Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

Free non-disclosure agreement template: When your practice needs one

Key takeaways

Key takeaways

A non-disclosure agreement is a binding contract that stops staff, contractors, and vendors from sharing your practice’s confidential information.

Practices need one for onboarding, locum and IT contractor access, vendor integrations, and any conversation with investors or buyers.

A one-way agreement covers almost every practice situation, and a mutual version suits merger talks or joint marketing.

An enforceable agreement defines what counts as confidential, sets a duration, names the governing law, and protects disclosure to regulators.

An NDA never replaces a HIPAA business associate agreement or a UK GDPR processor contract, so vendors still need both.

Practice management software like Pabau stores the signed agreement on the staff record, so you can prove who agreed to what.

Download your free non-disclosure agreement template

A ready-to-sign confidentiality agreement with separate clauses for employees, contractors, and vendors. It covers what counts as confidential information, how long the duty lasts, permitted disclosures, remedies for a breach, and signature blocks. Print it or send it out for a digital signature.

Download template

Every practice shares confidential information with people who are not on the payroll. A non-disclosure agreement turns the expectation of confidentiality into a contract you can enforce. It binds employees, locums, and outside vendors to keep private what they see.

The file above is a printable non-disclosure agreement that you can also send for a digital signature. Treat this free NDA template as a sample NDA to adapt, not a finished contract. Which clauses you keep depends on who is signing it.

This guide covers what an NDA protects, when your practice needs one, and which clauses hold up if you ever rely on them. It also shows where an NDA stops short, since GDPR obligations need a separate contract with any vendor that processes patient data.

What is a non-disclosure agreement?

A non-disclosure agreement is a binding contract that stops the people who sign it from repeating information you have named as confidential. You will also see it called a confidentiality agreement, or a confidential disclosure agreement in research and clinical trial work. The three terms carry the same legal weight.

In a practice, the named information is usually patient data, treatment protocols, pricing, supplier terms, and the systems you have built. The definition is the part that decides whether the document is worth anything.

So the label matters less than the scope. A one-page agreement naming four categories of information beats a ten-page one that says “all business information”. A court reads the definition, not the title on the front page.

When your practice needs one

Use an NDA whenever someone reaches sensitive practice data outside their normal role or relationship. The six situations below cover most of what a practice runs into.

  • New hires: Employees sign during onboarding, before they get a login to patient records, treatment protocols, or practice financials.
  • Independent contractors: Locums, physical therapists, and visiting injectors sign before you open a patient portal account for them.
  • Software vendors: IT contractors and system integrators who configure your platform or migrate data sign before the work starts.
  • Business partners: Referral partners and suppliers in joint marketing often ask for one, and may want a mutual agreement.
  • Investor conversations: Anyone reviewing your financials during a funding round or a practice sale signs first.
  • Med spas: Before-and-after photos are patient data, so everyone handling them at a med spa signs one.

What a HIPAA non-disclosure agreement template must cover

A HIPAA non-disclosure agreement template covers confidentiality between you and the signer, and nothing more, so it never satisfies HIPAA on its own. Any vendor that creates, receives, or stores protected health information, known as PHI, needs a business associate agreement as well.

The two documents do different jobs. The business associate agreement is what the HIPAA Privacy Rule demands, and it sets breach notification duties and the permitted uses of PHI. Your NDA is a private contract, so it can reach information HIPAA ignores.

Pricing, supplier terms, injector technique, and your marketing plans all sit outside PHI. A vendor could hand every one of them to a competitor without ever touching HIPAA. That is the part the NDA is there to close.

Sign the two documents with different counterparties. The business associate agreement goes to the vendor company, and the NDA goes to the individual engineer or technician who will be on site. A signed BAA does not stop one person repeating what they saw on a screen.

For your own team, the layering runs the other way. Employees count as your workforce under HIPAA, so no business associate agreement applies to them. Your HIPAA training and the signed NDA carry the weight instead.

