Permitted Uses
Specify exactly how PHI may be used and disclosed by the business associate, limiting use to performance of the contracted service and any allowed secondary uses.
A BAA documents legal responsibilities for PHI handling, reduces regulatory risk, and limits liability by specifying safeguards, breach procedures, and permitted uses. It is a HIPAA prerequisite when a vendor performs services involving PHI for a covered entity.
When in doubt, treat vendors that access, store, or transmit PHI as business associates and document responsibilities in a BAA prior to any PHI exchange.
Specify exactly how PHI may be used and disclosed by the business associate, limiting use to performance of the contracted service and any allowed secondary uses.
Require administrative, physical, and technical safeguards (access controls, encryption, incident response) and state measurable benchmarks or standards to evaluate compliance.
Mandate written agreements with subcontractors that mirror BAA obligations and require the business associate to obtain flow-down BAAs before sharing PHI.
Define timing, content, and escalation for breach notices and responsibilities for mitigation, investigation, and supporting the covered entity’s required external reporting.
Allow the covered entity to assess controls, receive audit results, and require remediation within stated timeframes following identified deficiencies.
Specify termination for material breach, obligations on termination (return or destruction of PHI), and procedures if return is infeasible.
| Field | Configuration |
|---|---|
| Signer Order | Set required signing sequence for parties |
| Authentication | Email/SMS code, or MFA for higher assurance |
| Required Fields | Signature, printed name, title, date |
| Retention | Auto-store signed copy and audit trail |
Ensure the platform provides encryption in transit and at rest and captures attribution data (IP, timestamp, signer identity) for enforceability.
Execute before any PHI is exchanged between parties
Conduct annual or trigger-based reviews of BAA terms and controls
Require prompt notice and executed flow-down BAAs when subcontractors change
Notify covered entity immediately per contractual terms and HIPAA requirements
Complete return/destruction of PHI within the timeframe specified in the BAA
Agree scope, safeguards, and liability allocation before signature.
Obtain authorized signatures and distribute executed copies to stakeholders.
Implement technical and administrative controls described in the BAA.
Return or securely destroy PHI and document disposition actions.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Available (Business Premium) | Depends on plan | Depends on plan | Depends on plan | Depends on plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Depends on plan | Depends on plan | Depends on plan |
Optica adopted an eSignature workflow to handle vendor agreements and BAAs efficiently.
The clinic standardized BAAs and related consent forms for third-party lab services.