COMPLIANCE · 2026

HIPAA & GDPR Compliant Form Builders in 2026

Three of the ten most popular form builders will sign a Business Associate Agreement. The rest will not — and several market HIPAA-adjacent language on pages where no BAA is on offer. Here is who signs what, where your data physically lives, and what compliance requires beyond the badge.

By Marcus Bellamy, Senior SaaS Reviewer Updated: September 18, 2026 12 min read ⚠️ Affiliate disclosure: we may earn a commission.

What this guide covers

  1. What compliance actually requires
  2. Who signs a BAA — the table
  3. GDPR, DPAs and data residency
  4. The free plan trap
  5. Vendor-by-vendor notes
  6. Six mistakes that break compliance
  7. Implementation checklist
  8. Frequently asked questions
This is not legal adviceThis guide summarises what vendors offer and what the frameworks generally require, based on vendor documentation reviewed in September 2026. Compliance depends on your organisation, your jurisdiction and how you configure the tool. Verify current terms with each vendor and take professional advice before collecting regulated data.

What compliance actually requires

Form builders market HIPAA as a feature, which encourages a damaging assumption: that buying the right plan makes you compliant. It does not. The plan supplies some of the technical safeguards; everything else remains your responsibility.

HIPAA — the six things a form touches

GDPR — the five things a form touches

The overlapBoth frameworks are built on the same instinct: collect less, secure what you hold, know where it is, and be able to delete it. A form designed around that instinct is most of the way to compliant under either regime.

Who signs a BAA — the table

Based on vendor documentation reviewed in September 2026. Availability and plan names change; confirm directly before you buy.

ToolBAA availableOn which planE-signatureAudit trailEU data residency
Zoho FormsYesPremiumYes (native + Zoho Sign)Record audit on PremiumEU data centre selectable
Cognito FormsYesEnterpriseYesEntry historyCheck with vendor
123FormBuilderYesPaid compliance tiersYesYesEU hosting available
TypeformEnterprise onlyEnterpriseNo native fieldEnterpriseEnterprise
Google FormsVia WorkspaceEligible Workspace editions, configuredNoWorkspace admin logsRegional storage on eligible plans
Microsoft FormsVia Microsoft 365Eligible tenants under the Microsoft agreementNoTenant audit logsTenant region
SurveyMonkeyHigher tiersEnterprise-level plansNoEnterpriseCheck with vendor
forms.appNoYes (signature field)No
TallyNoNoNoEU-based company
FilloutNoLimitedNo
Read this row carefullyforms.app is our highest-rated form builder overall and it does not offer a BAA. That is not a contradiction — it is the point of this guide. The best general-purpose tool and the right tool for protected health information are frequently different products, and healthcare teams often need both: a compliant tool for patient data, and a fast, cheap one for everything that is not.

GDPR, DPAs and data residency

The DPA is the easy part

Every serious vendor publishes a Data Processing Agreement, and most accept it automatically as part of their terms. Download it, file it somewhere your DPO or legal contact can find it, and record the date. The common failure is not the absence of a DPA — it is nobody being able to produce it two years later when asked.

Data residency is the hard part

Where your responses physically sit determines which transfer safeguards you need. Zoho lets you choose an EU data centre at signup — a choice you generally cannot change afterwards, so it needs to be made deliberately on day one. Microsoft stores tenant data in your tenant's region. Google offers regional data storage on eligible Workspace plans. Most smaller US-based tools host in the US, which is workable but means relying on an appropriate transfer mechanism and documenting it.

Consent that actually meets the standard

If consent is your lawful basis, the checkbox must be unticked by default, must not be bundled with accepting terms of service, must describe specifically what the person is agreeing to, and must be as easy to withdraw as it was to give. "I agree to the terms and to receive marketing" is two consents in one box and fails on the bundling requirement alone.

Retention and deletion

Set a retention period per form and actually enforce it. Most form builders will hold responses indefinitely by default, which quietly converts a form you built once into a growing liability. Decide how long you need each dataset, diarise the deletion, and confirm the vendor's deletion is real rather than a soft archive.

A useful testIf a respondent emailed today asking for everything you hold about them and its deletion, could you complete it within a month, across every form, integration and spreadsheet the data reached? If the answer involves searching someone's inbox, the process does not exist yet.

The free plan trap

No free plan is HIPAA compliant, at any vendor, and the reason is structural rather than technical. A BAA is a contract with an identified counterparty who has agreed to specific liabilities. Vendors do not extend those liabilities to anonymous free accounts.

