Sharing Documents using Secure Link (Beta)

Plan: Not Available: Intermediate Available: Pro or Elite

Users: Available: All users

Practice Management Source: Available: All sources

Secure Link (beta) allows practices to securely send sensitive FYI documents to clients or contacts by email when the recipient needs to access and download the files for their own records. A code will be sent by email or SMS to allow recipients to verify they are the intended recipient before downloading the documents.

When sharing documents using Secure Link, users will be able to select Forms (Elite plan only), Word, Excel, PowerPoint, and PDF documents stored in FYI. Form Templates (Elite plan only), Phone Calls, Meetings, File Notes, or any documents currently being edited, including internally co-edited, cannot be shared. Documents must be finished editing before sharing.

This feature is currently in beta. Learn more about beta registrations.

Setting up Secure Link

Before sharing documents, you will need to complete the following steps to configure Secure Link and prepare your data.

Email Template

When emailing documents using Secure Link, a Merge Field is used to insert the link that recipients will need to click to access the documents. An Email Template must be created containing this merge field; otherwise, the link will not be sent, and recipients will be unable to access the documents.

An FYI Admin or a user with permissions enabled for Templates must first create the email template containing the relevant link. 

For instructions on creating Email Templates, refer to Creating Email Templates.

  1. Create a new Email Template.
     
  2. Position the cursor in the location in the Email Template or Signature where you want the information to appear.
     
  3. Expand the Document section, and click Secure Link.
     
  4. The Merge Field code will be added to the body of the Email Template, displayed as {{ DocumentSecureLinkURL | web_link }}.

    Note: When sending the email, the link will be displayed as "Click here".
    5087_Email_Template_Secure_Link_Merge_Field.gif
Review Recipient Contact Details

When verifying the identity of the recipient accessing the files, Secure Link will use the contact details stored in FYI.

It's important to ensure these contact details are correct before sending documents using Secure Link. Incorrect or missing details will impact the ability of the recipient to enter a code and access the documents. Documents will need to be reshared if the details are updated.

Note: For practices on the Elite plan with Forms enabled, FYI offers a Custom Automation Example for updating client details, allowing practices to share a prepopulated Form for clients to review and provide their details.

Secure Link will check the following contact details:

If the phone and mobile fields are blank, the details for the Primary Contact will be used. If a valid mobile number is not available, the code will be sent by email instead.

Supported Phone Number Formats

For details on supported phone number formats, click on the relevant region below.

Australia

The following formats are supported phone number formats.

Supported Formats Example
Mobile number with an AU country code, excluding the 0. Spaces may or may not be included. +61412345678
+61 412 345 678
+61412 345 678
Local number (no country code) with a 0 prefix. Spaces may or may not be included. 0412345678
0412 345 678
Local number (no country code) with hyphens. 0412-345-678

The following formats are unsupported phone number formats.

Unsupported Formats Example
Missing a prefix. 412345678
Missing the + before the AU country code. 61412345678
Landline number (doesn't start with a 4 after the prefix). 0212345678
New Zealand

The following formats are supported phone number formats.

Supported Formats Example
Mobile number with an NZ country code, including short variants, excluding the 0. +64211234567
+6421123456
Local number (no country code) with a 0 prefix, including short variants. 0211234567
021123456

The following formats are unsupported phone number formats.

Unsupported Formats Example
Missing a prefix. 211234567
Missing the + before the NZ country code. 64211234567
Prefix is in brackets or parentheses. (+64) 211234567
Landline number (doesn't start with a 2 after the prefix). 0311234567
Mobile number contains spaces or hyphens. 021 123 4567
021-123-4567
United Kingdom

The following formats are supported phone number formats.

Please note that Mobile Numbers from the Republic of Ireland are not supported.

Supported Formats Example
Mobile number with a UK country code, excluding the 0. Spaces may or may not be included. +447911123456
+44 7911 123456
Mobile number with a UK country code, excluding the + prefix. 447911123456
Local number (no country code) with a 0 prefix. Spaces may or may not be included. 07911123456
07911 123456

The following formats are unsupported phone number formats.

