Independent vendor compliance review
Is Jotform HIPAA compliant?
Jotform may support HIPAA-regulated forms only when HIPAA features are enabled, the account is on an eligible plan, and a Business Associate Agreement is in place. Review every form, notification, payment, signature, file upload, and integration before collecting PHI.
Direct compliance answer
Jotform HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-07-27 | Confidence: High
| Direct answer | Jotform may support HIPAA-regulated forms only when HIPAA features are enabled, the account is on an eligible plan, and a Business Associate Agreement is in place. Review every form, notification, payment, signature, file upload, and integration before collecting PHI. |
|---|---|
| BAA availability | Jotform states that a BAA is available for covered entity customers that have enabled HIPAA compliance features. Verify the exact plan, account settings, and covered workflows before collecting PHI. |
| Can it handle PHI? | Intake questions, file uploads, e-signatures, appointment fields, payment descriptions, email notifications, and integrations can all collect or transmit PHI. |
| SOC 2 caveat | Jotform's security materials reference SOC 2 compliance. Enterprise buyers should request the current SOC 2 report and confirm product scope. |
| What to verify | Whether HIPAA compliance features are enabled and a current BAA is signed for the exact Jotform account. Whether form fields, uploads, signatures, payments, emails, autoresponders, PDFs, webhooks, and storage destinations are covered. |
Independent research view
Jotform HIPAA plan and BAA checklist
Jotform's public materials describe a conditional HIPAA path. Verify the current plan, complete the account-level activation and BAA process, and review every data path before collecting PHI.
| Review area | Vendor public signal | Buyer verification |
|---|---|---|
| Eligible plan | Jotform's current HIPAA pricing page lists HIPAA features for Gold and Enterprise plans, not Starter, Bronze, or Silver. | Confirm current plan eligibility and pricing directly with Jotform before building or migrating a regulated workflow. |
| HIPAA activation and BAA | Jotform documents an account upgrade wizard, migration to its HIPAA-enabled environment, form review, and a BAA signing step for covered entity customers. | Complete activation, retain the executed BAA, and confirm that the exact account and intended services are covered. |
| Notifications and documents | Submission data can appear in notifications, autoresponders, PDFs, uploads, signatures, and exports depending on configuration. | Keep PHI out of ordinary email paths and verify every notification, attachment, document, and export setting. |
| Integrations and downstream systems | Jotform limits available integrations in HIPAA-enabled accounts, but connected services still have their own agreement and configuration scope. | Map each webhook, payment processor, storage destination, CRM, calendar, and automation path and verify separate BAA coverage where required. |
HIPAA status signal
Conditional
BAA public signal
Available with HIPAA features
SOC 2 evidence signal
Public evidence
PHI warning: Intake questions, file uploads, e-signatures, appointment fields, payment descriptions, email notifications, and integrations can all collect or transmit PHI.
Search query answers
Is Jotform HIPAA compliant?
Jotform may support HIPAA-regulated forms only when HIPAA features are enabled, an eligible account is used, a BAA is in place, and every notification, upload, payment, signature, and integration path is reviewed for PHI.
Does Jotform offer a BAA?
Jotform's public HIPAA materials state that covered entity customers who enable HIPAA compliance features can receive a signed BAA. Buyers should verify the current plan, account settings, form features, and integrations before collecting PHI.
Can Jotform forms collect PHI?
Potentially, but only inside a verified HIPAA-enabled setup with BAA coverage and careful configuration. Form questions, file uploads, notifications, PDFs, payment fields, e-signatures, and integrations can expose PHI if they are outside covered scope.
Which Jotform plans offer HIPAA-enabled features?
Jotform's HIPAA pricing page currently lists HIPAA-enabled features for Gold and Enterprise plans. Plan names, prices, and feature scope can change, so confirm current eligibility directly with Jotform before collecting PHI.
Can the free Jotform plan be used for PHI?
Jotform's current pricing page marks HIPAA-enabled features as unavailable on the Starter free plan. Do not collect PHI until an eligible plan is active, HIPAA features are enabled, a BAA is executed, and the full workflow is reviewed.
How do you enable Jotform HIPAA features and obtain a BAA?
Jotform documents an account upgrade wizard that checks plan eligibility, reviews forms, migrates data to its HIPAA-enabled environment, and then provides a BAA signing step for covered entity customers. Verify completion and retain the executed agreement before using the account with PHI.
HIPAA, BAA, and SOC 2 summary
| HIPAA | Jotform publishes HIPAA-focused form materials and states that covered entity customers who enable HIPAA compliance features can receive a signed BAA. This does not make every Jotform form, plan, add-on, or integration suitable for PHI. |
|---|---|
| BAA | Jotform states that a BAA is available for covered entity customers that have enabled HIPAA compliance features. Verify the exact plan, account settings, and covered workflows before collecting PHI. |
| SOC 2 | Jotform's security materials reference SOC 2 compliance. Enterprise buyers should request the current SOC 2 report and confirm product scope. |
| PHI risk | Intake questions, file uploads, e-signatures, appointment fields, payment descriptions, email notifications, and integrations can all collect or transmit PHI. |
| Category | HIPAA-Compliant Forms and Intake Software |
| Last checked | 2026-07-27 |
| Confidence | High |
Public evidence and open questions
What public sources say
- Jotform publishes HIPAA-enabled form materials for covered entity customers.
