HIPAA Compliance & Security at FormHippo
FormHippo is designed to help healthcare providers collect and manage protected health information through secure online forms while supporting the administrative, physical, and technical safeguards required under HIPAA.
Security is not an add-on to FormHippo. It is built into the platform, the infrastructure that supports it, and the processes used by MailHippo, Inc., the parent company of FormHippo, to maintain its HIPAA compliance program.
From encryption and multi-factor authentication to secure data centers, vulnerability testing, audit controls, and Business Associate Agreements, FormHippo uses multiple layers of protection to help safeguard electronic protected health information.
A Documented HIPAA Compliance Program
HIPAA compliance involves more than using encrypted software. Organizations that create, receive, maintain, or transmit protected health information must maintain an ongoing compliance program that addresses administrative, physical, and technical safeguards.
MailHippo, Inc., the parent company of FormHippo, uses Compliancy Group’s healthcare compliance platform to help manage and document its HIPAA compliance program.
Compliancy Group’s platform includes tools for risk assessments, policies and procedures, employee training, incident management, vendor management, Business Associate Agreements, and ongoing compliance monitoring.
MailHippo, Inc. has also earned Compliancy Group’s HIPAA compliance verification badge following completion and review of its compliance program.
Security Built Into the FormHippo Platform
Encryption of Protected Health Information
FormHippo protects information both while it is transmitted and while it is stored.
Data transmitted between users and the FormHippo platform is protected using encrypted HTTPS connections.
Stored form data and documents are protected using AES-256 encryption at rest.
These protections help safeguard ePHI against unauthorized interception or access throughout the form workflow.
Multi-Factor Authentication Without Unnecessary Friction
FormHippo uses multi-factor authentication throughout the form lifecycle, not only when an account owner signs in.
Authentication protections are incorporated into interactions involving:
- FormHippo subscribers who create, send, or manage forms
- Individuals completing forms
- Authorized recipients accessing submitted forms
Rather than forcing every user through the same cumbersome authentication process, FormHippo applies authentication controls behind the scenes using techniques appropriate to the particular workflow.
These may include:
- Expiring authentication codes delivered by email
- Secure browser cookies
- Verified access links
- Session-based authentication controls
- Additional identity-verification mechanisms when appropriate
The objective is to provide strong authentication while minimizing unnecessary friction for healthcare staff, patients, and form recipients.
This is particularly timely because HHS has proposed strengthening the HIPAA Security Rule to require multi-factor authentication, with limited exceptions. Under the current rule, certain implementation specifications remain addressable; the proposed rule would eliminate most of that distinction and make MFA specifically required. The proposal has not yet been finalized, but FormHippo has already implemented MFA broadly throughout its platform.
Completed Forms Stay Inside the Secure FormHippo Platform
When a participant submits a FormHippo form, the completed form is not simply attached to an ordinary email.
Instead, the designated Recipient receives an email notification informing them that a new form submission is waiting.
The notification contains a secure link that directs the authorized recipient back to the FormHippo platform, where authentication controls are applied before the form can be accessed.
This approach helps prevent sensitive form data from being unnecessarily distributed through ordinary email attachments.
Access Controls and Authentication
FormHippo uses access controls designed to restrict sensitive information to authorized users.
Account access, form access, recipient access, and administrative functionality are separated according to the role and workflow involved.
Authentication controls help verify that individuals accessing protected information are the individuals they claim to be.
This aligns with the HIPAA Security Rule’s requirements around access control and person or entity authentication. HHS identifies access controls, audit controls, integrity protections, authentication, and transmission security among the technical safeguards required to protect ePHI.
Comprehensive Audit Controls & Activity Logging
Protecting electronic protected health information requires more than controlling who can access it. Organizations also need the ability to record and examine activity involving ePHI.
FormHippo maintains a comprehensive audit log of activity involving protected information throughout the platform. When authenticated users interact with forms, submissions, messages, attachments, and other protected information, those activities are recorded to create a chronological history of access and actions.
What FormHippo Records
FormHippo records activity including:
- Form submissions
- Access to submitted forms
- Form downloads
- Message views
- Attachment access and downloads
- Creation of protected information
- Other actions involving PHI within the platform
For each logged event, FormHippo records information such as:
Authenticated User — The authenticated account associated with the activity.
