NOVRASCALE
PlatformPricing
Client LoginBook a Free Call
NOVRASCALE
7 min read•Apr 28, 2026•By Matt Delgado

Your Contact Form Is Probably a HIPAA Violation

Most practice websites collect patient inquiries and route them to non-HIPAA-compliant platforms. Here's what that exposes, why it matters, and exactly how to fix it.

Someone fills out your contact form at 9pm. They type their name, phone number, and something like “I’ve been struggling with anxiety and I’d like to schedule an appointment.”

That message travels somewhere. The question is: where?

If you’re using a standard contact form — the kind that comes default with almost every website template — the answer is almost certainly a place that has no HIPAA obligation, no Business Associate Agreement, and no legal authority to receive that information. And if the Office for Civil Rights ever comes knocking, ”I didn’t know” is not a defense.

This is one of the most common HIPAA violations hiding on practice websites right now. It’s also one of the easiest to fix — once you know what to look for.

What Makes a Contact Form a HIPAA Problem

HIPAA’s Privacy Rule defines Protected Health Information (PHI) as any information that connects a person’s identity to their health status, care, or payment. That definition is broader than most people realize.

”I have anxiety” + a name = PHI. ”I’d like to schedule a therapy appointment” + an email address = PHI. ”Do you take Aetna?” + a phone number = PHI.

The moment a patient types anything about why they’re contacting you — their condition, their symptoms, what kind of appointment they want — that message becomes PHI. And the second it leaves your form, you are responsible for where it goes and who can read it.

Here’s where most contact forms send that data:

  • Web3Forms, Formspree, EmailJS, Netlify Forms — the most common form backends used by web developers because they’re free and easy. None are HIPAA-covered entities. None offer BAAs. Your patient’s message flows through their servers with zero legal protections.
  • Your Gmail or Outlook inbox — standard email is not encrypted in a way that meets HIPAA’s technical safeguards. Consumer email platforms are not HIPAA compliant by default.
  • Your CRM — if you’re routing form submissions into HubSpot, ActiveCampaign, or similar marketing CRMs, most require an enterprise tier and specific configuration before they’ll sign a BAA. The default setup is not covered.

Three hops. Zero BAAs. One HHS complaint and you’re looking at a corrective action plan at minimum, and a fine at worst.

The “But It’s Just an Appointment Request” Fallacy

The most common pushback: “My form just asks for name, phone, and preferred appointment time. That’s not sensitive.”

This misunderstands how HIPAA works. The violation isn’t about the sensitivity of the information — it’s about the combination. Name + phone number + the fact that they’re contacting a mental health practice is PHI. Name + email + ”I’m a new patient” sent to a psychiatric practice website is PHI.

Context determines classification. If a patient is contacting you specifically as a patient — or a prospective patient — the information is PHI by default, regardless of whether they disclosed a diagnosis.

The OCR has been explicit about this. The 2022 bulletin on tracking technologies specifically addressed how patient contact with covered entities creates PHI even when the contact itself seems innocuous.

Source: HHS.gov, ”Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates,” December 2022

Not sure where your form data goes? Get a free compliance check →

What a HIPAA-Compliant Contact Form Actually Requires

The good news: this is solvable. The solution has three parts.

1. A HIPAA-compliant form backend with a signed BAA

You need a form submission platform that will sign a Business Associate Agreement — a legal contract that obligates the vendor to protect PHI in accordance with HIPAA. Without one, you cannot legally use their service to collect patient information.

Platforms that offer BAAs for form submission include JotForm (HIPAA-compliant plan), Cognito Forms (HIPAA plan), and some healthcare-specific intake solutions. The free tier of every popular form tool does not qualify. Period.

2. Encrypted transmission and storage

Data must be encrypted in transit (TLS 1.2 or higher — standard HTTPS covers this) and encrypted at rest on whatever server stores it. This rules out most consumer email inboxes as the final destination.

3. Proper email routing

If form submissions route to your inbox, that inbox needs to be covered by a BAA. Google Workspace (the paid version, with a BAA on file with Google) can qualify. Microsoft 365 with a BAA can qualify. Personal Gmail, Apple Mail, and standard Outlook.com accounts do not.

This also means your front desk can’t just use their personal email to check form submissions. The entire chain — form → server → inbox — needs to be covered.

Three Questions to Ask Your Web Developer Right Now

If someone built your website, they should be able to answer these without hesitation:

  1. What platform handles our form submissions, and do you have a BAA with them? If they don’t know what a BAA is, you have your answer.
  2. Where do form submissions go after they’re submitted? Trace the full path. Form backend → email notification → inbox. Every stop needs to be covered.
  3. Is our email account HIPAA-eligible, and do we have a BAA with our email provider? If they say ”you use Gmail” and stop there, that’s a problem.

Most web developers — even competent ones — are not HIPAA specialists. They build functional forms. They don’t audit data flows for healthcare compliance. That’s not a criticism. It’s a different skill set. The responsibility for asking these questions falls on you, because you’re the covered entity.

This Is One Problem. Your Site Probably Has More.

Contact forms are the most obvious entry point, but they’re not the only one. The same PHI-leakage risk exists in live chat widgets (most route through non-HIPAA platforms), appointment scheduling tools (depends entirely on which one and how it’s configured), and the analytics trackers that run silently in the background of nearly every website.

The FTC and OCR have both signaled that enforcement is moving downstream — from large hospital systems toward independent practices. Small practices make easier targets and are far less likely to have legal teams reviewing their tech stack.

The cost of getting this right is low. The cost of getting it wrong is not.

Look up which platform handles your contact form submissions. Check if they offer a BAA. Check if you have one. If you don’t know where your form data goes, you have your answer about whether your site is compliant.

The practical move: A proper audit covers your form backend, your email routing, your analytics stack, your chat tools, and your scheduling software — every place patient data touches a third-party system. We do that audit for free for healthcare practices. No pitch, no obligation. You walk away with a clear picture of what’s exposed and what to do about it.

Find Out If Your Contact Form Is Leaking Patient Data

We audit every data touchpoint on your practice website (contact forms, chat widgets, email routing) and tell you exactly what's exposed. Free. No obligation.

Get Your Free Report Card

If you run a practice in this space, see how we build for Mental Health Practices.

Related Industries

Mental Health Practices →Dental Practices →Med Spas →

Start here

For the full picture, read the pillar guide: 7 HIPAA Violations Hiding on Your Practice Website Right Now.

NOVRASCALE

AI automation for small business. We build the AI system that catches every lead and books more work, so your schedule fills itself.

Get My Free Report Card

Features

  • Lead Generation
  • Website Design
  • Local SEO
  • AI Receptionist
  • AI Follow-Up
  • AI Review Responder
  • AI Quote Builder
  • Review Generation
  • CRM & Pipeline
All features

Industries

  • HVAC
  • Real Estate
  • Roofing
  • Dental
  • Mental Health
  • Law Firms
All 20 industries

Compare

  • vs. Wix
  • vs. Squarespace
  • vs. WordPress
  • vs. GoDaddy
  • vs. Webflow
All comparisons

Tools & resources

  • Free Website Report Card
  • Money-Leak Calculator
  • The platform
  • Request access
  • Demo walkthrough
  • Portfolio
  • Blog
  • Docs
All resources

Company

  • About
  • Reviews
  • Team
  • Contact
  • Talk to Sales
  • FAQ

© 2026 NovraScale LLC. All rights reserved.

Powered by the NovraScale One Platform
PrivacyTermsCancellationBAASecuritySitemap