PHI exposure through the signing layer
Clinicians often focus on the EHR and overlook the signing service. Consent forms, intake sheets and letters can contain enough identifying and clinical detail to be PHI in their own right.
For clinics, therapists and private practices
Every practice runs on signed paperwork: consent to treat, HIPAA acknowledgements, financial responsibility agreements, treatment plans, referral letters, vendor and staff agreements. Collecting those signatures is routine — but each one puts a question in front of you about PHI.
A cloud e-signature service holds a copy of whatever you send through it. When that document is a consent form with diagnosis codes or an intake sheet with a date of birth, the service is handling protected health information on your behalf, which is what triggers a business associate agreement and a set of obligations you then have to manage.
A tool that never receives the document changes the analysis. If no PHI is transmitted to us, we are not handling PHI, and there is no business associate relationship to paper. That is not a marketing claim — it follows from the fact that processing happens in your browser.
Where the friction is
Clinicians often focus on the EHR and overlook the signing service. Consent forms, intake sheets and letters can contain enough identifying and clinical detail to be PHI in their own right.
Signing a handful of staff or vendor agreements does not justify procuring, assessing and maintaining another vendor that processes PHI.
Printing, chasing and re-filing paper consent forms still consumes staff time, and patients increasingly expect to sign on a tablet or their own phone.
What you sign
Clear limits
HIPAA does not prescribe a particular electronic signature technology. It requires safeguards for protected health information and, where a vendor handles PHI on your behalf, a business associate agreement. Because this tool processes entirely in the browser and transmits nothing, no PHI reaches us and there is no business associate relationship to establish. Your own obligations are unaffected: you still need to store signed records securely, control access, and keep them for the required period.
How it works
The documents in this field are the ones people are least comfortable handing to an unfamiliar service. Our tools process them entirely in the browser.
PDF pages are rendered and written in the browser with open-source libraries that run entirely on the client. Signature strokes are captured on a canvas, and saved signatures are kept in your browser's own storage — the same mechanism any website uses to remember a preference. None of these components has a network call that transmits a file, and there is no backend for one to reach.
You do not have to take that on trust. Open your browser's developer tools, switch to the network tab, and sign a document. You will see the page's own assets load — fonts, scripts, stylesheets — and nothing else. No request carries your document, because none is made.
Where this is not the right tool. Browser-based signing is excellent for documents you sign yourself. It does not send a document to other people, collect their signatures, verify their identity, or produce an audit trail. When a counterparty or a compliance policy requires those things, use a platform built for it — the trade-off is real and worth naming rather than glossing over.
Related
FAQ
No. A BAA exists to cover a vendor that creates, receives, maintains or transmits PHI on your behalf. This tool does none of those things — the document is processed in your browser and never reaches a server we operate. If a vendor never receives PHI, there is no business associate relationship to paper.
We make no compliance guarantee about your overall workflow, and you should be sceptical of any tool that does. What is accurate is narrower and more useful: because nothing is transmitted to us, using this tool does not create a new HIPAA disclosure or a new business associate relationship. Your practice's own safeguards, record retention and access controls still apply.
Yes. The tool runs in a browser and supports touch input, so a patient can draw their signature on a tablet or their own phone and you save the completed file. Nothing is sent anywhere in the process.
Wherever you put them — your device, then your practice management system or secure file store. That is deliberate: the signed record belongs in your system of record, not in a third-party signing account.
Yes. Consent forms, acknowledgements, financial agreements, referral letters and staff or vendor contracts can all be signed this way. Payer-specific documents signed through a portal are the exception, since that workflow belongs to the payer.
The signature itself is valid under ESIGN and the state UETA. Whether the consent is effective also depends on your state's informed-consent requirements — what must be disclosed and how it is documented — which is a separate question from how the signature was applied.