HIPAA & PRIVACY

Is DocuSign HIPAA Compliant?

Docusign can be used for patient consent, intake, and authorization forms — but only on a plan where Docusign will sign a Business Associate Agreement, and only after you change a handful of default settings that otherwise email signed PHI straight to patients' inboxes. Here is exactly what qualifies, what to configure, and what a small practice should consider instead.

Cyanotype of a blank tablet on a closed document folder with a stylusFIG · 01
A blank tablet on a closed document folder with a stylus.

Yes — on a sales-led plan with a signed BAA

Docusign will sign a Business Associate Agreement for healthcare customers, but only through its sales team on an enterprise-tier (“Enhanced”) eSignature plan. The Personal and Standard plans you can buy with a credit card do not come with a BAA, and a BAA alone does not lock down the envelope settings that keep PHI out of email.

Enhanced / enterprise plan + signed BAA

HIPAA-eligible

Personal / Standard / free trial

No BAA — not for PHI

Which Docusign Plans Get a BAA?

Docusign publishes four eSignature tiers. As of August 2026, its plan comparison shows “HIPAA support through BAA” only in the sales-led Enhanced Plans column. Prices below are Docusign's published annual-billing rates and change often — confirm before budgeting. A BAA is mandatory before any PHI touches the platform, because Docusign is a business associate the moment it stores a signed intake form.

PlanPriceBAASMS/phone auth
Personal$11/mo
Standard$30/user/mo
Business Pro$45/user/mo
Enhanced Plans (enterprise)Custom quote

Legend: check = included · dash = ask sales · x = not offered. Prices as of Aug 2026, annual billing.

Small-practice reality check: an enterprise quote for two or three seats is often more than the whole practice spends on its EHR add-ons. If you only need patients to sign intake, consent, and release forms, the alternatives below include a BAA at a fraction of the cost.

How to Get the Docusign BAA

Unlike Microsoft (a self-service amendment) or Google Workspace (a toggle in the admin console), Docusign's BAA is handled contract-by-contract. Expect a few days to a couple of weeks. Use our BAA template to check that every required clause is present in what they send.

01

Contact Docusign sales, not support

The BAA is not a checkbox in the admin console. Request it through a sales representative (or your account executive if you already have one) and state that you are a HIPAA covered entity or business associate.

02

Get quoted on an Enhanced (enterprise) plan

Ask that the quote explicitly include the HIPAA BAA, SMS/phone recipient authentication, and any envelope volume you need. Get the envelope count in writing — overage fees are the most common surprise.

03

Review Docusign's standard BAA

It is Docusign paper, largely non-negotiable. Check what it covers (eSignature envelopes and stored documents), breach-notification timing, and subcontractor flow-down. Compare it against the required clauses in 45 CFR §164.504(e).

04

Sign it before you send the first envelope

Do not migrate templates or import patient contacts until the countersigned BAA is back. Any PHI sent before the effective date is an unauthorized disclosure.

05

File it for six years

45 CFR §164.530(j) requires you to keep the BAA for 6 years from the later of its creation or last effective date. Store it with your other vendor agreements.

06

Add Docusign to your risk analysis

Record it as a system that stores ePHI, list the envelope settings you enforced, and note who holds admin rights. Reviewers ask for this.

8 Envelope and Account Settings That Matter

The BAA covers Docusign's side. These settings cover yours. Menu paths reflect the current eSignature admin as of August 2026 and can shift between releases. Record each one in your risk assessment.

01

Stop attaching completed PDFs to email

Settings → Signing Settings → “Attach documents to completion email”

Uncheck it. Recipients get a link to the signed document instead of a PDF copy in their inbox.

This is the single biggest leak. A signed intake form with diagnoses and SSN lands in the patient's Gmail and every CC'd address, outside your BAA.

02

Require recipient authentication

Envelope → Recipients → Customize → Access code / SMS / Phone / ID verification

Turn on at least an access code for every patient envelope. SMS and phone authentication are enterprise features — make sure your quote includes them.

Without it, anyone holding the email link can open and sign. The Security Rule's person-or-entity authentication standard (§164.312(d)) applies here.