Unsupported Formats Example
Mobile number with hyphens. 0791-1123456
Configure Expiry Period

By default, access to documents will expire 30 days after they have been shared. An FYI Admin can customise the Expiry Period to a different length of time from within the Documents Practice Settings

Note: Changes to the Share Expiry Period will only take effect for new documents shared via Secure Link. Any existing shared documents will retain the expiry date configured when the documents were shared.

  1. Click Settings in the top-right corner, and select Practice Settings.
     
  2. Select Documents.
    2848_Practice_Settings_Documents.gif
  3. Click the Secure Link tab.
     
  4. Enter a new Share expiry period value, between 1 and 365 days.
    5127_Secure_Link_Document_Settings_Expiry.gif
  5. Click out of the field. The changes will be saved, and a message will be displayed to confirm that the settings were updated successfully.

An alert will be added to Practice Activity to record the change in the configuration.

Sharing Documents via Secure Link

When sharing documents using Secure Link, you can send one or more documents stored in FYI, including Forms (Elite plan only), Word, Excel, PowerPoint, and PDF. 

Form Templates (Elite plan only), Phone Calls, Meetings, File Notes, or any documents currently being edited, including internally co-edited, cannot be shared. Documents must be finished editing before sharing.

Note: Files are limited to a maximum of 50 MB each. Up to 10 files can be shared at the same time.

To share a document using Secure Link:

  1. Select one or more documents from the Documents list.
     
  2. Click the Share button in the toolbar to display the Create Email drawer.
    800_Share_button.gif
    Note: If the Share button is disabled, ensure that the selected documents are the correct Document Types and have been finished editing before sharing.
     
  3. You can select additional recipients to send the email to. Each recipient will be required to verify their identity separately to access the documents.

    Click the 1 Recipient link, and click the drop-down to display contacts or to enter a new email address.

    Recipients must be added as a "To" recipient. BCC and CC recipients cannot access documents shared via Secure Link.

    Note: If sharing a Form with multiple recipients, the form can only be submitted once and will become unavailable to other recipients. A reminder message will be displayed to users for confirmation when creating the email. Refer to Using Forms with Secure Link below.
     
  4. Select a Template from the drop-down. 
    Note: The selected template must have the Secure Link Merge Field included to ensure a link is sent to the email recipient.
     
  5. Update any filing details as relevant.
     
  6. Select Save or Send to save it as Draft in FYI, Draft in Outlook, or Send Immediately.
     
  7. Change the Send Attachments option to Secure Link.
    Note: To select Secure Link as the default Send Attachments method when sharing documents for this client, update the Send Attachments field in Client Settings.
    5094_Email_Drawer_Attachments_Secure_Link.gif
  8. The Expiry Period will be displayed at the bottom. Once expired, recipients will need to contact the practice to request a new link.

    Note: When sharing a Form, access to the form will expire based on the Secure Link Expiry Period, or if the form has been submitted.
     
  9. Click Create.
     
  10. A notification will be displayed in the bottom right corner that the email is being sent.

Accessing Documents using Secure Link

To ensure that shared documents are only opened by the intended recipients, the client or contact will be asked to verify their identity before they can access shared documents.

These steps must be completed each time the link is used to access the files.

  1. The client or contact receives an email notification with a link to the shared documents.
    5095_Outlook_Client_Secure_Link_Email.gif
     
  2. The recipient clicks on the link and is prompted to enter their email address

    The email address must be the same email address that the documents were shared with. If the email address does not match, an error will be displayed. 

    If a recipient's email address is changed after documents have been shared, the documents will need to be re-shared using the new address.

    Note: If the user enters an incorrect email address 3 times, access will be denied. The recipient will need to contact the practice to confirm their details and request a new link.
    5096_Secure_Link_Verify_Email.gif
  3. Click Continue.

    A Multi-Factor Authentication (MFA) code will be sent to the recipient. By default, an SMS text message will be attempted first. If a matching mobile number cannot be found in FYI for the recipient, an email will be sent instead. 

    The verification code will be valid for 5 minutes.

    Note: If more than one contact in FYI uses the same email address, the recipient will be asked to select their mobile number before the code is sent. Click "My number is not displayed" to send the code by email instead.

    Click the sections below to view more details.

    SMS

    An SMS will be sent to the recipient when a mobile phone number is stored in FYI in either the Phone or Mobile fields.