NDA clause checklist: What every agreement needs

Eleven clauses do the work, and the table below says what each one is for. Keep the ones that apply to the person in front of you, and cut the rest before you send it.

ClauseWhat it doesRequired or optionalTypical wording or duration
Definition of confidential informationNames the categories covered, so a court knows what you meantRequiredPatient records, treatment plans, pricing, staff data, system logins
Parties and access scopeIdentifies the practice and the signer, plus what they will seeRequiredFull name, job title, and the systems they are given
ObligationsSets the duty of care and says who else may be toldRequiredDisclose only to colleagues with a business need
DurationFixes how long the duty lasts after the relationship endsRequiredIndefinite for patient data, three years for business information
Permitted disclosuresCarves out what the signer may lawfully share anywayRequiredPublic knowledge, court orders, independently developed work
Whistleblower carve-outKeeps the route to a regulator open, which protects the rest of the documentRequired in the UKReports to the CQC or another prescribed body stay permitted
RemediesStates what follows a breachRequiredInjunction, damages, or termination
Return or deletion of informationCloses out access and copies when the contract endsRecommendedReturn or delete within 14 days of the last working day
Governing law and jurisdictionDecides whose courts hear a dispute, which matters for remote staffRequiredName the state or country, not just “applicable law”
Non-solicitationStops the signer approaching your patients or recruiting your teamOptional, separate clauseSix to 12 months after the last working day
Non-competeRestricts where the signer may work nextOptional, often unenforceableCheck state or national law before you use one
The required clauses hold the agreement up in court, and the optional ones deal with what happens after someone leaves.

The last two rows often get bolted onto the same document, and they are worth pulling apart. A combined non-compete non-disclosure agreement mixes confidentiality with a restriction on where someone can work next. The confidentiality half usually holds, while the non-compete half depends entirely on local law.

A non-solicitation agreement is the narrower and more durable of the two. It stops a departing injector contacting your patients or recruiting your front desk. It does not stop them practicing down the road, which is why courts uphold it more readily.

One more thing on layout. There is no legal format for non-disclosure agreement documents, so a signed one-page letter binds as tightly as a fifteen-page contract. Both signatures and a specific definition are what count. The same discipline applies to the rest of your practice documentation.

Employee agreements and their limits

An employee confidentiality agreement is the most common type, and the easiest to get wrong. Staff reach patient data as part of the job, so the document is about handling rules rather than access. Spell out what good handling looks like day to day.

GDPR and UK employment law both limit what you can restrict. An NDA cannot stop a nurse raising unsafe care with the CQC, and it cannot override statutory whistleblower rights. Those rights come from UK whistleblower protection law, which allows disclosure to prescribed persons and regulators.

Write the carve-out in plain words. A line such as “Nothing in this agreement prevents you from reporting safety concerns to a prescribed body, including the CQC” does the job.

Build signing into the first-day checklist so it never slips. Staff onboarding tools can hold the task, and a digital signature means the copy lands in the record instead of a drawer.

Contractor and vendor agreements

Contractors and vendors should sign an agreement scoped to what they actually touch. A locum sees clinical notes. An IT contractor usually sees database structures and staff names, and has no reason to open a consultation record.

Put that scope in the document itself. For a systems integrator, confidential information might cover system architecture, database structures, and integration settings, with clinical and financial data excluded.

Then make the software agree with the paperwork. A clause that limits a contractor to system settings means little if their login opens every client record. Permissions are what turn the written scope into something you can evidence later.

Staff permissions screen in Pabau showing per-user access controls
Pabau’s staff permissions decide which records a contractor can open, so the scope you wrote into the NDA is enforced in the system.

An NDA on its own is not enough for a vendor that handles patient data. UK GDPR requires a written processor contract with specific terms under Article 28. In the US, HIPAA requires a business associate agreement. Signing an NDA and stopping there leaves that requirement unmet.

Unilateral vs. mutual NDA: Which do you need?