03

Turn on Document Visibility

Settings → Sending Settings → Document Visibility

Set to “Must sign to view, unless sender” (or “Sender can set”). Combine with per-recipient visibility on multi-document envelopes.

A guarantor, interpreter, or second signer should not see clinical pages meant only for the patient. This is the minimum necessary rule applied to envelopes.

04

Set document retention and purge

Settings → Document Retention

Define a retention period, then let Docusign purge envelope documents (optionally with fields and metadata) after you have exported the signed PDF and certificate to your EHR or document system.

Your record of the authorization must live 6 years (§164.530(j)); it does not have to live in Docusign. Fewer copies means less breach surface.

05

Keep PHI out of envelope names and messages

Templates → Envelope subject / Email message

Use a reference or chart ID, not “Jane Doe – HIV consent”. Email subjects and message bodies are sent in plain email, not inside the envelope.

Email subject lines are not covered by Docusign's encryption of the document. A diagnosis in a subject line is a disclosure.

06

Enforce SSO or MFA for senders

Docusign Admin → Security Settings / Organization SSO

Require login through your identity provider with MFA; set session timeouts; disable password-only sign-in.

Sender accounts can download every completed envelope. Stolen sender credentials expose your whole archive.

07

Lock down user roles and shared access

Docusign Admin → Users / Permission Profiles

Give most staff a sender-only profile. Restrict who can share envelopes, export reports, or manage retention. Remove users the day they leave.

Role-based access is an addressable Security Rule safeguard; over-broad admin rights show up in almost every breach investigation.

08

Store the Certificate of Completion

Completed envelope → Certificate of Completion (PDF)

Export the certificate (signer email, IP, timestamps, authentication method) with the signed document to your record system.

It is your evidence that the signature is attributable to the patient, which is what makes an e-signed authorization valid under §164.508.

Account-level beats envelope-level

The attachment and visibility settings can be set per envelope, but a rushed front-desk user will forget. Set them at the account level so every template inherits them, then spot-check with the HIPAA audit checklist.

Are E-Signed Consent and Authorization Forms Valid?

Yes. HIPAA never required wet ink. The Privacy Rule says an authorization must carry the “signature of the individual and date” (45 CFR §164.508(c)(1)(vi)), and HHS has confirmed authorizations may be obtained electronically as long as the e-signature is valid under applicable law. That law is the federal ESIGN Act (15 U.S.C. §7001) plus UETA, adopted in 48 states, D.C. and the Virgin Islands; New York and Illinois use their own equivalent statutes.

ESIGN / UETA: four tests

  • Intent to sign

    Click-to-sign or drawn signature with a clear “I agree” action

  • Consent to do business electronically

    Docusign's Electronic Record and Signature Disclosure, accepted before signing

  • Attribution to the signer

    Email + access code / SMS / ID check, captured in the Certificate of Completion

  • Record retention

    Signed PDF and certificate stored and reproducible for the retention period

§164.508(c)(1): core elements

  1. 01A specific description of the information to be used or disclosed
  2. 02Who is authorized to make the disclosure
  3. 03Who may receive it
  4. 04The purpose (or “at the request of the individual”)
  5. 05An expiration date or event
  6. 06Signature of the individual and date; if a personal representative signs, their authority

Plus the three required statements in §164.508(c)(2): right to revoke, whether treatment is conditioned on signing, and the redisclosure warning. Plain language, and the patient gets a copy.

“The e-signature tool never makes a bad form valid. If the authorization is missing an expiration or the revocation statement, it is defective whether it was signed on paper or in Docusign.”

Build the form right first with the HIPAA release form generator or informed consent template, then load it as a Docusign template. Watch state-specific carve-outs: a few states still require wet or notarized signatures for advance directives and POLST forms, and psychotherapy-note releases need their own, separate authorization.

What the Docusign BAA Does — and Doesn't — Cover

The BAA follows the envelope, not the email around it. Most Docusign “breaches” in practice are ordinary email mistakes wearing a Docusign logo.

