Compliance · HIPAA

HIPAA-Compliant
E-Signature Software

Business Associate Agreement included on every paid plan. 256-bit AES encryption, comprehensive audit logs, and role-based access controls that satisfy HIPAA Security Rule requirements for PHI.

Free plan available · No credit card required · ESIGN Act compliant

BAA
Included on paid plans
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
Full
Audit log coverage
Key Features

Everything You Need

Built-in features that save time and close deals faster.

BAA Included

Business Associate Agreement on Every Paid Plan

HIPAA requires that any vendor handling Protected Health Information (PHI) sign a Business Associate Agreement (BAA). Zignature provides a standard BAA on all paid plans — covering all PHI processed through the platform. You don't need to negotiate a custom BAA or wait for legal review before getting compliant.

  • Standard BAA available immediately — no negotiation, no waiting for legal review.
  • Covers all PHI in Zignature documents — signer names, emails, and any PHI in document content.
  • Enterprise custom BAA — custom-negotiated BAA available for large healthcare organizations.
Regulatory Requirement
45 CFR §164.308(b) — Business Associate Agreement
All vendors handling PHI must sign a Business Associate Agreement before accessing protected health information
BAA must specify the permitted uses and disclosures of PHI by the business associate
Business associate must implement appropriate safeguards and notify covered entity of any PHI breaches within 60 days
Zignature satisfies this requirement
Technical Safeguards

256-Bit Encryption and Complete Audit Logs

Every HIPAA-regulated document in Zignature is encrypted at rest with AES-256 and in transit with TLS 1.3. Comprehensive audit logs record every document access, view, download, and modification — with user identity and timestamp — satisfying the HIPAA Security Rule's audit control requirements (45 CFR §164.312(b)).

  • AES-256 encryption at rest — industry-standard encryption for PHI stored in Zignature.
  • TLS 1.3 in transit — strongest available transport security for PHI in motion.
  • Complete audit logs — every access and action logged with user identity and timestamp.
Regulatory Requirement
45 CFR §164.312 — Technical Safeguards
Implement access controls to allow only authorized users to access ePHI (§164.312(a))
Implement audit controls to record and examine activity in information systems containing ePHI (§164.312(b))
Implement transmission security measures to guard against unauthorized access to ePHI in transit (§164.312(e))
Zignature satisfies this requirement
Access Controls

Role-Based Access for HIPAA Minimum Necessary

HIPAA's minimum necessary standard requires limiting PHI access to what's needed for a specific purpose. Zignature's role-based access controls let administrators grant document access at the team, department, or individual level — ensuring staff see only the PHI they need for their job function.

  • Granular role assignment — access controlled at team, department, and document level.
  • Field-level restrictions — limit which PHI fields appear to specific signers or viewers.
  • Session timeout controls — automatic session expiry to prevent unauthorized access after inactivity.
Regulatory Requirement
45 CFR §164.312(a)(2) & §164.514(b) — Minimum Necessary Standard
Assign unique user IDs to all workforce members requiring access to ePHI
Implement automatic logoff after a predetermined period of user inactivity
Limit PHI access to the minimum necessary for each user's specific role and job function
Zignature satisfies this requirement
Use Cases

Works for Every Scenario

From simple agreements to complex multi-party workflows.

Patient Consent Forms

HIPAA-compliant collection of informed consent for treatment, procedures, and research — with required disclosures enforced.

HIPAA Authorization Forms

PHI release authorization (45 CFR §164.508) with required elements enforced and automatic expiry for time-limited authorizations.

Business Associate Agreements

Execute BAAs with your own healthcare vendors and business associates — with template BAAs and multi-party signing.

Employee HIPAA Training Attestations

Annual workforce HIPAA training acknowledgments — bulk send to all staff with completion tracking for audit readiness.

Telemedicine Consent

State-specific telehealth consent forms with jurisdiction disclosures — signed before each remote patient encounter.

