How to Create HIPAA-Compliant Patient Intake Forms

Transform your paper intake process into secure, HIPAA-compliant digital forms that protect patient data and handle everything from medical history to e-signatures.

Build Time & Skill

30-45 min

Intermediate

What you'll learn

How to set up HIPAA compliance in Cognito Forms, build secure patient intake forms, and protect sensitive patient data from collection through storage

Screenshot of a digital patient registration form with the HIPAA logo next to it and the data encryption setting in Cognito Forms turned on

Switching from paper to digital intake forms is essential for efficiency and growth, but healthcare providers face unique challenges with patient privacy regulations. HIPAA requirements can be overwhelming, especially for small practices without dedicated IT staff or compliance professionals. The good news is that with the right approach, you can create secure, compliant digital intake forms that protect patient data while streamlining your workflow.

Digital patient intake forms help your practice by:

  • Reducing administrative burden by eliminating manual data entry from paper forms.
  • Improving day-of-appointment wait times, since patients can complete forms before appointments.
  • Ensuring compliance with federal regulations through built-in security features like encryption, access controls, and audit trails (without requiring technical expertise).
  • Improving the patient experience with convenient online forms that patients can complete on their own schedule from any device.

Understanding HIPAA-Compliance for Online Forms

hipaa compliance logo

Before building your intake forms, understand what makes a digital form HIPAA compliant. HIPAA (Health Insurance Portability and Accountability Act) protects patient privacy by requiring specific safeguards for Protected Health Information (PHI). PHI includes any health information that can identify a patient. PHI is not just obvious medical data like diagnoses and medications, but also identifiers like names, birthdates, addresses, and phone numbers when combined with health information.

When you use an online form builder to collect patient information, you’re working with a “business associate” under HIPAA rules. This means the form provider must sign a Business Associate Agreement (BAA) that legally obligates them to protect PHI according to HIPAA standards. Without a signed BAA, using that platform for patient data violates HIPAA regulations, even if the platform claims to be “secure.”

Key compliance requirements for online forms include:

  • Encryption of data both in transit (when being submitted) and at rest (when stored)
  • Access controls that restrict who can view patient information
  • Audit trails that track who accessed what data and when
  • Automatic timeouts to prevent unauthorized access from unattended devices
  • Secure transmission methods that protect data as it moves between systems

Cognito Forms provides all these safeguards and requires a signed BAA for any organization collecting PHI, giving you confidence that your patient data stays protected.

Question icon

Learn more about how Cognito Forms enforces HIPAA-Compliance.


Building HIPAA-Compliant Intake Forms: Step-by-Step

Creating a HIPAA-compliant patient intake form involves more than just building a form with medical questions. You’ll need to enable compliance features in your account, carefully configure security settings, and test everything before patients start submitting sensitive information. Follow these steps to create intake forms that protect patient privacy while streamlining your workflow.

Step 1: Enable HIPAA-compliance in your account

Before creating any forms that collect patient information, activate HIPAA compliance for your Cognito Forms organization. This changes several security settings and enables features specifically designed for healthcare data protection.

Animated GIF of how to turn on HIPAA compliance in your Cognito Forms organization

  1. Verify your organization is on the Enterprise plan. HIPAA features are only available at this subscription level because they require enhanced security infrastructure.
  2. Go to your organization’s Settings.
  3. Navigate to Plan & Billing, then find the Compliance section.
  4. Click Sign our BAA to get started to review the Business Associate Agreement.
  5. Read through the BAA carefully, then provide your title and signature at the bottom.
  6. Click I Agree to execute the agreement.
  7. Download a PDF copy of your signed BAA for your records. You’ll also receive a copy via email.

Important: The person signing the BAA must be an owner of your account and have the authority to sign legally binding contracts for your organization. This is typically the practice owner or an authorized administrator. See our sample standard agreement for your reference.

Once you establish the BAA, several security features activate automatically:

  • All new and existing forms immediately become encrypted at rest, including any files patients upload.
  • User sessions automatically time out after 1 hour of inactivity (instead of 8 hours).
  • Guest Access is enabled, requiring authentication for Workflow links in the Public role and Save & Resume links.
  • Certain features become restricted or require additional configuration for compliance.

