HIPAA software category hub
HIPAA-Compliant Forms and Intake Software
Forms and intake tools are high-risk because they intentionally collect sensitive information. Before using any form builder for PHI, verify BAA coverage, storage location, email notifications, file uploads, integrations, access controls, and deletion workflows.
Search intent and page scope
This category owns HIPAA-compliant forms, online forms, form builder, survey, and intake software comparison intent. Individual vendor profiles own exact Google Forms, Microsoft Forms, Jotform, Wix, and Airtable questions.
Review how PHI can move through SaaS fields, files, notifications, and integrationsDirect answer for buyers
Compare forms, surveys, app builders, and intake tools for PHI collection risk, BAA availability, and safer alternatives.
| BAA question | Confirm the exact vendor agreement, covered services, account, plan, region, and support path before PHI use. |
|---|---|
| PHI warning | Free-text answers, file uploads, signatures, hidden fields, URL parameters, payment notes, and confirmation emails. |
| SOC 2 caveat | SOC 2 can support security diligence, but it does not replace HIPAA, BAA, PHI workflow, or configuration review. |
| Verification focus | Does the vendor sign a BAA for the exact form, survey, upload, signature, and storage workflow? |
Last updated: 2026-08-28
| Buyer question | Public evidence signal | Important caveat |
|---|---|---|
| Which general form builders publish a BAA path? | Jotform documents HIPAA-enabled plans and activation, Wix documents PHI protection and BAA steps, and Microsoft and Google include Forms within qualifying cloud agreement scope. | Each path is conditional on account, plan, activation, covered services, storage, notifications, uploads, exports, and integrations. |
| Where does form PHI most often escape? | Notification email, autoresponders, files, webhooks, spreadsheets, analytics scripts, CRM syncs, payment tools, and downloaded exports. | A covered form database does not make the downstream intake workflow covered. |
| When is a healthcare-specific intake tool preferable? | When identity, consent, signatures, document exchange, routing, patient messaging, payments, and EHR integration need one governed workflow. | Compare the complete data path and contract scope, not only the form builder's feature list. |
How to choose forms and intake tools
Best for
- Patient intake or request forms where the form product, storage, notifications, and exports are covered by a BAA.
- Low-PHI contact forms that avoid collecting diagnosis, treatment, insurance, or patient identifier details.
- Structured intake workflows with clear ownership, retention, deletion, and access-control rules.
BAA requirements
- Confirm whether forms, file uploads, signatures, payments, email notifications, APIs, and integrations are covered.
- Verify whether submitted data is stored in a HIPAA-eligible environment and who can access support logs.
- Review whether third-party add-ons or automation tools break the covered workflow.
PHI risk areas
- Free-text answers, file uploads, signatures, hidden fields, URL parameters, payment notes, and confirmation emails.
- Notification emails, webhooks, spreadsheet exports, CRM syncs, analytics scripts, and embedded forms.
- Admin comments, support tickets, form revision history, and downloaded CSV files.
Recommended review order
Start with vendors that show clearer BAA signals
Treat these as higher-risk until verified
Vendor comparison table
| Vendor | Role | HIPAA signal | BAA signal | SOC 2 signal | Review focus | Last checked |
|---|---|---|---|---|---|---|
| Google Forms | SaaS vendor | Conditional | Google Workspace BAA | Google public evidence | Workspace BAA, Drive storage, uploads, scripts, add-ons | 2026-07-16 |
| Microsoft Forms | SaaS vendor | Conditional | Microsoft BAA in-scope service | Microsoft audit evidence | Microsoft BAA scope, tenant, uploads, exports, Power Automate | 2026-08-28 |
| Jotform | SaaS vendor | Conditional | Available with HIPAA features | Public evidence | HIPAA-enabled account, notifications, uploads, integrations | 2026-07-27 |
| Wix | SaaS vendor | Conditional | Available after PHI protection | Verify with vendor | Supported services, forms, booking data, apps, notifications | 2026-09-17 |
| Airtable | SaaS vendor | Conditional | Enterprise Scale only | Public evidence | Enterprise Scale terms, interfaces, forms, automations, syncs | 2026-09-17 |
| Google Workspace | SaaS vendor | Conditional | Google Workspace BAA | Public evidence | BAA-scoped workflow review | 2026-04-30 |
| Zapier | SaaS vendor | Not supported for PHI | Unable to confirm | Public evidence | Avoid PHI; compare alternatives | 2026-05-15 |
Avoid if
- The form sends PHI in notification emails or webhooks.
