Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

HIPAA-compliant form builders for clinical and research teams

Which HIPAA compliant form builder will actually sign a BAA, whether Google Forms qualifies, and the configuration mistakes that leak PHI regardless.

Ask about HIPAA-compliant form builders for clinical and research teams

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

For the public half of the funnel · Verified 18 August 2026

Unbounce — the right tool for the pages that must never touch PHI

From $29/mo ($22 billed annually)

Read this pick carefully, because it is not the one the headline of this page implies. Unbounce does not sign a Business Associate Agreement and must not be used to collect protected health information. What it is very good at is the other half of a clinical recruitment funnel: the public-facing page that describes the study, answers the questions a potential participant actually has, and captures nothing but a first name and a contact detail before handing over to a BAA-covered intake form. That split is the architecture most research teams end up at anyway, and it is worth building deliberately rather than discovering after a privacy review. Unbounce runs outside your institutional CMS, so a recruitment coordinator can publish and revise without a ticket to a central web team; Build is $99/mo ($74 annual), Experiment $149/mo ($112 annual) adds unlimited A/B testing, and Optimize $249/mo ($187 annual) adds Smart Traffic. Verified 18 August 2026. If your form itself must collect symptoms, dates of birth or medical record numbers, buy a HIPAA-enabled form vendor for that step and use this only for the page in front of it.

Try Unbounce Opens on the vendor’s site · CASRAI referral link

Compare the landing page builders properly → — If you have no PHI anywhere in the funnel, the choice is a straight landing-page decision and this page is the wrong one to read.

Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.

In summary

  • A form builder is HIPAA-compliant only if the vendor signs a BAA on the plan you are actually buying. “Encrypted”, “secure” and “SOC 2” are not the same thing.
  • Google Forms on a personal or free Google account: no. Under a Google Workspace agreement whose BAA covers Forms, and configured correctly: yes.
  • A signed BAA does not make your configuration compliant — email notifications, Zapier-style integrations, analytics scripts and embedded widgets all leak PHI out from under it.
  • The HIPAA-enabled tier usually costs several times the free plan. That price step, not the feature list, is the real decision.
  • Unbounce is our pick for the public recruitment page, not for PHI intake: Build $99/mo ($74 annual), Experiment $149/mo ($112 annual), Optimize $249/mo ($187 annual). Verified 18 August 2026.

Will they sign a BAA? The plain answer per tool

BAA availability as we understand it on 18 August 2026. We quote no competitor prices — we only publish figures we have read off a vendor pricing page and date-stamped. Confirm any BAA in writing before you collect a single record.

Dimension Signs a BAA? What it is gated behind Sensible use in a research setting
Google Forms (personal / free account) No Not offered to consumer accounts at all Non-identifiable admin only — room bookings, seminar sign-ups, internal polls
Google Forms (Google Workspace) Conditional A Workspace agreement whose BAA lists Forms as a covered service, plus correct sharing and notification settings Workable for institutional intake if your IT office confirms Forms is in scope
Microsoft Forms (Microsoft 365) Conditional Your organisation’s Microsoft 365 agreement and its list of in-scope services Often the path of least resistance where the university already runs Microsoft 365
Jotform Yes HIPAA-enabled paid tiers only; must be switched on per form Common choice where a department needs conditional logic without developer time
Formstack Forms Yes A HIPAA-designated plan, quoted rather than self-serve Heavier workflow and routing needs across a department
Qualtrics Conditional Contract-dependent; frequently already covered by a campus-wide licence Check your institutional licence first — many teams already have this
REDCap (institution-hosted) Not applicable No third-party vendor involved when your own institution hosts it The default for academic medical centres, and usually free at point of use
Typeform, Tally and similar design-led builders Confirm directly Varies; historically not offered on self-serve tiers Fine for non-PHI outreach; do not assume PHI coverage without a signature
Unbounce, and landing-page builders generally No Not a business associate; not designed for PHI Public recruitment pages that capture a contact detail and nothing clinical
Mailchimp, HubSpot and marketing-suite forms No / heavily restricted Marketing platforms generally exclude PHI in their terms Newsletter sign-up only — never screening questions

BAA availability moves. Vendors add HIPAA tiers, retire them, and change which sub-products are in scope. Treat this table as a shortlist generator, then get the current answer in writing from the vendor and keep the executed BAA where your privacy office and your monitor can find it.

