HIPAA Compliance & Security at FormHippo

FormHippo is designed to help healthcare providers collect and manage protected health information through secure online forms while supporting the administrative, physical, and technical safeguards required under HIPAA.

Security is not an add-on to FormHippo. It is built into the platform, the infrastructure that supports it, and the processes used by MailHippo, Inc., the parent company of FormHippo, to maintain its HIPAA compliance program.

From encryption and multi-factor authentication to secure data centers, vulnerability testing, audit controls, and Business Associate Agreements, FormHippo uses multiple layers of protection to help safeguard electronic protected health information.

A Documented HIPAA Compliance Program

HIPAA compliance involves more than using encrypted software. Organizations that create, receive, maintain, or transmit protected health information must maintain an ongoing compliance program that addresses administrative, physical, and technical safeguards.

MailHippo, Inc., the parent company of FormHippo, uses Compliancy Group’s healthcare compliance platform to help manage and document its HIPAA compliance program.

Compliancy Group’s platform includes tools for risk assessments, policies and procedures, employee training, incident management, vendor management, Business Associate Agreements, and ongoing compliance monitoring.

MailHippo, Inc. has also earned Compliancy Group’s HIPAA compliance verification badge following completion and review of its compliance program.

Security Built Into the FormHippo Platform

Encryption of Protected Health Information

FormHippo protects information both while it is transmitted and while it is stored.

Data transmitted between users and the FormHippo platform is protected using encrypted HTTPS connections.

Stored form data and documents are protected using AES-256 encryption at rest.

These protections help safeguard ePHI against unauthorized interception or access throughout the form workflow.

FormHippo HIPAA-compliant online forms protect ePHI with encrypted HTTPS connections and AES-256 encryption at rest.
FormHippo protects electronic protected health information (ePHI) using encrypted HTTPS connections for data in transit and AES-256 encryption for data at rest.

Multi-Factor Authentication Without Unnecessary Friction

FormHippo multi-factor authentication protects access to HIPAA-compliant online forms for subscribers, form users, and authorized recipients.
FormHippo uses multi-factor authentication throughout the online form lifecycle to help protect access to ePHI while minimizing unnecessary friction for users.

FormHippo uses multi-factor authentication throughout the form lifecycle, not only when an account owner signs in.

Authentication protections are incorporated into interactions involving:

    • FormHippo subscribers who create, send, or manage forms
    • Individuals completing forms
    • Authorized recipients accessing submitted forms

Rather than forcing every user through the same cumbersome authentication process, FormHippo applies authentication controls behind the scenes using techniques appropriate to the particular workflow.

These may include:

    • Expiring authentication codes delivered by email
    • Secure browser cookies
    • Verified access links
    • Session-based authentication controls
    • Additional identity-verification mechanisms when appropriate

The objective is to provide strong authentication while minimizing unnecessary friction for healthcare staff, patients, and form recipients.

This is particularly timely because HHS has proposed strengthening the HIPAA Security Rule to require multi-factor authentication, with limited exceptions. Under the current rule, certain implementation specifications remain addressable; the proposed rule would eliminate most of that distinction and make MFA specifically required.  The proposal has not yet been finalized, but FormHippo has already implemented MFA broadly throughout its platform.

Completed Forms Stay Inside the Secure FormHippo Platform

When a participant submits a FormHippo form, the completed form is not simply attached to an ordinary email.

Instead, the designated Recipient receives an email notification informing them that a new form submission is waiting.

The notification contains a secure link that directs the authorized recipient back to the FormHippo platform, where authentication controls are applied before the form can be accessed.

This approach helps prevent sensitive form data from being unnecessarily distributed through ordinary email attachments.

FormHippo keeps completed HIPAA forms inside its secure platform and emails recipients a secure link instead of sending form data as an attachment.
Completed forms remain inside the secure FormHippo platform. Recipients receive an email notification with a secure link to access the submission after authentication.

Access Controls and Authentication

FormHippo HIPAA access controls and authentication help restrict ePHI and sensitive form data to authorized users based on role and workflow.
FormHippo uses role-based access controls and authentication to help ensure that sensitive form data and ePHI are accessible only to authorized users.

FormHippo uses access controls designed to restrict sensitive information to authorized users.

Account access, form access, recipient access, and administrative functionality are separated according to the role and workflow involved.

Authentication controls help verify that individuals accessing protected information are the individuals they claim to be.

This aligns with the HIPAA Security Rule’s requirements around access control and person or entity authentication. HHS identifies access controls, audit controls, integrity protections, authentication, and transmission security among the technical safeguards required to protect ePHI.

Comprehensive Audit Controls & Activity Logging

Protecting electronic protected health information requires more than controlling who can access it. Organizations also need the ability to record and examine activity involving ePHI.

FormHippo maintains a comprehensive audit log of activity involving protected information throughout the platform. When authenticated users interact with forms, submissions, messages, attachments, and other protected information, those activities are recorded to create a chronological history of access and actions.