- File uploads, signatures, or payments are processed by unsupported add-ons.
- The vendor cannot define which services are covered by a BAA.
Methodology
- Review collection, storage, notification, export, and integration paths.
- Treat surveys, waitlists, and contact forms as PHI-capable until proven otherwise.
- Prefer tools with explicit healthcare workflows and clear BAA scope.
Verification checklist
- Does the vendor sign a BAA for the exact form, survey, upload, signature, and storage workflow?
- Can notifications be configured so PHI is not sent through ordinary email or unsupported webhooks?
- Are access controls, audit logs, deletion, exports, and retention policies enforceable?
- Are embedded scripts, analytics tools, and connected apps excluded from PHI collection?
Verify the complete workflow before PHI use
Use a vendor and configuration checklist to review BAA scope, covered services, data paths, integrations, support access, and customer responsibilities. Do not submit PHI or patient details.
Related guides
HIPAA SaaS BAA Availability Index
The ComplySaaS BAA Availability Index compares public HIPAA, BAA, PHI, and SOC 2 signals across 30 core SaaS vendors. It is a research starting point,...
What Is a Business Associate Agreement (BAA)?
A Business Associate Agreement is a HIPAA contract between a covered entity and a vendor that may create, receive, maintain, or transmit PHI. A BAA do...
Can You Store PHI in SaaS Tools?
You should only store PHI in a SaaS tool after verifying that the vendor, product, plan, agreement, configuration, and connected systems support that ...
How to Evaluate a HIPAA-Compliant App Builder
A no-code app builder may support HIPAA-regulated workflows only if the vendor covers the exact product, database, file storage, automations, integrat...
SOC 2 vs HIPAA for SaaS Vendor Review
SOC 2 and HIPAA answer different questions. SOC 2 is independent security-control evidence for a service organization, while HIPAA governs protected h...
FAQ
What is the biggest HIPAA risk with online forms?
The biggest risk is not only the form database. PHI can leak through notification emails, webhooks, file uploads, hidden fields, analytics scripts, exports, and connected tools that are outside the BAA scope.
What should HIPAA-compliant survey tools support?
Survey tools used with PHI should support a BAA, covered storage, controlled notifications, access controls, audit logging, export governance, deletion workflows, and clear limits on third-party integrations or analytics scripts.
How should buyers compare HIPAA-compliant telehealth platforms?
Start with BAA scope, video and messaging coverage, intake forms, file uploads, scheduling, payments, consent capture, notifications, audit logs, retention, and integrations. Do not choose a telehealth platform from a feature list alone; map where PHI enters and leaves the workflow.
Are HIPAA-compliant survey tools enough for patient intake?
Not by themselves. A survey tool may cover form submission storage, but patient intake also involves identity, consent, file uploads, routing, notifications, exports, EHR or CRM syncs, retention, deletion, and staff access.
Can patient intake forms send email notifications?
Only if the notification workflow is covered and configured so PHI is not exposed through ordinary email, previews, attachments, autoresponders, or downstream systems outside the BAA scope.
Can a general form builder collect PHI?
A general form builder should collect PHI only if the vendor confirms BAA coverage for the exact form product, storage, upload, notification, export, and integration path used by the organization.
What should buyers verify for forms and intake tools?
Verify BAA availability, covered services, product plan, data flows, admin controls, integrations, support access, retention, audit logs, and whether PHI appears in fields, messages, files, or notifications.
Does SOC 2 prove HIPAA readiness?
No. SOC 2 can provide useful security evidence, but HIPAA-regulated workflows also require BAA scope, PHI handling review, configuration, policies, and qualified legal or compliance guidance.