HIPAA-compliant eSignature workflows with signNow
Maintaining HIPAA compliance is easy with signNow
Two-factor signer authentication
SignNow allows document senders to authenticate the identity of a signer via a text message or phone call. SignNow also authenticates all senders when they enter the system.
Data encryption
SignNow delivers industry-leading data confidentiality with the NSA-developed SHA-256 encryption algorithm for documents. It protects transfers between you and another person, you and a server, and against external access.
Valid Audit Trail
SignNow creates and maintains a detailed document history that displays all document activity including the method of authentication, signatories actions, email and IP addresses, and time stamps.
HIPAA-compliant data storage
SignNow stores your documents in US-based Amazon S3 data centers, which set the industry standard for HIPAA-compliant security for data storage and protection against breaches.
Tamper-proof controls
SignNow employs anti-tamper technologies, including security system controls and signature certificates to ensure that your documents can not be altered once signed.
Disaster recovery plan
SignNow’s Disaster Recovery Plan ensures continuous operations with minimal interruptions in the case of an emergency. This includes procedures to preserve documents and document security.
Access controls
SignNow system of access controls ensures that access granted to each environment is appropriate and authorized. This includes defined processes, clear segregation of duties, appropriate approvals, audit trails, and access reviews.
Incident detection and response
SignNow infosecurity team promptly evaluates and responds to incidents that create suspicion of or indicate unauthorized access to or handling of services and information.
Vulnerability testing
SignNow information security team performs internal vulnerability scanning and retains external subject matter experts to conduct penetration tests. We have developed processes and tools that ensure timely identification and remediation of security vulnerabilities that could impact the product or physical security.
Business Associate Agreement
Contact us to sign your BAAJoin companies that speed up processes with signNow






Connect signNow with your apps
Healthcare professionals trust signNow

Enterprise-grade security and compliance
GDPR compliance
SOC 2 Type II Certified
PCI DSS certification
21 CFR Part 11
HIPAA compliance
CCPA compliance
-
Information security. We conduct regular risk management reviews, performance auditing, risk classification, and guidance.
-
Vulnerability testing. We perform internal vulnerability scanning and retain external subject matter experts to conduct penetration tests.
-
Access control. signNow’s system of access controls ensures that access granted to each environment is appropriate and authorized.