HIPAA Confidentiality Agreement: Template & Guide
Complete template and customization guide for healthcare workforce confidentiality agreements
What Is a HIPAA Confidentiality Agreement?
A HIPAA confidentiality agreement (also called a Non-Disclosure Agreement or NDA) is a legally binding contract between an employee and a healthcare organization that:
- Acknowledges the employee's access to Protected Health Information (PHI)
- Defines the employee's obligations under HIPAA
- Specifies confidentiality requirements and permitted uses
- Outlines consequences for unauthorized disclosure
- Establishes duty to report security incidents
- Applies during employment and after termination
Legal Requirement: While HIPAA doesn't explicitly require written confidentiality agreements, they are considered a best practice and provide legal protection for organizations. Many state laws and organizational policies mandate them.
Essential Components of a Confidentiality Agreement
1. Definition Section
- Definition of PHI and Protected Health Information
- Definition of "Confidential Information"
- Clarification of what information is covered
- Examples of information (medical records, demographic data, etc.)
2. Acknowledgment of Access
- Employee acknowledges they will access PHI in their role
- Specific types of PHI they may encounter
- Scope of data they may access
- Confirmation of understanding of sensitivity
3. Confidentiality Obligations
- Duty to maintain confidentiality of PHI
- Restriction on disclosure to unauthorized individuals
- Limitation of use to job duties (minimum necessary principle)
- Protection measures required (passwords, physical security, etc.)
4. Permitted Disclosures
- Disclosures permitted for patient care purposes
- Disclosures for treatment, payment, and operations (TPO)
- Disclosures required by law
- Disclosures to authorized supervisors and managers
5. Security Responsibilities
- Duty to follow security policies and procedures
- Requirement to use unique passwords
- Responsibility for physical security
- Obligation to report security incidents
6. Consequences & Remedies
- Disciplinary action for violations (up to termination)
- Potential legal liability for unauthorized disclosure
- Reference to HIPAA penalties and enforcement
- Organization's right to injunctive relief
7. Duration
- Agreement duration (during employment and after)
- Survival clause for post-employment obligations
- Return of confidential information procedures
Complete HIPAA Confidentiality Agreement Template
HIPAA CONFIDENTIALITY AND NONDISCLOSURE AGREEMENT
This Agreement is entered into on ________________ (date) by and between:
[ORGANIZATION NAME] ("Organization")
AND
[EMPLOYEE NAME] ("Employee")
RECITALS:
WHEREAS, the Organization is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations; and
WHEREAS, in the course of performing Employee's duties, Employee will have access to Protected Health Information (PHI) and other confidential information; and
WHEREAS, it is necessary to protect the privacy and security of such information.
NOW, THEREFORE, in consideration of employment and other valuable consideration, the parties agree as follows:
1. DEFINITIONS
"Protected Health Information" or "PHI" means any information in a medical record or health plan that can be used to identify an individual patient, including name, address, Social Security Number, date of birth, and medical history or diagnoses.
"Confidential Information" means all PHI and other non-public information about patients, employees, and the Organization's operations.
2. ACKNOWLEDGMENT OF ACCESS
Employee acknowledges that in performing duties as [JOB TITLE], Employee will have access to PHI and other Confidential Information. Employee understands the sensitive and private nature of this information.
3. CONFIDENTIALITY OBLIGATIONS
Employee agrees to:
- Maintain the confidentiality of all PHI and Confidential Information
- Not disclose PHI to any unauthorized person or entity
- Use PHI only for authorized purposes related to Employee's job duties
- Follow all organizational policies and procedures regarding information security
- Comply with all applicable HIPAA regulations and requirements
4. PERMITTED USES AND DISCLOSURES
Employee may access PHI only:
- To the extent necessary to perform assigned job duties
- For direct patient care purposes
- For treatment, payment, and healthcare operations (TPO)
- As specifically authorized by the Organization
- As required by law
5. SECURITY MEASURES
Employee agrees to:
- Protect the confidentiality and security of all PHI
- Use unique user ID and password credentials
- Never share passwords or login credentials with others
- Lock workstations when away
- Report any security incidents or unauthorized access immediately
- Comply with all information technology security policies
6. INCIDENT REPORTING
Employee agrees to immediately report any suspected or actual unauthorized access, use, or disclosure of PHI to the Organization's Privacy Officer or Security Officer.
7. DURATION AND SURVIVAL
This Agreement begins on the Employee's start date and continues during the term of employment. The confidentiality obligations survive termination of employment indefinitely. Upon termination, Employee shall return all Confidential Information and PHI to the Organization.
8. CONSEQUENCES OF VIOLATION
Violation of this Agreement may result in:
- Disciplinary action, up to and including termination of employment
- Monetary damages and legal action
- Reimbursement of costs associated with breach notification
- Criminal penalties under HIPAA and applicable state laws
9. ACKNOWLEDGMENT
Employee acknowledges that:
- Employee has read and understands this Agreement
- Employee understands the importance of protecting PHI
- Employee understands the penalties for violations
- Employee agrees to comply with all terms
IN WITNESS WHEREOF, the parties have executed this Agreement as of the date first written above.
ORGANIZATION:
_______________________
Authorized Representative
EMPLOYEE:
_______________________
Employee Signature
_______________________
Employee Printed Name
_______________________
Date
Customization Tips for Your Organization
Role-Specific Additions
- Clinical Staff: Add specific patient care scenarios and Electronic Health Record (EHR) access limitations
- Administrative Staff: Specify which databases and systems they may access
- IT Staff: Include security maintenance responsibilities and audit compliance
- Contractors/Vendors: Require Business Associate Agreement (BAA) instead of or in addition to this agreement
State Law Considerations
Important: Some states have additional requirements for confidentiality agreements in healthcare. Consult with legal counsel to ensure compliance with your state's laws, particularly regarding:
- Non-compete clauses (some states restrict these)
- Non-solicitation of patients/colleagues
- Specific language about patient records ownership
- State-specific privacy laws beyond HIPAA
Additional Provisions to Consider
- Non-Compete Clause: Restrict former employees from competing in the same market (if enforceable in your state)
- Non-Solicitation: Prevent solicitation of patients and staff
- Intellectual Property: Address ownership of work products and innovations
- Social Media: Restrict disclosure of organizational or patient information on social media
- Bring Your Own Device (BYOD): Specify security requirements for personal devices accessing PHI
Implementation Best Practices
Signing and Documentation
- Obtain signature before employee accesses any PHI
- Maintain original signed agreement in personnel file
- Provide a copy to the employee
- Update agreement when HIPAA policies change
- Require re-signature if changes are material
Training Integration
- Review agreement during onboarding training session
- Discuss specific confidentiality responsibilities in role context
- Provide examples of what constitutes unauthorized disclosure
- Clarify permitted vs. prohibited disclosures
- Explain incident reporting procedures
Ongoing Compliance
- Include agreement review in annual HIPAA refresher training
- Monitor compliance through audits and access reviews
- Enforce against violations consistently
- Update agreement when organizational policies change
- Document all signed agreements in compliance records
Frequently Asked Questions
Get Compliance-Ready Templates
Medcurity provides customizable HIPAA confidentiality agreement templates and legal guidance for healthcare organizations.
Access Templates