HIPAA-Compliant Engineering · BAA on Every Plan

Build healthcare forms patients trust

Perfect for patient intake forms

Drag-and-drop builder · AES-256-GCM encryption at rest · immutable audit trail · 39 field types including dedicated HIPAA fields for SSN, DOB, and consent.

Get HIPAA Vault Now
Loved by healthcare teams · Signed BAA on every plan
14-day free trial No credit card required Cancel anytime
forms.yourclinic.com/builder

Field Palette

Text
Email
Date
SSN · PHI
Date of Birth · PHI
Insurance ID · PHI
Signature
Patient Intake Form Auto-saved
Full name
Date of birth PHI · Encrypted
Social Security (last 4) PHI · Encrypted
Drop field here
Chief complaint
Consent / authorization PHI · Encrypted
Submit

Field Properties

Required
PHI flag
Encrypt at rest
Show in exports
Conditional logic

Validation

Mask: ###-##-####
Last 4 digits only
Audit trail recorded
Drag & drop builder
AES-256-GCM encrypted
HIPAA-ReadyEngineering AES-256-GCMEncryption at rest SHA-256 ChainImmutable audit trail Signed BAAOn every plan Zero PHIIn logs, URLs, emails
How It Works

Live in three simple steps

From blank canvas to collecting encrypted PHI — most practices publish their first form the same afternoon.

1

Build your form

Drag fields from the palette — or start from a template. PHI fields are flagged and encrypted automatically.

2

Publish anywhere

Share a direct link, embed with iFrame or JS, drop a Blade component, or paste a WordPress shortcode.

3

Collect, encrypted

Submissions land AES-256-GCM encrypted with a full audit trail. Your team is notified — without PHI in the email.

Core Features

Everything you need to collect PHI safely

From the drag-and-drop canvas to encrypted storage and compliance automation — it's all built in.

Drag-and-Drop Builder

React canvas powered by @dnd-kit. Pick fields from a 3-column palette, drop them in, reorder instantly. Two- and three-column layouts supported.

Dedicated HIPAA Fields

Purpose-built fields for SSN, Date of Birth, MRN, and Consent — each auto-flagged PHI and encrypted unconditionally.

AES-256-GCM Encryption

Every submitted value is encrypted before touching the database. Custom key service — not Laravel's CBC Crypt facade.

Immutable Audit Trail

Every action is written to an append-only audit log with a SHA-256 hash chain, verified on a schedule.

Conditional Logic

Show or hide any field based on another field's value. Hidden fields are excluded from submission validation.

Multi-Page Forms

Split long forms into stepped pages. Each step validates before advancing, with a customizable progress stepper.

4 Embed Methods

Direct URL, iFrame, Blade component, or a vanilla JS snippet — plus a WordPress plugin with shortcode.

Built-in Analytics

Views, starts, interactions, completions. Drop-off heat table, device breakdown, region map — all self-hosted.

Email Notifications

Team alerts on every submission; optional submitter confirmation. Emails carry links only — never PHI.

Industries

One form builder, for every practice

The same encrypted foundation, shaped to how your specialty actually collects information.

Medical Clinics & Family Practices

Replace clipboard intake with encrypted online forms patients complete before they arrive. Demographics, insurance, medication lists, and consent — all PHI-flagged and stored AES-256-GCM encrypted.

  • Patient intake & medical history templates, ready to publish
  • Conditional follow-ups: only ask what's relevant
  • Front-desk notified instantly — with no PHI in the email
See the intake template
Encrypted at rest
New Patient Intake

Dental Practices & Ortho Groups

New-patient paperwork, insurance verification, and treatment consent — collected before the chair, not in it. Multi-location groups manage every office's forms from one dashboard with role-based access.

  • Insurance ID and MRN fields encrypted unconditionally
  • Signature field for treatment & financial consent
  • Per-office access control for multi-location groups
How PHI is protected
Encrypted at rest
Dental Health History

Behavioral & Mental Health

Screenings and intake for the most sensitive category of PHI. Access controls restrict who can open each submission, auto-logoff protects shared workstations, and the audit trail shows exactly who viewed what, when.