Plan ahead: When copying forms, you cannot copy any associated form entry data. If you have existing forms with data, they’ll remain accessible, but entries will not be copied over if you copy the form. This protects patient information from being inadvertently copied.


Step 2: Plan your intake form structure

Before building your form, map out exactly what information you need to collect and how patients will move through the questions. Good planning prevents you from rebuilding the form later when you realize you’re missing critical fields or collecting unnecessary information. Use the questions below as a starting point for planning your intake form.


Step 3: Build your patient intake form

Now you’re ready to create the actual form. This step involves adding fields, organizing sections, and using features like Conditional Logic to keep the form relevant to each patient.

Create your form and add fields

  1. Create a new form and give it a clear, descriptive name like “New Patient Intake” or “Patient Registration Form.”
  2. Add fields for all of the information you want to collect, such as:
Quick Tip

Rather than creating 10 separate “Medication” fields (which wastes space for patients with no medications and limits patients with many medications), Repeating Sections and Tables let patients add exactly as many items as they need. This keeps your form clean and flexible. Learn more about Repeating Sections and Tables.

Use conditional logic for relevant questions only

Conditional logic shows or hides fields based on previous answers, keeping your form focused and preventing patients from seeing irrelevant questions. Focus on hiding entire sections or groups of related fields that only apply to specific patient populations. Reserve conditional logic for cases where showing unnecessary questions would genuinely confuse or frustrate patients.

Common conditional logic scenarios for intake forms:

  • Show pregnancy-related questions only for patients who indicate female gender
  • Display pediatric-specific questions only when the patient’s age is under 18
  • Ask about specific symptoms based on the selected appointment type or reason for visit
  • Show additional insurance fields only if the patient indicates they have secondary insurance

Animated GIF of making a secondary insurance section only visible when the person indicates that they do have secondary insurance

How to add conditional logic

  1. Click on the field you want to show or hide conditionally.
  2. Find the Show This Field setting in the field properties.
  3. Select When instead of “Always.”
  4. Build your condition using the dropdown menus. For example:
    • Show a “Parent Signature” field only when PatientAge < 18
    • Show a “Pregnancy History” section only when Gender = "Female"
  5. Test the logic thoroughly by previewing your form and entering different scenarios.

Screenshot of Cognito Forms UI for the Require This Field setting with Always selected

Make critical fields required

Ensure you receive complete information and prevent patients from accidentally skipping critical fields.

Screenshot of Cognito Forms UI for the Require This Field setting with Always selected

  1. Go through the fields on your form and find the Require This Field setting.
  2. Select Always or For Roles > Public for any field you want to be required by the patient.

Tips to improve the intake form experience for your patients

Make your form easier to complete and navigate using Page Breaks and Save & Resume:

  • Break long forms into multiple pages organized by topic, like demographics, insurance, medical history, and consent sections. Learn more about Multi-Page Forms.
  • Enable Save & Resume so patients can complete comprehensive intake over multiple sessions without losing progress, particularly helpful for elderly patients, busy parents, or patients with complex medical histories. Learn more about Save & Resume.

Set up field validation for data accuracy

  1. For fields where format matters, add validation rules:
    • Email fields automatically require an email format ("@" and “.” in the text).
    • Phone fields of the US type require ten digits, while International type are not formatted.
    • Date fields can be set to only accept dates in the past (like for date of birth or past surgeries).
    • For Textbox fields where you need specific formats (like insurance policy numbers), use the Format Validation setting.
  2. Add helpful Placeholder Text to guide patients on what information to enter, like “MM/DD/YYYY” for Date fields.
Question icon

Learn more about the Textbox field's Format Validation setting.


Step 4: Configure field security and validation

Once your form structure is complete, configure which fields are protected from appearing in email notifications and generated documents. This prevents sensitive patient information from being transmitted, which could violate HIPAA if not handled carefully.

