CompyMax

Is Jotform HIPAA compliant?

Only under specific conditions

Yes, if you are on the Gold or Enterprise plan and run Jotform's HIPAA setup wizard, which migrates your whole account to an isolated system and ends with you signing the agreement.

Applies to Jotform forms. Last reviewed against Jotform's own documentation. Next review January 7, 2027.

Reviewed by Margaret O'Brien — HIPAA Privacy Officer.

What you must do

  • Be on the Gold plan or Enterprise. Jotform states HIPAA features are available on Gold at no additional fee, and on Enterprise.
  • Run the setup wizard, which checks your subscription and requires a verified email and a strong password.
  • Consent to the data move. Jotform migrates your forms and existing submissions onto an isolated system, account-wide rather than per form.
  • Clear the form review — Jotform scans every form and allows only widgets and integrations that support these requirements.
  • Sign the agreement as the final wizard step, then keep the copy from the Data page.
  • Re-link everything after migration. Form URLs change during the move, breaking existing embeds and previously sent links.
  • Decide deliberately about email. Every field defaults to protected, so no submission content appears in notification emails until you connect compliant SMTP and un-protect specific fields.

Does Jotform sign a business associate agreement?

Yes. Jotform offers one. Gold plan (included at no extra fee) or Enterprise. Upgrade to Gold or Enterprise, run the HIPAA setup wizard to completion, then Data page → Sign BAA → submit. The countersigned copy arrives by email and stays downloadable.

See their documentation.

What this means in practice

Jotform sells this as a tier rather than an add-on: the Gold plan includes it at no extra cost, Enterprise includes it too, and nothing below Gold can be made to work.

Switching on is a one-way migration of the whole account. A wizard forces a strong password, scans every existing form for widgets and integrations it will not allow, then moves your forms and past submissions onto an isolated system. Form URLs change during that move, so anything embedded on your website or already emailed to patients needs re-linking.

The behaviour that surprises people most is email. By default no submission content appears in notification or autoresponder messages — you get an alert and log in to read the answers. You can restore the detail only by connecting compliant SMTP and un-protecting individual fields, which should be a deliberate decision.

How organizations get this wrong

The specific mistakes we see with Jotform, not generic advice.

  • Upgrading to a mid tier expecting HIPAA features. Only Gold and Enterprise carry them, and enabling is account-wide rather than per-form.
  • Migrating without re-embedding forms. The move changes form links, silently breaking every embed and previously emailed link.
  • Pushing submissions to Mailchimp, HubSpot or Zapier from one of these forms — Jotform passes only non-patient information to those integrations.
  • Un-protecting fields to get answers back into notification emails while still sending through Jotform's ordinary mail servers.

What the agreement does not cover

  • All plans below Gold.
  • Widgets and integrations Jotform's scan flags as unsuitable, which are blocked from these forms.
  • Airtable, Constant Contact, HubSpot, Mailchimp, MailerLite and Zapier, which Jotform says can carry only information that is not patient information.
  • Submission content in notification emails while fields remain protected and you send through ordinary mail servers.
  • Whatever happens to patient information once it lands in a connected third-party service.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Google Forms

    Free with a Workspace subscription you may already hold

  • Formstack

    A dedicated healthcare plan with a restricted integration allowlist

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Jotform, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Jotform’s own published documentation, read on the date shown.

  1. How to Enable HIPAA Compliance?Jotform. Published May 27, 2025. Read July 29, 2026.
  2. How to Receive a BAA for Your HIPAA AccountJotform. Published January 17, 2025. Read July 29, 2026.
  3. HIPAA Integrations of JotformJotform. Published January 30, 2025. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Jotform’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.