PHI Access Authorizations

Research data access authorizations, third-party disclosure consents, and de-identification agreements for data sharing.

How It Works

Up and Running in Minutes

No training required. Send your first document today.

1

Choose Your Template

Pick from pre-built compliant templates or upload your own document — our system applies the right compliance rules automatically.

2

Configure Compliance Settings

Enable HIPAA BAA, GDPR DPA, identity verification, or QES as required for your regulatory environment.

3

Send to Signers

Recipients get a secure link and are guided through the signing process with all required disclosures and consent flows.

4

Archive with Full Audit Trail

Every transaction is sealed with a tamper-proof certificate of completion — ready for audits, regulators, and legal proceedings.

Compliance Checklist

Does Zignature Check Every Box?

Here's exactly how Zignature satisfies each specific regulatory requirement — with citations.

Requirement Regulation Citation How Zignature Satisfies It Met
Business Associate Agreement §164.308(b) Standard BAA included on all paid plans
Access Controls (Unique User IDs) §164.312(a)(2)(i) Each user has unique, non-shareable credentials
Audit Controls §164.312(b) Complete audit log of all document access and actions
Integrity Controls §164.312(c)(1) SHA-256 document hashing detects any tampering
Transmission Security (Encryption) §164.312(e)(2)(ii) TLS 1.3 encryption for all ePHI in transit
Encryption at Rest §164.312(a)(2)(iv) AES-256 encryption for all stored PHI

Start HIPAA-Compliant Signing Today

BAA included. AES-256 encryption. Trusted by healthcare organizations nationwide.

Frequently Asked Questions

Everything you need to know.

Is Zignature HIPAA compliant?

Yes. Zignature is HIPAA compliant and provides a signed Business Associate Agreement (BAA) on all paid plans. The platform implements HIPAA Security Rule administrative, physical, and technical safeguards — including 256-bit AES encryption, comprehensive audit logs, and role-based access controls for PHI.

Does Zignature include a Business Associate Agreement (BAA)?

Yes. All paid Zignature plans include access to a standard BAA that covers PHI processed through the platform. The BAA is available in your account settings after upgrading to a paid plan. Enterprise customers can request a custom-negotiated BAA to address specific organizational requirements.

What PHI does Zignature process?

When used for healthcare documents, Zignature may process signer names, email addresses, IP addresses, signing timestamps, and any PHI included in the document content. All of this is covered by the BAA. The platform is designed to minimize PHI exposure — only data necessary for the signing workflow is processed.

Does Zignature satisfy HIPAA Security Rule technical safeguard requirements?

Yes. Zignature implements the required and addressable technical safeguards under 45 CFR §164.312, including: access controls (role-based, unique user ID), audit controls (comprehensive logging of all PHI access), integrity controls (document hashing to detect tampering), and transmission security (TLS 1.3 for all data in transit).

Can Zignature be used for 21 CFR Part 11 clinical trial consent?

Yes. Zignature supports 21 CFR Part 11 compliant electronic signatures for FDA-regulated clinical research, including unique user authentication, closed and open system controls, and complete audit trails. This makes Zignature suitable for informed consent in FDA-regulated clinical trials.

How long are HIPAA-related documents retained?

Zignature stores documents indefinitely by default. Healthcare organizations typically configure a 6-year minimum retention policy (per HIPAA Security Rule 45 CFR §164.530(j)). Enterprise plans support automated retention schedules with configurable deletion policies for PHI minimization requirements.

Does Zignature store PHI in the United States?

Yes. All Zignature data is stored in AWS data centers located in the United States. For organizations with HIPAA data residency requirements, US-only data storage is the default configuration. Enterprise plans can specify geographic data residency constraints.

What happens to PHI when a healthcare organization cancels their Zignature account?

Upon account cancellation, organizations can export all signed documents and audit trails. PHI in Zignature's systems is subject to secure deletion per the BAA terms and NIST SP 800-88 guidelines after the contractually specified retention period.

Related Resources