Data classification
Defines covered data categories (e.g., PHI, PII, financial data), scope of processing, and who is a data controller or processor.
Including a Schedule creates a clear, enforceable baseline for protecting sensitive information, allocates risk between parties, and documents technical and operational commitments that regulators or auditors may require. It reduces ambiguity about responsibilities for breaches, subcontractors, and regulatory reporting.
Legal, compliance, IT security, procurement, and contract managers all play roles in preparing and approving a Schedule; each brings a distinct perspective that shapes obligations and controls.
Effective collaboration across these groups produces a Schedule that is legally robust, operationally realistic, and auditable for regulators and business stakeholders.
Defines covered data categories (e.g., PHI, PII, financial data), scope of processing, and who is a data controller or processor.
Specifies encryption in transit (TLS 1.2/1.3) and at rest (AES-256), key management, and acceptable cipher suites.
Lists authentication methods, role-based access, privileged account controls, and multi-factor authentication requirements.
Requires audit trail retention, log integrity, timestamping, and procedures for producing logs during audits or incidents.
Sets notification timelines, data elements to report, remediation obligations, and who bears costs.
Requires subcontractor approval, flow-down clauses, and proof of certifications (SOC 2 Type II, ISO 27001) where applicable.
| Field | Configuration |
|---|---|
| Routing order | Sequential signers with conditional branches |
| Authentication | Email + SMS code; optional KBA for higher assurance |
| Attachments | Require certification docs (SOC 2, ISO 27001) where applicable |
| Audit export | Enable PDF/A signed export and event log retention |
Choose platforms and integrations that support required security controls, evidence collection, and the document formats your organization uses.
Ensure the chosen platform can deliver tamper-evident signed PDFs, an immutable audit trail, and secure long-term storage that meets contractual retention obligations.
72 hours for initial notification is common
Submit within 15 business days of discovery
Provide requested evidence within 30 days
Annual security review and certification
Respond within 30–45 days per applicable law
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No | No | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
A regional clinic required a BAA and detailed encryption controls during vendor onboarding.
A SaaS provider added a Schedule to its master subscription agreement to standardize security obligations.