Is DocuSign HIPAA Compliant?
Docusign can be used for patient consent, intake, and authorization forms — but only on a plan where Docusign will sign a Business Associate Agreement, and only after you change a handful of default settings that otherwise email signed PHI straight to patients' inboxes. Here is exactly what qualifies, what to configure, and what a small practice should consider instead.
FIG · 01Yes — on a sales-led plan with a signed BAA
Docusign will sign a Business Associate Agreement for healthcare customers, but only through its sales team on an enterprise-tier (“Enhanced”) eSignature plan. The Personal and Standard plans you can buy with a credit card do not come with a BAA, and a BAA alone does not lock down the envelope settings that keep PHI out of email.
Enhanced / enterprise plan + signed BAA
HIPAA-eligible
Personal / Standard / free trial
No BAA — not for PHI
Which Docusign Plans Get a BAA?
Docusign publishes four eSignature tiers. As of August 2026, its plan comparison shows “HIPAA support through BAA” only in the sales-led Enhanced Plans column. Prices below are Docusign's published annual-billing rates and change often — confirm before budgeting. A BAA is mandatory before any PHI touches the platform, because Docusign is a business associate the moment it stores a signed intake form.
| Plan | Price | BAA | SMS/phone auth | Notes |
|---|---|---|---|---|
| Personal | $11/mo | 5 envelopes/month, single user. Never for patient documents. | ||
| Standard | $30/user/mo | Self-serve. No BAA offered, no SMS/phone authentication. | ||
| Business Pro | $45/user/mo | Self-serve tier. Docusign's own plan table lists HIPAA/BAA under Enhanced only — ask sales before relying on it. | ||
| Enhanced Plans (enterprise) | Custom quote | “HIPAA support through BAA,” 21 CFR Part 11, SMS & phone authentication, SSO, custom envelope limits. |
Legend: check = included · dash = ask sales · x = not offered. Prices as of Aug 2026, annual billing.
Small-practice reality check: an enterprise quote for two or three seats is often more than the whole practice spends on its EHR add-ons. If you only need patients to sign intake, consent, and release forms, the alternatives below include a BAA at a fraction of the cost.
How to Get the Docusign BAA
Unlike Microsoft (a self-service amendment) or Google Workspace (a toggle in the admin console), Docusign's BAA is handled contract-by-contract. Expect a few days to a couple of weeks. Use our BAA template to check that every required clause is present in what they send.
Contact Docusign sales, not support
The BAA is not a checkbox in the admin console. Request it through a sales representative (or your account executive if you already have one) and state that you are a HIPAA covered entity or business associate.
Get quoted on an Enhanced (enterprise) plan
Ask that the quote explicitly include the HIPAA BAA, SMS/phone recipient authentication, and any envelope volume you need. Get the envelope count in writing — overage fees are the most common surprise.
Review Docusign's standard BAA
It is Docusign paper, largely non-negotiable. Check what it covers (eSignature envelopes and stored documents), breach-notification timing, and subcontractor flow-down. Compare it against the required clauses in 45 CFR §164.504(e).
Sign it before you send the first envelope
Do not migrate templates or import patient contacts until the countersigned BAA is back. Any PHI sent before the effective date is an unauthorized disclosure.
File it for six years
45 CFR §164.530(j) requires you to keep the BAA for 6 years from the later of its creation or last effective date. Store it with your other vendor agreements.
Add Docusign to your risk analysis
Record it as a system that stores ePHI, list the envelope settings you enforced, and note who holds admin rights. Reviewers ask for this.
8 Envelope and Account Settings That Matter
The BAA covers Docusign's side. These settings cover yours. Menu paths reflect the current eSignature admin as of August 2026 and can shift between releases. Record each one in your risk assessment.
Stop attaching completed PDFs to email
Settings → Signing Settings → “Attach documents to completion email”
Uncheck it. Recipients get a link to the signed document instead of a PDF copy in their inbox.
This is the single biggest leak. A signed intake form with diagnoses and SSN lands in the patient's Gmail and every CC'd address, outside your BAA.
Require recipient authentication
Envelope → Recipients → Customize → Access code / SMS / Phone / ID verification
Turn on at least an access code for every patient envelope. SMS and phone authentication are enterprise features — make sure your quote includes them.
Without it, anyone holding the email link can open and sign. The Security Rule's person-or-entity authentication standard (§164.312(d)) applies here.
