In February 2026, 360 Dental PC discovered that ransomware had entered its systems. The breach impacted approximately 11,273 patients. The exposed server stored patient names, dates of birth, contact information, insurance information, dental treatment records, and some Social Security numbers and it was reported that the breach did not stem from an online form. However, many of the data types referenced typically appear on patient intake forms and consent paperwork. For that reason, as it is necessary to protect all other digital and physical systems, digitizing dental forms should be viewed as both an administrative convenience and a patient-data security matter.
Physical forms also create workflows where staff need to print, scan, file, and manually reconcile the proper forms with patient charts. It also sometimes leads to patients sitting in your waiting room filling out paperwork that they could have completed before their appointment. The best solution is often going to be a purpose-built HIPAA compliant solution like Paubox Forms. With Paubox Forms, dental offices can create forms for patients to sign, embed the forms on their website, securely collect form responses, send HIPAA compliant email containing links to forms and follow-up care information.
When digital dental forms require HIPAA protection
Digital forms can gather patient names, medical history, treatment plans, insurance information, electronic signatures, and any other identifiable information. When connected to a patient’s care or payment for care, that information could be considered protected health information (PHI). According to a StatPearls overview of HIPAA, “The HIPAA Privacy Rule . . . sets strict standards for how we manage, transmit, and store protected health information.” It means when dentists choose technology for digital forms, they should consider the entire digital form workflow. How does the patient access the form? How can staff members access or download responses? How is that information transferred into the patient record?
A study comparing the HIPAA technical safeguards found that access control, encryption and decryption, and data-transmission security were the primary ways to protect electronic health records. All of these protections can apply to digital forms. Encrypting email ensures that the dental practice can send links to the forms, reminder emails, and completed PDF documents through a secure channel. However, secure email won’t fix vulnerabilities in the form platform. The email system and the web forms platform should both protect PHI.
Separate treatment consent from HIPAA authorization
Treatment consent confirms that a patient agrees to receive dental treatment after being informed about it. Meanwhile, a HIPAA authorization allows a provider to use or disclose specific PHI for a stated reason.
The two should not be confused. According to the authors of a 2026 study published through the Journal of Clinical and Translational Science that analyzed a dental practice-based research network, “Therefore, HIPAA authorization is provided as a standalone document.”
The study focused on dental research rather than typical dental treatments. However, the practices highlighted by the study can benefit dental offices as well. Maintaining separate HIPAA authorizations from treatment consent forms allows each document to clearly serve its intended purpose. Dental providers can create individual templates for general treatment consent, authorization for the release of dental records, etc. Maintaining separate forms can help staff ensure they are using the right document. It also prevents providers from utilizing a general consent when a specific HIPAA authorization is required.
What digital dental consent forms should include
A Patient Preference and Adherence literature review about dentist-patient communication notes, “The consent form itself should be written in lay terms that are easily understood.”
Include an explanation of the treatment, why it’s being recommended, its benefits and risks, alternatives, and what the patient can expect as a result of the treatment. Also provide patients with an opportunity to ask questions. Remember that a completed form is only one part of the informed consent process. As an article published in Breathe about informed consent points out, “Informed consent is not just a form that is signed, it is a process.”
Continue discussing the procedure, answer questions, and make sure the patient understands what they will experience. Use HIPAA compliant email to securely send patients preparation information or written explanations ahead of the appointment. They can read it in advance and come prepared with questions for their dentist or oral hygienist.
Using electronic signatures
In another review published by the American Journal of Translational Research on privacy/security in digital health, “If a study is conducted in such a manner that requires written informed consent … then the use of electronic, including digital signatures, is allowed.” Paubox Forms enables time-stamped electronic signatures. Send consent forms and HIPAA authorization forms that patients can sign electronically from their own devices by embedding signable fields in your documents and sending them via HIPAA-compliant email or linking directly from your practice’s website. Users can email forms to patients before their appointments so they can review and sign on their own schedule.
When using electronic signatures for HIPAA authorization forms or informed consent for routine dental treatment, however, dentists should ensure that the method used is valid under applicable state law, any dental-board rules, and meets any procedure-specific consent requirements. Additionally, the platform being used should preserve the signature, date and time stamped when it was signed, what version of the form was signed, and some form of identifying information for the signer. If someone other than the patient signs on their behalf, dental practices should retain documentation of the signer’s authority.
Managing completed forms
Providers should limit access to forms based on job duties. While front-desk staff should be able to verify that a form has been turned in, perhaps only dentists and certain clinical staff should see information about the treatment details.
Policies should consider “establishing, altering, and revoking access…” Access should be taken away from employees who no longer need it, such as when they switch duties or leave the practice. Dentists can accomplish this by creating individual accounts and managing permissions from a central location, rather than using group passwords.
Completed forms shouldn’t get lost forever in someone’s personal inbox, on their computer’s downloads folder, or on a non-approved shared drive. Move the final document to the practice’s approved patient-records system, where it can be stored according to a written retention schedule based on the type of form and state guidelines.
FAQs
Does the form provider need to sign a BAA?
Yes, when the provider handles PHI on behalf of a HIPAA covered dental practice. The practice should obtain the BAA before collecting patient information through the platform.
Can a patient request an electronic copy of a completed digital intake form?
Yes, the HIPAA Right of Access, patients generally have the right to obtain copies of PHI maintained in a designated record set, including completed intake forms if they form part of the medical record.
How should healthcare organizations handle abandoned or incomplete digital forms?
Organizations should establish retention and deletion policies for incomplete submissions. If abandoned forms contain PHI, they should be protected with the same administrative, technical, and physical safeguards as completed records until they are securely deleted according to organizational policy.
