Purpose and scope
Describe why access is granted, which registry data sets are covered, and the specific public health activities permitted under the agreement.
A written agreement clarifies legal responsibilities for protecting sensitive health data, supports compliance with HIPAA and state public health rules, and documents user consent and accountability. Under the ESIGN Act (15 U.S.C. ch. 96) and applicable state law, an electronically signed agreement can be enforceable if intent, consent, attribution, and retention are met.
The agreement is used by entities and individuals who need authorized registry access to report, review, or manage blood lead test results.
Completing the agreement assigns clear responsibilities and documents who may query, export, or share registry records for authorized public health purposes.
Typically an individual clinician or lab technician whose job requires registry access. The user attests to limited-purpose use, safeguards account credentials, and follows role-based access controls set by their employer and the registry administrator.
A supervisor, laboratory director, or public health program manager who certifies institutional compliance, requests access on behalf of staff, and accepts responsibility for training, audits, and breach reporting obligations under the agreement.
Describe why access is granted, which registry data sets are covered, and the specific public health activities permitted under the agreement.
Specify role-based access levels, queries allowed, export rights, and any prohibitions on redisclosure or re-identification of individuals.
Require compliance with applicable privacy laws, internal policies, minimum necessary use, and any required confidentiality acknowledgments by individuals.
List required technical safeguards such as unique user IDs, strong authentication, encrypted transmission and storage, and session timeout policies.
State timeframes and procedures for reporting suspected breaches to the registry and affected parties, and for cooperating with investigations.
Require signers to certify authority, training completion, and acceptance of sanctions for noncompliance or unauthorized disclosures.
| Field | Configuration |
|---|---|
| Authentication Method | Email link, SMS code, or stronger multi-factor authentication |
| Access Expiration | Set automatic expiration date matching Effective Date end |
| Data Export Permission | Enable or disable CSV/PDF export based on role |
| Audit Trail Retention | Retain logs for minimum period required by registry |
Use a document platform that supports secure signatures, audit trails, and required file formats to preserve evidentiary integrity.
Ensure the selected platform can produce an immutable audit trail, support required authentication strength, and integrate with your records management system; common integrations include EHR connectors and cloud storage providers.
Submit before needed access start date to allow verification and provisioning
Reauthorize or review user access at least annually per policy
Report breaches without unreasonable delay; HIPAA guidance limits to 60 days for large breaches
Retain access logs for a minimum period required by registry or law
Process patient amendment requests per state public health procedures
A county epidemiologist requests access for case investigations
A clinic clinician needs results to manage a child's care
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card required | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA available) | Yes (BAA available) | Yes (BAA available) | No | No |