Turn on Document Visibility
Settings → Sending Settings → Document Visibility
Set to “Must sign to view, unless sender” (or “Sender can set”). Combine with per-recipient visibility on multi-document envelopes.
A guarantor, interpreter, or second signer should not see clinical pages meant only for the patient. This is the minimum necessary rule applied to envelopes.
Set document retention and purge
Settings → Document Retention
Define a retention period, then let Docusign purge envelope documents (optionally with fields and metadata) after you have exported the signed PDF and certificate to your EHR or document system.
Your record of the authorization must live 6 years (§164.530(j)); it does not have to live in Docusign. Fewer copies means less breach surface.
Keep PHI out of envelope names and messages
Templates → Envelope subject / Email message
Use a reference or chart ID, not “Jane Doe – HIV consent”. Email subjects and message bodies are sent in plain email, not inside the envelope.
Email subject lines are not covered by Docusign's encryption of the document. A diagnosis in a subject line is a disclosure.
Enforce SSO or MFA for senders
Docusign Admin → Security Settings / Organization SSO
Require login through your identity provider with MFA; set session timeouts; disable password-only sign-in.
Sender accounts can download every completed envelope. Stolen sender credentials expose your whole archive.
Lock down user roles and shared access
Docusign Admin → Users / Permission Profiles
Give most staff a sender-only profile. Restrict who can share envelopes, export reports, or manage retention. Remove users the day they leave.
Role-based access is an addressable Security Rule safeguard; over-broad admin rights show up in almost every breach investigation.
Store the Certificate of Completion
Completed envelope → Certificate of Completion (PDF)
Export the certificate (signer email, IP, timestamps, authentication method) with the signed document to your record system.
It is your evidence that the signature is attributable to the patient, which is what makes an e-signed authorization valid under §164.508.
Account-level beats envelope-level
The attachment and visibility settings can be set per envelope, but a rushed front-desk user will forget. Set them at the account level so every template inherits them, then spot-check with the HIPAA audit checklist.
Are E-Signed Consent and Authorization Forms Valid?
Yes. HIPAA never required wet ink. The Privacy Rule says an authorization must carry the “signature of the individual and date” (45 CFR §164.508(c)(1)(vi)), and HHS has confirmed authorizations may be obtained electronically as long as the e-signature is valid under applicable law. That law is the federal ESIGN Act (15 U.S.C. §7001) plus UETA, adopted in 48 states, D.C. and the Virgin Islands; New York and Illinois use their own equivalent statutes.
ESIGN / UETA: four tests
Intent to sign
Click-to-sign or drawn signature with a clear “I agree” action
Consent to do business electronically
Docusign's Electronic Record and Signature Disclosure, accepted before signing
Attribution to the signer
Email + access code / SMS / ID check, captured in the Certificate of Completion
Record retention
Signed PDF and certificate stored and reproducible for the retention period
§164.508(c)(1): core elements
- 01A specific description of the information to be used or disclosed
- 02Who is authorized to make the disclosure
- 03Who may receive it
- 04The purpose (or “at the request of the individual”)
- 05An expiration date or event
- 06Signature of the individual and date; if a personal representative signs, their authority
Plus the three required statements in §164.508(c)(2): right to revoke, whether treatment is conditioned on signing, and the redisclosure warning. Plain language, and the patient gets a copy.
“The e-signature tool never makes a bad form valid. If the authorization is missing an expiration or the revocation statement, it is defective whether it was signed on paper or in Docusign.”
Build the form right first with the HIPAA release form generator or informed consent template, then load it as a Docusign template. Watch state-specific carve-outs: a few states still require wet or notarized signatures for advance directives and POLST forms, and psychotherapy-note releases need their own, separate authorization.
What the Docusign BAA Does — and Doesn't — Cover
The BAA follows the envelope, not the email around it. Most Docusign “breaches” in practice are ordinary email mistakes wearing a Docusign logo.
