Privacy

Online patient intake forms: which tools need a BAA, and what not to ask

A form builder that stores patient answers is a business associate under HIPAA, even if the data is encrypted. Here is how to tell which of your tools need a signed agreement.

By Mariya Di Luzio, Founder and Creative Strategist · Published · 6 min read

The short answer

If your practice is a HIPAA covered entity, any outside service that stores or processes patient answers from an online form is a business associate and needs a signed business associate agreement first. HHS says this holds even when the data is encrypted and the vendor lacks the key.1 Public contact forms should ask for almost no health detail.

Key takeaways

  • A form builder, cloud drive or email service that receives patient information for you is a business associate. No signed agreement, no patient data in it.12
  • Encryption does not remove the need for an agreement. HHS answers that question directly.1
  • The minimum necessary rule applies to what you request, not only to what you share. Ask only for what the next step needs.3
  • Practices outside HIPAA, such as many cash-pay coaches, still answer to the FTC Act for how they handle health information.5

Does HIPAA apply to your practice’s forms at all?

HIPAA’s rules bind covered entities and their business associates. HHS defines a covered health care provider as one "who conducts certain billing and payment related transactions electronically".1 Most chiropractic, dental and acupuncture practices that bill insurance meet that definition. A cash-only health coach who never sends an electronic claim may not.

Being outside HIPAA is not a free pass. The FTC says its Act applies to covered entities and business associates "as well as to companies that collect, use, or share health information that aren’t required to comply with HIPAA".5 If your website promises privacy and your form tool shares answers with an ad platform, that gap is what the FTC looks at. The rest of this post assumes you are covered, and the same habits are sound either way.

Which tools count as a business associate?

HHS describes a business associate as a person or entity that performs functions or activities involving protected health information on behalf of a covered entity, other than its own workforce.2 The Privacy Rule requires the covered entity to get "satisfactory assurances", in writing, that the business associate will safeguard the information.2 That written contract is the business associate agreement (BAA).

The cloud computing guidance settles the question most practices ask. When a covered entity uses a cloud service to "create, receive, maintain, or transmit" electronic health information on its behalf, the cloud service is a business associate. HHS adds: "This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data."1 The vendor is then liable both under the contract and directly under the HIPAA Rules.1

So the working test is simple. If patient answers pass through or rest on a vendor’s servers, you need a signed BAA with that vendor before the first patient submits anything. Check whether the vendor signs a BAA for the exact plan you pay for. If it does not, that plan is not suitable for intake, whatever its security page says.

Common intake tools, and whether a BAA is needed when patient information goes through them
ToolHandles patient answers?BAA needed?
Online form builder used for intakeYes, stores submissionsYes
Email service that receives form notifications with answersYes, transmits and storesYes
Cloud drive where completed PDFs are savedYes, storesYes
Practice management or EHR system with a patient portalYesYes, usually offered as standard
Website host for a page with no formNo patient answersUsually no
Scheduling tool that records only name, phone and timeCan still be health information for a providerTreat as yes

The last row surprises people. For a covered provider, a person’s name linked to an appointment at a named practice can already reveal something about their health. Treat booking tools the same way as intake forms and ask for the agreement.

What the minimum necessary rule means for form fields

HHS summarizes the standard this way: covered entities must "take reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary to accomplish the intended purpose".3 Note the word requests. The rule is not only about what you send out. It is about what you ask for.

Applied to a website, that points to a two-stage design:

  • A public contact or booking-request form that asks for name, preferred contact method, and a general reason for the visit chosen from a short list, with a line telling people not to include medical details.
  • A full intake form, with history, medications and symptoms, sent only after the appointment exists, through a tool covered by a BAA, ideally inside the practice management system’s patient portal.

A free-text box on the home page that says "tell us about your symptoms" invites exactly the detail you do not want in a general inbox. Most people will write far more than the front desk needs to book them.

