HIPAA & compliance

5 Elements of a HIPAA-Compliant Digital Form (2026)

A HIPAA-compliant digital form needs five things: access controls, encryption in transit and at rest, secure storage, backups, and documented disposal, plus a signed BAA.

A HIPAA-compliant digital form needs five technical elements: access controls, encryption in transit, encryption at rest, backup and recovery, and documented disposal, all under a signed Business Associate Agreement. Miss any one and the form is not compliant, even if it looks identical to one that is. Here is what each element requires in 2026.

What makes a digital form HIPAA compliant?

1. Access controls

Only the right people should see PHI. That means role-based access that limits visibility by job function, unique user IDs and passwords for every staff member, automatic session timeouts, and audit logs that record who accessed what, when, and what they did. Logs must be retained and reviewable for audits.

2. Encryption in transit

Every submission travels over the network, so it must be encrypted in transit. The Security Rule requires TLS 1.2 or higher (the same bank-grade HTTPS your browser shows as a lock). A form submitted over plain HTTP violates this outright. Encryption here is mandatory, not "addressable."

3. Encryption at rest

Data sitting in a database, cloud environment, or server must be encrypted at rest with a documented standard such as AES-256. The updated 2025 Security Rule strengthened this from addressable to effectively mandatory, so every stored submission should be encrypted.

4. Backup and recovery

Compliance includes availability. You need automated, regular backups of all submissions, geographically separate backup systems, and a disaster-recovery plan with a defined recovery-time objective. Ask any vendor to specify backup frequency, retention, and RTO.

5. Documented disposal

The most-overlooked element: when data is no longer needed, it must be permanently and verifiably destroyed, not just deleted. Compliant disposal means overwriting, degaussing, or physical destruction, and cloud vendors must provide documented procedures and written confirmation of destruction.

Do you need a BAA with your form platform?

Yes, and this is non-negotiable. Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate, so a signed Business Associate Agreement is required. Collecting intake on a platform without a BAA is a violation on its own, regardless of the platform's security. It is also why general tools like Google Forms or Typeform are off-limits for PHI: they typically will not sign a BAA. (See who must follow HIPAA for the full picture.)

Note too that a breach triggers a 60-day patient-notification clock, and 76% of cloud breaches trace to human error (Thales, 2024), so the controls above are as much about people as technology.

How Zentake covers all five

Zentake is built around these requirements. Customizable online forms enforce role-based access and audit logging, data is encrypted in transit and at rest, e-signatures are captured and stored securely, and a signed BAA is available on every plan. You get the five elements without assembling them yourself. For the flip side, see the most common HIPAA violations.

The bottom line

If a form collects PHI, it needs all five elements and a BAA, no exceptions. The fastest way to get there is a platform built for HIPAA rather than a general form tool with security bolted on. Start a free trial or browse HIPAA-ready form templates.

Frequently asked questions

Are online patient intake forms subject to HIPAA?

Yes, whenever they collect protected health information for a covered entity. The form, its transmission, and its storage all fall under HIPAA, which is why a compliant platform and a signed BAA are required.

What encryption is required for HIPAA-compliant forms?

TLS 1.2 or higher for data in transit and AES-256 for data at rest. Forms submitted over plain HTTP, or stored unencrypted, do not meet the Security Rule.

Do I need a BAA with my intake form vendor?

Yes. Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate. Using an intake platform without a signed BAA is itself a violation, no matter how secure the platform is.

Can I use Google Forms or Typeform for patient intake?

No, not for PHI. General-purpose form tools typically will not sign a BAA and are not designed for the Security Rule's controls. Use a platform built for healthcare.

How long must patient intake data be retained?

HIPAA requires related documentation be kept for six years, and state medical-record retention laws often require longer. Confirm your vendor's retention and disposal policies in writing.

Start your free trial← Back to the journal