ShockSignStart free
HomeGuides › HIPAA-Compliant E-Signature: What HIPAA Actually Requires of a Signing Tool (Checklist)

HIPAA-Compliant E-Signature: What HIPAA Actually Requires of a Signing Tool (Checklist)

'HIPAA compliant' on a pricing page tells you almost nothing. HIPAA does not certify software; it imposes obligations on covered entities and their business associates, and a signing tool either helps you meet them or gets in the way. This guide lists what the Privacy and Security Rules actually require when patients sign intake forms, consents and authorizations electronically, and turns it into a checklist. It is general information, not legal or compliance advice.

By the ShockSign team · Updated September 19, 2026 · 10 min read

First, does HIPAA apply to your e-signature use?

HIPAA applies to covered entities (providers who bill electronically, health plans, clearinghouses) and to business associates that create, receive, maintain or transmit protected health information on their behalf. A patient intake form contains PHI. A treatment consent contains PHI. A release of information authorization contains PHI. So if a signing tool holds those documents, the vendor is a business associate, and both of you have obligations. If you only use e-signature for vendor contracts and employment paperwork that contains no PHI, HIPAA does not reach that use, though other privacy rules may.

What HIPAA does not require

Clearing up two myths saves a lot of time. HIPAA does not require a specific signature technology; the ESIGN Act and UETA govern signature validity, and HIPAA is silent on drawing versus typing. HIPAA also does not offer a certification; "HIPAA certified" software is a marketing phrase. What HIPAA requires is that PHI be protected by administrative, physical and technical safeguards, that a business associate agreement be in place, and that you can prove it through documentation and audit records.

The requirements, mapped to a signing tool

1. A Business Associate Agreement

Before any PHI touches a vendor's system, the Privacy Rule requires a written BAA that sets out permitted uses, safeguards, breach reporting and what happens to PHI at termination. No BAA means you cannot lawfully put PHI in the tool, regardless of how good its encryption is. ShockSign offers a BAA on enterprise arrangements; contact us before you send patient documents, and do not use a plan without one for PHI.

2. Access controls (Security Rule technical safeguards)

The Security Rule requires unique user identification, emergency access procedures, and, as addressable specifications, automatic logoff and encryption. For a signing tool that means: every staff member has their own login (no shared front-desk account), sessions time out when idle, roles limit who can see which documents, and strong authentication is available. ShockSign's HIPAA-oriented configuration includes a 15-minute idle timeout with automatic logoff, role-based team access, two-factor authentication using passkeys, authenticator apps or emailed codes, and Google or Microsoft sign-in for organizations that manage identities centrally.

3. Audit controls

Covered entities must implement mechanisms that record and examine activity in systems containing PHI. Your signing tool should log who created, viewed, sent, signed, downloaded and deleted each document, with timestamps and origin. ShockSign writes an audit event for every document and account action, stores the log entries encrypted, and seals completed documents with a SHA-256 hash and an RFC 3161 trusted timestamp so alterations are detectable. Our guide on audit trails explains how to read one.

4. Integrity

PHI must be protected from improper alteration or destruction. The hash and timestamp on each completed document, plus the public verification page that confirms a file has not changed, satisfy the integrity control for signed records.

5. Transmission security and encryption

PHI in transit must be guarded against unauthorized access; encryption at rest is addressable, which in practice means you need it or a documented reason why not. ShockSign encrypts documents at rest with AES-256-GCM, encrypts sensitive database fields such as audit-log IP addresses, and serves everything over TLS.

6. Person or entity authentication for signers

You must have reasonable assurance that the patient signing is the patient. E-signature tools do this with a unique emailed link and, where you require it, a verification code the signer must enter before viewing the document. Turn that on for authorizations and anything sensitive.

7. Retention

HIPAA requires that required documentation, including policies and authorizations, be retained for six years from creation or last effective date. State medical-record laws often require longer. ShockSign's retention policies default to seven years for documents under a HIPAA policy and can be configured; whatever you set, make sure the signed PDF and certificate also land in your EHR or document system.

8. Minimum necessary and workforce training

These are administrative, not technical, but they touch the tool. Only staff who need to send or view patient documents should have access; role-based team accounts make that enforceable. Train the front desk on what to do when a patient signs on a shared tablet (start an in-person session, hand it over, and make sure the previous patient's document is closed).

9. Breach notification

Your BAA must require the vendor to report breaches of unsecured PHI. Encrypted PHI that is lost without the key is generally not "unsecured," which is one practical reason encryption at rest matters so much.

The checklist

Which documents healthcare teams sign electronically

Patient intake and registration forms, notice of privacy practices acknowledgments, treatment and procedure consents, HIPAA authorizations for release of information, financial responsibility and insurance assignment forms, telehealth consents, and staff-side documents such as confidentiality agreements and policy acknowledgments. Most are templates with a few fields, which means they can be set up once and sent from a tablet at check-in or by email before the appointment. Details on the HIPAA e-signature page.

Questions to ask any vendor

  1. Will you sign a BAA, and on which plan?
  2. Is data encrypted at rest and with what algorithm? Are audit logs themselves encrypted?
  3. What is the default idle timeout, and can I change it?
  4. Does every user get their own login, and are roles supported?
  5. Can I export the complete audit trail for a document?
  6. What is your retention default, and can documents be deleted on schedule?
  7. How do you notify me of a breach, and how quickly?

A vendor that answers those in writing is one you can put in your risk analysis. A vendor that points you to a badge on the website is not.

Frequently asked questions

Does HIPAA require a specific kind of electronic signature?

No. HIPAA does not prescribe signature technology. Signature validity comes from the ESIGN Act and UETA. HIPAA's concern is that the PHI in the signed documents is protected by appropriate safeguards and that a business associate agreement is in place with the vendor.

Do I need a BAA with my e-signature vendor?

Yes, if patient documents containing PHI will be stored or transmitted by the vendor. The Privacy Rule requires a written BAA before PHI is shared with a business associate. ShockSign offers a BAA on enterprise arrangements; contact us before sending PHI.

Is a 'HIPAA compliant' badge meaningful?

Not by itself. There is no HIPAA certification. Evaluate the specific controls: BAA, encryption at rest and in transit, unique logins, automatic logoff, role-based access, audit logging, integrity protection and retention.

How long must signed patient forms be kept?

HIPAA requires six years for required documentation such as authorizations and policies. Many states require medical records to be kept longer. ShockSign's HIPAA retention policy defaults to seven years and is configurable; also store copies in your EHR.

Can patients sign intake forms on a shared tablet at the front desk?

Yes, using in-person signing: staff open the document, hand over the tablet, the patient signs, and the session closes. Make sure the previous patient's document is closed first and that the tablet is on a staff account with automatic logoff.

Which ShockSign plan is right for a clinic?

Choose based on monthly document volume: Professional at $29 per month covers 50 documents with 5 team logins; Business at $99 covers unlimited documents and team members. For PHI, arrange a BAA with us first.

Try ShockSign free

Start on the free plan (1 document, 7-day trial) or take a 7-day trial of Professional. No credit card, no annual contract.

See pricingCreate a free account