Understanding protected fields

In HIPAA-compliant organizations, you can mark individual fields as “Protected” to prevent their data from appearing in email notification content or generated documents. When you sign a BAA, the entire form submission remains secure and encrypted by default. Protected field settings specifically control whether that field’s data can be included in emails sent by your forms or included in generated documents.

Common fields to protect on patient intake forms include: medical history sections, current medications, allergies, reason for visit, insurance policy numbers, date of birth, and Social Security Number (if collected).

Animated GIF of turning on data encryption for a form, enabling the field protection setting for Name and Date of Birth fields, and how to add placeholder text to a field

How to configure protected fields

  1. Ensure that Data Encryption is enabled in Form Settings.
  2. Click on a field that contains or could contain PHI.
  3. Select the Protect Field? option at the bottom of the field settings.
  4. The field will display a lock icon, indicating that it is protected.

Step 5: Set up secure access and sharing

Control who can access your form and how patients can view or update their information after submission. These settings determine whether your form is publicly available or requires email verification, how submitted data is shared with patients, and how that data can be accessed after submission.

Animated GIF of where to find Public Link authentication and Workflow Link authentication settings in Cognito Forms

Configure form access settings

  1. Go to your form’s Workflow settings.
  2. Under Public Links, decide which option for Require Authentication makes the most sense for you.

Here’s a breakdown of how each authentication type works and when to use them:

Authentication type How it works When to use this method
Never Anyone on the internet can access this form if they have the form’s Public Link, with no authentication required. If you want patients to be able to open and complete the form without verifying their email address.
Users Only Access to this form is only allowed for users of your Cognito Forms organization. They must log in to open the form. If you want your staff to be the only people to be able to open and complete the form (unlikely for intake forms).
Guests & Users Anyone can access the form via the Public Link, but they must first verify their email via login providers (Microsoft, Google, Facebook) or a device verification code. If you want anyone on the internet to be able to open and complete the form, but also track the submitter’s email address.

Set up Workflow Link Sharing

Workflow Links let you send patients secure, personalized links to view or update their specific form submission. This is useful when patients need to review what they submitted or update information.

  1. Navigate to Workflow in your form’s settings.
  2. Toggle Workflow Link Sharing to On.
  3. Configure Allow Links settings:
    • Always if patients can access their submission indefinitely.
    • When or By Date if you want to set conditions, such as only allowing access until their appointment date.
  4. Decide whether to Require Authentication for Workflow Links:
    • Changing this to Always adds extra security by requiring patients to verify their email before accessing the link. The submission can only be opened when the email address the form was sent to is the same email that is verified and accessing the link.
    • Most practices enable this for patient submissions containing detailed medical information.

Keep learning

If you want to learn how to let customers open their submissions and control what they can and cannot edit, check out this guide: How to Let Customers Edit Their Form Submissions.

Animated GIF of how to find user permissions in your Cognito Forms organization

Configure user permissions for staff

User permissions are an important aspect of security and protecting PHI. Each user in your organization can be assigned a Global Permission Level and more granular permissions on the form and folder levels.

  1. Go to your organization’s Users & Authentication settings (not form-specific settings).
  2. Review which team members have access to your organization.
  3. Assign each user a Global Permission Level that fits their necessary access to PHI. Use the Override option to assign different permission levels for specific forms or folders.
  4. For granular control on individual entries, create Entry Views using the Shared with Current User filter.
Question icon

Refer to our Help Topic to understand what can and cannot be accessed at each permission level.

Enable Two-Factor Authentication

This is an optional, but beneficial security feature. Two-factor authentication adds significant security by requiring both a password and a time-based code, protecting against unauthorized access even if a password is compromised.

  1. Go to Organization Settings > Users & Authentication.
  2. Switch the toggle to “On” for the “Require two-factor authentication for all users in your organization” option.
  3. Each team member will need to set up 2FA when they next log in, using an authenticator app.

Step 6: Configure email notifications carefully

Email notifications can alert staff when patients submit forms and send confirmations to patients. However, you must configure these carefully to avoid sending PHI via email without proper consent.

