What this guide covers
What compliance actually requires
Form builders market HIPAA as a feature, which encourages a damaging assumption: that buying the right plan makes you compliant. It does not. The plan supplies some of the technical safeguards; everything else remains your responsibility.
HIPAA — the six things a form touches
- A signed BAA. Non-negotiable. Without it the vendor is not a business associate, and sharing protected health information with them is itself a violation.
- Encryption in transit and at rest. Table stakes, and the part every vendor advertises.
- Access controls. Only staff with a legitimate need should be able to open a response. Shared logins defeat this entirely.
- Audit logging. You must be able to establish who accessed which record and when.
- Retention and secure deletion. A documented period, and a mechanism that actually deletes rather than hides.
- Breach notification. The BAA sets out the vendor's obligation to tell you; you remain responsible for notifying affected individuals.
GDPR — the five things a form touches
- A lawful basis for every field you collect. "It might be useful" is not one of the six.
- A Data Processing Agreement with the vendor, who acts as your processor.
- Consent that meets the standard where consent is your basis: unbundled, specific, freely given, and as easy to withdraw as to give. A pre-ticked box is not consent.
- Data subject rights — access, correction, deletion and portability, handled inside your response deadlines.
- Data residency and transfer safeguards if responses leave the EEA.
Who signs a BAA — the table
Based on vendor documentation reviewed in September 2026. Availability and plan names change; confirm directly before you buy.
| Tool | BAA available | On which plan | E-signature | Audit trail | EU data residency |
|---|---|---|---|---|---|
| Zoho Forms | Yes | Premium | Yes (native + Zoho Sign) | Record audit on Premium | EU data centre selectable |
| Cognito Forms | Yes | Enterprise | Yes | Entry history | Check with vendor |
| 123FormBuilder | Yes | Paid compliance tiers | Yes | Yes | EU hosting available |
| Typeform | Enterprise only | Enterprise | No native field | Enterprise | Enterprise |
| Google Forms | Via Workspace | Eligible Workspace editions, configured | No | Workspace admin logs | Regional storage on eligible plans |
| Microsoft Forms | Via Microsoft 365 | Eligible tenants under the Microsoft agreement | No | Tenant audit logs | Tenant region |
| SurveyMonkey | Higher tiers | Enterprise-level plans | No | Enterprise | Check with vendor |
| forms.app | No | — | Yes (signature field) | No | — |
| Tally | No | — | No | No | EU-based company |
| Fillout | No | — | Limited | No | — |
GDPR, DPAs and data residency
The DPA is the easy part
Every serious vendor publishes a Data Processing Agreement, and most accept it automatically as part of their terms. Download it, file it somewhere your DPO or legal contact can find it, and record the date. The common failure is not the absence of a DPA — it is nobody being able to produce it two years later when asked.
Data residency is the hard part
Where your responses physically sit determines which transfer safeguards you need. Zoho lets you choose an EU data centre at signup — a choice you generally cannot change afterwards, so it needs to be made deliberately on day one. Microsoft stores tenant data in your tenant's region. Google offers regional data storage on eligible Workspace plans. Most smaller US-based tools host in the US, which is workable but means relying on an appropriate transfer mechanism and documenting it.
Consent that actually meets the standard
If consent is your lawful basis, the checkbox must be unticked by default, must not be bundled with accepting terms of service, must describe specifically what the person is agreeing to, and must be as easy to withdraw as it was to give. "I agree to the terms and to receive marketing" is two consents in one box and fails on the bundling requirement alone.
Retention and deletion
Set a retention period per form and actually enforce it. Most form builders will hold responses indefinitely by default, which quietly converts a form you built once into a growing liability. Decide how long you need each dataset, diarise the deletion, and confirm the vendor's deletion is real rather than a soft archive.
The free plan trap
No free plan is HIPAA compliant, at any vendor, and the reason is structural rather than technical. A BAA is a contract with an identified counterparty who has agreed to specific liabilities. Vendors do not extend those liabilities to anonymous free accounts.
