---
title: HIPAA-compliant eSignatures | Blog | SigningHub™
description: Does your organisation require HIPAA-compliant eSignatures? See how SigningHub delivers electronic signatures with compliance in mind. Learn more:
image: https://blog.ascertia.com/hubfs/blog-migration/HIPPA%20Compliant.jpg
---

[![](https://blog.ascertia.com/hubfs/asc-blog-logo-detail.png)](https://blog.ascertia.com/)

##### [View all posts](https://blog.ascertia.com/)

[Contact Us](https://www.ascertia.com/company/contact-us/)

# How SigningHub implements HIPAA-compliant security standards

Posted by [Pieter Rensburg](https://blog.ascertia.com/author/pieter-rensburg) on Jan 2, 2018, 7:37:24 AM

![](https://blog.ascertia.com/hubfs/Pieter%20Rensburg-HS-Profile-Picture-299261546.jpg)

In this blog, we discuss how SigningHub implements HIPAA-compliant eSignatures.

What is HIPAA?

HIPAA (Health Insurance Portability and Accountability Act of 1996) is a United States legislation that provides data privacy and security provisions for safeguarding medical information.

![How SigningHub implements HIPAA compliant security standards](https://cdn2.hubspot.net/hub/511375/hubfs/HIPPA%20Compliant.jpg?width=1024&name=HIPPA%20Compliant.jpg "How SigningHub implements HIPAA compliant security standards")

Follow this quick check list to know how SigningHub implements HIPAA compliant security standards. The below is extracted from: [https://www.ihs.gov/hipaa/documents/IHS\_HIPAA\_Security\_Checklist.pdf](https://www.ihs.gov/hipaa/documents/IHS_HIPAA_Security_Checklist.pdf)

More details can be found [here](http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf)

 

.

 

| Clause | Description | Supported? | Details |
| --- | --- | --- | --- |
| 164.312(a)(2)(i) | Have you assigned a unique name and/or number for identifying and tracking user identity? | Yes | Each SigningHub account holder has a unique ID (generally an email address) to access SigningHub. All user activities and actions are tracked using this. |
| 164.312(a)(2)(ii) | Have you established (and implemented as needed) procedures for obtaining the necessary ePHI during an emergency? | Yes | SigningHub is deployed on Azure cloud which is fully HIPAA compliant. In case of any disaster, SigningHub is automatically re-located by Azure to ensure access. Learn more [here](https://www.microsoft.com/en-us/TrustCenter/Compliance/HIPAA). |
| 164.312(a)(2)(iii) | Have you implemented procedures that terminate an electronic session after a predetermined time of inactivity? | Yes | Yes, after 15 minutes of inactivity SigningHub prompts the user to terminate the session and then logs the user out after a further one minute of inactivity. |
| 164.312(a)(2)(iv) | Have you implemented a mechanism to encrypt and decrypt ePHI? | Yes | All communication between a browser and the SigningHub server is protected with SSL/TLS. We only support strong SSL versions (TLS 1.0 onwards) and strong ciphers. Check our rating from Qualys SSL Labs [here](https://www.ssllabs.com/ssltest/analyze.html?d=signinghub.com). Also, all documents are encrypted using AES 256 before being storing in the database. |
| 164.312(b) | Have you implemented Audit Controls, hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI? | Yes | SigningHub creates secure logs and workflow evidence reports which provide complete tracking of which activity was performed and when. The workflow evidence [report is also digitally signed](https://www.signinghub.com/digital-signatures/) recording who, when, where, how and what was performed on a document. Click [here](http://manuals.ascertia.com/SigningHubv7/#pageid=1130) to find out more information. Separately, SigningHub maintains operator logs letting auditors examine staff activities. |

 