  • Allowed-user lists: name exactly who can view responses
  • Auto-logoff on idle sessions, on every screen
  • Per-form data retention with automatic verified purge
Compliance automation
Restricted access
Wellness Screening

Chiropractic & Physical Therapy

Injury intake, pain scales, and progress check-ins that patients complete from their phone. Rating and slider fields capture progress visit-to-visit, and analytics show where long forms lose patients.

  • Slider & rating fields for pain and mobility scores
  • Multi-page intake with progress stepper
  • Drop-off heat table shows exactly where patients stop
See the analytics
Mobile-first
Injury Intake & Pain Scale

Med Spas & Aesthetic Clinics

Consultation requests, treatment consent, and medication disclosures — collected securely while your marketing keeps running. GTM, GA4, and Meta Pixel track campaign conversions without ever touching PHI.

  • Consent & medication-list fields, encrypted by default
  • Campaign tracking with zero PHI shared to ad platforms
  • Embed on WordPress or any landing page in minutes
Marketing integrations
No PHI to ad tools
Consultation Request
Why HIPAA Vault

Top reasons practices switch to HIPAA Vault

Reason 1 · The Builder

Powerful forms, without touching code

The React drag-and-drop canvas makes the tenth form as fast as the first. A searchable 39-field palette, live patient preview, 30-step undo/redo, and auto-save every six seconds — with safety modals before anything destructive.

  • Two- and three-column layouts, headings, dividers, page breaks
  • Conditional logic — show fields only when relevant
  • Multi-page forms with step-by-step validation
Auto-saved
Medical History Page 2 of 3
Current medications
Diagnosis code PHI
Drop field here
Allergies
Undo · 30 steps
Reason 2 · PHI Protection

PHI is flagged, encrypted, and audited — automatically

Eight dedicated HIPAA field types encrypt unconditionally. And if staff add a plain text field that looks like PHI, the auto-scanner flags it before the form goes live. Every view and change lands in a SHA-256-chained audit log.

  • AES-256-GCM before any value reaches the database
  • PHI auto-scanner catches unflagged sensitive fields
  • Append-only audit trail, verified on a schedule
See the full security model
PHI detected — encryption enforced
// submissions table dob: gcm:v2:a9f3…c41e ssn_l4: gcm:v2:7b02…e88d consent: gcm:v2:d54c…901a
Audit chain verified · 2 min ago
Reason 3 · Publishing

Publish anywhere your patients are

Every form gets a clean shareable URL the moment it's published. Embed it on your website with an iFrame or one JS snippet, render it natively in Laravel with a Blade component, or paste a shortcode into WordPress.

https://forms.yourclinic.com/f/patient-intake
<iframe src="https://forms.yourclinic.com/f/patient-intake" width="100%" style="border:0" loading="lazy"></iframe>
<x-hipaa-vault::form slug="patient-intake" />
<div data-hv-form="patient-intake"></div> <script src="https://forms.yourclinic.com/embed.js" defer></script>
[hipaa_vault form="patient-intake"]
QR at reception
On any device
WordPress plugin included
Reason 4 · Notifications

Your team knows instantly — PHI stays put

Every submission can alert your front desk, and patients can receive a confirmation. But unlike generic form tools, emails contain a secure link only. The data itself never leaves your encrypted database.

  • Team alerts with secure view-links, never raw answers
  • Optional patient confirmation emails
  • Webhooks with signed payloads for your own systems
No PHI in this email
New submission — Patient Intake
To: frontdesk@yourclinic.com
A new intake form was submitted at 9:42 AM.
View securely in dashboard →
39 Field Types

The right field for every clinical question

Standard form fields, HIPAA-specific PHI fields, and layout helpers — all in one palette.

Text Textarea Name (First + Last) Email Phone Number Decimal Currency Date Time Date & Time Month / Year URL Select Multi-select Radio Checkboxes Yes / No Rating Slider Signature File Upload Address Hidden Rich Text
SSN Date of Birth Medical Record Number Consent / Authorization Insurance ID Diagnosis Code Medication List Emergency Contact
Heading Paragraph Divider Page Break Two Columns Three Columns
Security

Defense-in-depth, by default

Encryption, session hygiene, and tamper-evidence are not settings you enable. They're how the system works.

Patient submits

TLS in transit, honeypot & rate-limit checks

Value encrypted

AES-256-GCM via dedicated DEK / KEK key service

Stored at rest

Ciphertext only — nothing readable in the database

Audit logged

Append-only entry, chained with SHA-256

AES-256-GCM at rest

Every value encrypted with authenticated encryption before it reaches the database.

