappropriate access and describe the internal escalation process and timelines.
State consequences for violations, from retraining to termination and potential legal action, consistent with company policy.
A signature block confirming the signer has read the policy, understands obligations, and agrees to comply with HIPAA requirements.
| Field | Configuration |
|---|---|
| Signer Authentication | Email link plus optional SMS or SSO for higher assurance |
| Required Fields | Name, employee ID, title, effective date, signature block |
| Retention Tag | Apply HIPAA retention metadata (6 years) to stored records |
| Audit Trail | Enable full action logging (IP, timestamp, actions) |
Retain signed copies in a secure repository with access controls and searchable metadata to support audits and incident response.
Complete at hire before access to PHI is granted.
Require re‑acknowledgment when privacy or security policies materially change.
Require a new acknowledgment when responsibilities or system access changes.
Consider annual or biennial re‑acknowledgment per internal policy.
Secure and log immediate re‑acknowledgment if a breach involves workforce conduct.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Depends on plan | Depends on plan | Depends on plan |