Este sitio está disponible en español.Ver en español
All posts
HealthcareSeptember 22, 2026·12 min read

Healthcare Contract Red Flags: What to Check Before You Sign

A healthcare contract covers more ground than most people expect, patient service terms, a business associate agreement, a physician employment or practice agreement, a telemedicine consent form. Each type carries its own risk, and the language that protects the practice or platform is written in well before you ever see a draft. Here are the thirteen provisions worth reading closely before you sign.

Healthcare paperwork tends to arrive in a stack, alongside insurance forms, intake questionnaires, and a consent form you are handed at the front desk. It is easy to treat all of it as procedure rather than as a set of contracts, each with its own terms. A patient service agreement, a provider employment contract, and a HIPAA business associate agreement are three different documents with three different sets of stakes, and none of them is boilerplate in the sense of being interchangeable with any other industry.

The checklist below covers thirteen provisions that appear across these document types, roughly in the order a careful reader checks them. Several of the items below turn on state law or on the specific type of provider or platform involved, so this checklist tells you what to look for and where the variation lives, rather than asserting one rule that covers every state and every kind of healthcare relationship.

1. Liability Waivers and What They Actually Cover

A liability waiver, sometimes labeled an assumption of risk or a release, is meant to acknowledge that a medical procedure or treatment carries inherent risk even when performed correctly. What it should not do, and what many states will not enforce even if the document says otherwise, is release the provider from liability for gross negligence or willful misconduct. A waiver written broadly enough to cover ordinary negligence, and in some states even that is limited, is worth reading closely rather than signing as a formality.

The scope of the waiver matters as much as its existence. A waiver naming the specific procedure and its known risks is a normal part of informed consent. A waiver phrased broadly enough to cover any injury from any cause during your time at the practice is a different, much larger release, and the two are easy to confuse at a glance.

What a reasonable version looks like: a waiver scoped to the specific procedure and its disclosed risks, with no language purporting to excuse gross negligence or willful misconduct, since most states will not enforce that regardless of what the page says.

2. Informed Consent Scope

An informed consent form is supposed to describe the specific procedure, its material risks, the reasonable alternatives, and what happens if you decline treatment, in language you can actually understand before you agree to it. A form that names the procedure in general terms but omits the risks specific to your situation, or that bundles consent for a whole category of future treatment into a single signature, gives you less information than informed consent is meant to provide.

Watch in particular for a consent form that also authorizes something beyond the immediate procedure, a broader research use of your data, or a standing authorization for future related treatments without a new consent each time. Those uses deserve their own separate, clearly labeled consent rather than a line buried inside a procedure-specific form.

What a reasonable version looks like: a consent form naming the specific procedure, its material risks, and the alternatives, with any additional use of your information or standing authorization for future treatment called out separately rather than folded into the same signature.

3. HIPAA Business Associate Agreement Presence

If a vendor, billing service, cloud storage provider, or telemedicine platform will see, store, or process protected health information on behalf of a covered provider, federal law requires a business associate agreement between them, a separate contract governing exactly how that vendor may use and protect the data. A services contract that involves handling patient information but includes no business associate agreement, or folds a thin version of one into a single boilerplate clause, is missing a document the relationship is required to have.

Read what the business associate agreement actually requires the vendor to do: specific security safeguards, a limit on further disclosure, and a commitment to assist with a patient access or deletion request. A business associate agreement that only restates the statute in general terms, with no specific security or breach commitments, gives you little to point to if something goes wrong.

What a reasonable version looks like: a standalone business associate agreement, or an equivalent, clearly labeled section, that names specific security safeguards and a defined process for a patient data request, not a single sentence acknowledging HIPAA applies.

4. Breach Notification Timeline

Federal law sets an outer limit for notifying affected patients after a breach of unsecured protected health information, but a business associate agreement can, and often should, set a tighter internal deadline for the vendor to notify the covered provider, since the provider still has to notify patients within the federal window and needs time to do it. A business associate agreement silent on this internal timeline, or one that gives the vendor as long as the law allows before telling the provider anything, leaves little room to actually meet the patient-facing deadline.

What a reasonable version looks like: a specific internal notification deadline from the vendor to the provider, meaningfully shorter than the outer statutory limit, so the provider has real time left to notify patients within it.