The pattern we see repeatedly in healthcare and financial services: a team starts on a free plan for a pilot, the pilot works, the form quietly becomes production, and nobody revisits the compliance question because the tool never changed. Two years later a patient intake form has been running on an unsigned free account the whole time.

Use caseFree plan acceptable?Why
Staff satisfaction survey (no health data)YesNo PHI involved
Appointment request (name and phone only)BorderlineBecomes PHI the moment anyone adds a reason for visit
Patient intake or symptom questionnaireNoPHI — requires a BAA
Consent or authorisation formNoPHI plus signature retention requirements
Event registration for a clinic open dayYesNo PHI, provided you do not ask about conditions
Anonymous research surveyDependsOnly if genuinely anonymous and not re-identifiable in combination

The practical arrangement for most clinics: a compliant paid tool for anything touching patients, and a free tool such as forms.app for staff surveys, events and marketing. Two tools, one clear rule about which goes where. Our healthcare form builder guide covers the patient-facing side in more depth.

Vendor-by-vendor notes

Zoho Forms — the most complete compliant package

HIPAA support with a signed BAA arrives on the Premium plan, which also brings record audit trails and scheduled reports. Three things make it our default recommendation for clinics: EU data centre selection at signup for organisations with GDPR residency requirements, offline capture in the mobile app for field and community work, and per-organisation pricing — Premium covers up to 100 users on one plan, which is dramatically cheaper per clinician than per-seat enterprise pricing elsewhere. The trade-off is that Premium is the top tier, so compliance means buying the most expensive plan. Compare it in our Zoho Forms vs Typeform breakdown.

Cognito Forms — best for complex compliant forms

HIPAA support sits on the Enterprise plan at $129/month, which includes 20 users and unlimited entries. Where Cognito earns its place is the form itself: a genuine calculation engine, repeating sections, lookup fields, e-signatures and save-and-resume. Long clinical intake forms and financial applications are exactly the shape of form it was designed for, and save-and-resume matters more than it sounds when a form takes fifteen minutes and requires documents. See our Cognito Forms comparison.

123FormBuilder — compliance at mid-market pricing

Offers both HIPAA and GDPR-oriented plans with EU hosting, at prices below most enterprise tiers, plus the widest payment gateway support in the category — relevant for copay and deposit collection. A sensible middle option when Zoho Premium is more than you need. More in our 123FormBuilder vs Typeform comparison.

Typeform — Enterprise only, and that is the whole story

Typeform's standard paid plans carry no BAA. For a clinic, this means the plan you would naturally buy is not the plan you can lawfully use, and Enterprise pricing is negotiated rather than listed. Combined with per-response caps that make high-volume intake expensive, it is rarely the efficient choice for regulated data. Our Typeform pricing guide covers the tiers.

Google Forms and Microsoft Forms — covered by the suite, if configured

Both can fall under an organisation's existing agreement with Google or Microsoft, given the right edition and configuration. That is genuinely convenient when your organisation already runs on one of those suites and the governance is in place. The limitation is functional rather than legal: neither has native e-signature fields, neither offers granular per-form access control, and neither is designed for clinical intake. Compare the free options in our Microsoft Forms vs Google Forms guide.

forms.app, Tally, Fillout — excellent tools, not for PHI

None offers a BAA. Use them freely for everything that is not regulated data — staff surveys, events, marketing, feedback — and keep them away from patient information. forms.app in particular remains our top overall pick; it simply is not the tool for this job.

Six mistakes that break compliance

  1. Email notifications containing the data. The form stores the submission securely, then emails the whole thing to a staff inbox in plain text. Configure notifications to announce that a submission exists and link to the record — never to carry the content.
  2. Collecting more than you need. Date of birth "for the records" on a form that never uses it is pure liability under both frameworks.
  3. Shared logins. One account used by six people makes audit logging meaningless and access control fictional.
  4. Indefinite retention. Default settings keep responses forever. Set a period per form and enforce it.
  5. Unreviewed integrations. Sending submissions onward to a spreadsheet, CRM or Slack channel moves the data to a system that may have no BAA and no access control. Every downstream destination is in scope.
  6. Assuming the paid plan did it for you. The plan supplies safeguards. Training, risk analysis, access reviews and retention policy are yours.
The one-line ruleEvery place the data lands is in scope — the form, the notification, the spreadsheet, the CRM, the Slack channel and the laptop someone exported it to. Map that path before you launch, not after an incident.

