Mandatory website ADA compliance starts on May 11, 2027Are you compliant?

BlogHIPAA Compliance

5 HIPAA red flags hiding in your website's intake forms

Website intake forms can quietly expose sensitive patient information through insecure tools, unencrypted email, and missing vendor agreements. These five red flags can help practices spot hidden HIPAA risks before they become a bigger problem.


James Thompson
By James Thompson
Published on: August 19, 2026
Read time: 5 min
HIPAA Compliance5 HIPAA red flags hiding in your website's intake forms

Your new patient intake form is the single most sensitive piece of software on your website, and it's probably the one nobody's reviewed since it was installed.

Most practices audit their EHR. Almost none audit the form a patient fills out before they ever become a patient, the contact form, the intake form, the "request an appointment" widget. That form collects protected health information the moment someone types a symptom into a message field, and from that moment, HIPAA applies.

When "just a contact form" stops being just a contact form

A form that only asks for name, email, and phone number isn't covered. A form that asks "what brings you in today," or lets a patient describe symptoms in a free-text box, is. The moment a form field can capture health information, it's handling PHI, regardless of what the form was originally designed for.

Most contact-form plugins were built for restaurants and real estate agents, not medical practices. They were never designed with PHI in mind, which is exactly why they're the most overlooked risk on a healthcare website.

For a hypothetical example, a small practice switched website builders a couple of years ago. The old contact form got swapped for a newer one, same fields, nicer design, and nobody thought to ask where the submissions actually went. It turned out every message, including a patient's note about a medication reaction, was landing as plain text in a shared front-desk inbox, no encryption, no BAA with the plugin vendor, no retention policy. Fortunately, nothing malicious happened. Had something actually happened, the practice would have had no audit trail, no vendor agreement, and no way to demonstrate they'd taken the data seriously. 

That's a hypothetical example, but it's a common one, not an edge case.

Five red flags to check on your own forms today

  1. Unencrypted email delivery. If form submissions land in your inbox as a plain email, that data may be traveling and sitting unencrypted, readable by anyone with access to that inbox or the mail server in between.

  2. No Business Associate Agreement with the form vendor. If a third-party plugin or form builder touches PHI, that vendor is a business associate under HIPAA, and you need a signed BAA with them. Most practices have never asked.

  3. Free-text fields with no minimum necessary limit. An open "tell us more" box invites patients to overshare: medications, diagnoses, family history, none of which your intake process actually needs at that stage.

  4. Form data is stored indefinitely with no retention policy. If submissions sit in a plugin's backend forever, with no defined deletion schedule, you're holding PHI longer than you can justify.

  5. No audit trail on who can access submissions. If every staff member with website access can see every form submission, you have no way to demonstrate access was limited to those with a legitimate need.

Why this matters more than your EHR

Your EHR was built for healthcare. It has HIPAA-aware defaults baked in. Your website's contact form almost certainly wasn't, and that mismatch is exactly where risk hides. The tools that feel the least "medical" are often the ones handling PHI with the least protection.

What to actually do about it

Start with these steps, in order.

First, pull up your live intake form and read every field on it. For each one, ask whether it needs to exist at the intake stage, or whether it's collecting more than you need.

Second, trace where a submission actually goes. Open your form builder's settings and check the delivery method: plain email, a database, a third-party dashboard. If you can't find that setting, that's itself a red flag.

Third, confirm whether that delivery path is encrypted end to end, not just "the website has an SSL certificate," but the actual submission data in transit and at rest.

Fourth, contact the form vendor directly and ask for a Business Associate Agreement in writing. If they don't have one, or don't know what you're asking for, that tells you what you need to know about their readiness to handle PHI.

Fifth, set a retention and access policy: how long submissions are kept, and who on your staff can see them.

None of this requires rebuilding your website. It requires actually looking at software you installed once and never audited again.

The bottom line

The most sensitive data on your website usually isn't in the parts that look medical. It's in the form nobody's looked at since launch.

Have you ever actually read your intake form's privacy settings, or have you been trusting that "it's just a plugin" means it's not your problem?

Frequently asked questions

Does a simple contact form count as PHI under HIPAA?
It depends on what it asks. A form limited to name and phone number generally doesn't. A form that lets a patient describe symptoms or medical history does, the moment health information is captured, HIPAA applies.
Do I need a Business Associate Agreement with my form plugin or website builder?
Yes, if that vendor's tool touches protected health information. Most practices never ask for one because they don't realize their contact form qualifies.
Is email a safe way to receive patient form submissions?
Only if it's encrypted end to end. Standard, unencrypted email delivery leaves PHI exposed in transit and in your inbox.
How long should I keep form submission data?
Only as long as you have a defined, documented reason to. Indefinite retention with no policy is itself a compliance gap.
Who should have access to form submissions on our website?
Only staff with a legitimate need to see that specific data, and you should be able to demonstrate that access is limited and tracked.
James Thompson
James Thompson

James Thompson is a UX and Product Design Leader with over 20 years of experience driving multi-million dollar revenue growth through user-centric design. A Nielsen Norman Group UX Master Certified practitioner, James specializes in digital transformation, heuristic evaluations, and modular design systems. He has led UX design for HIPAA-compliant, patient-facing platforms and ADA/WCAG-compliant healthcare products, translating complex regulatory requirements into interfaces that support both clinical workflows and diverse patient populations.

Ready for a website that earns trust and books more patients?

Mederi Digital builds healthcare websites that are accessible, private, and made to convert. Grab a free 30-minute strategy call and we'll map the quickest wins for your practice.

Book a free strategy call

Ready to see what your website is telling you?

See your accessibility, privacy-risk, and speed signals in one dashboard, ranked by what to fix first. Set up in minutes.