Operations · Digital Forms
The form goes out. The answers come back. Both ends inside the platform.
Most practice forms leave as a PDF and come back as a scan, an email attachment, or a photograph taken on somebody's phone. The information is collected either way. What differs is whether the return journey happened anywhere you can account for.
HIPAA mapping
Where this fits in the HIPAA rules.
3 provisions this capability contributes to, each with the specific Digital Forms behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.
§164.502(b)Minimum necessary
Requires reasonable efforts to limit PHI to the minimum necessary for the purpose, with specific exceptions including disclosures to a provider for treatment. A form is the most concrete place this obligation shows up: every field is a decision to collect something, and a field nobody can justify is a decision nobody made.
§164.530(c)Safeguards
Requires appropriate administrative, technical and physical safeguards for PHI. A clipboard at a front desk in a waiting room is the safeguard question people picture least and fail most.
§164.312(e)(1)Transmission security
Applies to ePHI moving over a network. Where a completed form travels back to the practice, how it travels is governed by this provision — which is the argument for a channel rather than an emailed PDF.
What it does
Collecting the information is easy. Getting it back safely is not.
A practice needs a form filled in — new patient details, a records request, an acknowledgment, a staff attestation. The form is easy. The return journey is the problem: a PDF emailed out comes back as a reply attachment in one person's inbox, or as a scan on the front desk machine, or on paper that gets filed and then re-typed. Every one of those routes puts information somewhere nobody chose.
Digital Forms closes both ends. The office builds the form here, with reusable widgets and variables so the same address block or office name is defined once rather than retyped onto every document. The form can be embedded on your website or sent to the person who needs to complete it — a patient, or a member of staff. When they finish, the submission comes back into Patient Protect rather than into an inbox.
One thing the builder will not let you do is ask for a card number. That is deliberate: collecting card details would pull the practice into PCI DSS obligations that have nothing to do with HIPAA and everything to do with a second audit regime you did not sign up for. It is unusual for a product to refuse to collect something, and it is worth knowing before you design payment into an intake form.
Being precise about the boundary: a form is not compliant because it is digital. What matters is what it asks for, who can see the answers, and how they travel. Digital Forms governs the third of those and gives you somewhere to think about the first two.
How it works
5 mechanisms keep Digital Forms working.
Build once, with widgets and variables.
Forms are built here rather than maintained as documents on a shared drive, and they support reusable widgets and variables — the practice's name, an address block, the fields you use on four different forms — defined in one place. That is the difference between a set of forms that stay consistent and three versions of an intake sheet where nobody can say which is current.
Send it, or put it on your website.
A form can be shared or emailed to the person who needs to complete it, staff or patient, and it can be embedded on the practice's own website. Both routes matter: the first is how a records request or an attestation reaches one person, and the second is how new-patient paperwork gets done before somebody arrives at reception with a clipboard.
Submissions come back into the platform.
This is the half most form workflows lose. A completed submission is captured digitally inside Patient Protect rather than landing as an attachment in whichever mailbox the recipient replied to. The information a practice collects ends up somewhere it chose, which is the entire argument, and it is why the alternative — a PDF and an email address — is worse than it looks.
Card fields are blocked outright.
The builder will not accept a card number. Collecting card details would pull the practice into PCI DSS obligations that are a separate audit regime with nothing to do with HIPAA. A product refusing to collect something is rare enough to be worth stating, and it is the kind of decision you only appreciate after the first time somebody adds a payment field to an intake form.
Pro, with Basic covered by the channel.
A Basic office exchanges documents with patients through Secure Messaging — governed, gated and recorded. Digital Forms is the Pro addition, and it is a different job: not sending a document to a person you already have a channel with, but collecting structured answers from someone who may not be in the platform at all.
Who this is for
Built for the practices that need it most.
Practices whose intake form is inherited.
Bought the practice, kept the paperwork. It is the ordinary case and the one where an unreviewed form is most likely to be collecting something nobody would choose to collect today.
Practices with several versions in circulation.
One at the front desk, one in the shared drive, one attached to an old email. The problem is not that any of them is wrong; it is that nobody can say which is current.
Practices already on Pro.
If you hold Pro for the patient workspace, templates belong in the same place as the rest of it. If you are on Basic and forms are the reason you are considering Pro, ask us what the module does today rather than deciding from this page.
What you get
4 outcomes you’ll feel in week one.
Reusable widgets and variables.
Define the address block once instead of on every document.
Both ends in one place.
The form goes out and the submission comes back inside the platform.
No card fields.
The builder refuses them, keeping PCI scope out of your intake.
Embed or send.
On your website, or to a member of staff or a patient directly.
Can a Basic office send a patient a form?
What can the builder do?
Does a digital form make our intake HIPAA compliant?
How should we decide what to put on a form?
What it does not do.
- Pro only. A Basic office exchanges files with patients through Secure Messaging instead.
- Forms collect what the practice designs them to collect; deciding what is minimum necessary to ask is the practice's judgement.
Continue exploring
Related features in the platform.
Network
Secure Messaging
Encrypting a message is the part everyone gets right. Knowing whether the person receiving it is covered by an agreement, and refusing to send when they are not, is a different job — and it is the one this channel does.
Learn moreNetwork
Patient Management
Your EHR holds the clinical story. The administrative one — who this patient is to your office, what has passed between you, what is still outstanding — usually holds together only in somebody's head.
Learn moreOperations
Compliance Evidence & Records
The question is almost never whether the practice did the work. It is whether the practice can produce what the work generated — and do it this week rather than after a month of archaeology.
Learn moreOut through your website. Back into the platform.
The information gets collected either way. What changes is whether the return journey ended somewhere you chose.
