HIPAA compliant form builders
Intake and questionnaire tools. Form responses are the most common accidental route for patient information into an uncovered system.
Form responses are the most common accidental route for patient information into a system nobody vetted. A form is quick to build, it is usually built by whoever felt the friction rather than by whoever owns compliance, and every submission is stored twice — once in the form tool and again wherever the notification email lands.
There are two workable shapes. Either the form builder is already part of a suite whose agreement covers it, in which case the form and its response spreadsheet are in scope together and the work is administrative; or the vendor sells a distinct healthcare configuration. The second is rarely a self-serve upgrade. It tends to be a plan a vendor provisions for you, or an account-wide switch that migrates existing forms, changes their URLs, and strips out widgets and integrations it will not permit.
Expect the healthcare configuration to be defined by what it takes away. Notification emails commonly stop carrying the answers, attachments may be removed, integrations are cut back to a short allowlist, and encryption you have to enable yourself may be required. Those restrictions are the security control, so working around them defeats the point of being on the plan.
5 form builders compared
4 of 5 can be used with patient information under a signed agreement; 1 should not be used with it at all. Each row is drawn from that vendor’s published documentation as read on the date shown — open an entry for the full conditions and sources.
| Vendor | Verdict | Agreement and plan | How to get it | Not covered | Reviewed |
|---|---|---|---|---|---|
| FormstackFormstack Forms | Conditional | A Formstack healthcare plan, provisioned by Formstack rather than bought self-serve. | Contact Formstack support or your account representative to convert onto a healthcare plan. The standard agreement comes with it; custom requests are evaluated case by case. | Any integration outside the healthcare allowlist. | |
| Google FormsGoogle Forms (Google Workspace) | Conditional | A paid Google Workspace or Cloud Identity subscription. Google names no edition requirement, and there is no separate Forms product to buy. | Sign in as a super administrator → Admin console → Account settings → Legal and compliance → accept the HIPAA Business Associate Amendment. | Forms created under a free personal Google account. | |
| JotformJotform forms | Conditional | Gold plan (included at no extra fee) or Enterprise. | Upgrade to Gold or Enterprise, run the HIPAA setup wizard to completion, then Data page → Sign BAA → submit. The countersigned copy arrives by email and stays downloadable. | All plans below Gold. | |
| TypeformTypeform forms and surveys | Conditional | Enterprise, or the sales-negotiated custom growth plan. Ask sales — the latter does not appear on public pricing. | Eligible customers request it from Typeform sales with the organization name and account email. Everyone else must move onto an eligible plan first. | Every self-serve plan. | |
| Squarespace website formsSquarespace website forms and form blocks | No | No agreement offered | — | Contact form features including the form block, which Squarespace says cannot be used as part of a compliant solution. |
What to check before you adopt one
- Find out whether enabling this is per-form or account-wide, and whether it is reversible. An account-wide, one-way migration is a project rather than a setting, and it can change form URLs and break every existing embed and previously emailed link.
- Ask what happens to notification and autoresponder emails. Many configurations deliberately stop including submission content, so you receive an alert and log in to read the answers — and restoring the detail usually means connecting your own mail server.
- Get the integration allowlist before you commit, and check that the tools your workflow depends on are on it. Anything outside it is the control working as designed, not a bug to route around.
- Confirm whether file uploads and attachments are supported at all, because some healthcare configurations remove them from submissions entirely.
- Check whether database or submission encryption is on by default or something you must switch on, and who holds the password — where only holders can read submissions, losing it is unrecoverable.
- Control who can see the response store. Where responses land in a spreadsheet or shared file, link-based sharing puts patient answers outside your access controls regardless of the agreement.
- Treat add-ons and marketplace extensions as outside scope unless the vendor names them, including any advertised specifically as adding HIPAA features to the form builder.
The expensive mistake
Building the intake form first and asking the compliance question afterwards. By then submissions already exist, they are sitting in a tool with no agreement behind it, and the answers have been emailed to several inboxes in plain text. The related trap is migrating an existing account onto a healthcare configuration without re-embedding the forms — the move changes the links, silently breaking every embed and every URL already sent to patients.
Tracking which of these your organization uses?
The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.
Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.