Immutable audit trail with hash chain

Append-only logs, each entry chained with SHA-256. Tampering breaks the chain and raises a flag.

Auto-logoff & session management

Idle sessions expire automatically across every authenticated surface.

PHI-safe headers on all responses

No PHI ever appears in logs, URLs, headers, or emails.

Multi-layer anti-spam

Honeypots, rate limits, and validation keep junk out — without CAPTCHAs frustrating patients.

Key rotation, zero-downtime

Rotate data-encryption keys on schedule; records re-encrypt in the background.

// storage specification cipher: AES-256-GCM key_service: dedicated DEK / KEK rotation: scheduled, zero-downtime scope: every submitted value // audit trail table: audit_logs (append-only) integrity: SHA-256 hash chain verification: scheduled job // exposure policy logs: zero PHI urls: zero PHI emails: links only
6 Starter Templates

Launch in under 60 seconds

Six starting points, each pre-wired with the right fields and PHI flags. Or begin from a blank canvas.

Blank Form

An empty canvas. Bring your own structure and pull from all 39 field types.

0 fields · your call

Patient Intake

Demographics, insurance, history, and consent — the front-desk staple, PHI-flagged.

Multi-page · PHI ready

Contact Us

A simple, encrypted contact form for your practice website.

Single page

Medical History

Conditions, medications, allergies, and family history with conditional follow-ups.

Conditional logic · PHI ready

Appointment Request

Preferred dates, provider, and reason for visit — routed to your team by email.

Notifications on

Feedback Survey

Ratings, sliders, and open text to hear how visits actually went.

Analytics ready
Publishing

Publish anywhere in seconds

Five ways to put a form in front of a patient — from a shareable link to a WordPress shortcode.

Direct URL

Every published form gets a clean, shareable link. Send it by email or SMS, or print the QR code at reception.

https://forms.yourclinic.com/f/patient-intake

iFrame Embed

Drop the form into any page. Auto-resizes to fit its content.

<iframe src="https://forms.yourclinic.com/f/patient-intake" width="100%" style="border:0" loading="lazy"></iframe>

Blade Component

Rendering inside your own Laravel app? Use the first-party component.

<x-hipaa-vault::form slug="patient-intake" />

JS Snippet

One script tag mounts the form on any external website.

<div data-hv-form="patient-intake"></div> <script src="https://forms.yourclinic.com/embed.js" defer></script>

WordPress Plugin

Install the plugin, paste the shortcode into any page or post.

[hipaa_vault form="patient-intake"]
Analytics

PHI stays on your servers

Everything is measured in-house — no third-party analytics ever touches a submission.

Submissions — last 6 months

Monthly
Jan
Feb
Mar
Apr
May
Jun

Completion funnel

This month
Views
12,480
Starts
8,912
Completions
7,304

Drop-off heat table shows the exact field where people leave.

Completion rateMobile 62% · Desktop 25% · Tablet 13%
+18% viewsvs. last monthTrending up
Region mapSee where submissions come from

Export: PDF & CSV

Take reports to your next staff meeting.

Funnel Visualization

View → start → complete, step by step.

Monthly & Yearly Trends

Submission volume over time, at a glance.

Device Breakdown

Mobile vs. desktop vs. tablet completion.

Integrations

Connect your existing tools

Marketing and measurement plug in at the edges — PHI never leaves your server.

Google Tag Manager

Fire tags on view, start, and complete events.

No PHI shared

Google Analytics 4

Track conversions alongside site traffic.

No PHI shared

Meta Pixel

Measure campaigns that drive completions.

No PHI shared

Custom Webhook

Push submission events to any endpoint.

Signed payloads

WordPress Plugin

Shortcode embedding for any WP site.

Free plugin
Loved by Clinics

Built for the people behind the front desk

Practices replace paper intake, insecure email attachments, and generic form tools that were never meant for PHI.

"We moved intake off paper in a week. Patients fill forms from home, and everything lands encrypted with a clean audit trail for our compliance officer."
SR
Practice ManagerFamily medicine clinic
"The PHI auto-scanner caught fields our staff added as plain text. That alone justified the switch from a generic form builder."
JT
IT AdministratorMulti-location dental group
"Drop-off analytics showed exactly which question was losing patients. We fixed one field and completion went up double digits."
MK
Operations LeadBehavioral health practice
Access & Workflow

A builder that gets out of your way

Fine-grained access control on every form, plus ergonomics that make the tenth form as fast as the first.

