Establishing secure connection…Loading editor…Preparing document…

Wisconsin Blood Lead Registry Security and Confidentiality Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!
Wisconsin Blood Lead Registry Security and Confidentiality Agreement

What this Security and Confidentiality Agreement covers

The Wisconsin Blood Lead Registry Security and Confidentiality Agreement establishes the terms governing authorized access, use, and protection of blood lead test results and related personally identifiable information submitted to the Wisconsin Blood Lead Registry. It defines permitted users, access purposes, technical and administrative safeguards, data-sharing limits, breach notification obligations, and the recordkeeping required to comply with state public health rules and federal privacy laws such as HIPAA. The agreement also documents attestations by signatories that they will handle registry data only for authorized public health purposes and in accordance with applicable law.

Why a formal security and confidentiality agreement matters

A written agreement clarifies legal responsibilities for protecting sensitive health data, supports compliance with HIPAA and state public health rules, and documents user consent and accountability. Under the ESIGN Act (15 U.S.C. ch. 96) and applicable state law, an electronically signed agreement can be enforceable if intent, consent, attribution, and retention are met.

Why a formal security and confidentiality agreement matters

Organizations and roles that typically complete this agreement

The agreement is used by entities and individuals who need authorized registry access to report, review, or manage blood lead test results.

  • Clinical laboratories and reference labs reporting test results to the state registry for public health surveillance and case management.
  • Healthcare providers, pediatric clinics, and community health centers accessing results for patient follow-up and care coordination.
  • Local public health agencies, environmental health teams, and childcare oversight programs that investigate exposures or oversee interventions.

Completing the agreement assigns clear responsibilities and documents who may query, export, or share registry records for authorized public health purposes.

Signatories who may bind an organization

Authorized User

Typically an individual clinician or lab technician whose job requires registry access. The user attests to limited-purpose use, safeguards account credentials, and follows role-based access controls set by their employer and the registry administrator.

Program Official

A supervisor, laboratory director, or public health program manager who certifies institutional compliance, requests access on behalf of staff, and accepts responsibility for training, audits, and breach reporting obligations under the agreement.

Core elements to include in a professional agreement

A robust Security and Confidentiality Agreement should be concise but comprehensive, covering who may access registry data, permitted uses, technical safeguards, and procedures for incidents and termination.

Purpose and scope

Describe why access is granted, which registry data sets are covered, and the specific public health activities permitted under the agreement.

Data access limits

Specify role-based access levels, queries allowed, export rights, and any prohibitions on redisclosure or re-identification of individuals.

Confidentiality obligations

Require compliance with applicable privacy laws, internal policies, minimum necessary use, and any required confidentiality acknowledgments by individuals.

Security controls

List required technical safeguards such as unique user IDs, strong authentication, encrypted transmission and storage, and session timeout policies.

Breach notification

State timeframes and procedures for reporting suspected breaches to the registry and affected parties, and for cooperating with investigations.

Signatory attestations

Require signers to certify authority, training completion, and acceptance of sanctions for noncompliance or unauthorized disclosures.

Essential information to capture on the form

Patient identifiers: Name, DOB, and MRN
Test results: Lead value, units, specimen date
Ordering provider: Name and NPI
Authorized user: Name, title, contact email
Access purpose: Public health case or clinical follow-up
Effective dates: Access start and end dates

Step-by-step: completing the agreement

Follow these sequential steps to prepare, sign, and submit the agreement to gain authorized registry access.

  • 01
    Start: Confirm authority to request access and gather organizational details.
  • 02
    Enter parties: Complete legal names, roles, and contact information accurately.
  • 03
    Set controls: Choose minimum necessary access level and authentication requirements.
  • 04
    Sign and submit: Sign using an authorized signer and send to the registry or local health authority.

Configuring an online workflow for the agreement

Configure fields, authentication, and routing rules so submissions are auditable and compliant with registry requirements.

