Digital signatures can be used to meet certain requirements of the final HIPAA security rule, but they are not required. They were included in the draft security rule, but were dropped due to various implementation and standards issues from what I understand. According to HHS in the final security rule, "All comments concerning the proposed electronic signature standard, responses to these comments, and a final rule for electronic signatures will be published at a later date."
For more info on this topic, visit these SearchSecurity.com resources:
Dig Deeper on HIPAA
HITECH (Health Information Technology for Economic and Clinical Health) Act of 2009
HIPAA-covered entities: Time to act on business associate agreements
HIPAA omnibus rule (Health Insurance Portability and Accountability Act of 1996 omnibus rule)
Final HIPAA omnibus rule deadline looms for healthcare MSPs, VARs