Loading…
Loading…
If your forms collect protected health information, the Jotform HIPAA plan is the right starting point, and not the finish line. WorkflowKits ships the whole compliant loop: BAA, form, notifications, integrations, access control. Same engineer who worked on the HIPAA plan from inside Jotform, now on your side.
Yes: Jotform is HIPAA-compliant on the Gold plan ($99/month billed annually, $129 monthly) and Enterprise, with a signed Business Associate Agreement (BAA). Submission data, file uploads, and account access all fall under the BAA. Bronze and Silver do not include HIPAA. But the plan alone doesn't make your workflow compliant. Your integrations, email notifications, and exports also have to be HIPAA-aware. WorkflowKits sets that whole loop up for you.
Source: WorkflowKits /hipaa : by Buri (Mustafa Burak Ilter), former Jotform engineer (2020-2025).
Each kit deploys into your own Jotform HIPAA account. No middleware, no platform fees, no vendor lock-in. Pricing covers the build and a window of support.
The flagship HIPAA-aware patient intake. Insurance capture, e-signature consent, EHR-ready exports.
View the kitMental health intake with sliding-scale fees, telehealth preference, no-show policy, and consent.
View the kitPre-appointment telehealth flow: identity, tech check, screening, e-consent for video session.
View the kitFor chiropractors, massage, PT: health history, treatment consent, photo release where applicable.
View the kitThe Jotform HIPAA plan covers the platform side. The other three pillars are on you - and they are where almost every audit finding comes from.
If you handle protected health information, Jotform's HIPAA plan is the right starting point, but the plan alone doesn't make your workflow compliant. Here's what the plan covers, what it doesn't, and what most teams still get wrong.
Read the noteThe Jotform HIPAA plan covers Jotform. It does not cover what happens to a submission once it lands in Zapier, Google Sheets, Slack, or your CRM. Here is the integration-by-integration verdict from a Jotform HIPAA expert who built the integration codepath.
Read the noteThe Jotform BAA is a 10-minute task once you know which screen to click. Here is the exact path: what to enable, what to ask for, and how to verify it actually got signed.
Read the noteTwelve items to check before any Jotform form that handles PHI goes live. If any of these are unchecked, the workflow is not ready. Save the page or copy the list into your decision log.
Read the noteGoogle Forms on a free Gmail account is not HIPAA compliant. With a Google Workspace BAA and specific configuration changes, it can be made compliant. But it lacks clinical workflow features, e-signature, and integration audit trails. Here is the honest breakdown.
Read the noteMost form builders that advertise HIPAA compliance are telling you about one thing: they signed a BAA. A BAA is necessary but nowhere near sufficient. Here is what a compliant form setup actually requires, from a former Jotform engineer.
Read the noteJotform email notifications fail for six common reasons. Here is how to diagnose and fix each one in under 10 minutes.
Read the noteYes: on the Gold plan ($99/month billed annually, $129 monthly) and Enterprise, with a signed BAA from Jotform. The BAA covers Jotform's storage, encryption, account handling, and PDF generation. It does not cover what your downstream tools do with the data, so your integrations and notifications need their own audit. Bronze and Silver do not include HIPAA.
If you collect protected health information, you need the Gold plan or Enterprise with a signed BAA. There is no compliant way to handle PHI on Starter, Bronze, or Silver. The BAA is the legal instrument that lets Jotform act as your business associate, and it only attaches to Gold and Enterprise accounts.
Most general-purpose integrations break HIPAA the moment a submission with PHI touches them, unless you have a separate BAA with that vendor. Zapier offers a HIPAA plan; Google Sheets is only compliant via a Google Workspace BAA; Slack is only compliant on Enterprise Grid. The integration audit is part of every WorkflowKits HIPAA setup.
A clean HIPAA Jotform setup has: the HIPAA-tier account, a signed BAA on file, every integration audited (and either confirmed compliant or removed), email notifications stripped of PHI, 2FA on every account that can read submissions, and a documented decision log. WorkflowKits delivers this end-to-end in a 2-week engagement for most practices.
Buri spent 2020-2025 inside Jotform as an engineer and product team lead. The HIPAA plan, the BAA flow, the integration architecture, the email infrastructure. Those were the codepaths he worked on. Most generalist consultants Google their way through HIPAA Jotform setups; this one shipped them. If you are searching for a Jotform HIPAA expert, you are looking for someone who built the HIPAA plan from inside the company. That is what you get here.
Jotform HIPAA is available on the Gold plan at $99/month billed annually ($129 monthly) or on Enterprise with custom pricing. The Gold plan includes a signed BAA, HIPAA-eligible field markers, e-signature with audit metadata, encrypted submission storage, and 100,000 submissions per month. Bronze and Silver do not include HIPAA. For a detailed plan comparison, see the Jotform pricing guide.
No form builder offers a free HIPAA plan with a signed BAA. The BAA is the legal instrument that extends HIPAA liability to a third party, and it requires a paid plan from every vendor that offers one. Jotform Gold ($99/month billed annually) is the most affordable HIPAA-compliant form builder that includes a BAA. Free tiers from any form tool do not cover HIPAA.
Free 20-minute call. Bring your current Jotform setup (or a blank account); leave with a straight answer about what compliance actually requires for your practice.