 

FormHippo HIPAA audit controls showing a chronological activity log of user access, form activity, message views, downloads, and actions involving ePHI.
FormHippo maintains chronological audit logs that record authenticated user activity involving forms, messages, attachments, downloads, and other protected information.

What FormHippo Records

FormHippo records activity including:

    • Form submissions
    • Access to submitted forms
    • Form downloads
    • Message views
    • Attachment access and downloads
    • Creation of protected information
    • Other actions involving PHI within the platform

For each logged event, FormHippo records information such as:

Authenticated User — The authenticated account associated with the activity.

Date and Time — When the activity occurred.

Resource Accessed — The specific form, submission, message, attachment, or other element involved.

Action Performed — What occurred, such as creation, viewing, submission, access, or download.

A Chronological Record of PHI Activity

Authorized users with appropriate permissions can view audit activity in a tabular, chronological format within the FormHippo platform.

This provides organizations with visibility into who interacted with protected information, what information was involved, what action was performed, and when the activity occurred.

Audit records can help healthcare organizations investigate activity, monitor access to sensitive information, identify unexpected behavior, and maintain accountability for interactions involving ePHI.

Supporting the HIPAA Security Rule’s Audit Control Requirement

The HIPAA Security Rule specifically requires regulated entities to implement:

“hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”

That’s the language of 45 CFR § 164.312(b), Audit Controls.

FormHippo’s platform-level audit logging is designed to provide this type of visibility by recording activity involving ePHI and making those records available to appropriately authorized users.

Tamper Protection and Document Integrity

For electronically signed documents, FormHippo provides tamper-evident digital certification after completion.

If a completed document is subsequently modified, the integrity protections can indicate that the document has changed.

This supports an important principle of the HIPAA Security Rule: protecting ePHI from improper alteration or destruction. HHS specifically identifies integrity protections as a required component of the Security Rule’s technical safeguards.

Regular Independent Vulnerability Testing

FormHippo’s network environment is subject to quarterly external vulnerability scanning as part of the organization’s PCI DSS security obligations associated with payment processing.

These scans are performed on a recurring basis and must meet passing requirements.

PCI DSS requires qualifying organizations to conduct external vulnerability scans at least once every three months and to remediate identified vulnerabilities and verify remediation through rescanning.

Although PCI DSS and HIPAA are separate compliance frameworks, regular external vulnerability scanning provides an additional layer of security assurance by helping identify internet-facing vulnerabilities that could otherwise be exploited.

FormHippo quarterly external vulnerability scanning process showing vulnerability assessment, remediation, rescanning, and improved security.
FormHippo undergoes quarterly external vulnerability scanning to identify internet-facing security risks, remediate vulnerabilities, and verify remediation through rescanning.

Secure Data Center Infrastructure

Physical Security Protecting FormHippo Infrastructure

FormHippo infrastructure is hosted in professionally managed colocation facilities designed to protect critical systems from unauthorized physical access, environmental hazards, and service interruptions.

The 365 Data Centers facility used for FormHippo infrastructure includes multiple layers of physical security, including keycard and biometric access controls, along with 24/7/365 onsite support and resilient infrastructure.

Biometric Access

Physical access controls help restrict entry to authorized personnel

24/7 Monitoring & Support

Onsite personnel provide continuous operational coverage.

Environmental Protection

Fire suppression and early smoke detection systems help protect critical infrastructure.

Redundant Connectivity

Multiple carrier and fiber options help maintain reliable network availability.

Administrative, Physical and Technical Safeguards

The HIPAA Security Rule establishes administrative, physical, and technical safeguards to help protect electronic protected health information (ePHI). FormHippo’s security and compliance program incorporates controls across all three areas, from organizational policies and workforce practices to secure data center infrastructure and technical protections built directly into the platform.

Administrative Safeguards

    • Documented HIPAA compliance program
    • Security risk assessments
    • Policies and procedures
    • Workforce training
    • Vendor management
    • Incident response processes
    • Business Associate Agreements
    • Ongoing compliance monitoring

Physical Safeguards

    • Controlled data-center access
    • Biometric authentication
    • Keycard access controls
    • Restricted infrastructure access
    • Environmental monitoring
    • Fire detection and suppression
    • Professionally managed facilities

Technical Safeguards

    • AES-256 encryption at rest
    • HTTPS encryption in transit
    • Multi-factor authentication
    • Access controls
    • Comprehensive audit controls & activity logging
    • Secure form retrieval
    • Authentication codes
    • Session controls
    • Document integrity protections
    • Regular vulnerability scanning

Business Associate Agreements Included

A BAA Without an Enterprise Upgrade

For covered entities and other organizations using FormHippo to create, receive, maintain, or transmit protected health information, a Business Associate Agreement is available during signup at no additional charge.

Healthcare providers should not have to purchase an enterprise plan simply to obtain a BAA.