The pattern we see repeatedly in healthcare and financial services: a team starts on a free plan for a pilot, the pilot works, the form quietly becomes production, and nobody revisits the compliance question because the tool never changed. Two years later a patient intake form has been running on an unsigned free account the whole time.
| Use case | Free plan acceptable? | Why |
|---|---|---|
| Staff satisfaction survey (no health data) | Yes | No PHI involved |
| Appointment request (name and phone only) | Borderline | Becomes PHI the moment anyone adds a reason for visit |
| Patient intake or symptom questionnaire | No | PHI — requires a BAA |
| Consent or authorisation form | No | PHI plus signature retention requirements |
| Event registration for a clinic open day | Yes | No PHI, provided you do not ask about conditions |
| Anonymous research survey | Depends | Only if genuinely anonymous and not re-identifiable in combination |
The practical arrangement for most clinics: a compliant paid tool for anything touching patients, and a free tool such as forms.app for staff surveys, events and marketing. Two tools, one clear rule about which goes where. Our healthcare form builder guide covers the patient-facing side in more depth.
Vendor-by-vendor notes
Zoho Forms — the most complete compliant package
HIPAA support with a signed BAA arrives on the Premium plan, which also brings record audit trails and scheduled reports. Three things make it our default recommendation for clinics: EU data centre selection at signup for organisations with GDPR residency requirements, offline capture in the mobile app for field and community work, and per-organisation pricing — Premium covers up to 100 users on one plan, which is dramatically cheaper per clinician than per-seat enterprise pricing elsewhere. The trade-off is that Premium is the top tier, so compliance means buying the most expensive plan. Compare it in our Zoho Forms vs Typeform breakdown.
Cognito Forms — best for complex compliant forms
HIPAA support sits on the Enterprise plan at $129/month, which includes 20 users and unlimited entries. Where Cognito earns its place is the form itself: a genuine calculation engine, repeating sections, lookup fields, e-signatures and save-and-resume. Long clinical intake forms and financial applications are exactly the shape of form it was designed for, and save-and-resume matters more than it sounds when a form takes fifteen minutes and requires documents. See our Cognito Forms comparison.
123FormBuilder — compliance at mid-market pricing
Offers both HIPAA and GDPR-oriented plans with EU hosting, at prices below most enterprise tiers, plus the widest payment gateway support in the category — relevant for copay and deposit collection. A sensible middle option when Zoho Premium is more than you need. More in our 123FormBuilder vs Typeform comparison.
Typeform — Enterprise only, and that is the whole story
Typeform's standard paid plans carry no BAA. For a clinic, this means the plan you would naturally buy is not the plan you can lawfully use, and Enterprise pricing is negotiated rather than listed. Combined with per-response caps that make high-volume intake expensive, it is rarely the efficient choice for regulated data. Our Typeform pricing guide covers the tiers.
Google Forms and Microsoft Forms — covered by the suite, if configured
Both can fall under an organisation's existing agreement with Google or Microsoft, given the right edition and configuration. That is genuinely convenient when your organisation already runs on one of those suites and the governance is in place. The limitation is functional rather than legal: neither has native e-signature fields, neither offers granular per-form access control, and neither is designed for clinical intake. Compare the free options in our Microsoft Forms vs Google Forms guide.
forms.app, Tally, Fillout — excellent tools, not for PHI
None offers a BAA. Use them freely for everything that is not regulated data — staff surveys, events, marketing, feedback — and keep them away from patient information. forms.app in particular remains our top overall pick; it simply is not the tool for this job.
Six mistakes that break compliance
- Email notifications containing the data. The form stores the submission securely, then emails the whole thing to a staff inbox in plain text. Configure notifications to announce that a submission exists and link to the record — never to carry the content.
- Collecting more than you need. Date of birth "for the records" on a form that never uses it is pure liability under both frameworks.
- Shared logins. One account used by six people makes audit logging meaningless and access control fictional.
- Indefinite retention. Default settings keep responses forever. Set a period per form and enforce it.
- Unreviewed integrations. Sending submissions onward to a spreadsheet, CRM or Slack channel moves the data to a system that may have no BAA and no access control. Every downstream destination is in scope.
- Assuming the paid plan did it for you. The plan supplies safeguards. Training, risk analysis, access reviews and retention policy are yours.
Implementation checklist
Before you build
- Confirm the vendor will sign a BAA on your plan
- Download and file the BAA and the DPA
- Choose data residency — usually irreversible
- Document a lawful basis for each field
- Agree a retention period per form
- Map every downstream destination
Before you launch
- Individual logins for everyone, no shared accounts
- Access limited to staff with a genuine need
- Notifications carry no regulated data
- Audit logging switched on and verified
- Consent language reviewed and unbundled
- Deletion process tested end to end, not assumed
Compare every form builder on compliance
Our main comparison scores 14 alternatives on BAA availability, data residency, payments and pricing.
See all 14 alternatives → Healthcare guide