**164.312(c)(1) - Integrity**

 

| Clause | Description | Supported? | Details |
| --- | --- | --- | --- |
| 164.312(c)(2) | Have you implemented electronic mechanisms to corroborate that EPHI has not been altered or destroyed in an unauthorised manner? | Yes | SigningHub signatures are cryptographically protected - any change in the document after signing is easily identified within SigningHub and also using third party free software like Adobe Acrobat Reader. Click [here](https://www.signinghub.com/security/) to know more about SigningHub's security functions - it uses a secure crypto engine (ADSS Server) which auto-detects any data alteration and notifies administrators. |
| 164.312(d) | Have you implemented Person or Entity Authentication procedures to verify that a person or entity seeking access to ePHI is the one claimed to be? | Yes | SigningHub provides multiple authentication options including two factor authentication before the user or entity is authorised to view and sign the document. These include: - SigningHub ID (email/password) - Smart Cards (SSL Client) - One Time Password - Active Directory - SAML - Salesforce - Office 365 - Entrust IDG - Freja Mobile - Linked In - Ubisecure In the case of One Time Passwords, note that this doesn't contain any Protected Health Information as well rather only one time codes. More details on ePHI can be found [here](http://www.hipaa.com/hipaa-protected-health-information-what-does-phi-include/). |

 

 

**164.312(e)(1) - Transmission Security**

 

| Clause | Description | Supported? | Details |
| --- | --- | --- | --- |
| 164.312(e)(2)(i) | Have you implemented security measures to ensure that electronically transmitted ePHI is not improperly modified without detection until disposed of? | Yes | - All communication between the browser and SigningHub server is over secure TLS - All documents are encrypted before stored - All external communication with other identity providers is on TLS - User can configure to avoid sending any document via email - SigningHub adheres to EU data protection directive hence no data is exported out of Europe. Read more PII information [here](https://blog.signinghub.com/eu-us-data-transfer-deal-reached-a-safe-harbor) |
| 164.312(e)(2)(ii) | Have you implemented a mechanism to encrypt EPHI whenever deemed appropriate? | Yes | See above. |

[Visit Ascertia.com](https://www.ascertia.com/)

This is a search field with an auto-suggest feature attached.

 Search

- There are no suggestions because the search field is empty.

### Recent Posts

### Posts by Topic

- [News (64)](https://blog.ascertia.com/tag/news)
- [Digital Trust (52)](https://blog.ascertia.com/tag/digital-trust)
- [Esignatures & Digital Signatures (41)](https://blog.ascertia.com/tag/esignatures-digital-signatures)
- [Case Study (32)](https://blog.ascertia.com/tag/case-study)
- [Esignatures, Digital Signatures & Digital Signing (25)](https://blog.ascertia.com/tag/esignatures-digital-signatures-digital-signing)
- [Remote Signing (21)](https://blog.ascertia.com/tag/remote-signing)
- [Ascertia Partners (16)](https://blog.ascertia.com/tag/ascertia-partners)

### Subscribe to Blog

### Download this essential eBook

Choosing the right type of e-signature  
for your business

[![Download your eBook](https://no-cache.hubspot.com/cta/default/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8.png)](https://cta-redirect.hubspot.com/cta/redirect/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8)

- Signing
- EU eIDAS Compliant Advanced & Qualified Signatures
- [SigningHub](https://www.ascertia.com/products/signinghub/)
- [ADSS Signing Server](https://www.ascertia.com/products/adss-signing-server/)

- PKI
- Modular solution for your Trust Service needs
- [ADSS Certificate Authority](https://www.ascertia.com/products/adss-ca-pki-server/)
- [ADSS Registration Authority](https://www.ascertia.com/products/adss-ra-server/)
- [ADSS Validation Authority](https://www.ascertia.com/products/adss-ocsp-server/)
- [ADSS Time Stamp Authority](https://www.ascertia.com/products/adss-tsa-server/)
- [ADSS Archive Authority](https://www.ascertia.com/products/adss-ltans-evidence-server/)

- Tools
- Integrate, test & monitor your Trust Services
- [ADSS Auto File Processor](https://www.ascertia.com/products/adss-auto-file-processor/)
- [ADSS Client SDK](https://www.ascertia.com/products/adss-client-sdk/)

- Solutions
- [Mobile Signatures](https://www.ascertia.com/solutions-by-technology/mobile-signing/)
- [Remote (Cloud) Signing](https://www.ascertia.com/solutions-by-technology/remote-signing/)
- <https://www.linkedin.com/company/ascertia> <https://www.youtube.com/user/ESIGNwithAscertia>

[Terms of Use](https://www.ascertia.com/terms-of-use/)   |   [Privacy Policy](https://www.ascertia.com/company/privacy-policy/)   |   © Ascertia. All rights reserved. ISO 9001:2015 Certified