Animated GIF of adding an Email Notification in Cognito Forms with a Workflow Link going to a staff member

  1. Go to Workflow > Actions.
  2. Click on the Submit Action (this triggers when patients submit the form) or any other Action that you want to send an email.
  3. Under Send Emails, click + Add Email.
  4. Configure your notification’s To, Subject, and Message.
  5. Instead of including patient data in the email, Share Workflow Link that for staff or patients to click on and securely view the full submission.
    • Be sure you select the correct Role for who is accessing the link. This ensures they only see and can edit the fields intended for them.
Quick Tip

Cognito Forms prevents protected field data from appearing elsewhere. Therefore, Protected Fields will not be available to select in the Insert Field picker when adding content to email notifications, confirmation messages, and text piping.


Step 7: Test your form before going live

Thorough testing catches issues before patients encounter them, ensuring your form works correctly and complies with your security requirements.

Animated GIF of the full patient registration form experience with Cognito Forms, including what the placeholder text looks like, conditional logic for different sections, and how a Signature field works

  • Use Preview mode to test fields, sections, Workflow logic, and more, with the ability to easily make changes in the form builder as needed.
  • Submit real sample entries to confirm the submission appears in the Entries page correctly. Check email notifications, task assignments, Workflow Links, and file uploads.
  • After submitting a test entry, use View As User to see your organization from another user’s perspective, seeing what they can and cannot access or edit.

Real-World Examples: HIPAA-Compliant Intake Forms in Action

Digital, HIPAA-compliant patient intake forms are important to all healthcare practices, regardless of your specialty, size, or services offered.

Multi-specialty and multi-provider clinics

A practice with pediatrics, general medicine, and women’s health uses conditional logic on a single intake form to show relevant questions based on appointment type selected. Pediatric patients see immunization history fields while women’s health appointments show OB/GYN-specific questions. This eliminates the need for separate intake forms while ensuring each patient only answers relevant questions.

Solo mental health practitioners

A therapist transitions from paper to digital with a streamlined intake form collecting contact information, insurance details, therapy goals, mental health history, and Signature fields for treatment consent and HIPAA acknowledgments. The digital forms reduce first-session paperwork time and lets the therapist focus on the patient instead of clipboards, while all sensitive information stays encrypted and secure.

Home health companies

A home health agency collects patient and caregiver information in their intake form. Repeating Sections flexibly handle information for multiple caregivers, File Uploads capture insurance cards and physician authorization forms, and secure Workflow Links allow family members to update information as patient care needs evolve. The form ensures all staff working with the patient see consistent, current information.

Enhance Your Intake Forms with These Additional Features

Once your basic HIPAA-compliant intake form works smoothly, these features create more sophisticated workflows:

  • Create a patient portal with Guest Access: Instead of sending separate form links for intake, consent forms, and follow-up questionnaires, assign all forms as tasks to access from a secure patient portal. Patients see a personalized dashboard with their pending forms and completed submissions.
  • Set up automated Workflows: Route completed intake forms to the appropriate department or provider automatically based on appointment type.
  • Integration with practice management systems: Connect Cognito Forms to your EMR or scheduling software using one of our integration options: Zapier, Make, Power Automate, webhooks, or the Cognito Forms API.

Start Building HIPAA-Compliant Intake Forms Today

Moving your patient intake process from paper to digital protects sensitive health information while creating a better experience for patients and staff. With HIPAA compliance built directly into Cognito Forms on the Enterprise plan, you don’t need technical expertise or expensive consultants to create secure forms.

Whether you’re a solo practitioner creating your first digital form or a multi-provider clinic streamlining intake for different specialties, HIPAA-compliant forms save time, reduce errors, and demonstrate your commitment to patient privacy. Patients appreciate the convenience of completing forms on their own schedule while you gain the efficiency of automated data collection and secure digital records.

Start with a customizable template

Get a head start with our pre-built patient intake forms. New Patient Registration, Medical Consent, and Medical History forms include all the essential fields discussed in this guide, ready to customize for your practice's specific needs.


FAQ