Field Configuration
Authentication Method Email link, SMS code, or stronger multi-factor authentication
Access Expiration Set automatic expiration date matching Effective Date end
Data Export Permission Enable or disable CSV/PDF export based on role
Audit Trail Retention Retain logs for minimum period required by registry

Where to send completed agreements

Completed agreements must follow the registry's submission path so access provisioning and audits are applied correctly.

  • Submit to Registry: Upload or email to the Wisconsin Blood Lead Registry intake address.
  • Local Health Department: Copy local public health unit when requested for jurisdictional oversight.
  • Laboratory Records: Retain a signed copy in the laboratory's compliance file.
  • Secure Archive: Store final executed agreements in an encrypted, access-controlled repository.

Digital signing and technical compatibility

Use a document platform that supports secure signatures, audit trails, and required file formats to preserve evidentiary integrity.

  • Formats Supported: PDF, Word DOCX, and archived copies (PDF/A)
  • Integrations: Connectors for EHRs and cloud storage reduce manual uploads
  • Authentication Options: Email, SMS, KBA, or enterprise SSO

Ensure the selected platform can produce an immutable audit trail, support required authentication strength, and integrate with your records management system; common integrations include EHR connectors and cloud storage providers.

Penalties and risks for improper handling or errors

HIPAA Violations: Potential civil and criminal penalties
Civil Penalties: Fines, corrective action plans
Data Breach: Notification, mitigation, reputational harm
Unauthorized Access: User account suspension or revocation
Misreporting: Public health investigation consequences
Contract Voidance: Access privileges rescinded

Common mistakes to avoid when preparing the agreement

  • Using informal or abbreviated organization names that prevent verifying signatory authority and delay access approvals.
  • Granting broader access than necessary for the stated public health purpose, increasing exposure and audit findings.
  • Failing to record effective dates or expiration, which complicates audits and can allow unintended long-term access.
  • Neglecting to require periodic review or reauthorization, leaving stale accounts active and increasing breach risk.

Key timing expectations and statutory deadlines

Be aware of submission windows, review cycles, and incident notification timeframes to maintain compliance and timely access.

Access Request Submission:

Submit before needed access start date to allow verification and provisioning

Annual Review:

Reauthorize or review user access at least annually per policy

Breach Notification Timing:

Report breaches without unreasonable delay; HIPAA guidance limits to 60 days for large breaches

Audit Log Retention:

Retain access logs for a minimum period required by registry or law

Record Amendment Requests:

Process patient amendment requests per state public health procedures

Real-world scenarios showing how the agreement is used

These illustrative examples show typical ways organizations use the agreement to enable authorized registry access while protecting privacy.

County Health Department

A county epidemiologist requests access for case investigations

  • Access limited to case management tools and export disabled
  • The signed agreement documents responsibilities, triggers annual reauthorization, and supports audit requests from state public health.

Pediatric Clinic

A clinic clinician needs results to manage a child's care

  • Clinic selects view-only access for clinicians and export for supervisors
  • Signed attestations require staff training and immediate reporting of any suspected unauthorized access to the registry.

Practical tips for accurate and efficient completion

Adopt consistent processes and produce executable records that support audits and rapid provisioning.

Use minimal access
Grant only the specific permissions required for the task; document justification and review access at least annually to reduce exposure.
Standardize names
Use legal entity and job titles consistently across agreements to speed verification and avoid authority disputes.
Keep audit trails
Ensure your platform records signer identity, IP, timestamp, and actions so the registry can verify provenance and the organization can demonstrate compliance.
Choose compliant eSign
Select an eSignature provider that supports required technical safeguards; signNow, for example, supports HIPAA with a BAA and produces detailed audit trails.

Sample eSignature vendor comparison for executing the agreement

Basic pricing and feature availability across common eSignature vendors to consider when enabling electronic execution of the agreement.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card required Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes (BAA available) Yes (BAA available) No No

Frequently asked questions about execution and enforcement

Answers to common questions on electronic signing, authority, breach handling, and retention to help complete the agreement correctly.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users