Inside the BAA
Envelopes and documents at rest
AES-256 at rest, TLS in transit, inside the BAA once signed
Templates and stored form data
Field values (DOB, insurance ID) are stored with the envelope
Certificate of Completion / audit trail
Signer identity, IP, timestamps, authentication method
Recipient authentication
Access code, SMS, phone, ID verification (enterprise features)
Docusign mobile app and web signing
Same envelope, same controls
Outside the BAA
The patient's email inbox
Attached PDFs and PHI in subject lines leave the BAA the moment they are sent
Third-party integrations
Zapier, CRM, or EHR connectors need their own BAA (Docusign's covers Docusign only)
Docusign AI / agreement summaries
Confirm in writing whether AI features are inside the BAA scope before enabling them
Downloads to personal devices
A signed PDF on a staff laptop is your problem, not Docusign's
Personal or trial accounts
Any envelope sent from a non-BAA account is an unauthorized disclosure
5 Mistakes That Break Docusign Compliance
None of these require a hacker. They are the ordinary HIPAA violations an e-signature tool makes faster.
Sending patient forms from a Standard or trial account
No BAA exists, so every envelope is an impermissible disclosure to a vendor. The plan's encryption is irrelevant — the Privacy Rule violation is contractual, not technical.
Fix: Move patient-facing templates to the BAA-covered account only. Delete or downgrade stray self-serve seats staff opened on their own.
Leaving completed-document email attachments on
Signed intake and history forms are emailed as PDFs to the patient and every CC. Once in a consumer inbox, you have no control and no BAA.
Fix: Uncheck “Attach documents to completion email” at the account level and re-test with a dummy envelope.
Putting the patient's name and condition in the envelope subject
Subject lines travel in ordinary email headers. “Hep C treatment consent – Maria Lopez” is a disclosure before anyone opens anything.
Fix: Use chart or reference numbers in subjects and messages. Put context inside the document.
Skipping recipient authentication to make signing “easier”
Anyone with the forwarded link can open and sign. That undermines attribution, and a disputed signature on an authorization is a disputed disclosure.
Fix: Access code at minimum; SMS or ID verification for releases of sensitive records.
Treating Docusign as the medical record
Staff leave, seats get reassigned, and retention purges run. If the only copy of a signed authorization lives in Docusign, you may not be able to produce it in year five.
Fix: Export the signed PDF plus Certificate of Completion to your EHR or document system, then let Docusign purge on schedule.
If PHI already went out as an attachment to the wrong address, work through the breach risk assessment — a misdirected signed form is a reportable breach unless you can document a low probability of compromise.
Docusign vs. HIPAA E-Signature Alternatives
The question is rarely “is Docusign secure” — it is whether you can get the BAA at a price that makes sense for your seat count. Prices are vendor list prices checked August 2026; all four change them without notice.
| Tool | BAA | Price | Best for |
|---|---|---|---|
| Docusign eSignature | Enhanced / enterprise plan, via sales | Custom quote (Business Pro lists at $45/user/mo without BAA) | Health systems already on Docusign, high volume, EHR integrations |
| Adobe Acrobat Sign | Enterprise tier only, requested through sales with your account ID | Custom quote; Individual and Business tiers not eligible | Organizations standardized on Adobe with an enterprise agreement |
| Jotform + Jotform Sign | Included on Gold and Enterprise plans (HIPAA features toggle) | Gold roughly $99/mo billed annually, as of Aug 2026 | Intake forms with signature fields, single-user practices |
| Hushmail for Healthcare | Included on every Healthcare plan | E-signature plans from about $25/mo, as of Aug 2026 | Solo therapists and small clinics that also need encrypted email |
“Under ten users and no EHR integration? A BAA-included forms tool usually beats an enterprise Docusign quote. Over fifty users with Epic or Salesforce in the mix? Docusign or Acrobat Sign earn their price.”
Quick Reference: Docusign HIPAA Compliance
Plans that qualify
Enhanced / enterprise eSignature plans with a signed BAA. Personal and Standard never; Business Pro only if sales confirms in writing.
BAA — through sales
Standard Docusign paper, request before the first envelope, keep 6 years under §164.530(j).
8 settings
No completed-doc attachments, recipient authentication, document visibility, retention/purge, clean subject lines, SSO/MFA, tight roles, export the certificate.
Signatures are valid
ESIGN/UETA make e-signed consent and §164.508 authorizations enforceable — if the form itself has every core element and statement.
Related Tools & Guides
Informed Consent Form Template
Build a consent form with every required element before you load it into an e-signature tool.
HIPAA Release Form Generator
A 45 CFR §164.508-compliant authorization with all core elements and statements.
BAA Template Generator
Check a vendor's BAA against the required §164.504(e) clauses.
Is Google Drive HIPAA Compliant?
Where to store the signed PDFs once they leave Docusign.
Best HIPAA Compliant File Sharing
Platforms compared for sending and storing patient documents.