You need a unilateral agreement in almost every case, because only one side is handing over confidential information. Reach for a mutual non-disclosure agreement template when both parties share something sensitive, such as merger talks with another practice.

TypeWhich party is boundTypical practice useRisk exposureSample clause language
Unilateral (one-way)The recipient onlyNew hires, locums, IT contractors, marketing agenciesSits with the signer, and you take on no duty at all“The Recipient shall not disclose the Confidential Information to any third party.”
Mutual (two-way)Both parties equallyMerger or acquisition talks, joint ventures, shared care pathwaysShared, so your own team can breach your own agreement“Each Party shall keep the other Party’s Confidential Information in confidence.”
Multilateral (three or more)Every named partyA group sale with several selling partners, or a three-way referral networkSpread across everyone, and the hardest version to police“Each Party owes every other Party the obligations set out in Clause 2.”
Read the parties clause rather than the title, because a document you sent out one-way often comes back mutual.

The mutual version costs you something the one-way version does not. Once you owe a duty back, your team has to know what they may not repeat about the other side. That turns a filing job into a briefing job.

Watch for the quiet swap. A vendor sent a one-way agreement will often return a mutual one, which puts your practice under the same restrictions. The heading on page one rarely changes, so check the parties clause before anyone signs.

Are NDAs enforceable?

Yes, in both the UK and the US, provided the agreement is specific and reasonable. Courts decline to enforce terms that are vague, unreasonably wide, or unsupported by consideration. Consideration means each side gets something of value, such as the job offer itself.

  • Define the information: “All business information” is too broad, so list the categories you actually mean.
  • Set a reasonable duration: Indefinite protection suits patient data, and several years is typical for trade secrets.
  • Name the governing law: A practice with remote billing staff in another state has to say whose courts decide a dispute.
  • Respect the law above it: HIPAA rules in the US and ICO GDPR guidance in the UK sit above any private contract.
  • Keep the whistleblower carve-out: UK law protects disclosure to regulators, and blocking it puts the whole agreement at risk.

Governing law is the clause practices skip most often. A remote coder in another state, or a locum who lives abroad, can leave you arguing about venue before anyone looks at the breach. Name a single state or country and be done with it.

If you suspect a breach, take legal advice before you act. Injunctions are available but expensive, so a tight agreement and controlled access to data are the cheaper protection.

How to customize the template

Read the file as an example of non-disclosure agreement template wording rather than as legal advice for your jurisdiction. Fill in your details, keep the clauses that apply to the signer in front of you, and cut the rest.

  1. Insert your practice details: Add the practice name, address, and registration number to the header.
  2. Define confidential information: List the categories that apply to you, such as patient records, treatment photos, pricing, and system access.
  3. Name the signer and their scope: Record the individual, their title, and what they will be able to see.
  4. Set the confidentiality period: Use indefinite for patient data and three years after employment for business information.
  5. Add the exceptions: Include legally required disclosures, whistleblower protection, and information already in the public domain.
  6. Name the governing law: State which country or state the agreement runs under, and whose courts hear a dispute.

Send it for signature through your digital forms rather than printing it. Signed copies then sit in one place, and access stays with the people who need it.

Digital forms in Pabau
Pabau’s digital forms let a new hire sign the NDA on screen, so the signed copy files itself against their record.

Which practices need one?

Any practice holding patient data or proprietary information needs one on file. That covers private practices, med spas, physical therapy, mental health practices, and diagnostic centers.

UK practices regulated by the CQC should treat these agreements as part of information governance. US practices under HIPAA use them alongside the business associate agreements vendors must sign. Compliance tools track who signed and when each agreement expires.

HIPAA compliance settings in Pabau
Pabau’s compliance settings hold the HIPAA and GDPR controls behind your agreement, from user permissions to how long records are kept.

What a signed agreement protects

A signed agreement gives you legal recourse if information leaks. It also sets expectations for staff and contractors before anything goes wrong, which is where most of its value sits.