There is no HIPAA certification, only a signed agreement

No government body certifies software as HIPAA-compliant. A vendor claiming to be “HIPAA certified” is describing a self-assessment or a paid audit badge, not a legal status. The rule itself is narrow and easy to apply: if a third party creates, receives, maintains or transmits protected health information on behalf of a covered entity, that third party is a business associate and there must be a Business Associate Agreement in place before the data starts flowing.

So when you evaluate a form builder, the question is not “is it secure?” but “will you sign a BAA, on the plan I am buying, covering the specific product I am using?” That last clause matters more than teams expect. Large vendors sell suites, and a BAA that covers the mail and storage products may not cover the forms product, the analytics product or the workflow-automation product you were planning to wire into it.

The same reasoning drives every other compliance decision in a research operation, and it is why our HIPAA-compliant fax guide reaches the same conclusion from a different direction: the BAA is the whole answer, and the encryption everyone advertises is table stakes underneath it. If you are also collecting signatures on consent or delegation documents, apply the identical test to your e-signature platform — and note that on Sign.Plus, as on most vendors in that category, HIPAA and the BAA sit on the top tier only.

Is Google Forms HIPAA-compliant?

The short answer is: not on the account most people are using, and conditionally on the account an institution provides.

On a personal or free Google account, no. Google does not enter into Business Associate Agreements with consumer accounts. It does not matter that the form is private, that responses go to a restricted spreadsheet, or that only two people have the link. Without a BAA, putting PHI through it is not compliant, and this is the single most common quiet violation in academic health settings — a coordinator builds a screening form in ten minutes on their own account because the official route takes three weeks.

Under Google Workspace, conditionally yes. Google offers a BAA to Workspace customers, and Forms can fall within the set of covered services. Three conditions have to hold at once. Your organisation must have executed the BAA — an institutional Workspace licence does not automatically mean one exists. Forms must actually be in scope under the agreement your IT or privacy office signed, which is a list you can ask for. And the form must be configured within the covered boundary: responses staying in Workspace, sharing restricted to the domain, no response notifications escaping to an unrelated mailbox, and no add-ons pushing data to a third party without its own BAA.

The practical upshot for a research team is that “is Google Forms HIPAA compliant” is a question for your own IT office, not for Google’s marketing pages. Ask two things: is Forms named in our BAA, and are we allowed to use it for PHI under local policy? Plenty of institutions answer yes to the first and no to the second, because they have standardised on REDCap and would rather not maintain two governance paths.

A BAA does not make your configuration compliant

This is the part that costs institutions money, and it is almost never on the vendor’s comparison page. You can buy the correct plan, sign the correct agreement, and still leak protected health information out of the covered boundary within the first week. Four routes account for most of it.

Email notifications. The default behaviour of nearly every form builder is to email you the submission. That email contains the response body, travels to whatever address you typed, and lands in a mailbox that may sit entirely outside the BAA. The correct pattern is a bare notification — “a new response has been received, log in to view it” — with no response data in the message. Check this before go-live, because switching it off after a fortnight of submissions does not unsend anything.

Integrations and automations. Wiring a form to a spreadsheet, a project tracker, a chat channel or an automation service is exactly the thing a no-code tool makes easy, and each hop is a new business associate. A BAA with the form vendor covers the form vendor. It does not cover the automation platform in the middle or the destination at the end, and a PHI record moving through three services on one BAA is three-quarters uncovered.

