HIPAA software category hub

HIPAA-Compliant Forms and Intake Software

Forms and intake tools are high-risk because they intentionally collect sensitive information. Before using any form builder for PHI, verify BAA coverage, storage location, email notifications, file uploads, integrations, access controls, and deletion workflows.

Reviewed by Evidence: Public first-party sources

Search intent and page scope

This category owns HIPAA-compliant forms, online forms, form builder, survey, and intake software comparison intent. Individual vendor profiles own exact Google Forms, Microsoft Forms, Jotform, Wix, and Airtable questions.

Review how PHI can move through SaaS fields, files, notifications, and integrations

Direct answer for buyers

Compare forms, surveys, app builders, and intake tools for PHI collection risk, BAA availability, and safer alternatives.

BAA questionConfirm the exact vendor agreement, covered services, account, plan, region, and support path before PHI use.
PHI warningFree-text answers, file uploads, signatures, hidden fields, URL parameters, payment notes, and confirmation emails.
SOC 2 caveatSOC 2 can support security diligence, but it does not replace HIPAA, BAA, PHI workflow, or configuration review.
Verification focusDoes the vendor sign a BAA for the exact form, survey, upload, signature, and storage workflow?

Last updated: 2026-08-28

Buyer questionPublic evidence signalImportant caveat
Which general form builders publish a BAA path?Jotform documents HIPAA-enabled plans and activation, Wix documents PHI protection and BAA steps, and Microsoft and Google include Forms within qualifying cloud agreement scope.Each path is conditional on account, plan, activation, covered services, storage, notifications, uploads, exports, and integrations.
Where does form PHI most often escape?Notification email, autoresponders, files, webhooks, spreadsheets, analytics scripts, CRM syncs, payment tools, and downloaded exports.A covered form database does not make the downstream intake workflow covered.
When is a healthcare-specific intake tool preferable?When identity, consent, signatures, document exchange, routing, patient messaging, payments, and EHR integration need one governed workflow.Compare the complete data path and contract scope, not only the form builder's feature list.
hipaa compliant formshipaa compliant online formshipaa compliant web formshipaa compliant form builderhipaa compliant survey softwarehipaa compliant survey toolsbest hipaa compliant telehealth platformhipaa compliant patient intakehipaa intake formis google forms hipaa compliant

How to choose forms and intake tools

Best for

  • Patient intake or request forms where the form product, storage, notifications, and exports are covered by a BAA.
  • Low-PHI contact forms that avoid collecting diagnosis, treatment, insurance, or patient identifier details.
  • Structured intake workflows with clear ownership, retention, deletion, and access-control rules.

BAA requirements

  • Confirm whether forms, file uploads, signatures, payments, email notifications, APIs, and integrations are covered.
  • Verify whether submitted data is stored in a HIPAA-eligible environment and who can access support logs.
  • Review whether third-party add-ons or automation tools break the covered workflow.

PHI risk areas

  • Free-text answers, file uploads, signatures, hidden fields, URL parameters, payment notes, and confirmation emails.
  • Notification emails, webhooks, spreadsheet exports, CRM syncs, analytics scripts, and embedded forms.
  • Admin comments, support tickets, form revision history, and downloaded CSV files.

Recommended review order

Vendor comparison table

VendorRoleHIPAA signalBAA signalSOC 2 signalReview focusLast checked
Google FormsSaaS vendorConditionalGoogle Workspace BAAGoogle public evidenceWorkspace BAA, Drive storage, uploads, scripts, add-ons2026-07-16
Microsoft FormsSaaS vendorConditionalMicrosoft BAA in-scope serviceMicrosoft audit evidenceMicrosoft BAA scope, tenant, uploads, exports, Power Automate2026-08-28
JotformSaaS vendorConditionalAvailable with HIPAA featuresPublic evidenceHIPAA-enabled account, notifications, uploads, integrations2026-07-27
WixSaaS vendorConditionalAvailable after PHI protectionVerify with vendorSupported services, forms, booking data, apps, notifications2026-09-17
AirtableSaaS vendorConditionalEnterprise Scale onlyPublic evidenceEnterprise Scale terms, interfaces, forms, automations, syncs2026-09-17
Google WorkspaceSaaS vendorConditionalGoogle Workspace BAAPublic evidenceBAA-scoped workflow review2026-04-30
ZapierSaaS vendorNot supported for PHIUnable to confirmPublic evidenceAvoid PHI; compare alternatives2026-05-15

Avoid if

  • The form sends PHI in notification emails or webhooks.
  • File uploads, signatures, or payments are processed by unsupported add-ons.
  • The vendor cannot define which services are covered by a BAA.

Methodology

  • Review collection, storage, notification, export, and integration paths.
  • Treat surveys, waitlists, and contact forms as PHI-capable until proven otherwise.
  • Prefer tools with explicit healthcare workflows and clear BAA scope.

Verification checklist

  • Does the vendor sign a BAA for the exact form, survey, upload, signature, and storage workflow?
  • Can notifications be configured so PHI is not sent through ordinary email or unsupported webhooks?
  • Are access controls, audit logs, deletion, exports, and retention policies enforceable?
  • Are embedded scripts, analytics tools, and connected apps excluded from PHI collection?

Verify the complete workflow before PHI use

Use a vendor and configuration checklist to review BAA scope, covered services, data paths, integrations, support access, and customer responsibilities. Do not submit PHI or patient details.

Related guides

FAQ

What is the biggest HIPAA risk with online forms?

The biggest risk is not only the form database. PHI can leak through notification emails, webhooks, file uploads, hidden fields, analytics scripts, exports, and connected tools that are outside the BAA scope.

What should HIPAA-compliant survey tools support?

Survey tools used with PHI should support a BAA, covered storage, controlled notifications, access controls, audit logging, export governance, deletion workflows, and clear limits on third-party integrations or analytics scripts.

How should buyers compare HIPAA-compliant telehealth platforms?

Start with BAA scope, video and messaging coverage, intake forms, file uploads, scheduling, payments, consent capture, notifications, audit logs, retention, and integrations. Do not choose a telehealth platform from a feature list alone; map where PHI enters and leaves the workflow.

Are HIPAA-compliant survey tools enough for patient intake?

Not by themselves. A survey tool may cover form submission storage, but patient intake also involves identity, consent, file uploads, routing, notifications, exports, EHR or CRM syncs, retention, deletion, and staff access.

Can patient intake forms send email notifications?

Only if the notification workflow is covered and configured so PHI is not exposed through ordinary email, previews, attachments, autoresponders, or downstream systems outside the BAA scope.

Can a general form builder collect PHI?

A general form builder should collect PHI only if the vendor confirms BAA coverage for the exact form product, storage, upload, notification, export, and integration path used by the organization.

What should buyers verify for forms and intake tools?

Verify BAA availability, covered services, product plan, data flows, admin controls, integrations, support access, retention, audit logs, and whether PHI appears in fields, messages, files, or notifications.

Does SOC 2 prove HIPAA readiness?

No. SOC 2 can provide useful security evidence, but HIPAA-regulated workflows also require BAA scope, PHI handling review, configuration, policies, and qualified legal or compliance guidance.