Learn about HIPAA
Health Insurance Portability and Accountability Act (HIPAA)
HIPAAtizer is all about compliance with the Health Insurance Portability and Accountability Act (HIPAA). HIPAA mandates certain levels of data privacy and security as it relates to protected health information (PHI) and electronic protected health information (ePHI). This covers all paper and electronically stored or transmitted individually identifiable information relating to a patient’s past, present, or future health status.
HIPAAtizer is a Business Associate as defined by the HIPAA regulations. Our forms are ONLY functional in an exclusively HIPAA‑Compliant environment. There is no guesswork with HIPAAtizer, our forms are always HIPAA Compliant.
HIPAA Requirements
So that all of our partner Covered Entities can sleep well at night knowing we are on top of the HIPAA requirements, we’ve implemented the following:
-
- Completed all 5 required HIPAA audits
-
- Privacy Policy Audit
-
- Security Standards Audit
-
- HITECH Act Subtitle D, IT Security Risk Analysis
-
- Asset & Device Audit
-
- Physical Site Audit
-
- Completed all 5 required HIPAA audits
-
- Undertake an Annual Security Risk Analysis
-
- We’ve implemented the necessary breach notification policies
-
- Ensure that all employees rigorously follow the training requirements
-
- Monitor changes to HIPAA legislation
-
- Adopted all relevant policies to ensure that the PHI you entrust us with is handled safely, following the strictest guidelines
-
- Undergone full certification and audit of our policies and procedures by a third party.
If you have any questions regarding our HIPAA policies and procedures, please contact our Security Officer at info@hipaatizer.com.
HIPAA-Compliant online forms are those that meet the Security and Privacy guidelines of the Health Insurance Portability and Accountability Act (HIPAA). For online forms to be fully HIPAA-Compliant, all PHI data should be encrypted at rest and in transit. For this, HIPAAtizer uses FIPS 140-2 compliant encryption. In addition to data encryption, HIPAA requires that the PHI data be securely backed-up and that all deletions are permanent.
Related blog posts:
-
- The Hidden Costs of Non-Compliance: Why Your Online Forms Need to Be HIPAA-Compliant. Learn more
-
- How to Build and Publish a Secure HIPAA-Compliant Form in 3 Easy Steps. Learn more
-
- How to Make Your Existing Online Forms HIPAA Compliant: Step-by-Step Guide. Learn more.
-
- The Most Comprehensive Guide to HIPAA-Compliant Web Forms. Learn more.
A release form is a legal document signed by one party that grants another party permission to use specific information, images, content, or services, and waives certain rights or claims in exchange. In healthcare, release forms most commonly refer to medical records release forms (also called a Release of Information or ROI form), which authorize a provider to share a patient’s Protected Health Information (PHI) with a designated recipient, such as another provider, insurer, or the patient themselves.
Release forms typically specify what information is being released, to whom, for what purpose, and for how long the authorization remains valid. Under HIPAA, a valid authorization form must meet specific requirements before PHI can be lawfully disclosed.
Beyond healthcare, release forms are also used in media production, employment, research, and events to document consent and limit liability.
For healthcare practices collecting release forms digitally, using a HIPAA-Compliant platform like HIPAAtizer ensures patient signatures and submitted data are securely stored and legally protected under your Business Associate Agreement (BAA).
ePHI stands for electronic protected health information: health information that identifies a patient and is created, stored, or transmitted electronically. A paper intake form in a filing cabinet is PHI. The same form filled out on your website, emailed to your front desk, or saved in your EHR is ePHI. That is the version the HIPAA Security Rule governs, so it has to be encrypted in transit and at rest, restricted to the people who need it, and logged. Online forms are usually the first place ePHI enters a practice.
PHI is protected health information in any format: spoken, written, or electronic. ePHI is the electronic subset, so web form submissions, emails, files, database records, backups. All ePHI is PHI. Not all PHI is ePHI. The Privacy Rule covers both. The Security Rule adds the technical safeguards that apply only to the electronic kind, including encryption, unique user logins, and audit trails.
HIPAA was signed into law on August 21, 1996. The 1996 text did not contain the privacy rules most people mean when they say “HIPAA.” Those arrived through later rulemaking: the Privacy Rule in 2003, the Security Rule in 2005, HITECH in 2009, which added breach notification and made business associates directly liable, and the Omnibus Rule in 2013. Anyone checking whether a tool is HIPAA Compliant today is checking it against those rules.
A business associate is a person or company outside your workforce that creates, receives, stores, or transmits PHI while doing work for a covered entity. Billing companies, IT and hosting providers, cloud storage, transcription services, and online form builders all qualify. You need a signed Business Associate Agreement in place before any PHI reaches them. Since HITECH, they carry their own liability for a breach, which is a reason vendors take the BAA seriously. A vendor that will not sign one cannot handle patient data for you. Read more about a BAA HIPAAtizer offers.
They are two separate frameworks that often apply to the same practice. HIPAA is federal law and protects patient health information. PCI DSS is a payment card industry standard enforced through your contract with your bank and the card brands, and it protects cardholder data. A clinic that takes an intake form and a card payment on the same page is subject to both. The technical controls look similar (encryption, access control, audit logging, vendor agreements), but neither one substitutes for the other. You still need a BAA for the health data and a PCI Compliant processor for the payments.

Your website is always HIPAA Compliant with HIPAAtizer
Other Resources
