
Based on our research, Jotform is HIPAA compliant because it meets the requirements set by the U.S. Department of Health and Human Services (HHS) to safeguard protected health information (PHI).
What is Jotform?
Jotform is an online form builder that allows users to create and manage various types of forms, such as surveys, registrations, applications, and payment forms, without needing to code. It provides a drag-and-drop interface, customizable templates, and integration with third-party apps like Google Drive, PayPal, and Salesforce.
With Jotform, businesses, healthcare providers, educators, and nonprofits can collect data, automate workflows, and make online payments. It also offers HIPAA compliant forms for handling sensitive medical information securely.
Will Jotform sign a business associate agreement (BAA)?
Yes, Jotform will sign a business associate agreement, which can be reviewed here.
What does the Jotform BAA cover?
The Jotform BAA covers the protected health information (PHI) of its healthcare clients who use its HIPAA compliant forms. According to the BAA, “Jotform shall not, and shall ensure that its directors, officers, admin users, employees, contractors do not, use or disclose [PHI] created, maintained, or transmitted for the customer in any manner that would violate HIPAA. Jotform acknowledges and agrees that it will not use or disclose PHI other than as permitted or required by this HIPAA BAA or as required by law.”
Included with the Jotform BAA are HIPAA-related administrative, physical, and technical safeguards, subcontractor BAAs, and requests for restrictions from healthcare clients. Such measures ensure the security of PHI through Jotform. The BAA covers:
- The overall protection of PHI
- PHI segmentation
- Auditing, logging, and scanning
- Backups every 24 hours
- Notifications of PHI use or disclosure and security incidents
- Notifications of the breach of unsecured PHI
- Access by HHS requests
Is Jotform HIPAA compliant?
Jotform signs a BAA, and as a result, is HIPAA compliant.
The HIPAA compliant solution: Paubox
Paubox has developed a HIPAA compliant email and texting solution that makes it easier for providers to connect with their patients. It eliminates the need for third-party apps or logins, allowing patients to receive secure, encrypted texts and emails directly on their phones.
Learn more: HIPAA Compliant Email: The Definitive Guide
FAQS
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Go deeper: What is HIPAA?
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
Read also: Can you be a covered entity and a business associate?
What is a business associate agreement?
A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.