Commercial

Secure Client Portal with eSign (2026)

Build a secure client portal with file sharing and eIDAS-compliant e-signatures. GDPR, access controls, and audit trails.

By Platform EditorialPublished 9 min read
Secure Client Portal with eSign (2026)
Summary

Build a secure client portal with file sharing and eIDAS-compliant e-signatures. GDPR, access controls, and audit trails. It covers what a secure client portal covers, GDPR requirements for client portals, key features to evaluate, and platform comparison.

Secure Client Portal with File Sharing and eSign (2026 Guide)

A secure client portal with file sharing and electronic signature capability gives clinics and service businesses a single place to exchange documents with clients — without email attachments, paper forms, or courier deliveries. Clients log in, see documents awaiting their signature, sign them, and access signed copies. The practice sees real-time signature status and retains a legally valid audit trail.

For EU-based practices handling health data, legal documents, or financial agreements, the security and compliance requirements for these portals are specific. This guide covers what the portal must do, what eSign legally requires under eIDAS, and how to evaluate platforms.

What a Secure Client Portal Covers

File sharing

Bidirectional document sharing between the practice and the client:

Practice → client: Clinical letters, test results, invoices, care plans, referral letters, policy documents, consent forms awaiting signature, and post-visit summaries. Documents sent from the practice appear in the client's portal inbox with a notification.

Client → practice: Completed intake questionnaires, insurance documents, identification uploads, referral letters from other providers, or any document the client needs to submit. Client uploads appear in the practice's inbox for review.

Security requirements for file sharing:

  • Files transmitted over HTTPS (encrypted in transit)
  • Files stored encrypted at rest
  • Access controls: the client sees only their own documents; no client can access another client's portal
  • Audit log: who accessed which document and when
  • Download controls: some documents (referral letters, clinical reports from third parties) should be viewable but not downloadable by clients — the portal should support configurable download permissions

eSign functionality

Electronic signatures on documents through the portal fall under EU Regulation 910/2014 (eIDAS), which defines three legally recognised signature types:

Simple Electronic Signature (SES): The lowest level — any electronic indication of intent to sign. A typed name, a checkbox, a digital signature image. Legally valid for most routine documents: standard consent forms, service agreements, appointment policy acknowledgements. An SES with timestamp and IP address record is sufficient for the vast majority of clinical consent forms.

Advanced Electronic Signature (AES): Linked uniquely to the signatory, capable of identifying the signatory, created using data under the signatory's sole control, and detects any subsequent changes to the signed data. AES is appropriate for contracts with higher financial value, specialist referral consents, and documents where identity verification is important. AES typically requires SMS OTP verification or equivalent before signing.

Qualified Electronic Signature (QES): Created with a qualified electronic signature device and based on a qualified certificate. QES has the same legal effect as a handwritten signature across all EU member states. Required for the highest-stakes documents — notarial acts, court submissions, some regulated financial instruments. QES is not required for clinical consent in most contexts.

For most clinical practices, SES is sufficient for routine consents, and AES is appropriate for high-value contracts, specialist procedure consents, and any document where identity verification adds material value.

Audit trail

The audit trail is the legal evidence that a document was signed by the correct person, with knowledge of what they were signing, at a recorded date and time. A complete audit trail record contains:

  • Document identifier and hash (proof the document has not been modified after signing)
  • Signer email address (must match the client's registered portal email)
  • Timestamp (UTC, not local time)
  • IP address of the signing device
  • For AES: verification method and result (e.g., "SMS OTP verified to +44 7xxx xxx")
  • Signature event log (document opened, signature field accessed, signature completed)

The audit trail should be exportable as a PDF certificate alongside the signed document — so that a signed consent form and its audit certificate can be stored together as a complete legal record.

GDPR Requirements for Client Portals

Data classification

A client portal for a clinical practice processes special category data (health records under Article 9 GDPR). The portal must meet the security requirements appropriate for special category data:

  • Access controls with strong authentication (password plus optional 2FA)
  • Session timeout for inactive sessions
  • Encryption at rest and in transit
  • Audit logging of all access events
  • processor terms with the portal vendor
  • EU data residency or SCCs for third-country transfers

Lawful basis for portal access

Portal access for clinical purposes is typically based on Art. 6(1)(b) (performance of a contract — the clinical care contract) and Art. 9(2)(h) for health data (clinical care exemption). The portal's privacy notice must state these bases clearly.

Marketing communications sent through the portal require separate consent under Art. 6(1)(a). Do not mix clinical portal communications with marketing communications — they have different legal bases and different opt-out implications.

Client data subject rights via the portal

The portal is an effective channel for facilitating GDPR rights:

  • Subject access request: The portal can serve as the delivery mechanism for DSAR responses — export the client's complete record and make it downloadable via the portal
  • Rectification: Clients can review their contact details and clinical history in the portal and flag corrections
  • Erasure: The portal should clearly explain how clients can request erasure, even if the actual erasure is processed manually by the practice

Key Features to Evaluate

Document workflow

How does a document move from the practice to the client's signature? The workflow should be:

  1. Practice uploads or generates document
  2. Practice assigns it to a client for signature and sets the signature type (SES or AES)
  3. Client receives notification (email or SMS)
  4. Client opens portal, reviews document, and signs
  5. Practice receives notification that the document is signed
  6. Both practice and client retain access to the signed document with audit trail

Evaluate: Can the practice set a signature deadline? Can they send a reminder to a client who hasn't signed after X days? Is the notification email branded as the practice (not the software vendor)?

Multi-document envelopes

For clients who need to sign multiple documents at once (standard for new patient intake — privacy notice acknowledgement, treatment consent, payment terms), the portal should support grouping documents into an envelope that the client signs in one session. This is significantly better UX than requiring the client to open and sign five separate notifications.

Template-based document generation

Practices that generate high volumes of standardised documents (consent forms, referral letters, post-visit summaries) need template support: the practice creates a document template with merge fields, the system populates the fields from the client record (name, date of birth, treatment type), and the populated document is sent for signature. Without templates, every document is created manually.

Storage and retrieval

Signed documents must be stored accessibly for the mandatory retention period (clinical records: commonly ten years or more under EU healthcare law). The portal should provide:

  • Searchable document library by client, document type, and date range
  • Download of signed documents with audit trail certificate as a single package
  • Configurable retention periods with automated notifications when documents approach their retention limit

Platform Comparison

FeatureTregoviaDocuSignPracticeHubHelloSign
SES supportYesYesYesYes
AES supportYesYesVariesYes
Multi-document envelopesYesYesVariesYes
Template-based generationYesYesYesVaries
Integrated client portalYesNo (standalone)YesNo
Clinical record integrationYesNoYesNo
Privacy controlsReviewEU optionVariesEU option
Privacy termsReview current termsYesVariesYes
Flat-rate pricingYesPer envelopePer userPer envelope

Verify current features and pricing at each vendor's website.

Setting Up in Tregovia

Tregovia's contracts & eSign module (EUR 15/month) and client portal (included in base plan) together provide a secure client portal with file sharing and electronic signature:

File sharing:

  • Practice → client document upload with client notification
  • Client → practice upload from portal
  • Configurable download permissions per document
  • Document access audit log per client

eSign:

  • SES on all documents: name, timestamp, IP address, document hash
  • AES with SMS OTP verification for high-stakes documents
  • Multi-document envelopes: clients sign all required documents in one session
  • Signature status visible in real time to practice staff

Templates:

  • Consent form templates with merge fields populated from client record
  • Bulk send to multiple clients (e.g., annual policy update requiring client acknowledgement)

Audit trail:

  • Exportable PDF audit certificate per signed document
  • Document hash proving post-signature integrity
  • Complete event log: opened, signed, by whom, when, from where

Privacy controls: Configure access roles, consent records, exports, deletion requests, and retention rules before publishing this workflow.

Pricing: Contracts & eSign module EUR 15/month. Base plan EUR 47/month (flat rate, up to 2 staff, up to 100 clients (extra users EUR 10/month per 5 seats)). 14-day free trial.

FAQ

Is a simple electronic signature (SES) legally valid for clinical consent forms in the EU?

Yes, for the vast majority of routine clinical consents. eIDAS establishes that electronic signatures cannot be denied legal effect solely on the grounds that they are in electronic form. SES is sufficient for: appointment consent forms, treatment policy acknowledgements, standard care consent for elective procedures, and privacy notice acknowledgements. The SES must be recorded with sufficient evidence to identify the signatory (email address matching the portal account), the time of signing, and the fact that the signatory reviewed the document before signing. AES adds identity verification via OTP — appropriate when the identity of the signatory needs to be confirmed more rigorously.

Can a client sign documents on a mobile phone through the portal?

Yes, provided the portal has a mobile-responsive design. Most modern client portals render correctly on smartphones and tablets. The client taps through the document, reaches the signature field, types their name or uses a touch-draw signature, and confirms. The audit trail records the device type and IP address alongside the signature event. Test the mobile signing experience specifically during any platform trial — some portals that work well on desktop have cumbersome mobile interfaces that clients abandon.

How long must signed clinical consent forms be retained?

Under EU healthcare law, clinical records (including signed consents as part of the clinical record) are typically subject to minimum retention periods set by national legislation — commonly ten years from the last clinical contact with the patient, or until the patient reaches age 18 plus ten years for minors (whichever is later). These are minimum periods; the practice may choose to retain records longer. Signed consent forms should be retained for at least as long as the clinical records to which they relate. Configure the portal's retention settings accordingly and confirm the applicable period for your member state with a legal adviser.

What should a practice do if a client refuses to sign a document electronically?

Offer a paper alternative. GDPR and clinical care standards require that clients are not excluded from care because they prefer paper signatures. Have a paper version of any document the portal sends for eSign. When a client refuses electronic signing, send the paper version by post, collect the wet signature, scan the signed document, and upload it to the client's portal record manually. Note that paper signatures require more staff time and create a physical document management process — this is the legitimate operational reason to encourage (but not mandate) electronic signing.

Does the eSign audit trail satisfy the requirements for legal proceedings?

In most EU jurisdictions, yes — a well-constructed SES or AES audit trail (document hash, timestamp, IP address, signer email verified against a portal account) is sufficient evidence of signing for civil legal proceedings. QES provides the highest legal certainty as it has statutory equivalence with handwritten signatures across all EU member states. For documents that may be needed as evidence in litigation — high-value service contracts, specialist procedure consents, employment agreements — consult a legal adviser on whether AES or QES is appropriate for your specific use case and jurisdiction.

14-day free trial

Give clients a professional self-service portal

Platform's client portal handles intake forms, consent signatures, invoice payments, and secure file sharing — all without your staff getting involved.