Adult, Adolescent & Geriatric Neurology

Private Patient Workflows

Secure Patient Services

Security depends on configuration.

A logo or “HIPAA” label alone does not make a workflow compliant. Each service must be configured in the correct healthcare plan, covered by an appropriate Business Associate Agreement when required, restricted to authorized staff, and tested before patients use it.

DrChrono / OnPatient Portal

Patient-facing portal for available records, refill requests, appointment requests, and portal messages.

Open Patient Portal Connected to a public production URL

Jotform Secure New Patient Intake

HIPAA-enabled intake workflow for registration, history, consent, signatures, and approved document collection.

Open Secure Intake Connected to a public production URL

Spruce Secure Messaging

Approved patient invitation or secure-message link for protected communication and files.

Open Spruce Connected to a public production URL

Paubox Secure Email

Approved secure-email or protected-contact destination for private communication.

Open Secure Email Connected to a public production URL

Jotform Secure Document Upload

HIPAA-enabled form for records, identification, insurance documents, and approved uploads.

Upload Documents Connected to a public production URL

Jotform Secure Payment

Production payment form connected to the practice-approved payment processor.

Open Payment Portal Connected to a public production URL

Jotform Secure Chat

Verified healthcare chat destination for non-emergency patient communication.

Open Secure Chat Connected to a public production URL

Public Website Rule

Keep ordinary forms administrative and move PHI to approved systems

The built-in contact and appointment forms ask only for basic administrative contact information. Symptoms, diagnoses, medications, insurance cards, records, and other protected information should be sent through the configured portal, Spruce, Paubox, or HIPAA-enabled Jotform workflow.

Required before launch

  • HIPAA-enabled plan and signed BAA where applicable
  • Multi-factor authentication for administrators
  • Least-privilege staff access
  • Retention, export, and deletion settings reviewed
  • Test submissions and notification routing
  • No passwords, API secrets, or private keys placed in page content