- B5ConnectionsAsked on October 14, 2015 at 11:05 PM
I am working on some websites for some Counseling organizations and hope to do more business with other organizations in the Mental Health, Psychology, etc. professions. Security with form submission is a huge deal and I need to verify if your product is HIPPA compliant. Can you please provide documentation indicating it is or is not?
- SammyAnswered on October 15, 2015 at 05:02 AM
At the moment JotForm does not hold the HIPPA compliance certificate, however we do have features and provisions that will enable you to use our forms in a HIPPA compliant manner.
Here are the steps you can undertake to ensure compliance;
1. Always use the SSL (https) version of JotForm site on your browser. Use "https://www.jotform.com" to login to your account, create your forms, look at your submissions and link to your forms.
2. Edit emails on all forms to make sure no specific information is used on them. We send emails in plain text. So, they are not secure. Only use emails to get alerts to know there is a new submission. Once you receive an email alert, log into the secure JotForm site and then look at the submissions.
3. If you use the Reports feature only do it with password protection. That will both ask for a password, and it will transfer all data over SSL.
4. Same for uploads. They are not password protected.
5. Logout immediate after you are done with the site.
6. Regularly download submissions and then delete them.
7. Enable the form encryption feature to encrypt submissions collected with your form
Please let us know if you will need clarification and further information
You can also refer to this thread for more information http://www.jotform.com/answers/333046-is-JotForm-HIPAA-Compliant