- Jotform states that HIPAA compliance features and a signed BAA are part of its HIPAA workflow.
- Jotform's current HIPAA pricing page lists HIPAA-enabled features for Gold and Enterprise plans.
- Jotform security materials reference SOC 2 compliance signals that buyers should scope to the exact service.
What remains unconfirmed
- Whether the buyer's exact plan, form features, upload storage, e-signature, payments, notifications, and integrations are covered.
- Whether PHI appears in email notifications, PDFs, webhooks, third-party storage, payment descriptions, or support records.
What it may be used for
- HIPAA-enabled intake forms after BAA coverage, account settings, notifications, storage, and integrations are verified.
- PHI-minimized screening forms that avoid unnecessary clinical detail and route data only to covered systems.
- Vendor comparison for healthcare forms, intake, consent, upload, and signature workflows.
What not to use it for
- Collecting PHI through a standard form before HIPAA features and BAA coverage are confirmed.
- Sending PHI in notification emails, autoresponders, webhooks, PDFs, or third-party integrations without covered-service review.
- Assuming payment, calendar, storage, or signature integrations inherit Jotform's HIPAA controls.
What to verify with the vendor
- Whether HIPAA compliance features are enabled and a current BAA is signed for the exact Jotform account.
- Whether form fields, uploads, signatures, payments, emails, autoresponders, PDFs, webhooks, and storage destinations are covered.
- Whether third-party integrations, calendar sync, CRM sync, payment processors, and cloud storage have separate BAA coverage where needed.
- Whether access controls, retention, deletion, audit trails, exports, and support access match the intended PHI workflow.
Safer alternatives and related profiles
Safer alternatives to consider
- A healthcare-specific intake platform when PHI-heavy forms, consent, file uploads, and patient communication must be covered end to end.
- Google Forms only if used inside eligible Google Workspace BAA scope and configured appropriately.
- A covered EHR, patient portal, or practice-management intake workflow for clinical data collection.
FAQ
Is Jotform HIPAA compliant?
Jotform may support HIPAA-regulated forms only when HIPAA features are enabled, an eligible account is used, a BAA is in place, and every notification, upload, payment, signature, and integration path is reviewed for PHI.
Does Jotform offer a BAA?
Jotform's public HIPAA materials state that covered entity customers who enable HIPAA compliance features can receive a signed BAA. Buyers should verify the current plan, account settings, form features, and integrations before collecting PHI.
Can Jotform forms collect PHI?
Potentially, but only inside a verified HIPAA-enabled setup with BAA coverage and careful configuration. Form questions, file uploads, notifications, PDFs, payment fields, e-signatures, and integrations can expose PHI if they are outside covered scope.
Which Jotform plans offer HIPAA-enabled features?
Jotform's HIPAA pricing page currently lists HIPAA-enabled features for Gold and Enterprise plans. Plan names, prices, and feature scope can change, so confirm current eligibility directly with Jotform before collecting PHI.
Can the free Jotform plan be used for PHI?
Jotform's current pricing page marks HIPAA-enabled features as unavailable on the Starter free plan. Do not collect PHI until an eligible plan is active, HIPAA features are enabled, a BAA is executed, and the full workflow is reviewed.
How do you enable Jotform HIPAA features and obtain a BAA?
Jotform documents an account upgrade wizard that checks plan eligibility, reviews forms, migrates data to its HIPAA-enabled environment, and then provides a BAA signing step for covered entity customers. Verify completion and retain the executed agreement before using the account with PHI.
Will Jotform sign a BAA?
Jotform states that a BAA is available for covered entity customers that have enabled HIPAA compliance features. Verify the exact plan, account settings, and covered workflows before collecting PHI.
Can Jotform be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Does SOC 2 mean Jotform is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using Jotform with PHI?
Whether HIPAA compliance features are enabled and a current BAA is signed for the exact Jotform account. Whether form fields, uploads, signatures, payments, emails, autoresponders, PDFs, webhooks, and storage destinations are covered. Whether third-party integrations, calendar sync, CRM sync, payment processors, and cloud storage have separate BAA coverage where needed. Whether access controls, retention, deletion, audit trails, exports, and support access match the intended PHI workflow.
Last checked and source notes
- Last checked
- 2026-07-27
- Confidence
- High
- Dataset rows
- 271 vendors
- Reviewed Jotform HIPAA pricing, activation, BAA, and security materials on 2026-07-27.
- Jotform suitability depends on plan, HIPAA feature activation, BAA scope, form configuration, notifications, storage, payments, signatures, and integrations.
- ComplySaaS did not verify a private Jotform contract or account-specific BAA scope.
- Jotform HIPAA forms
- Jotform HIPAA pricing
- Jotform HIPAA activation guide
- Jotform security