Analytics and marketing scripts. If the page hosting the form carries analytics, a tag manager, an advertising pixel or a session-replay tool, you have to reason about what those scripts capture. Session replay in particular can record field contents keystroke by keystroke; the URL itself can carry identifiers in query parameters; and health-related page paths have been treated as sensitive in their own right. Regulators have taken a dim view of tracking technologies on pages in a clinical context, and the safe posture for a PHI intake form is a page with no third-party scripts at all.

Embeds and iframes. Embedding a HIPAA-enabled form into an ordinary web page is only safe if the surrounding page is not doing something the form vendor’s controls cannot see — the analytics problem again, plus chat widgets and consent banners. A hosted form on the vendor’s own domain is easier to defend than a pretty embed on a page with six other scripts.

The discipline here is dull and effective: draw the data path on one sheet of paper, from the participant’s browser to wherever the record finally rests, and name the covering agreement for every hop. Any hop you cannot name is the one that will appear in the incident report.

The no-code angle: building forms when nobody will build them for you

Most of the demand for a no-code form builder in a research organisation comes from the same place — a department that needs an intake, screening or referral form this month and has no realistic access to developer time. Central IT has a queue measured in quarters, the study starts recruiting in six weeks, and the coordinator is the person who will actually maintain the thing.

That is a legitimate reason to buy a commercial form builder rather than wait, and it changes what you should be looking for. Conditional logic that a non-developer can edit matters more than API depth, because the eligibility criteria will change after the first protocol amendment. Versioning and an audit trail matter, because you will be asked which version of the form a given participant saw. Role-based access matters, because the person who builds the form is rarely the person who should read the responses. And export needs to be honest — a CSV that drops multi-select answers or reformats dates silently will cost you a day of reconciliation for every month of collection.

What no-code does not remove is governance. A form that collects PHI still needs privacy-office sign-off, still needs the BAA in place, and if it is participant-facing recruitment material its wording is usually part of what your ethics committee approved. Changing a screening question in a drag-and-drop editor is technically trivial and procedurally a protocol deviation. Build the approval step into the workflow before the tool makes it easy to skip.

Check accessibility early, too. Institutional web teams are held to accessibility standards, and a departmentally purchased tool quietly routes around that review. Ask for the vendor’s accessibility conformance documentation and test one real form with a keyboard and a screen reader before you commit.

What the compliant tier actually costs you

Across this whole category the pattern repeats: the free or entry plan is genuinely capable, and the HIPAA-enabled tier costs several times more. That is not vendors being cynical. A BAA transfers real liability, and the tier that carries it comes with the access controls, logging, retention settings and support commitments that make the liability manageable. But it does mean the honest framing of this purchase is a budget conversation rather than a feature comparison.

We deliberately quote no competitor prices here. We only publish figures we have read off a vendor pricing page and stamped with a date, and for HIPAA tiers in particular many vendors quote rather than publish. Ask for the number in writing, and clarify whether it is per user, per form or per organisation before comparing anything.

Three questions save money more often than shopping around does. First: does your institution already hold a licence that covers this? Campus-wide Qualtrics agreements and institution-hosted REDCap instances are extremely common, and a department paying for a third form tool while both sit unused is the most frequent avoidable spend we see. Second: does this form actually need to collect PHI, or has it accumulated fields nobody uses? Third: how many forms will really run on it? Per-form HIPAA switches mean pricing that looks reasonable for one intake form can look very different at fifteen.

Do not buy a HIPAA-enabled form builder if your institution already runs REDCap and your data would be at home in it. REDCap is less pleasant to build in, the interface will not win any design awards, and it will take you longer to get the first form live. It is also already covered, already known to your privacy office, already familiar to your monitors, and free at the point of use. Paying for a slicker commercial tool to avoid a two-hour learning curve is a decision you will explain repeatedly at audit. Buy the commercial tool when REDCap genuinely cannot do the job — public-facing recruitment, complex participant-facing design, or a workflow that has to reach people with no institutional login — not because it is nicer to use.