Public access

Anyone with the link can submit — ideal for intake and contact forms.

Logged-in users only

Restrict submission to authenticated accounts on your instance.

Allowed user list

Name exactly who may open and submit a given form.

Share link with token

Revocable tokenized URLs for one-off or time-boxed access.

PHI auto-scanner

Flags fields that look like PHI even when added as plain text.

Undo / redo, 30 steps

Experiment freely — nothing is more than a keystroke from recovery.

Searchable palette & live preview

Find any of 39 fields instantly; see the patient's view as you build.

Auto-save with safety modals

Six-second debounced saves, plus confirmation before destructive actions.

Compliance Automation

HIPAA safeguards, automated

The administrative work of compliance runs on a schedule, not on memory.

Data Retention & Purge

Set retention windows per form; expired submissions purge automatically and verifiably.

Breach Notification

Structured incident logging and notification workflows, ready before you need them.

Audit Chain Verification

Scheduled jobs re-verify the SHA-256 hash chain and alert on any inconsistency.

DEK Key Rotation

Rotate data-encryption keys with zero-downtime background re-encryption.

Compliance Checker

A built-in checklist audits each form's configuration against HIPAA safeguards.

Role-Based Permissions

Admins, editors, and viewers — least-privilege access to forms and submissions.

Pricing

Simple, transparent pricing

Every plan includes a signed BAA and encrypted PHI storage. Start with a 14-day free trial — no card required.

Lite
$49/mo

Billed monthly

Start 14-Day Free Trial
  • Up to 10 forms
  • 1,000 submissions / month
  • 3 users / staff
  • Signed BAA included
  • Secure PHI storage
  • Email support
Enterprise
Custom

Contact us for pricing

Talk to Us
  • White-glove migration & setup
  • Unlimited forms & submissions
  • Unlimited users / staff
  • Signed BAA included
  • Secure PHI storage
  • Full EHR integration
  • Dedicated account manager

14-day free trial · No credit card required · Cancel anytime · Signed BAA on all plans

FAQ

Frequently asked questions

Is HIPAA Vault Form Builder HIPAA compliant? Do I get a BAA?
Every plan includes a signed Business Associate Agreement, and the platform is engineered around HIPAA safeguards: AES-256-GCM encryption at rest, an immutable SHA-256-chained audit trail, auto-logoff, role-based access, and zero PHI in logs, URLs, or emails. Note that HIPAA compliance is a shared responsibility — the software provides the technical safeguards, and your organization's policies, training, and hosting BAA complete the picture.
How is patient data (PHI) stored?
Every submitted value is encrypted with AES-256-GCM before it reaches the database, using a dedicated key service with DEK/KEK separation — not a framework default. Only ciphertext is stored at rest, keys rotate on schedule with zero-downtime re-encryption, and every access is written to an append-only audit log.
Can I embed forms on my WordPress site?
Yes — a free WordPress plugin lets you place any form with a simple shortcode like [hipaa_vault form="patient-intake"]. You can also use a direct URL, an auto-resizing iFrame, a one-line JS snippet on any website, or a Blade component inside a Laravel application.
What happens to old submissions? Can I set retention rules?
Each form can have its own data-retention window. When submissions expire, they are purged automatically and verifiably, and the purge itself is recorded in the audit trail — so your retention policy runs on a schedule, not on somebody remembering.
Do marketing integrations expose patient data?
No. Google Tag Manager, GA4, and Meta Pixel integrations only receive anonymous events — form viewed, started, completed. Actual answers never leave your encrypted database, and webhook payloads are signed so your own systems can verify authenticity.
Is there a free trial? What do I need to start?
Every plan starts with a 14-day free trial, no credit card required. Pick a template (patient intake, medical history, appointment request and more), adjust the fields, and publish — most practices have their first form live the same afternoon. You can cancel anytime.

Ready to build HIPAA-compliant forms?

Activate your license, build your first form, and have it live in minutes. All PHI encrypted. Audit trail on.

AES-256-GCM Immutable audit trail 39 field types 6 templates Built-in analytics Auto-logoff Key rotation Breach notification