Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Compliance Operations

Is DocuSign HIPAA Compliant? Yes, Through Sales

Docusign acts as a business associate for eSignature documents containing PHI, with a BAA. Its pricing puts HIPAA support behind Contact sales, not a self-service plan.

Patient ProtectPatient Protect Editorial Team·March 25, 2026·7 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
DocuSign HIPAA compliance requirements for healthcare electronic signatures

Docusign can be used in HIPAA-regulated workflows with an executed Business Associate Agreement and the right settings in place. On Docusign's published pricing comparison, HIPAA support through a BAA is marked "Does Not Include" against Personal, Standard and Business Pro, and "Contact sales" against the fourth column — so those three self-service plans are not a route to PHI.

DocuSign's current position: HIPAA support requires a BAA-enabled arrangement that customers request through DocuSign sales rather than self-serve at checkout. If your practice uses DocuSign for consent forms, treatment authorizations, or any document containing protected health information, an executed BAA under a qualifying offering is what determines whether that use is compliant.

What DocuSign Provides for HIPAA Compliance

With an executed BAA in place, Docusign provides security features that align with HIPAA's technical safeguard requirements:

  • BAA execution. Available only through a DocuSign sales-managed HIPAA-enabled offering. Covers the signing workflow, document storage, and audit trail. Must be signed before any PHI enters the platform.
  • AES-256 encryption at rest. Documents stored in DocuSign are encrypted using AES-256, meeting the HIPAA standard for data at rest.
  • TLS encryption in transit. Data between signers' devices and DocuSign's servers is encrypted via TLS, protecting PHI during the signing process.
  • Detailed audit trail. Every envelope generates a Certificate of Completion recording who signed, when, their IP address, and the authentication method used — supporting HIPAA's audit control requirements under 45 CFR § 164.312(b).
  • Document retention controls. Administrators can configure retention windows and purging schedules that align with HIPAA requirements.
  • Role-based access controls. Administrators can restrict which users send, view, or manage envelopes containing PHI.

These features provide the technical foundation. Having them available and having them correctly configured are two different things.

Plans That Qualify

On Docusign's published eSignature pricing comparison, HIPAA support through a BAA reads "Does Not Include" against Personal, Standard and Business Pro, and "Contact sales" against the fourth column. So the route is a conversation with Docusign rather than a plan you select at checkout. What Docusign does not publish is a named HIPAA package, a minimum contract value or a required term — if someone tells you the answer is a specific tier, ask them to show you where Docusign says so.

Personal, Standard, and Business Pro do not include HIPAA BAA support. If anyone in your practice sends patient documents through one of these self-serve plans, that is a HIPAA violation regardless of how the document is structured.

Visit DocuSign's pricing page for the current published tiers and Contact Sales for HIPAA-eligible offerings.

Settings to Configure

Signing the BAA is step one. These settings must be addressed before sending any envelope containing PHI:

  • Execute the BAA first. Contact DocuSign sales or access the BAA through your account's administrative settings. This must be signed before any document containing patient information is created, sent, or stored.
  • Configure PowerForms access controls. If you use PowerForms — self-service signing links on your website — ensure forms containing PHI are not publicly indexable or shareable without controls.
  • Set document retention policies. HIPAA requires compliance documentation be maintained for a minimum of six years. Ensure automated purging does not delete PHI-containing documents before that window closes.
  • Restrict sharing and forwarding. Disable envelope delegation and forwarding for documents containing PHI.
  • Enable SSO if available. On Enterprise plans, configure SAML-based single sign-on and require multi-factor authentication for all users.
  • Keep PHI out of email notifications. If an envelope subject line reads "Consent Form — Jane Doe — Anxiety Treatment," that PHI appears in unencrypted email. Use generic subject lines and keep clinical details inside the document.

