Get HIPAA Guidance

HIPAA Confidentiality Agreement: Template & Guide

Complete template and customization guide for healthcare workforce confidentiality agreements

Quick Answer: A HIPAA confidentiality agreement is a legally binding document that employees sign acknowledging their responsibility to protect PHI. It's required for workforce members with access to patient data.

What Is a HIPAA Confidentiality Agreement?

A HIPAA confidentiality agreement (also called a Non-Disclosure Agreement or NDA) is a legally binding contract between an employee and a healthcare organization that:

Legal Requirement: While HIPAA doesn't explicitly require written confidentiality agreements, they are considered a best practice and provide legal protection for organizations. Many state laws and organizational policies mandate them.

Essential Components of a Confidentiality Agreement

1. Definition Section

2. Acknowledgment of Access

3. Confidentiality Obligations

4. Permitted Disclosures

5. Security Responsibilities

6. Consequences & Remedies

7. Duration

Complete HIPAA Confidentiality Agreement Template

HIPAA CONFIDENTIALITY AND NONDISCLOSURE AGREEMENT

This Agreement is entered into on ________________ (date) by and between:

[ORGANIZATION NAME] ("Organization")

AND

[EMPLOYEE NAME] ("Employee")

RECITALS:

WHEREAS, the Organization is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations; and

WHEREAS, in the course of performing Employee's duties, Employee will have access to Protected Health Information (PHI) and other confidential information; and

WHEREAS, it is necessary to protect the privacy and security of such information.

NOW, THEREFORE, in consideration of employment and other valuable consideration, the parties agree as follows:

1. DEFINITIONS

"Protected Health Information" or "PHI" means any information in a medical record or health plan that can be used to identify an individual patient, including name, address, Social Security Number, date of birth, and medical history or diagnoses.

"Confidential Information" means all PHI and other non-public information about patients, employees, and the Organization's operations.

2. ACKNOWLEDGMENT OF ACCESS

Employee acknowledges that in performing duties as [JOB TITLE], Employee will have access to PHI and other Confidential Information. Employee understands the sensitive and private nature of this information.

3. CONFIDENTIALITY OBLIGATIONS

Employee agrees to:

  • Maintain the confidentiality of all PHI and Confidential Information
  • Not disclose PHI to any unauthorized person or entity
  • Use PHI only for authorized purposes related to Employee's job duties
  • Follow all organizational policies and procedures regarding information security
  • Comply with all applicable HIPAA regulations and requirements

4. PERMITTED USES AND DISCLOSURES

Employee may access PHI only:

  • To the extent necessary to perform assigned job duties
  • For direct patient care purposes
  • For treatment, payment, and healthcare operations (TPO)
  • As specifically authorized by the Organization
  • As required by law

5. SECURITY MEASURES

Employee agrees to:

  • Protect the confidentiality and security of all PHI
  • Use unique user ID and password credentials
  • Never share passwords or login credentials with others
  • Lock workstations when away
  • Report any security incidents or unauthorized access immediately
  • Comply with all information technology security policies

6. INCIDENT REPORTING

Employee agrees to immediately report any suspected or actual unauthorized access, use, or disclosure of PHI to the Organization's Privacy Officer or Security Officer.

7. DURATION AND SURVIVAL

This Agreement begins on the Employee's start date and continues during the term of employment. The confidentiality obligations survive termination of employment indefinitely. Upon termination, Employee shall return all Confidential Information and PHI to the Organization.

8. CONSEQUENCES OF VIOLATION

Violation of this Agreement may result in:

  • Disciplinary action, up to and including termination of employment
  • Monetary damages and legal action
  • Reimbursement of costs associated with breach notification
  • Criminal penalties under HIPAA and applicable state laws

9. ACKNOWLEDGMENT

Employee acknowledges that:

  • Employee has read and understands this Agreement
  • Employee understands the importance of protecting PHI
  • Employee understands the penalties for violations
  • Employee agrees to comply with all terms

IN WITNESS WHEREOF, the parties have executed this Agreement as of the date first written above.

ORGANIZATION:
_______________________
Authorized Representative

EMPLOYEE:
_______________________
Employee Signature

_______________________
Employee Printed Name

_______________________
Date

Customization Tips for Your Organization

Role-Specific Additions

State Law Considerations

Important: Some states have additional requirements for confidentiality agreements in healthcare. Consult with legal counsel to ensure compliance with your state's laws, particularly regarding:

  • Non-compete clauses (some states restrict these)
  • Non-solicitation of patients/colleagues
  • Specific language about patient records ownership
  • State-specific privacy laws beyond HIPAA

Additional Provisions to Consider

Implementation Best Practices

Signing and Documentation

Training Integration

Ongoing Compliance

Frequently Asked Questions

Q: Is a written confidentiality agreement legally required by HIPAA?
A: While HIPAA doesn't explicitly require a written agreement, 45 CFR 164.308(a)(3) requires organizations to implement workforce policies and procedures. A written agreement is the best practice for documenting these policies and proving compliance. It also provides legal protection if disputes arise.
Q: Can we use a generic confidentiality agreement or must it be HIPAA-specific?
A: While a generic agreement is better than nothing, a HIPAA-specific agreement is strongly recommended. It demonstrates awareness of HIPAA requirements, specifically addresses PHI obligations, and provides better legal protection. Generic agreements often lack necessary HIPAA language.
Q: What happens if we don't have signed confidentiality agreements?
A: You lack documented evidence that employees understood their confidentiality obligations. In a HIPAA enforcement action or breach investigation, absence of signed agreements undermines your defense. OCR may cite this as a violation of workforce training and policy requirements.
Q: Should contractors and temporary staff sign separate agreements?
A: Yes. Contractors and third-party service providers should either sign a confidentiality agreement or a Business Associate Agreement (BAA), depending on their role. Temporary staff accessing PHI should sign the same agreement as permanent employees.

Get Compliance-Ready Templates

Medcurity provides customizable HIPAA confidentiality agreement templates and legal guidance for healthcare organizations.

Access Templates