Digital informed consent is fully legally valid under Italian and European law. Medical practices can collect consent forms signed digitally with a graphometric or OTP signature, obtaining legally binding documents that can be archived securely.
What is digital informed consent?
Digital informed consent is the collection of the patient's consent by electronic means. The patient signs documents on a tablet, computer or smartphone. The signature is legally valid and binding. It has no lesser value than paper.
Italian law expressly allows digital consents. Law 219/2017 governs the patient's right to self-determination. The Digital Administration Code (CAD) recognises the validity of advanced digital signatures.
Medical practices that digitise consents cut the cost of paper archiving. The time spent managing documentation drops considerably. Patients sign faster than they do on paper.
The regulations governing digital consents
Law 219/2017 (Rules on informed consent and advance treatment directives) is the Italian legal foundation. It guarantees the patient's right to full and informed information.
The Digital Administration Code (CAD, Legislative Decree 82/2005) governs digital signatures. The graphometric signature and the OTP signature are recognised as advanced electronic signatures (FEA). Both have full legal force in healthcare.
The eIDAS Regulation (no. 910/2014) harmonises digital signatures across Europe. A signature collected in Italy is valid throughout the EU. This helps facilities with international patients.
The GDPR (EU Regulation 2016/679) governs the protection of personal data. Medical practices that digitise consents must ensure data security. Archiving must comply with privacy regulations.
The circular of the Agenzia delle Entrate (Italian Revenue Agency) has clarified that digital consents are fully valid. There is no need to keep a paper duplicate for legal validity.
Manage informed consent digitally and compliantly
BeebeeDoc is the cloud medical practice management software that digitises informed consent with graphometric and OTP signatures, secure archiving and full GDPR compliance. 15-day free trial, no card required.
Graphometric signature: the biometric signature on a tablet
The graphometric signature captures the biometric characteristics of the patient's signature. The patient signs directly on a tablet or touch screen during the visit. The system records the speed, pressure and acceleration of the pen.
The graphometric signature is an Advanced Electronic Signature under the CAD (Digital Administration Code). It has the same validity as a signature on paper. Italian courts recognise it as firm proof of authenticity.
The graphometric signature has many advantages. The patient signs in real time during the consultation. There is no need to print the form first. The biometric data adds a further layer of security and authenticity to the signature.
In the event of a dispute, the graphometric signature is hard to challenge. The biometric parameters show that only the holder could have signed. Medical practices have very solid documentation from a legal point of view.
OTP signature: signing with a one-time code
The OTP (One-Time Password) signature uses a one-time code sent by SMS or email. The patient receives the code on their phone or at their email address. They enter the code to sign the digital document.
The OTP signature is also an advanced electronic signature under the CAD. It gives documents full legal validity. It is worth no less than the graphometric signature.
The OTP signature is ideal for remote patients or patients not present in the practice. It can be collected by email or WhatsApp message. The patient signs from home or from anywhere.
Every OTP is unique and cannot be reused. This guarantees the security of the transaction. The system records the date, the time and the device from which the code was entered.
In telemedicine, the OTP signature is the best solution. The patient completes the appointment online and receives the digital consent form by email. They sign the form with an OTP without coming to the practice.
Digital consent vs. paper consent: the differences
Paper consent requires printing, signing by hand and filing in physical folders. Finding a specific document can take time. The storage space grows quickly with the number of patients.
Digital consent removes all printing and paper archiving costs. Finding a specific consent takes milliseconds through the search engine. Storage space is unlimited and cheap in the cloud.
Paper consent risks being lost or damaged by wear. Digital consent is replicated on secure servers and protected by automatic backups. It cannot be lost if the practice suffers a fire or a flood.
Paper consent is not traceable in real time. Digital consent automatically records the date, time and identity of the person who signed it. Traceability is complete and immutable.
Paper consent cannot easily be shared between professionals. Digital consent allows authorised access by several users at the same time. The data is available to every doctor treating the patient.
Legal validity of digital consent in Italy
The Court of Cassation has confirmed the validity of the advanced digital signature several times. Consent signed with a graphometric or OTP signature has the same value as one on paper. No supporting paper document is needed.
The Ordine degli Assistenti Sociali (Italy's professional body for social workers) has recognised the validity of digital consents. The medical associations confirm that digital consents fully comply with the law. No supervisory body has ever challenged their validity.
In a hearing or a trial, a digital consent form is admissible as evidence. The graphometric signature is hard to challenge because of the biometric component. The OTP signature is protected by the certain date on which the code was sent.
Public and private healthcare facilities now use digital consent. AGID (Agenzia per l'Italia Digitale) supports this practice. Medical insurers accept digital consent as valid documentation without objection.
GDPR compliance for digital consents
The GDPR also governs the processing of personal data in digital consent. The medical practice must tell the patient how the data is collected and stored. The consent form must set this out clearly.
Digital consents must be stored on servers with end-to-end encryption. The data must be protected against unauthorised access. Only authorised staff may view signed consents.
The practice must have a Data Protection Officer if it processes a large amount of sensitive data. An automatic backup policy guarantees the availability of the data. Backups must be kept for the legally required period.
Patients have the right to access their consents at any time. They can ask for copies of the signed documents. The practice must reply within 30 days of the request.