5. Non-Compete Radius and Duration for Practitioners

A physician, dentist, or other licensed practitioner signing an employment or practice agreement will often find a non-compete clause restricting where they can practice, for how long, and within what radius of the current location, after the relationship ends. Non-compete enforceability for healthcare practitioners specifically varies a great deal by state, separate from the general non-compete rules that apply to other kinds of employment, and several states restrict or bar them for licensed medical providers even where they allow non-competes more broadly. Check the specific rule in the state where you will practice rather than assuming the general non-compete landscape applies.

Where a non-compete is enforceable, the radius and duration should be proportionate to where the practice actually draws patients from and how long it takes a departing provider’s patient relationships to naturally transfer, not a wide multi-county restriction applied by default from a template.

What a reasonable version looks like: a radius and duration proportionate to the practice’s actual patient draw, and confirmation of the specific rule for licensed practitioners in the state where you will practice, since that rule can differ from the general non-compete rule in the same state.

6. Insurance Assignment and Billing Terms

An insurance assignment clause lets the provider bill your insurer directly and collect payment on your behalf, rather than billing you and leaving you to seek reimbursement. Read what the agreement says happens if the insurer pays less than billed, denies the claim, or delays payment past a stated window, since some agreements make you responsible for the full remaining balance immediately, while others build in an appeals period or a payment plan before that balance comes due.

For a provider-side agreement with a payer or a billing service, check the fee schedule reference, the timely filing deadline for submitting claims, and who bears the cost of a clawback if the payer later determines a claim was paid in error. A clawback provision with no time limit at all can leave a claim reopened years after it was paid.

What a reasonable version looks like: a clear statement of what happens on a partial payment or denial, including any appeals or payment-plan period before the full balance is due, and, on the provider side, a defined and reasonable clawback window rather than an open-ended one.

7. Termination and Patient Record Transition

When a provider agreement ends, whether the provider is leaving a practice or the practice is closing a location, patients need a way to get their records and continue care without a gap. Read what the agreement requires: a notice period to patients, a defined process for transferring or copying records, and who bears the cost of producing them. An agreement silent on record transition can leave a departing provider unable to take even a patient contact list to help with an orderly handoff.

What a reasonable version looks like: a stated patient notice period, a defined records transfer or copy process at a reasonable or no cost to the patient, and clarity on what a departing provider may take with them for continuity of care.

8. Indemnification

An indemnification clause in a provider or vendor agreement says who pays if a third party, including a patient, brings a claim connected to the services. A one-sided clause making a provider or practice indemnify a platform or management company for essentially any claim, with no cap and no requirement that the claim actually be caused by the indemnifying party’s own conduct, shifts risk well beyond what a normal services relationship should carry. This sits alongside, but is legally distinct from, medical malpractice coverage, which insures against a claim of professional negligence rather than allocating contractual risk between the parties to the agreement.

What a reasonable version looks like: mutual indemnification scoped to each party’s own conduct, with a defined cap, and a clear statement that it does not replace or limit either party’s separate malpractice insurance obligations.

9. Scope of Services and Standard of Care

A provider or platform agreement should describe the actual scope of services covered, which procedures, which patient population, which setting, rather than a broad grant to provide medical services generally. For a telemedicine platform specifically, check whether the agreement addresses which states you are authorized to treat patients in, since a license typically only covers the state where a patient is physically located at the time of the visit, and a platform contract silent on this can leave a provider unknowingly practicing outside their licensed scope.

What a reasonable version looks like: a specific description of the services and patient population covered, and, for telemedicine, an explicit statement of which states the arrangement is licensed and authorized to cover.

10. Confidentiality Beyond HIPAA

HIPAA governs protected health information specifically, but a provider or vendor agreement often includes a separate, broader confidentiality clause covering business terms, pricing, and operational details that are not patient data at all. Read this clause the way you would read any confidentiality provision in a business contract: what counts as confidential, what is excluded, and how long the duty lasts after the relationship ends. Conflating this business confidentiality clause with the agreement’s HIPAA compliance language can leave one of the two thinner than it should be.

What a reasonable version looks like: a confidentiality clause for business and operational information that is separate from, and as specific as, the agreement’s HIPAA and patient-data provisions, with a defined survival period after the relationship ends.

11. Fee Schedules and Balance Billing

Where an agreement sets or references a fee schedule, confirm whether it is a fixed schedule for the term of the agreement or subject to change on notice, and how much notice is required before a change takes effect. Separately, check what the agreement says about balance billing, charging a patient the difference between the provider’s billed rate and what the insurer actually paid, since balance billing rules for a given type of care and setting vary by state and, for many emergency and certain non-emergency services, are restricted or barred under federal law.