    5097_Secure_Link_MFA_Code_Text.gif

    If more than one contact in FYI uses the same email address, the recipient will be asked to select their mobile number before the code is sent. Select "My number is not displayed" to send the code by email instead.

    5098_Secure_Link_MFA_Code_Select_Number.gif

    When the SMS is received:

    • The sender will be displayed as "FYI".
    • The practice's name will be displayed at the start of the message.
    • The message will be displayed as follows:

      "(Practice name) has shared documents with you. Your verification code is (Code). This code expires in 5 minutes. Do not share this code with anyone."
    Email

    If a mobile number cannot be found in FYI for the entered email address, or the recipient selects "My number is not displayed", the code will be sent by email.

    5099_Secure_Link_MFA_Code_Email.gif

    When the email is received:

    • The email will be sent from the email address no-reply@fyi.app.
    • The email subject will be "Your FYI verification code".
    • The message will be displayed as follows:

      "(Practice name) has shared documents with you securely via FYI. Your verification code is:

      (code)

      This code expires in 5 minutes. If you did not request this code, you can ignore this email - no further action is required.

      Do not share this code with anyone.
  4. The recipient enters the verification code. 

    The verification code is valid for 5 minutes, with the expiry date and time displayed in the recipient's local time. If the recipient doesn't enter the code before the expiry time, they can click the Resend Code link. A new code can be requested once the current code expires.

    If an invalid code is entered 5 times, the recipient will be locked out for 30 minutes. After the lockout time expires, they will be able to request a new code. 
     
  5. The code will be authenticated, and if successful, a link will be displayed to download the documents or open the form. If only a single form is shared, recipients will be automatically redirected to the form. Click on the examples below for details.

    Single Document

    The following is an example of when only a single document has been shared using Secure Link.

    5101_Secure_Link_Documents_Download.gif

    Single Form

    The following is an example of where a Form has been shared using Secure Link.

    5120_Secure_Link_Form_Redirect.gif

    Multiple Documents

    The following is an example of when multiple documents have been shared using Secure Link.

    5119_Secure_Link_Archive_Zip.gif

    Multiple Forms

    The following is an example of when multiple forms have been shared using Secure Link.

    5117_Secure_Link_Multiple_Forms.gif

    Documents and Forms

    The following is an example of when both a document and a form have been shared using Secure Link.

    5116_Secure_Link_Documents_Forms.gif

Working with Secure Link

Activity Tracking

The Activity section of the Document Drawer will display various updates when using Secure Link. This includes when:

  • A Secure link is generated.
  • A Secure link MFA Code is requested.
  • The shared document has been accessed using the link.
  • There have been 3 unsuccessful email attempts.
  • An incorrect code has been entered more than 5 times, and the user is locked out for 30 minutes.
  • If the verification code could not be delivered by SMS or Email.

5100_Secure_Link_Document_Drawer_Activity.gif

Using Forms with Secure Link

Form names will only be displayed to the recipient after they have verified their identity and accessed the shared documents. 

Where multiple forms have been shared, the recipient can click on the Open Form link to open and complete the form in a new window.

5117_Secure_Link_Multiple_Forms.gif

If sharing a form with multiple recipients, the form can only be submitted by one recipient. Once submitted, the form will become unavailable to the remaining recipients.

A reminder will be displayed to the user in FYI prior to sending the email. 

5118_Secure_Link_Form_Multiple_Recipients_Warning.gif

If the form is required to be submitted by each recipient, you will need to create and share a separate form for each recipient.

Secure Link Share Expiry

Access to documents sent via Secure Link will expire automatically depending on the configured Expiry Period and the date the documents were shared. 

When access expires, the recipient will not be able to access the documents using the link. An entry will be added to the document - Activity section to show that the Secure Link has expired.

Shared documents are not deleted from FYI, and the practice will continue to have access as required. 

If the recipient needs access to the documents, they will need to be re-shared from FYI.

Was this article helpful?
0 out of 0 found this helpful

Stay Up-To-Date

  • Events

    We host a range of product demos, training webinars, workshops and more.

  • Service Status

    Check for updates on the FYI Platform

  • What's New

    Round-up of new features, fixes, and other important announcements.