Digital consent must let the patient withdraw consent easily. The withdrawal has to be recorded and dated. The practice can no longer use the data covered by the withdrawn consent.
How BeebeeDoc handles digital informed consents
BeebeeDoc is the cloud medical practice management software specialising in informed consent. It has built-in graphometric signing on a tablet and OTP signing by email. Every consent form is automatically dated and tracked in the system.
The BeebeeDoc platform lets you create custom consent forms. The forms adapt to every medical specialty and every type of procedure. Required fields make sure no information is left out.
During the appointment, the doctor presents the consent to the patient on a tablet. The patient signs graphometrically in front of the doctor. The signature is encrypted and archived in the cloud immediately.
For remote patients, BeebeeDoc sends the form by email with a protected link. The patient clicks the link, reads the form and signs with OTP. The consent is instantly available in the digital record.
BeebeeDoc automatically produces a signed PDF of the consent. The document contains the graphometric signature reproduced digitally. Cryptographic hashes guarantee that the document cannot be altered.
All consent forms are archived in data centres with automatic backup. End-to-end encryption protects the data from unauthorised access. Access is logged and monitored for every user of the practice.
Secure archiving and GDPR compliance in BeebeeDoc
BeebeeDoc uses European data centres with ISO 27001 certification. The servers are physically located in Italy and subject to Italian law. Data sovereignty is guaranteed without exception.
AES-256 encryption protects all signed consents. The encryption keys are managed separately from the data. Only authorised practice users have access to the consents.
BeebeeDoc applies a legal retention policy to every consent form. The forms are kept for as long as the law requires. After the legal retention period they are automatically and securely deleted.
The system records every access to the digital consent forms in the audit trail. The practice owner can see who has viewed each consent form. The date, time and device used for access are always tracked.
BeebeeDoc lets the patient download their consents at any time. The download happens through a protected link with an expiry date. The practice keeps the archived copy for the required retention years.
Digital certification and evidential value
BeebeeDoc applies timestamping to every consent form. The timestamp is provided by accredited Certification Authorities. This automatically gives the documents a certain date.
The digital certificate attached to each consent makes it possible to verify its integrity. Any change to the document would be detected immediately. The signature remains valid and verifiable for decades.
Consents signed in BeebeeDoc comply with the international XAdES standard. This format guarantees compatibility with systems in other European countries. The consents remain verifiable in the future too.
In a dispute, the digital consent held in BeebeeDoc is firm evidence. The court recognises the graphometric signature as authentication of the patient. The digital chain of custody proves the integrity of the document.
How to introduce digital consents in your practice
The first step is to review your practice's consent forms. Make sure they contain all the information required by Law 219/2017. The minimum elements are diagnosis, procedure, risks and alternatives.
Configure BeebeeDoc with your own customised consent forms. The platform offers templates for different medical specialties. Each form can carry the practice logo and patient-specific data.
Train the practice staff in the use of the digital signature. Operators must understand how the graphometric signature and OTP work. Training ensures correct and consistent implementation.
Start with a graphometric signature on a tablet during appointments at the practice. The patient signs in front of the doctor just as they would have signed on paper. The process is identical to paper but without printing costs.
Add the OTP signature later for remote and telemedicine patients. Patients will receive a form by email with a protected link. Signing takes a few seconds, with no complicated procedures.
Keep the GDPR compliance reports up to date monthly. BeebeeDoc supplies the audit trail data automatically. The reports demonstrate compliance with the regulations in the event of an inspection.
Frequently asked questions about digital consent
Is it legal to collect digital consent in Italy? Yes, it is fully legal under the Digital Administration Code (CAD), Law 219/2017 and the GDPR. Graphometric and OTP signatures have full legal validity.
Do I have to keep the paper consent as well as the digital one? No, digital consent is enough. Keeping a paper duplicate is not required for legal compliance.
How long must I keep digital consent forms? The period depends on the type of procedure and on civil liability law. Generally 10 years for adults, longer for minors. BeebeeDoc handles retention automatically.
Is the OTP signature as secure as the graphometric one? Yes, both are Advanced Electronic Signatures with identical legal validity. The choice depends on the situation: graphometric for patients present in person, OTP for remote ones.
What happens if a patient denies having signed the consent? The graphometric signature contains biometric data that are extremely hard to forge. The OTP signature is protected by the certified date on which the code was sent. The court recognises both as reliable evidence.
Conclusions on digital informed consent
Digital informed consent is not the future: it is the present of modern medicine. Over the past five years, healthcare organisations have adopted digital signing on a large scale. The technology is mature, secure and recognised by law.
The advantages of digital far outweigh paper consent. Lower costs, full traceability, secure archiving and GDPR compliance are mandatory standards today. Practices that delay digitisation risk becoming obsolete.
BeebeeDoc offers a complete, ready-to-use solution for digital consent. Graphometric and OTP signatures are built into the platform. Storage complies with GDPR and keeps data secure.
Introducing digital consents in your practice is simple and quick. It requires no investment in complex infrastructure. BeebeeDoc provides all the support needed for a risk-free transition.
The digital signature is the first step towards fully digital practice administration. With BeebeeDoc you manage consents, medical reports and clinical records on a single secure platform. Save time, paper and storage costs.