Common Healthcare Uses for DocuSign

Practices commonly use DocuSign for documents that contain or reference PHI:

  • Patient consent forms — informed consent for treatment, procedure-specific consents, and general consent to treat.
  • HIPAA acknowledgments — Notice of Privacy Practices forms that patients sign confirming receipt of your NPP.
  • BAAs with vendors — Business Associate Agreements with IT companies, billing services, and cloud vendors.
  • Treatment authorization forms — prior authorizations, referral forms, and release-of-information authorizations containing patient identifiers and diagnoses.
  • Employment agreements with confidentiality clauses — workforce confidentiality agreements, onboarding documents, and HIPAA training acknowledgments.

Every one of these document types can contain PHI. If they are processed through DocuSign, the platform must be operating under a signed BAA on a qualifying plan.

Common Mistakes

These errors create real compliance exposure — and they happen frequently in practices that adopted DocuSign before considering HIPAA.

Using Personal, Standard, or Business Pro for patient documents. The most common mistake. Docusign's own pricing marks HIPAA support through a BAA as not included on those three, so a consent form sent through one of them travels without an agreement behind it.

Assuming a paid plan automatically includes the BAA. On Docusign's published pricing, no self-service column — Business Pro included — shows HIPAA support through a BAA. The agreement has to be arranged with Docusign and executed before any PHI enters the platform.

Including PHI in email notification previews. If the envelope subject reads "Consent Form — Jane Doe — Anxiety Treatment," that PHI appears in unencrypted email. Keep clinical details inside the document.

Not restricting access to completed documents. If access controls are too permissive, staff who do not need access to specific patient documents can view them — violating the minimum necessary standard.

Where Electronic Signatures Fit in Your Compliance Program

If you are choosing between platforms, the compliance question is narrower than it looks: both major options put HIPAA support behind a sales conversation, so compare them on workflow and integration and treat the BAA as a step in either path. Adobe Acrobat Sign is the other side of that comparison. Before you sign anything, what a BAA has to contain is what to read the draft against — particularly whether it names the specific product and the storage that goes with it.

Electronic signatures are one workflow in your practice's data flow — not your compliance program. Getting DocuSign configured correctly covers a single vendor in what is typically a stack of 8 to 15 systems that touch patient data.

You still need a documented risk assessment, written policies, workforce training, vendor management across every business associate, and an incident response plan. Each is a separate HIPAA requirement. None are optional.

Patient Protect tracks your full compliance state — including vendor BAAs, data flows, risk assessments, staff training, and policy documentation — in a single platform built for independent practices. Plans start at $39/month with no long-term contracts.

Frequently Asked Questions

Which DocuSign plan is HIPAA compliant?

Business Pro and Enterprise. These are the only plans where DocuSign will execute a BAA and where the necessary administrative controls are available. Personal and Standard plans do not qualify regardless of configuration.

Does DocuSign sign a BAA?

Yes — but only for Business Pro and Enterprise plans. The BAA covers signing workflows, document storage, and the audit trail. You must request and execute it before transmitting any PHI. It is not automatic with plan purchase.

Can I use DocuSign for patient consent forms?

Yes, on a Business Pro or Enterprise plan with a signed BAA, configured to keep PHI out of email notifications and restrict document access to authorized users. The right plan without proper configuration is not sufficient.

Is DocuSign's audit trail sufficient for HIPAA?

DocuSign's Certificate of Completion records who signed, when, their IP address, and authentication method — satisfying the audit trail for the signing workflow. Your overall HIPAA audit obligations extend beyond any single vendor.

What about Adobe Sign as an alternative?

Adobe Acrobat Sign offers BAA execution on certain business plans. Visit Adobe's website to review current BAA availability and qualifying plans. Evaluate each platform against your specific workflow requirements. The same evaluation applied across the other categories a practice buys is which tools can hold patient information.

Can I use the free DocuSign trial for patient documents?

No. Trial accounts do not include a BAA and are not eligible for HIPAA compliance. Use test data with no real patient information until you have a qualifying paid plan and an executed BAA.


Patient Protect tracks your full compliance state, including vendor BAAs and electronic signature configurations, starting at $39/month.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA