Dan,

A number of things:

1. How will the autonumber be generated? You could have them ask for a password
2. Ever considered calling HIPAA to see if it would satisfy the requirements or what they would suggest?
3. With email, if you send them an email telling them their data is as secure as you can get it for email, and they send it back stating they agree by virtue of their name being on the reply address, you can use that for email.
4. So, why not just have a disclaimer stating this is SSL secure 128-bit encrypted, but I can't 100% guarantee it is 100% secure. If they check that off, you should be golden.

Just thinking off the top of my head.


Bert
Pediatrics
Brewer, Maine