Since Forms is not HIPAA-compliant (due to no auditing of who has accessed data from either the Monitoring tab or from Custom Reports), we're trying to find a workaround that will allow us to still use Forms to automate some critical processes that contain patient data.
Question to this end:
If we delete an instance from Forms, is that data scrubbed from the database, or would it still be discoverable? If the data lives on in the DB, is there any other way to get that cleared?
Our proposed workflow would be to create an input form in Forms. Upon submission, a Workflow would take that information and populate a fillable PDF (which would not be saved to the repository). We would then delete the input form from Forms (and hopefully remove the patient information from our system, thus removing our risk).
For reference regarding the question of HIPAA compatibility, I'm attaching a screenshot from my chat in the Laserfiche Security and Administration virtual booth at Empower 2022.
Thanks in advance!