Definitions
Define 'Protected Health Information', 'Business Associate', 'Covered Entity', 'Subcontractor', and other key terms to prevent interpretive gaps during enforcement or audit.
A compliant HIPAA Business Associate Agreement reduces regulatory risk, clarifies liability for PHI handling, and documents required safeguards and breach procedures. It is a foundational control for HIPAA compliance and a contractual prerequisite before sharing PHI with vendors.
Each signer should confirm authority to bind their organization and ensure internal controls align with the BAA's obligations.
Define 'Protected Health Information', 'Business Associate', 'Covered Entity', 'Subcontractor', and other key terms to prevent interpretive gaps during enforcement or audit.
List specific, limited purposes for PHI use and disclosure; avoid sweeping clauses that permit unrelated processing or secondary uses without consent.
Require administrative, physical, and technical controls such as encryption in transit and at rest, role-based access, and regular security testing and monitoring.
Set timelines and responsibilities for breach detection, notification to the covered entity, and cooperation in investigations and notifications to affected individuals and regulators.
Obligate business associate to require equivalent protections from subcontractors and to provide proof of compliance on request by the covered entity.
Specify end-of-contract obligations for PHI return or destruction, and conditions triggering termination for material noncompliance.
| Field | Configuration |
|---|---|
| Authentication Level | Email & optional SMS code |
| Document Template | Locked fields and required signatures |
| Signer Order | Sequential or parallel signing |
| Retention Setting | Store signed copy and audit trail |
Ensure the platform supports a signed audit trail, strong encryption in transit and at rest, and a written BAA when PHI will be handled.
Enter MM/DD/YYYY; obligations begin on this date.
Obtain signed BAA before sharing PHI with the associate.
HIPAA requires prompt notice; larger breaches often reported within 60 days.
Review safeguards and subcontractor lists at least annually.
Retain signed BAAs per applicable retention rules.
Draft terms, scope, and security obligations for review.
Security and counsel verify obligations and liability language.
Authorized signers complete signatures and date the agreement.
Only after execution grant systems access to PHI.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial (no card) | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |