Client Login
All notes

HIPAA Compliant Online Forms: 5 Questions to Ask a Vendor

Most form tools will tell you they are HIPAA compliant. Five questions separate the ones that are from the ones that have a page about it.

Every form vendor has a HIPAA page. Most of them say roughly the same thing, and the language is close enough that comparing them is genuinely hard.

These five questions produce different answers from different vendors, which is what makes them useful. You can ask all five in one email.

1. Will you sign a BAA on the plan I am actually on?

Not "do you support HIPAA." Not "do you offer BAAs." The question is whether they will sign for your account, on your current plan.

This is where most form tools quietly fail. Several popular ones sign only on an enterprise tier that costs several times what a practice is paying. The HIPAA page is accurate and the practice reading it is not covered by any of it.

If the answer involves upgrading, get the number before you go further. It often changes the decision.

2. Which features does the BAA cover?

Vendors sign for their product. Products have parts, and the agreement covers the parts it names.

Newer features are the usual gap: an integration, an AI assistant, a scheduling add-on shipped after the agreement was drafted. The BAA is real and the feature sits outside it.

Ask for the coverage in writing, then check that the thing you actually use is on the list.

3. Where does the submission come to rest?

A form is a pipe. What matters is the other end.

Some tools store submissions on their servers indefinitely. Some email them onward, which quietly turns your inbox into the storage system and drags your email provider into scope. Some drop them into a spreadsheet. Some do several of these at once, by default, without saying so.

You want a plain answer: where the data sits, for how long, who can read it, and how it is deleted. A vendor who cannot answer quickly has not been asked often enough.

4. Who else touches it?

Your form tool runs on a host. That host may sit behind a content network. Any company in that chain that handles patient information needs its own signed agreement with the one above it.

Ask the vendor to describe their chain. This is the single most revealing question on the list, because it cannot be answered from a marketing page. Either they have worked it out or they have not.

5. What loads on the page alongside the form?

This one is not about the vendor at all, and it is the one people forget.

An embedded form sits on your page. Your page loads whatever your site loads. If a tracking script is running there, it is running while somebody fills in their name and their reason for visiting, regardless of how carefully the form vendor has built their product.

We scanned 4,601 independent practice websites in July 2026 and found a third-party tracker on a page carrying a patient form at 44.9% of them. The most common was ordinary Google Analytics, on 58.2% of sites. Nobody installed it to collect health information. It was added by a marketing agency and never revisited.

A perfectly compliant form tool on a page with a tracker on it is still a problem, and it is your page rather than their product.

What good answers look like

A vendor worth using answers all five quickly and in writing, says plainly when something is not covered, and does not use the word "certified," because no such certification exists.

A vendor to be careful with answers question one with a marketing page, cannot answer question four at all, and treats question five as somebody else's problem.

The sixth question, which has no vendor to ask

Get all five answered and you have a correct picture of one vendor on one day. That is worth having and it is not the same as being finished.

Of the 4,601 sites we scanned, 88.0% produced at least one finding and 10.7% came back with nothing to report. Almost none of them launched broken. They launched fine, and then a year happened.

The form vendor shipped an AI summarising feature, genuinely useful, not named in an agreement drafted two years earlier. The host changed its subcontractors and disclosed it on a page nobody reads. The marketing agency added a conversion tag to the appointment page, which is exactly where a competent agency puts a conversion tag. Somebody built a new location page and copied the old form onto it. Every one of those is ordinary work by somebody doing their job correctly, and each one quietly invalidates part of what you confirmed.

So the sixth question is who re-checks the other five, and how would you find out if an answer changed.

There is no vendor to ask, because no vendor can answer it. Each one speaks only for their own product. Nobody is looking at the whole chain unless somebody has been given the job, and at most practices that job does not exist. That is not negligence. It is that the work is invisible, unscheduled, and requires seeing your own pages the way a scanner sees them, which you cannot do by looking at them.

The shortcut

If you would rather see the answers than collect them, our scan reports which form and hosting vendors on your current site will sign a BAA, and what is loading on the pages where your patients enter information. It also tells you what it could not determine from outside your systems, which is the part that needs account access rather than a page load.

See my exposure now

If the honest answer to the sixth question is that nobody is doing it, our Managed Plan is the version where somebody is. The form path, the hosting, the agreements and the pages around them are one relationship, and the chain gets rechecked rather than remembered.

More from the studio

Start here

Find out if you’re exposed.

The free audit reads only what is publicly available: your live site, its forms, where a submission appears to go, and the third parties already riding along on the page. We never touch your systems, and all we need is your URL. You get your likely exposure in writing, at no cost.

Free · public information only · no access to your systems