Split the funnel: public page, then covered intake

The pattern that survives a privacy review looks like this. A public recruitment page — fast, well written, honest about what the study involves, carrying whatever ethics-approved text you were given — collects nothing beyond a first name and one contact detail. It then hands over to a BAA-covered form or a call-back from a coordinator for anything clinical. Nothing on the public page asks about symptoms, diagnoses, medications or dates of birth, and the page is instrumented conservatively.

Two honest caveats before you treat that as a free pass. If you are a covered entity and the mere fact of expressing interest in a condition-specific study is itself health information about an identifiable person, then even a name-and-email capture may need to sit inside the covered boundary. Run the design past your privacy office rather than assuming the split works. And “instrumented conservatively” means exactly that: if a page is dedicated to a single condition, the analytics record of a visit is more revealing than a generic page view, so think about what your testing and analytics stack is collecting on a health-related URL.

Where the split does hold, it gives you the best of both: a public page the person accountable for the recruitment target can edit and test themselves — the whole argument for a standalone builder, covered in our Unbounce review and the wider landing page builder comparison — and a covered form that stays boring, locked down and inside an agreement your institution has already signed. Most teams that get into difficulty here did so by making one tool do both jobs.

For the recruitment page in front of the form

Unbounce is not a HIPAA option and should never hold PHI — but it is a strong choice for the public study page that captures a contact detail and hands off to a covered intake form. Build $99/mo ($74 annual), 25% off annual billing. Verified 18 August 2026.

From $29/mo ($22 billed annually)

See Unbounce plans Opens on the vendor’s site · CASRAI referral link

Frequently asked questions

What makes a form builder HIPAA compliant?

A signed Business Associate Agreement covering the specific product on the specific plan you are buying. Encryption in transit and at rest, access controls, audit logging and SOC 2 reports are all necessary supporting substance, but none of them is the legal requirement. If a vendor will not sign a BAA, no amount of security marketing makes it lawful to put PHI through it.

Is Google Forms HIPAA compliant?

Not on a personal or free Google account — Google does not sign BAAs with consumer accounts, so any PHI collected that way is uncovered. Under Google Workspace it can be, provided your organisation has an executed BAA that lists Forms as a covered service and the form is configured so responses, notifications and add-ons stay inside that boundary. Ask your IT or privacy office for the in-scope service list rather than assuming.

Which HIPAA compliant form builder should a research department choose?

Start by checking what your institution already has: an institution-hosted REDCap instance or a campus-wide Qualtrics licence usually beats buying a third tool. If you genuinely need a commercial builder, shortlist the vendors that sign a BAA on a plan you can actually purchase — Jotform and Formstack both do, on their HIPAA-designated tiers — and confirm the agreement in writing before you collect anything.

Does a BAA mean our forms are compliant?

No. The BAA covers the vendor; your configuration is still yours to get right. The common leaks are email notifications that include the response body, automation platforms in the middle of an integration with no BAA of their own, analytics or session-replay scripts on the form page, and embeds sitting inside a page full of third-party widgets. Map every hop the data takes and name the agreement covering each one.

Can we use a landing page builder like Unbounce to collect patient information?

No. Landing page builders are not business associates, do not sign BAAs, and are not designed to hold protected health information. Use one for the public recruitment page that captures a contact detail and describes the study, then hand off to a BAA-covered form or a coordinator call-back for anything clinical — and check that split with your privacy office, because expressing interest in a condition-specific study can itself be health information.

How much more does the HIPAA tier cost?

Expect a multiple of the free or entry plan rather than a small uplift, and expect several vendors to quote rather than publish. We only print prices we have read off a vendor pricing page and date-stamped, so we do not quote competitor figures here — ask for the number in writing, and clarify whether it is per user, per form or per organisation before you compare anything.

Do we need a BAA for a form that collects no health information?

If no protected health information reaches the vendor, there is no business associate relationship and no BAA requirement. The difficulty is that forms accumulate fields, and a screening question added after a protocol amendment can move a form across that line without anyone re-running the assessment. Review the field list whenever the form changes, and treat a form as covered if it is even ambiguous.

Related on CASRAI

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →