Definitions
Clear definitions of 'Protected Health Information', 'Covered Entity', 'Business Associate', and any role-specific terminology to avoid scope ambiguity and support enforceability.
A written BAA is required by HIPAA when a vendor handles PHI; it allocates risk, mandates safeguards, and establishes breach reporting timelines to meet federal obligations.
Covered entities and their third-party vendors use BAAs to formalize PHI handling obligations and controls before any PHI exchange.
Privacy or security officer at the covered entity who ensures the BAA maps to organizational policies, confirms safeguards meet HIPAA, and signs on behalf of the entity when authorized by corporate governance.
An authorized representative (CEO, CIO, or delegated contracting officer) from the business associate who accepts responsibilities, confirms technical controls, and signs to bind the vendor to contractual obligations.
Clear definitions of 'Protected Health Information', 'Covered Entity', 'Business Associate', and any role-specific terminology to avoid scope ambiguity and support enforceability.
Explicitly state permitted uses and disclosures of PHI (e.g., treatment, payment, operations) and prohibit any unauthorized secondary uses such as marketing or sale of PHI.
Require administrative, physical, and technical safeguards aligned with the HIPAA Security Rule, including access controls, encryption where appropriate, and incident response procedures.
Obligate the business associate to flow down BAA terms to subcontractors who create, receive, or access PHI and to maintain written agreements with those subcontractors.
Specify prompt notification obligations for breaches of unsecured PHI, timelines for notification to the covered entity, and cooperation with required HHS notifications.
Set termination rights for material breaches, procedures for return or secure destruction of PHI on termination, and conditions where limited retention is permitted for legal reasons.
Date BAA starts (MM/DD/YYYY)
Review security controls yearly
Notify promptly; HHS notifications within 60 days (45 CFR §164.408)
Update flow-down terms when subcontractors change
Return or destroy PHI on termination
Include an exhibit listing PHI categories, systems in scope, and processing activities; attach technical safeguards and contact lists for incident response.
Save the fully executed document as an audit-ready PDF with timestamped audit trail metadata to preserve signature attribution and integrity.
Retain copies in PDF and DOCX; keep the original signed PDF (ISO-compatible) for legal admissibility and rapid retrieval.
Keep system access logs and encryption key management records alongside the BAA for audit purposes and breach investigations.
Fertility Centers adopted an e-signed BAA to support remote patient intake and records sharing.
Xerox integrated e-signatures into existing ERP workflows to collect vendor BAAs electronically.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |