Every major e-signature platform advertises HIPAA compliance. The claim is common enough to be nearly meaningless without context. HIPAA compliance isn't a binary certification — it's a set of administrative, physical, and technical safeguards that must be implemented by both the covered entity (your organization) and any business associate (the software vendor) that handles protected health information (PHI) on your behalf. A HIPAA-compliant e-signature platform means something specific. Most vendors don't explain what it means — or what it doesn't cover.
This guide explains what HIPAA actually requires for electronic signatures in healthcare, what a Business Associate Agreement (BAA) covers and doesn't cover, and what to look for when evaluating any e-signature platform for PHI-containing documents.
Does HIPAA Require Electronic Signatures?
HIPAA does not mandate electronic signatures. It doesn't require paper signatures either. HIPAA establishes standards for protecting PHI — whether that information is transmitted electronically, stored physically, or exchanged verbally. If a document contains PHI and that document is transmitted or stored through an e-signature platform, HIPAA's electronic safeguards apply to that transmission and storage.
In practice, many documents healthcare organizations need signed do contain PHI: patient consent forms, treatment authorizations, insurance assignments, Notice of Privacy Practices acknowledgments, release of information authorizations, and telehealth agreements. Any e-signature platform handling these documents is processing PHI and must have appropriate safeguards in place.
What a Business Associate Agreement (BAA) Is — and Isn't
Before any HIPAA-covered entity can transmit PHI to a software vendor (including an e-signature platform), it must execute a Business Associate Agreement with that vendor. The BAA is a contract in which the vendor agrees to:
- Use PHI only for the purposes specified in the agreement
- Implement appropriate administrative, physical, and technical safeguards to protect PHI
- Report breaches involving PHI within the timeframes required by HIPAA
- Return or destroy PHI at the conclusion of the relationship
- Ensure that any subcontractors (subprocessors) who handle PHI are bound by similar obligations
A BAA is necessary but not sufficient. Signing a BAA doesn't make an e-signature platform HIPAA compliant — it establishes the contractual relationship and allocates responsibility. The platform still needs to implement the technical safeguards described in the agreement. Your organization still needs to implement its own safeguards for how you use the platform.
Critical point: Several major e-signature vendors offer BAAs only on Enterprise plans or as paid add-ons. Using a lower-tier plan without a BAA while sending PHI-containing documents is a HIPAA violation — even if the platform itself is technically capable of compliance. Always verify that your specific plan tier includes BAA availability.
The Technical Safeguards HIPAA Requires
HIPAA's Security Rule (45 CFR Part 164, Subpart C) specifies technical safeguards for electronic PHI. Applied to an e-signature platform, these require:
Access Controls
Only authorized users can access documents containing PHI. This means unique user credentials, role-based access controls, and automatic session timeouts. Shared logins — one account used by multiple staff members — violate this requirement.
Audit Controls
The platform must maintain hardware, software, and procedural mechanisms that record and examine activity in systems containing PHI. For e-signatures, this means a complete audit trail of who sent the document, when it was viewed, when each field was completed, the signer's IP address and device, and when the completed document was accessed.
Integrity Controls
PHI must not be improperly altered or destroyed. For signed documents, this means tamper-evident sealing — any modification to the document after signing is detectable. SHA-256 or equivalent cryptographic hashing applied at the document level satisfies this requirement.
Transmission Security
PHI transmitted over electronic communications networks must be encrypted. For e-signature platforms, this means TLS 1.2 or higher for all data in transit and AES-256 or equivalent encryption for data at rest. Unencrypted email delivery of signed documents — where the document is attached to an email rather than accessed through an authenticated link — creates a transmission security gap.
What Healthcare Organizations Must Do on Their End
HIPAA compliance is not achieved by selecting a compliant platform alone. Your organization is responsible for:
- Risk analysis: Conducting and documenting a periodic risk analysis of how PHI flows through your e-signature workflow, including what happens to completed documents and who has access.
- Workforce training: Training staff on HIPAA requirements specific to electronic document signing — including not sharing credentials, not sending PHI-containing documents to personal email addresses, and understanding what the audit trail records.
- Minimum necessary standard: Only including PHI in documents that genuinely require it. A consent form that can be structured without including specific diagnosis codes should be.
- Breach notification procedures: Having documented procedures for notifying your BAA vendor, affected individuals, and HHS in the event of a breach involving e-signed documents.
The 21 CFR Part 11 Standard: When You Need More Than HIPAA
Healthcare organizations that conduct clinical trials or work with the FDA face an additional standard: 21 CFR Part 11, which governs electronic records and signatures in FDA-regulated environments. Part 11 requirements go beyond HIPAA's safeguards and include:
- Specific signer identity verification tied to electronic signatures (not just authentication)
- Electronic signature linking — the signature must be permanently linked to the record it applies to
- System validation documentation — evidence that the e-signature system functions as intended
- Audit trail requirements that exceed HIPAA's standard (complete time-stamped record of any change to any record)
Organizations subject to Part 11 should explicitly ask e-signature vendors for their 21 CFR Part 11 compliance documentation — not just their HIPAA documentation. These are different standards, and a platform can satisfy one without the other.
Evaluating an E-Signature Platform for HIPAA: The Checklist
Before deploying any e-signature platform for PHI-containing documents, verify:
- BAA is available on your plan tier (not just Enterprise)
- Encryption at rest (AES-256 or equivalent) and in transit (TLS 1.2+)
- Tamper-evident document sealing with cryptographic hash
- Complete audit trail retained for HIPAA's minimum retention period (6 years)
- Role-based access control with unique user credentials
- Session timeout enforcement
- SOC 2 Type II certification (independent verification of security controls)
- Subprocessor documentation (who else handles your data, and under what agreement)
- Breach notification procedures and contractual notification SLA
Zignature HIPAA Compliance
Zignature includes BAA execution as part of the Enterprise plan, which covers unlimited users at $99/month. Enterprise plan features specifically relevant to HIPAA-covered entities include: AES-256 encryption at rest and in transit, complete tamper-evident audit trails retained for 10 years, role-based access control, automatic session timeout, SOC 2 Type II certification, 21 CFR Part 11 compliance documentation, and RON with full identity verification for situations requiring notarized consent.
BAA execution is available directly from the Enterprise plan dashboard — no separate procurement process required.
Review Zignature's compliance documentation or schedule a demo with our compliance team to walk through your specific requirements.