It gives you something to show an inspector or a buyer. During a practice sale, the buyer’s advisors will ask how patient data is controlled, and signed agreements are part of that answer.

Patients and referral partners notice the difference too. Keeping confidential notes inside one system, rather than in email threads and personal phones, is what makes the agreement more than paperwork. Client records with per-user access do most of that work.

AI powered patient letters in Pabau
Pabau drafts patient letters from the treatment note itself, so confidential detail never gets copied into a document outside the record.

How Pabau keeps signed agreements with the staff record

Most practices email the NDA as a PDF and hope the signed copy comes back. It gets printed, signed, scanned, and saved somewhere on a shared drive. When an inspector or a buyer asks who signed what, someone loses an afternoon looking for it.

Practice management software like Pabau turns that paperwork into a digital form instead. The signer completes it on any device, and the signed copy is stored against their record with a date on it. Nothing sits in an inbox waiting to be filed.

Access control does the other half of the job. Permissions decide which staff can open a client record, and the system logs who looked at it. That gives your confidentiality clause something to stand on when a regulator asks how patient data is protected.

Keep signed agreements with the right record

Digital forms, user permissions, and access logs keep every signed agreement attached to the person who signed it. You can show who agreed to what, and when.

Pabau practice management dashboard

Conclusion

Filling in the template takes ten minutes. Making it hold up takes a little more thought. Name the information you actually mean, scope each signer to what they touch, and pick a governing law.

Leave the whistleblower route open, and remember that a vendor handling patient data needs a processor contract or a business associate agreement as well. Do that, and confidentiality stops depending on everyone remembering the rules. It becomes a term someone agreed to, with a date and a signature behind it.

Storage is the last piece, since an agreement nobody can find protects nothing. Book a demo to see how Pabau keeps signed agreements and access records together for your practice.

Continue your research

Continue your research

Need another form ready to sign? The cosmetic surgery consent form follows the same structure, with the risks a patient has to acknowledge before treatment.

Documenting a psychiatric intake? The psychiatric evaluation template covers the history and risk sections those records need.

Chasing insurers for approvals? The medical prior authorization form collects the clinical detail payers ask for before they approve treatment.

Want team meetings on record? The meeting summary template keeps decisions and action items in one place after every staff meeting.

Running nutrition consultations? The nutrition assessment form structures intake, dietary history, and goals in a single document.

Frequently asked questions

What is a non-disclosure agreement?

It is a binding contract that stops the people who sign it from sharing confidential information. In healthcare, that means patient data, treatment protocols, pricing, and anything proprietary about how the practice runs.

What should be included in an NDA?

Define confidential information, name the parties, and set out the obligations. Add a duration, the exclusions, and the remedies for a breach. UK practices also need a carve-out permitting disclosure to regulators.

Are NDAs enforceable in healthcare?

Yes, when they are specific and reasonable. Courts look for a clear definition of confidential information, a sensible duration, and terms that respect GDPR and HIPAA. Vague or overly wide agreements often fail.

Can an NDA stop an employee reporting safety concerns?

No. UK whistleblower protection under the Enterprise and Regulatory Reform Act 2013 and US federal law both allow disclosure to regulators and legal counsel. Your agreement should say so explicitly.

How long should confidentiality last?

Patient confidentiality runs indefinitely under GDPR and HIPAA duties. For commercial information and trade secrets, three to five years after the contract ends is common. Set different periods for different categories.

Do contractors need to sign an NDA?

Yes, if they can reach practice information. Scope it to what they actually encounter, such as system architecture for an IT contractor rather than clinical notes.

Does an NDA need to be notarized?

No. A non-disclosure agreement binds both sides the moment they sign it, with no notary or witness needed for a standard contract. Keep a dated copy of every signature instead, since proving who signed and when is what matters later.

Is a non-compete the same as an NDA?

No. An NDA restricts what someone may repeat, while a non-compete restricts where they may work next. Practices often sign both, but only the confidentiality terms travel reliably, because non-compete rules differ by state and country.

×