FormHippo was built specifically to make secure online forms practical for independent healthcare providers and organizations of all sizes.

Security Across the Entire Form Lifecycle

FormHippo secure HIPAA online form workflow showing Create, Publish, Complete, Submit, Notify, Authenticate, and Retrieve.
The FormHippo secure form workflow protects information throughout the process—from creating and publishing forms to encrypted submission, authentication, and secure retrieval.

Create
Authorized users build forms or upload existing PDFs.

Publish
Forms are distributed through secure web links, QR codes, or embedded forms.

Complete
Participants enter information over encrypted connections.

Submit
Completed form data is securely transmitted to the FormHippo platform.

Notify
The designated recipient receives an email notification, not the PHI itself as an ordinary attachment.

Authenticate
FormHippo applies authentication controls before protected information can be accessed.

Retrieve
Authorized recipients access submitted forms securely within the FormHippo platform.

Preparing for Stronger HIPAA Security Requirements

Designed With Modern Authentication Standards in Mind

Healthcare cybersecurity requirements continue to evolve.

In December 2024, HHS proposed significant changes to the HIPAA Security Rule intended to strengthen cybersecurity protections for ePHI. Among other changes, the proposal would:

    • Make multi-factor authentication required with limited exceptions
    • Remove the current distinction between required and addressable implementation specifications
    • Require vulnerability scanning at least every six months
    • Require annual penetration testing
    • Require network segmentation
    • Require more explicit documentation and testing of security controls

FormHippo has already implemented multi-factor authentication throughout its form workflow and maintains recurring vulnerability-scanning practices as part of its broader security program.

The proposed HIPAA Security Rule has not yet been finalized, and the current HIPAA Security Rule remains in effect.

HIPAA Compliance Is an Ongoing Process

HIPAA compliance is not achieved by enabling one security feature or signing one agreement.

It requires an ongoing program of administrative processes, technical controls, risk management, workforce practices, policies, vendor oversight, physical safeguards, and documentation.

FormHippo’s approach combines:

secure software + protected infrastructure + documented compliance management + recurring security testing + contractual safeguards

to provide healthcare organizations with a platform designed for workflows involving protected health information.

Shared Responsibility for HIPAA Compliance

FormHippo provides security and compliance features designed to support HIPAA-regulated workflows. HIPAA compliance also depends on how each covered entity or business associate configures and uses technology, manages access, trains its workforce, maintains policies and procedures, and fulfills its own obligations under HIPAA.

Secure Online Forms Built for Healthcare

FormHippo combines easy-to-use online forms with layered security controls designed for workflows involving protected health information.

Create web forms, publish existing PDFs, collect electronic signatures, and securely manage submissions, all within a platform built around HIPAA compliance and practical healthcare workflows.

Start Your Free 30-Day Trial or View Plans & Pricing

Frequently Asked Questions

Yes, FormHippo is operated by MailHippo, Inc., which maintains a documented HIPAA compliance program supported by Compliancy Group’s compliance platform. The organization has completed Compliancy Group’s HIPAA compliance verification process and provides Business Associate Agreements for customers using FormHippo with protected health information.

No federal agency issues an official HIPAA certification. Compliancy Group provides independent verification of an organization’s documented compliance program and good-faith effort to satisfy HIPAA requirements.

Yes. FormHippo incorporates multi-factor authentication and identity-verification controls throughout the platform, including subscriber workflows, form completion, and recipient access.

Yes. FormHippo uses encrypted HTTPS connections for data in transit and AES-256 encryption for protected information stored within the platform.

No. The designated recipient receives an email notification containing a secure link to the submission residing within FormHippo. Authentication controls are applied before protected information can be accessed.

FormHippo’s network environment undergoes recurring quarterly external vulnerability scanning as part of PCI DSS-related security requirements. PCI DSS requires applicable external scans at least once every three months and remediation of identified vulnerabilities.

FormHippo infrastructure is hosted in professionally managed colocation data-center facilities. The relevant 365 Data Centers facility uses multiple layers of physical security, including keycard and biometric access controls.

Yes. A BAA is available during signup for covered entities and other qualifying customers using FormHippo with PHI, at no additional charge.

The current HIPAA Security Rule remains in effect. HHS has proposed a revised rule that would specifically require multi-factor authentication with limited exceptions, but that proposal has not yet been finalized.

When a patient submits a completed form, FormHippo securely stores the submission within the FormHippo platform and sends an email notification to the user designated as the Recipient. The notification lets the Recipient know that a new form submission is waiting and includes a secure link to access it.

The completed form itself is not sent as an email attachment. Instead, the Recipient follows the secure link in the notification email to access the submitted form within the secure FormHippo platform, helping keep protected health information (PHI) out of ordinary email attachments.

© 2026 MailHippo, Inc.
2637 E. Atlantic Blvd.
#1063 Pompano Beach, FL  33062

View our Privacy Policy or contact our Customer Service team.