Drag-and-drop builder · AES-256-GCM encryption at rest · immutable audit trail · 39 field types including dedicated HIPAA fields for SSN, DOB, and consent.
Field Palette
Field Properties
Validation
From blank canvas to collecting encrypted PHI — most practices publish their first form the same afternoon.
Drag fields from the palette — or start from a template. PHI fields are flagged and encrypted automatically.
Share a direct link, embed with iFrame or JS, drop a Blade component, or paste a WordPress shortcode.
Submissions land AES-256-GCM encrypted with a full audit trail. Your team is notified — without PHI in the email.
From the drag-and-drop canvas to encrypted storage and compliance automation — it's all built in.
React canvas powered by @dnd-kit. Pick fields from a 3-column palette, drop them in, reorder instantly. Two- and three-column layouts supported.
Purpose-built fields for SSN, Date of Birth, MRN, and Consent — each auto-flagged PHI and encrypted unconditionally.
Every submitted value is encrypted before touching the database. Custom key service — not Laravel's CBC Crypt facade.
Every action is written to an append-only audit log with a SHA-256 hash chain, verified on a schedule.
Show or hide any field based on another field's value. Hidden fields are excluded from submission validation.
Split long forms into stepped pages. Each step validates before advancing, with a customizable progress stepper.
Direct URL, iFrame, Blade component, or a vanilla JS snippet — plus a WordPress plugin with shortcode.
Views, starts, interactions, completions. Drop-off heat table, device breakdown, region map — all self-hosted.
Team alerts on every submission; optional submitter confirmation. Emails carry links only — never PHI.
The same encrypted foundation, shaped to how your specialty actually collects information.
Replace clipboard intake with encrypted online forms patients complete before they arrive. Demographics, insurance, medication lists, and consent — all PHI-flagged and stored AES-256-GCM encrypted.
New-patient paperwork, insurance verification, and treatment consent — collected before the chair, not in it. Multi-location groups manage every office's forms from one dashboard with role-based access.
Screenings and intake for the most sensitive category of PHI. Access controls restrict who can open each submission, auto-logoff protects shared workstations, and the audit trail shows exactly who viewed what, when.
Injury intake, pain scales, and progress check-ins that patients complete from their phone. Rating and slider fields capture progress visit-to-visit, and analytics show where long forms lose patients.
Consultation requests, treatment consent, and medication disclosures — collected securely while your marketing keeps running. GTM, GA4, and Meta Pixel track campaign conversions without ever touching PHI.
The React drag-and-drop canvas makes the tenth form as fast as the first. A searchable 39-field palette, live patient preview, 30-step undo/redo, and auto-save every six seconds — with safety modals before anything destructive.
Eight dedicated HIPAA field types encrypt unconditionally. And if staff add a plain text field that looks like PHI, the auto-scanner flags it before the form goes live. Every view and change lands in a SHA-256-chained audit log.
Every form gets a clean shareable URL the moment it's published. Embed it on your website with an iFrame or one JS snippet, render it natively in Laravel with a Blade component, or paste a shortcode into WordPress.
Every submission can alert your front desk, and patients can receive a confirmation. But unlike generic form tools, emails contain a secure link only. The data itself never leaves your encrypted database.
Standard form fields, HIPAA-specific PHI fields, and layout helpers — all in one palette.
Encryption, session hygiene, and tamper-evidence are not settings you enable. They're how the system works.
TLS in transit, honeypot & rate-limit checks
AES-256-GCM via dedicated DEK / KEK key service
Ciphertext only — nothing readable in the database
Append-only entry, chained with SHA-256
Every value encrypted with authenticated encryption before it reaches the database.
Append-only logs, each entry chained with SHA-256. Tampering breaks the chain and raises a flag.
Idle sessions expire automatically across every authenticated surface.
No PHI ever appears in logs, URLs, headers, or emails.
Honeypots, rate limits, and validation keep junk out — without CAPTCHAs frustrating patients.
Rotate data-encryption keys on schedule; records re-encrypt in the background.
Six starting points, each pre-wired with the right fields and PHI flags. Or begin from a blank canvas.
An empty canvas. Bring your own structure and pull from all 39 field types.
0 fields · your callDemographics, insurance, history, and consent — the front-desk staple, PHI-flagged.
Multi-page · PHI readyA simple, encrypted contact form for your practice website.
Single pageConditions, medications, allergies, and family history with conditional follow-ups.
Conditional logic · PHI readyPreferred dates, provider, and reason for visit — routed to your team by email.
Notifications onRatings, sliders, and open text to hear how visits actually went.
Analytics readyFive ways to put a form in front of a patient — from a shareable link to a WordPress shortcode.
Everything is measured in-house — no third-party analytics ever touches a submission.
Drop-off heat table shows the exact field where people leave.
Take reports to your next staff meeting.
View → start → complete, step by step.
Submission volume over time, at a glance.
Mobile vs. desktop vs. tablet completion.
Marketing and measurement plug in at the edges — PHI never leaves your server.
Fire tags on view, start, and complete events.
No PHI sharedTrack conversions alongside site traffic.
No PHI sharedMeasure campaigns that drive completions.
No PHI sharedPush submission events to any endpoint.
Signed payloadsShortcode embedding for any WP site.
Free pluginFine-grained access control on every form, plus ergonomics that make the tenth form as fast as the first.
Anyone with the link can submit — ideal for intake and contact forms.
Restrict submission to authenticated accounts on your instance.
Name exactly who may open and submit a given form.
Revocable tokenized URLs for one-off or time-boxed access.
Flags fields that look like PHI even when added as plain text.
Experiment freely — nothing is more than a keystroke from recovery.
Find any of 39 fields instantly; see the patient's view as you build.
Six-second debounced saves, plus confirmation before destructive actions.
The administrative work of compliance runs on a schedule, not on memory.
Set retention windows per form; expired submissions purge automatically and verifiably.
Structured incident logging and notification workflows, ready before you need them.
Scheduled jobs re-verify the SHA-256 hash chain and alert on any inconsistency.
Rotate data-encryption keys with zero-downtime background re-encryption.
A built-in checklist audits each form's configuration against HIPAA safeguards.
Admins, editors, and viewers — least-privilege access to forms and submissions.
Every plan includes a signed BAA and encrypted PHI storage. Start with a 14-day free trial — no card required.
Billed monthly
Start 14-Day Free TrialBilled monthly · 50% launch discount
Start 14-Day Free TrialContact us for pricing
Talk to Us14-day free trial · No credit card required · Cancel anytime · Signed BAA on all plans
[hipaa_vault form="patient-intake"]. You can also use a direct URL, an auto-resizing iFrame, a one-line JS snippet on any website, or a Blade component inside a Laravel application.Activate your license, build your first form, and have it live in minutes. All PHI encrypted. Audit trail on.
Built for the people behind the front desk
Practices replace paper intake, insecure email attachments, and generic form tools that were never meant for PHI.