Inside the BAA

  • Envelopes and documents at rest

    AES-256 at rest, TLS in transit, inside the BAA once signed

  • Templates and stored form data

    Field values (DOB, insurance ID) are stored with the envelope

  • Certificate of Completion / audit trail

    Signer identity, IP, timestamps, authentication method

  • Recipient authentication

    Access code, SMS, phone, ID verification (enterprise features)

  • Docusign mobile app and web signing

    Same envelope, same controls

Outside the BAA

  • The patient's email inbox

    Attached PDFs and PHI in subject lines leave the BAA the moment they are sent

  • Third-party integrations

    Zapier, CRM, or EHR connectors need their own BAA (Docusign's covers Docusign only)

  • Docusign AI / agreement summaries

    Confirm in writing whether AI features are inside the BAA scope before enabling them

  • Downloads to personal devices

    A signed PDF on a staff laptop is your problem, not Docusign's

  • Personal or trial accounts

    Any envelope sent from a non-BAA account is an unauthorized disclosure

5 Mistakes That Break Docusign Compliance

None of these require a hacker. They are the ordinary HIPAA violations an e-signature tool makes faster.

Sending patient forms from a Standard or trial account

No BAA exists, so every envelope is an impermissible disclosure to a vendor. The plan's encryption is irrelevant — the Privacy Rule violation is contractual, not technical.

Fix: Move patient-facing templates to the BAA-covered account only. Delete or downgrade stray self-serve seats staff opened on their own.

Leaving completed-document email attachments on

Signed intake and history forms are emailed as PDFs to the patient and every CC. Once in a consumer inbox, you have no control and no BAA.

Fix: Uncheck “Attach documents to completion email” at the account level and re-test with a dummy envelope.

Putting the patient's name and condition in the envelope subject

Subject lines travel in ordinary email headers. “Hep C treatment consent – Maria Lopez” is a disclosure before anyone opens anything.

Fix: Use chart or reference numbers in subjects and messages. Put context inside the document.

Skipping recipient authentication to make signing “easier”

Anyone with the forwarded link can open and sign. That undermines attribution, and a disputed signature on an authorization is a disputed disclosure.

Fix: Access code at minimum; SMS or ID verification for releases of sensitive records.

Treating Docusign as the medical record

Staff leave, seats get reassigned, and retention purges run. If the only copy of a signed authorization lives in Docusign, you may not be able to produce it in year five.

Fix: Export the signed PDF plus Certificate of Completion to your EHR or document system, then let Docusign purge on schedule.

If PHI already went out as an attachment to the wrong address, work through the breach risk assessment — a misdirected signed form is a reportable breach unless you can document a low probability of compromise.

Docusign vs. HIPAA E-Signature Alternatives

The question is rarely “is Docusign secure” — it is whether you can get the BAA at a price that makes sense for your seat count. Prices are vendor list prices checked August 2026; all four change them without notice.

ToolBAAPriceBest for
Docusign eSignatureEnhanced / enterprise plan, via salesCustom quote (Business Pro lists at $45/user/mo without BAA)Health systems already on Docusign, high volume, EHR integrations
Adobe Acrobat SignEnterprise tier only, requested through sales with your account IDCustom quote; Individual and Business tiers not eligibleOrganizations standardized on Adobe with an enterprise agreement
Jotform + Jotform SignIncluded on Gold and Enterprise plans (HIPAA features toggle)Gold roughly $99/mo billed annually, as of Aug 2026Intake forms with signature fields, single-user practices
Hushmail for HealthcareIncluded on every Healthcare planE-signature plans from about $25/mo, as of Aug 2026Solo therapists and small clinics that also need encrypted email

“Under ten users and no EHR integration? A BAA-included forms tool usually beats an enterprise Docusign quote. Over fifty users with Epic or Salesforce in the mix? Docusign or Acrobat Sign earn their price.”

Quick Reference: Docusign HIPAA Compliance

Plans that qualify

Enhanced / enterprise eSignature plans with a signed BAA. Personal and Standard never; Business Pro only if sales confirms in writing.

BAA — through sales

Standard Docusign paper, request before the first envelope, keep 6 years under §164.530(j).

8 settings

No completed-doc attachments, recipient authentication, document visibility, retention/purge, clean subject lines, SSO/MFA, tight roles, export the certificate.

Signatures are valid

ESIGN/UETA make e-signed consent and §164.508 authorizations enforceable — if the form itself has every core element and statement.

Related Tools & Guides