What a reasonable version looks like: a fee schedule with a defined change process and notice period, and a balance billing practice consistent with the applicable state and federal rules for the specific type of care involved.

12. Dispute Resolution and Arbitration

Many healthcare agreements, on both the patient-facing and provider-facing side, include an arbitration clause requiring disputes to be resolved outside of court. Read whether the clause is mutual, applies the same way regardless of which side raises the claim, and whether it includes a class action waiver, requiring any dispute to be brought individually. For a patient-facing agreement specifically, check whether signing the arbitration clause is a genuine condition of receiving care or a separate, optional agreement, since bundling it with a required consent form removes the practical ability to decline it.

What a reasonable version looks like: a mutual arbitration clause, clearly separated from any required treatment consent so declining it does not affect access to care, and plain disclosure of any class action waiver rather than language buried in a longer paragraph.

13. Assignment on a Sale or Change of Ownership

Healthcare practices and platforms change ownership more often than patients or providers may expect, through an acquisition, a merger, or a private equity transaction. An assignment clause decides whether the agreement, and the obligations in it, automatically transfer to a new owner without your separate consent. For a provider employment or practice agreement, this can mean waking up working for a company you never chose to join, under terms you negotiated with someone else. For a patient, it typically means the same consent and data-handling commitments should carry over, which is worth confirming rather than assuming.

What a reasonable version looks like: assignment permitted only with notice, and ideally consent, on a change of ownership, with an explicit statement that existing patient consents and data protections carry over to the new owner unchanged.

Most healthcare contracts you are handed will pass this checklist without needing a change, because most practices, platforms, and vendors are not trying to write a one-sided agreement, they are reusing a template built for a typical case. The value of reading one item by item is catching the minority of provisions that genuinely need a question before you sign, particularly the ones, like non-compete enforceability and balance billing, where the right answer depends on the state you are in rather than on the document alone.

BeforeJD includes a dedicated read for healthcare and medical agreements, checked clause by clause against a list very close to this one.

Before you sign your next healthcare contract, run it through BeforeJD and see exactly which of these items need your attention.

Questions people ask

What should I check before signing a healthcare contract?
Thirteen provisions decide whether a healthcare contract is ordinary or one-sided, and which ones matter most depends on the type of document. Start with the liability waiver and informed consent scope, then check for a HIPAA business associate agreement and its breach notification timeline if a vendor will handle patient data. For a provider or practice agreement, check non-compete radius and duration, insurance assignment and billing terms, and what happens to patient records at termination. Indemnification, scope of services, confidentiality beyond HIPAA, fee schedules, arbitration, and assignment on a sale round out the list. Several of these turn on state law, so this checklist tells you what to look for rather than asserting one rule everywhere.
Can a healthcare provider waive liability for negligence in a consent form?
Generally not for gross negligence or willful misconduct, even if the form says otherwise, and many states limit how far a waiver can go even for ordinary negligence. A liability waiver naming a specific procedure and its disclosed risks is a normal part of informed consent. A waiver broad enough to cover any injury from any cause deserves a closer read, and the specific limits on what a waiver can excuse vary by state.
What is a HIPAA business associate agreement, and when do I need one?
It is a required contract between a covered healthcare provider and any vendor, billing service, cloud storage provider, or platform that will see, store, or process protected health information on the provider’s behalf. It should specify security safeguards, limits on further disclosure, and a process for a patient data request, not just a single sentence acknowledging that HIPAA applies. A services contract that involves patient data with no such agreement is missing a document the relationship is required to have.
Are physician non-compete clauses enforceable?
It depends on the state, and the rule for licensed medical practitioners specifically can differ from a state’s general non-compete rule for other kinds of employment. Several states restrict or bar non-competes for licensed providers even where they allow non-competes more broadly for other workers. Check the specific rule for practitioners in the state where you will practice rather than assuming the general non-compete landscape applies.
What happens to my healthcare contract if the practice is sold?
That depends on the assignment clause. Healthcare practices and platforms change ownership through acquisitions and mergers more often than patients or providers expect, and an assignment clause decides whether the agreement transfers automatically to the new owner without separate consent. A reasonable version requires notice, and ideally consent, on a change of ownership, and states explicitly that existing patient consents and data protections carry over unchanged.
Share:XLinkedIn