Implementation checklist

Before you build

  • Confirm the vendor will sign a BAA on your plan
  • Download and file the BAA and the DPA
  • Choose data residency — usually irreversible
  • Document a lawful basis for each field
  • Agree a retention period per form
  • Map every downstream destination

Before you launch

  • Individual logins for everyone, no shared accounts
  • Access limited to staff with a genuine need
  • Notifications carry no regulated data
  • Audit logging switched on and verified
  • Consent language reviewed and unbundled
  • Deletion process tested end to end, not assumed
Review annuallyVendors change plan structures and move features between tiers. A tool that signed a BAA on your current plan two years ago may have moved that capability upmarket since. Put a calendar reminder against every compliance-relevant subscription.

Compare every form builder on compliance

Our main comparison scores 14 alternatives on BAA availability, data residency, payments and pricing.

See all 14 alternatives → Healthcare guide

Frequently Asked Questions

Which form builders sign a HIPAA BAA?+
Among the tools we review, Zoho Forms (Premium plan), Cognito Forms (Enterprise plan) and 123FormBuilder offer a signed Business Associate Agreement. Typeform offers HIPAA only on its Enterprise tier. forms.app, Google Forms on a personal account, Tally and Fillout do not offer a BAA and should not be used for protected health information. Google Workspace can be configured to cover Google Forms under a BAA for eligible organisations, but this requires the right Workspace edition and explicit configuration — a personal Gmail account never qualifies.
Is Typeform HIPAA compliant?+
Only on its Enterprise plan. Typeform's standard paid tiers do not include a BAA, which means a healthcare organisation cannot lawfully use them to collect protected health information in the United States. This is one of the most common compliance mistakes we see: a clinic buys a normal Typeform subscription, builds a patient intake form, and has no idea it is out of compliance until an audit asks for the agreement.
Does a free plan ever qualify as HIPAA compliant?+
No. Every vendor that offers HIPAA support gates it behind a paid tier, because a BAA is a contract that requires an identified, paying counterparty. If a form builder advertises HIPAA on a free plan, the claim is about their infrastructure rather than your legal position — and your legal position is what matters. Budget for the compliant tier from the start.
What does a BAA actually cover?+
A Business Associate Agreement is a contract in which the vendor accepts responsibility for safeguarding protected health information it processes on your behalf. It sets out permitted uses, required safeguards, breach notification obligations and what happens to the data when the contract ends. Without one, the vendor is not a business associate under HIPAA, and sharing PHI with them is itself a violation — regardless of how well encrypted their servers are.
Is encryption enough for HIPAA compliance?+
No. Encryption in transit and at rest is necessary but it is one of several requirements. HIPAA also expects access controls so only authorised staff can see records, audit logging so access is traceable, workforce training, a documented risk analysis, a retention and secure-deletion policy, and a signed BAA with every vendor touching PHI. A form builder can supply some of these; the rest are your organisation's responsibility and no purchase will discharge them.
Are these tools GDPR compliant?+
Most mainstream form builders can be used compliantly under GDPR, which is a different question from whether they are compliant by default. What you need: a Data Processing Agreement with the vendor, a lawful basis for collecting each field, clear consent language where consent is the basis you rely on, a documented retention period, and a workable process for access and deletion requests. Data residency matters too — Zoho lets you choose an EU data centre, and Google Workspace offers regional data storage on eligible plans. Check where your responses physically live before you collect anything.
Can I use Google Forms for patient data?+
Only under a properly configured Google Workspace account whose edition supports a BAA, with Forms explicitly included in the covered services and the account configured accordingly. A personal Gmail account is never covered. Even where it is covered, Google Forms lacks features clinics usually need — e-signature fields, structured audit trails, and granular per-form access control — so a purpose-built tool is generally the better answer.
What is the most common compliance mistake with forms?+
Collecting more than you need. HIPAA's minimum necessary principle and GDPR's data minimisation principle are the same idea from two directions: if you do not need a field, collecting it is a liability and not an asset. The second most common mistake is the email notification — a form may store data securely and then send the entire submission, including health details, to a staff inbox in plain text. Configure notifications to say a submission has arrived and link to the secure record, never to contain the data.

Related Guides

Best for Healthcare → All 14 Typeform Alternatives → Zoho Forms vs Typeform → Cognito Forms vs Typeform → How to Migrate From Typeform → Form Conversion Optimization →