Date and Time — When the activity occurred.
Resource Accessed — The specific form, submission, message, attachment, or other element involved.
Action Performed — What occurred, such as creation, viewing, submission, access, or download.
A Chronological Record of PHI Activity
Authorized users with appropriate permissions can view audit activity in a tabular, chronological format within the FormHippo platform.
This provides organizations with visibility into who interacted with protected information, what information was involved, what action was performed, and when the activity occurred.
Audit records can help healthcare organizations investigate activity, monitor access to sensitive information, identify unexpected behavior, and maintain accountability for interactions involving ePHI.
Supporting the HIPAA Security Rule’s Audit Control Requirement
The HIPAA Security Rule specifically requires regulated entities to implement:
“hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”
That’s the language of 45 CFR § 164.312(b), Audit Controls.
FormHippo’s platform-level audit logging is designed to provide this type of visibility by recording activity involving ePHI and making those records available to appropriately authorized users.
Tamper Protection and Document Integrity
For electronically signed documents, FormHippo provides tamper-evident digital certification after completion.
If a completed document is subsequently modified, the integrity protections can indicate that the document has changed.
This supports an important principle of the HIPAA Security Rule: protecting ePHI from improper alteration or destruction. HHS specifically identifies integrity protections as a required component of the Security Rule’s technical safeguards.
Regular Independent Vulnerability Testing
FormHippo’s network environment is subject to quarterly external vulnerability scanning as part of the organization’s PCI DSS security obligations associated with payment processing.
These scans are performed on a recurring basis and must meet passing requirements.
PCI DSS requires qualifying organizations to conduct external vulnerability scans at least once every three months and to remediate identified vulnerabilities and verify remediation through rescanning.
Although PCI DSS and HIPAA are separate compliance frameworks, regular external vulnerability scanning provides an additional layer of security assurance by helping identify internet-facing vulnerabilities that could otherwise be exploited.
Secure Data Center Infrastructure
Physical Security Protecting FormHippo Infrastructure
FormHippo infrastructure is hosted in professionally managed colocation facilities designed to protect critical systems from unauthorized physical access, environmental hazards, and service interruptions.
The 365 Data Centers facility used for FormHippo infrastructure includes multiple layers of physical security, including keycard and biometric access controls, along with 24/7/365 onsite support and resilient infrastructure.
Biometric Access
Physical access controls help restrict entry to authorized personnel
24/7 Monitoring & Support
Onsite personnel provide continuous operational coverage.
Environmental Protection
Fire suppression and early smoke detection systems help protect critical infrastructure.
Redundant Connectivity
Multiple carrier and fiber options help maintain reliable network availability.
Administrative, Physical and Technical Safeguards
The HIPAA Security Rule establishes administrative, physical, and technical safeguards to help protect electronic protected health information (ePHI). FormHippo’s security and compliance program incorporates controls across all three areas, from organizational policies and workforce practices to secure data center infrastructure and technical protections built directly into the platform.
Administrative Safeguards
- Documented HIPAA compliance program
- Security risk assessments
- Policies and procedures
- Workforce training
- Vendor management
- Incident response processes
- Business Associate Agreements
- Ongoing compliance monitoring
Physical Safeguards
- Controlled data-center access
- Biometric authentication
- Keycard access controls
- Restricted infrastructure access
- Environmental monitoring
- Fire detection and suppression
- Professionally managed facilities
Technical Safeguards
- AES-256 encryption at rest
- HTTPS encryption in transit
- Multi-factor authentication
- Access controls
- Comprehensive audit controls & activity logging
- Secure form retrieval
- Authentication codes
- Session controls
- Document integrity protections
- Regular vulnerability scanning
Business Associate Agreements Included
A BAA Without an Enterprise Upgrade
For covered entities and other organizations using FormHippo to create, receive, maintain, or transmit protected health information, a Business Associate Agreement is available during signup at no additional charge.
Healthcare providers should not have to purchase an enterprise plan simply to obtain a BAA.
FormHippo was built specifically to make secure online forms practical for independent healthcare providers and organizations of all sizes.
Security Across the Entire Form Lifecycle
Create
Authorized users build forms or upload existing PDFs.
Publish
Forms are distributed through secure web links, QR codes, or embedded forms.
Complete
Participants enter information over encrypted connections.