Security Rule basics for the systems behind the form

The Security Rule requires administrative, physical and technical safeguards for electronic health information, and it starts with a risk analysis: "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability" of that information.4 Among the technical safeguards are access control, audit controls, authentication, and transmission security, which means protecting information "being transmitted over an electronic network".4

Some specifications are labeled addressable. HHS is explicit that "addressable" does not mean optional: you implement it where reasonable and appropriate, or document an alternative that meets the same purpose.4 For a small practice, the practical steps are an encrypted connection on every form page, individual logins for each staff member, two-step sign-in on the form and email accounts, and a written record of which tools hold patient data and whose BAA covers each one.

A short audit you can run this week

  1. List every form on the website and every tool that receives its submissions, including notification emails.
  2. For each tool, find the signed BAA. If there is none, stop sending patient information through it.
  3. Read each form’s fields and delete any that the next step does not need.
  4. Add a one-line notice to public forms asking people not to include medical details.
  5. Check that no analytics or advertising tag fires on the intake pages. Tracking on booking pages is a separate HHS topic and deserves its own review.

Privacy wording matters in public too: the same care applies when you respond to online reviews. Mapping forms, tools and agreements across a site is part of a technical and compliance rebuild. This post explains HHS and FTC guidance as published. It is not legal advice, and a practice unsure whether it is a covered entity should ask a healthcare lawyer.

Questions practice owners ask

Is an encrypted form tool exempt from needing a BAA?

No. HHS guidance on cloud computing says a service that stores or processes only encrypted health information, and has no decryption key, is still a business associate and needs a business associate agreement.

Can I use a free form builder for new patient intake?

Only if the vendor signs a business associate agreement covering that plan. Check the plan terms before you build the form. Without a signed agreement, a covered practice should not collect patient health information through the tool.

What should a public contact form ask for?

Name, a preferred way to reach the person, and a general reason for the visit picked from a short list. Add a line asking people not to include medical details. Collect history and symptoms later through a secure intake tool.

My coaching practice does not bill insurance. Does any of this apply?

You may not be a HIPAA covered entity, but the FTC Act still applies to how you collect, use and share health information. Keeping forms short and vendors contracted is still the safer path.


Sources, and how much weight each one carries

  1. U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance on HIPAA and Cloud Computing".
    Official regulator guidance. Primary source for cloud vendors being business associates even without an encryption key.
  2. U.S. Department of Health and Human Services, Office for Civil Rights, "Business Associates" (45 CFR 164.502(e), 164.504(e)).
    Official regulator guidance on who is a business associate and what the written agreement must contain.
  3. U.S. Department of Health and Human Services, Office for Civil Rights, "Minimum Necessary Requirement" (45 CFR 164.502(b), 164.514(d)).
    Official regulator guidance. Source for the minimum necessary standard covering requests as well as disclosures.
  4. U.S. Department of Health and Human Services, Office for Civil Rights, "Summary of the HIPAA Security Rule".
    Official regulator summary. The Security Rule text at 45 CFR Part 164, Subpart C governs where they differ.
  5. Federal Trade Commission, "Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule", business guidance, August 2024.
    Official regulator guidance on how the FTC Act applies to health information inside and outside HIPAA.

This article is about marketing, website and compliance practice. It is not medical or legal advice, and nothing in it is intended to diagnose, treat, cure or prevent any disease. For a decision about your own practice, speak with a qualified attorney or the relevant regulator.

Do you know which of your tools hold patient answers?

The free check looks at your forms, booking flow and what they connect to, alongside what patients and AI assistants find about you. Then thirty minutes on a call to go through it.

Run the free check

Free check · findings by email within one working day

What does AI say about your practice?

  1. 1 Tell us what a patient would search for, and where.
  2. 2 An AI assistant searches the live web and answers, as a patient would see it.
  3. 3 Mariya reads the result and emails you the findings, with what they mean.

The search it will run

The free check comes with the studio’s emails. Occasional updates and offers, which is what keeps the check free. Unsubscribe any time; the findings are yours either way.

For practices in the US and Canada. Your name, email and practice go to the studio to send the findings and the emails you agreed to. Never sold, never shared for advertising. How data is handled.

This is one question. The full check asks a fixed list of 25 in both ChatGPT and Claude, and records every answer word for word. We go through it on the call.

More insights