HIPAA and GDPR set strict standards for managing sensitive health and personal data in digital documents. Organizations must implement safeguards such as encryption, access controls, and audit trails to remain compliant. PDF management platforms with features such as password protection, secure sharing, two-factor authentication, and audit logs ensure compliance while streamlining workflows.
- Is pdfFiller HIPAA compliant? Yes, pdfFiller offers HIPAA compliance features, including encryption and strict access controls, to protect sensitive health information.
- Does pdfFiller sign a BAA? Yes, pdfFiller provides a signed Business Associate Agreement (BAA) for users on specific plans to ensure legal compliance.
- How does pdfFiller handle GDPR? The platform supports GDPR compliance through features that enable data minimization, secure sharing, and “right to be forgotten” protocols.
- Is sharing PDFs secure? pdfFiller uses bank-level security, two-factor authentication, and password protection to ensure document sharing is safe.
- Can I track who views my documents? Yes, the Audit Trail feature logs every action taken on a document, providing a clear history of access and edits.
Healthcare providers, legal professionals, financial institutions, and any organization handling sensitive personal information face growing pressure to protect data while maintaining efficient digital workflows. HIPAA and GDPR represent two of the most stringent regulatory frameworks governing how organizations must handle sensitive information in digital formats.
This PDF compliance FAQ article breaks down complex HIPAA and GDPR regulations and explains pdfFiller’s compliance with them. We’ll address key questions about pdfFiller’s reliability and show how to keep your PDF workflows secure, compliant, and efficient.
HIPAA-compliant PDF tools
1. What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996, sets national standards to protect sensitive patient health information. Businesses handling protected health information (PHI) must implement physical, network, and process security measures to comply. If you manage medical records, insurance claims, or patient intake forms, using HIPAA-compliant PDF tools is key to avoiding costly penalties.
2. Is pdfFiller HIPAA compliant?
Yes, pdfFiller meets HIPAA standards for handling Protected Health Information (PHI). We use bank-level encryption to protect data at rest and in transit. Strict physical and digital access controls prevent unauthorized access, enabling healthcare professionals to securely collect, edit, and store patient forms.
3. Does pdfFiller sign a HIPAA Business Associate Agreement (BAA)?
Yes, pdfFiller offers a Business Associate Agreement (BAA) for customers on enterprise or business plans. A BAA is a legal contract that defines a business associate’s responsibilities for protecting PHI under HIPAA. Since this agreement is required for any third-party service handling health data, we offer it to ensure our partnership fully supports your compliance needs.
4. Can I collect patient information (ePHI) in fillable PDF forms securely?
Yes, pdfFiller allows you to create fillable PDF forms that patients can complete online from any device. Because the connection is secured with advanced encryption protocols (HTTPS/TLS), the electronic protected health information (ePHI) entered into these forms remains private during transmission. Once the form is submitted, it is stored securely in your account, where you can manage access permissions to ensure only authorized staff view the data.
5. How does pdfFiller protect protected health information (PHI)?
pdfFiller protects PHI with a multi-layered security approach that includes data encryption, user authentication, and activity monitoring. All documents are secured with 256-bit encryption, the industry standard for sensitive data. To prevent unauthorized access, our platform also includes features like two-factor authentication (2FA). We conduct regular security audits and vulnerability assessments to keep our defenses strong against new threats.
6. How do I enable HIPAA compliance in pdfFiller?
To enable HIPAA compliance in pdfFiller, ensure your account is on an Enterprise plan, which includes HIPAA features. To turn on HIPAA compliance, follow these steps:
1. Click My Account, then go to Settings in the left-side menu.
2. Under Authentication and Access Security, proceed to HIPAA Compliance.
3. Click the toggle switch to turn it on, then click Upgrade.
To obtain a Business Associate Agreement (BAA), required for HIPAA compliance, contact pdfFiller’s support team. After signing the BAA, administrators can configure account settings to meet HIPAA requirements, such as managing user permissions and enabling security features, such as two-factor authentication. For more information, see the account and security section in our Help Center.

Enable HIPAA compliance and enhance security with features like 2-step verification and confidential folders in your account settings.
7. How do I send a HIPAA-compliant document?
You can send a HIPAA-compliant document using pdfFiller’s LinkToFill feature.
- In the Dashboard, click menu > LinkToFill > turn on the toggle to create a link for the document.
- Proceed to More Settings and set access permissions to control who can view or complete the document.
- Click Select security settings, then turn on HIPAA to ensure compliance with HIPAA’s privacy guidelines for this document. Note: After enabling the feature, the Email, Mail by USPS, and Notarize features will be unavailable for this document.

Customize your document security settings and turn on HIPAA compliance when sending a PDF via the LinkToFill feature for secure document sharing.
Understanding GDPR PDF compliance
8. What is GDPR?
The General Data Protection Regulation (GDPR) is a privacy and security law from the European Union (EU). It applies to any organization that collects data about people in the EU, no matter where the organization is located.
The main goal of GDPR is to give people more control over their personal data. Key principles include:
- Transparency: Being clear about how data is used.
- Data minimization: Only collecting data that is necessary.
- Security: Protecting personal data from being misused.
9. Is pdfFiller GDPR-compliant?
Yes, pdfFiller is fully GDPR compliant and helps users meet their obligations under the regulation. We’ve implemented measures to ensure the security and privacy of personal data on our platform. Users can access, correct, or delete their data upon request, in line with the “right to be forgotten.” We also ensure all data transfers comply with international protection standards.
10. What GDPR security controls are required when sharing PDFs with personal data?
When sharing PDFs that contain personal data, GDPR requires you to maintain confidentiality, integrity, and availability. You can do this by:
- Using secure channels like encrypted links or password-protected files, rather than unencrypted email attachments.
- Verifying the recipient’s identity to prevent unauthorized access.
- Using a secure platform like pdfFiller, which offers secure sharing options that track delivery and restrict access.
Explore our guide on encrypting PDF files to keep your data secure.
11. How can I support GDPR “data minimization” when sending PDFs?
Data minimization is the principle of collecting and processing only the data that is absolutely necessary for the specific purpose. pdfFiller helps you achieve this by allowing you to create custom forms where you ask only for required fields, avoiding free-text areas where users might overshare. You can also edit existing PDFs to redact or blackout unnecessary personal information before sharing a document with a third party. By sharing only the specific version of the document needed, you reduce the risk of exposing excessive data.
12. How do I reduce the risk of emailing PDFs with personal data?
Email is often insecure and vulnerable to interception, making it a poor choice for sending sensitive PDFs. pdfFiller’s LinkToFill feature is an optimal way for secure document sharing of PDFs with sensitive data. It sends a secure link to the document, which remains hosted on our encrypted servers. You can further secure this link by adding a password or an expiration date, ensuring that even if the email is intercepted, the document remains safe.

Effortlessly activate and customize LinkToFill to securely share documents with multiple recipients for filling and signing.
13. How do I demonstrate accountability for document access under GDPR?
GDPR requires organizations to demonstrate accountability, meaning you must prove that you are managing data responsibly. pdfFiller helps you do this through a comprehensive Audit Trail that records exactly “who did what” with a document. These logs track viewing, editing, signing, and sharing activities, complete with timestamps and IP addresses. During an internal review or compliance audit, these records serve as clear evidence that you maintained strict control over data access.
Privacy and PDF security
14. Is pdfFiller safe to use for sensitive PDFs?
pdfFiller prioritizes safety for all users, from individuals to enterprises. Our secure infrastructure is hosted in SOC 2 Type II-certified data centers, ensuring reliability and security. Advanced threat detection monitors for suspicious activity 24/7. Whether managing financial records, legal contracts, or personal forms, pdfFiller keeps your sensitive PDFs secure. Learn more on the platform’s security and compliance page.
15. Can I add two-factor authentication (2FA) when sending PDFs for signature?
Yes, you can add extra security with two-factor authentication (2FA) for recipients. When sending a document for signature with pdfFiller, require recipients to enter a password or verify their identity via text or phone call before accessing it. This ensures only the intended recipient opens the document, reducing the risk of fraud or accidental access.
16. Can pdfFiller restrict editing and copying in PDFs?
Yes, pdfFiller gives you granular control over what recipients can do with your documents. When you share a PDF, you can adjust permissions to restrict editing and signing:
- Click the Share icon at the top of the editor.
- Enter your recipients’ emails or choose them from Contacts.
- Choose Full access / Can edit/ Can comment/ Can view for each recipient.
- Alternatively, share your PDF via a secure link and select Anyone with the link can view / can comment /can edit.

Easily share documents in pdfFiller with flexible access permissions, allowing recipients to view, comment, or edit your PDFs.
Locking permissions ensures document integrity and prevents unauthorized edits or distribution.
17. How do I password-protect a PDF in pdfFiller?
To password-protect a PDF from pdfFiller Dashboard, click the menu next to the file name, select Tools > Protect document, and enter the secret combination into the Set Password field. You can also do it while sharing a PDF via email or a LinkToFill feature. Anyone trying to open the file must enter the correct password to view its contents. This feature ensures that only those with the password can access the information, whether you’re storing the file in your account or sending it to a client.
18. Can pdfFiller help with the secure sharing of compliant PDFs?
Yes, secure sharing is one of pdfFiller’s key compliance features. Instead of risky email attachments, you can share documents via secure, authentication-required links with optional expiration dates. Full audit logging tracks who accessed the document and when, ensuring a complete chain of custody for compliant sharing.
19. How does pdfFiller make PDFs tamper-proof?
pdfFiller keeps your documents secure by creating a sealed record once they’re completed and signed. Any attempt to alter a finalized document breaks the digital seal, immediately flagging potential tampering. Additionally, our Audit Trail logs every action taken on a document from start to finish. This creates a permanent, unchangeable history, proving the document is authentic and hasn’t been modified.
20. Is it more secure to share sensitive documents via email or through pdfFiller?
When managing sensitive documents, the delivery method matters as much as the content itself. Here’s how email vs. pdfFiller secure sharing compares.
| Feature | Standard email attachment | pdfFiller secure sharing |
|---|---|---|
| Encryption | Often unencrypted in transit; stored in plain text in inboxes. | Encrypted in transit and at rest (256-bit encryption). |
| Access control | None. Once sent, anyone with access to the email can open it. | Password protection and 2-Factor Authentication (2FA). |
| Revocability | Impossible. You cannot “un-send” an attachment. | You can revoke access to the document link instantly at any time. |
| Tracking | Read receipts are unreliable and often blocked. | Detailed Audit Trail logs of who viewed/signed the doc and when. |
| Compliance | Risky for HIPAA/GDPR data due to a lack of control. | Supports HIPAA/GDPR workflows with audit trails and encryption. |
Disclaimer: This article is for informational purposes only and does not constitute legal advice.
Final thoughts
Meeting HIPAA and GDPR requirements while maintaining efficient document workflows requires more than good intentions—it demands strong technical controls, clear processes, and secure, compliance-focused platforms. Organizations handling sensitive health or personal data cannot rely on generic tools without proper encryption, access controls, audit trails, and accountability features required by modern regulations.
pdfFiller gives healthcare providers, legal professionals, and other regulated businesses the security and compliance tools they need to handle sensitive PDFs with confidence. With HIPAA-compliant workflows, GDPR-aligned security, and detailed audit logging, the platform meets regulatory requirements while streamlining document management.
Ready to secure your document workflow? Start your free 30-day trial with pdfFiller today.
Glossary
- Encryption: A process that scrambles your data into a code to prevent unauthorized access. pdfFiller uses 256-bit encryption, rendering your data unreadable to anyone without the correct digital key.
- PHI (Protected Health Information): Any health information that can identify an individual, such as medical records, insurance details, or test results. Under HIPAA, this data requires strict protection measures to ensure patient privacy.
- BAA (Business Associate Agreement): A legally-binding contract required by HIPAA between a covered entity (like a doctor) and a business associate (like software services), that sets the rules for how the associate must protect PHI.
- Audit Trail: A digital record tracking all activities related to an operation or document. In pdfFiller, it shows who accessed a document and what changes were made, ensuring audit security.
- Two-Factor Authentication (2FA): A security method that requires two forms of identification to access a system. Usually, this means a password plus a code sent to your phone, making it much harder for hackers to break in.