Customers are responsible for implementing appropriate privacy and security safeguards within Adobe Acrobat Sign Solutions, discussed further below, in order to protect Protected Health Information (PHI) in compliance with HIPAA.
The HIPAA readiness capability is only available through an Acrobat Sign Solutions for enterprise subscription plan.
Not all enterprise accounts will qualify for enablement.
The process starts with signing a HIPAA Business Associate Agreement (BAA).
Once the BAA is signed, Acrobat Sign Solutions will adjust back-end settings that will cause the HIPAA Compliance setting on the Global Settings page to show as checked, indicating that it is enabled.
Note that this setting is view only and never editable by the customer admin.
This article is meant for customers who have a BAA in place with Acrobat Sign Solutions. Customers that do not have a BAA may not enable this setting.
The following are general security recommendations from Adobe to harden your Acrobat Sign Solutions account for use with PHI data.
It is the customer's responsibility to consider these and all other Acrobat Sign Solutions security features and apply them as needed to protect the electronic protected health information (ePHI) stored in Acrobat Sign Solutions.
It is strongly recommended that the account use SAML/Federated authentication.
Accounts that manage their users within the Acrobat Sign Solutions web application (not going through the Adobe Admin Console or SAML) should configure strong authentication controls.
Log in as an account-level admin and:
Email is generally considered a less secure medium when sending electronic personal health information as there are several ways that notifications can be a source of ePHI leakage.
Keep in mind that the name of the agreement is listed in the notification, so patient information (eg, names) should never be used in the title of the agreement.
Additionally, the agreement itself contains ePHI, and so attaching the agreement to the notifications can expose ePHI if the email is intercepted.
Do not use personal information in the file names of Acrobat Sign Solution agreements.
Completed agreements need to be secured, whether viewed as PDFs or online.
We strongly recommend that account administrators review the other security settings in Account Settings > Security Settings
Before processing protected health information through Acrobat Sign Solutions, your organization must enter into a Business Associate Agreement (BAA) with Adobe.
Contact your sales or channel representative to determine eligibility and establish a BAA with Adobe.
When contacting your sales or channel representative regarding BAA eligibility, you must include the Account ID for your Acrobat Sign Solutions account. The Account ID can be found in the Global Settings section of the account-level admin menu:
After the BAA is accepted and executed, the check box for linking the BAA will be checked, and your account will be enabled.