Submit
Completed form data is securely transmitted to the FormHippo platform.
Notify
The designated recipient receives an email notification, not the PHI itself as an ordinary attachment.
Authenticate
FormHippo applies authentication controls before protected information can be accessed.
Retrieve
Authorized recipients access submitted forms securely within the FormHippo platform.
Preparing for Stronger HIPAA Security Requirements
Designed With Modern Authentication Standards in Mind
Healthcare cybersecurity requirements continue to evolve.
In December 2024, HHS proposed significant changes to the HIPAA Security Rule intended to strengthen cybersecurity protections for ePHI. Among other changes, the proposal would:
- Make multi-factor authentication required with limited exceptions
- Remove the current distinction between required and addressable implementation specifications
- Require vulnerability scanning at least every six months
- Require annual penetration testing
- Require network segmentation
- Require more explicit documentation and testing of security controls
FormHippo has already implemented multi-factor authentication throughout its form workflow and maintains recurring vulnerability-scanning practices as part of its broader security program.
The proposed HIPAA Security Rule has not yet been finalized, and the current HIPAA Security Rule remains in effect.
HIPAA Compliance Is an Ongoing Process
HIPAA compliance is not achieved by enabling one security feature or signing one agreement.
It requires an ongoing program of administrative processes, technical controls, risk management, workforce practices, policies, vendor oversight, physical safeguards, and documentation.
FormHippo’s approach combines:
secure software + protected infrastructure + documented compliance management + recurring security testing + contractual safeguards
to provide healthcare organizations with a platform designed for workflows involving protected health information.
Shared Responsibility for HIPAA Compliance
FormHippo provides security and compliance features designed to support HIPAA-regulated workflows. HIPAA compliance also depends on how each covered entity or business associate configures and uses technology, manages access, trains its workforce, maintains policies and procedures, and fulfills its own obligations under HIPAA.
Secure Online Forms Built for Healthcare
FormHippo combines easy-to-use online forms with layered security controls designed for workflows involving protected health information.
Create web forms, publish existing PDFs, collect electronic signatures, and securely manage submissions, all within a platform built around HIPAA compliance and practical healthcare workflows.
Frequently Asked Questions
Yes, FormHippo is operated by MailHippo, Inc., which maintains a documented HIPAA compliance program supported by Compliancy Group’s compliance platform. The organization has completed Compliancy Group’s HIPAA compliance verification process and provides Business Associate Agreements for customers using FormHippo with protected health information.
No federal agency issues an official HIPAA certification. Compliancy Group provides independent verification of an organization’s documented compliance program and good-faith effort to satisfy HIPAA requirements.
Yes. FormHippo incorporates multi-factor authentication and identity-verification controls throughout the platform, including subscriber workflows, form completion, and recipient access.
Yes. FormHippo uses encrypted HTTPS connections for data in transit and AES-256 encryption for protected information stored within the platform.
No. The designated recipient receives an email notification containing a secure link to the submission residing within FormHippo. Authentication controls are applied before protected information can be accessed.
FormHippo’s network environment undergoes recurring quarterly external vulnerability scanning as part of PCI DSS-related security requirements. PCI DSS requires applicable external scans at least once every three months and remediation of identified vulnerabilities.
FormHippo infrastructure is hosted in professionally managed colocation data-center facilities. The relevant 365 Data Centers facility uses multiple layers of physical security, including keycard and biometric access controls.
Yes. A BAA is available during signup for covered entities and other qualifying customers using FormHippo with PHI, at no additional charge.
The current HIPAA Security Rule remains in effect. HHS has proposed a revised rule that would specifically require multi-factor authentication with limited exceptions, but that proposal has not yet been finalized.
When a patient submits a completed form, FormHippo securely stores the submission within the FormHippo platform and sends an email notification to the user designated as the Recipient. The notification lets the Recipient know that a new form submission is waiting and includes a secure link to access it.
The completed form itself is not sent as an email attachment. Instead, the Recipient follows the secure link in the notification email to access the submitted form within the secure FormHippo platform, helping keep protected health information (PHI) out of ordinary email attachments.
© 2026 MailHippo, Inc.
2637 E. Atlantic Blvd.
#1063 Pompano Beach, FL 33062
View our Privacy Policy or contact our Customer Service team.