HIPAA compliant form builders
Intake and questionnaire tools. Form responses are the most common accidental route for patient information into an uncovered system.
Form responses are the most common accidental route for patient information into a system nobody vetted. A form is quick to build, it is usually built by whoever felt the friction rather than by whoever owns compliance, and every submission is stored twice — once in the form tool and again wherever the notification email lands.
There are two workable shapes. Either the form builder is already part of a suite whose agreement covers it, in which case the form and its response spreadsheet are in scope together and the work is administrative; or the vendor sells a distinct healthcare configuration. The second is rarely a self-serve upgrade. It tends to be a plan a vendor provisions for you, or an account-wide switch that migrates existing forms, changes their URLs, and strips out widgets and integrations it will not permit.
Expect the healthcare configuration to be defined by what it takes away. Notification emails commonly stop carrying the answers, attachments may be removed, integrations are cut back to a short allowlist, and encryption you have to enable yourself may be required. Those restrictions are the security control, so working around them defeats the point of being on the plan.
Can be used with patient information
Each of these requires a signed agreement and, usually, specific settings. Open an entry for the exact conditions.
Formstack
ConditionalYes, if Formstack moves you onto one of its healthcare plans, which comes with a signed agreement but restricts your integrations, email and attachments.
Google Forms
ConditionalYes, if you use Forms inside a paid Google Workspace account where a super administrator has accepted Google's amendment — Forms is covered as part of Google Drive.
Jotform
ConditionalYes, if you are on the Gold or Enterprise plan and run Jotform's HIPAA setup wizard, which migrates your whole account to an isolated system and ends with you signing the agreement.
Typeform
ConditionalOnly on Typeform's enterprise-level plans, after you tell Typeform in advance and it agrees to sign — on the ordinary self-serve plans Typeform's own terms bar you from collecting patient information.
What to check before you adopt one
- Find out whether enabling this is per-form or account-wide, and whether it is reversible. An account-wide, one-way migration is a project rather than a setting, and it can change form URLs and break every existing embed and previously emailed link.
- Ask what happens to notification and autoresponder emails. Many configurations deliberately stop including submission content, so you receive an alert and log in to read the answers — and restoring the detail usually means connecting your own mail server.
- Get the integration allowlist before you commit, and check that the tools your workflow depends on are on it. Anything outside it is the control working as designed, not a bug to route around.
- Confirm whether file uploads and attachments are supported at all, because some healthcare configurations remove them from submissions entirely.
- Check whether database or submission encryption is on by default or something you must switch on, and who holds the password — where only holders can read submissions, losing it is unrecoverable.
- Control who can see the response store. Where responses land in a spreadsheet or shared file, link-based sharing puts patient answers outside your access controls regardless of the agreement.
- Treat add-ons and marketplace extensions as outside scope unless the vendor names them, including any advertised specifically as adding HIPAA features to the form builder.
The expensive mistake
Building the intake form first and asking the compliance question afterwards. By then submissions already exist, they are sitting in a tool with no agreement behind it, and the answers have been emailed to several inboxes in plain text. The related trap is migrating an existing account onto a healthcare configuration without re-embedding the forms — the move changes the links, silently breaking every embed and every URL already sent to patients.
Tracking which of these your organization uses?
The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.
Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.