Forms · Patient information
Where do your website’s patient form submissions actually go?
An email arrives at the front desk. Where else were the patient’s answers saved, and who can read them? Here is how to find out and simplify the setup.
The email arrived. Where else did the answers go?
Imagine a prospective patient explaining something personal in your website form. Your front desk receives the email and calls them back. From the patient’s point of view, the job is done.
But the form may also have saved those answers in a website dashboard or sent them to a connected app. Does your practice know who can open each copy? Could the person who used to manage the website still see them? That uncertainty is the problem this review is meant to resolve.
Follow one submission before buying another form tool.
Use invented answers to trace your current form. Check where they are stored, what the notification email contains, and which staff or connected services can read them. Several copies are not automatically evidence of a violation; they are several places to understand and manage.
You may find that the existing service is suitable and only its access or notifications need changing. Or clinical intake may belong in the patient portal your team already uses.
A callback request and a clinical intake form ask different things.
Someone asking when you can call does not need the same questionnaire as someone completing intake. Ask only for what staff need to respond, and tell visitors where to share medical details.
Even a short request can reveal a healthcare relationship. Fewer fields help limit collection, but do not make the destination irrelevant. Review the fields and the delivery path together.
What would a clearer setup look like?
One possible arrangement is a website button that opens the practice’s chosen intake service. Staff review the completed form there. An email alert says a submission is ready without repeating the answers.
For protected health information, the appropriate business associate agreements and safeguards still matter. A BAA sets responsibilities between the parties; it does not configure access or decide how long records stay. Those decisions belong in the actual setup.
Moving the form does not move yesterday’s submissions.
A new button changes what happens next. It does not transfer old entries, attachments, or copies in an inbox. Before retiring the old tool, decide what must be retained, who checks completeness, and where staff will find it.
A useful form review ends with named destinations and account owners, rather than just another subscription.
Your next steps
- 1
Find every form
Include landing pages, pop-ups, booking pages, and old campaign links.
- 2
Trace the copies
Check the dashboard, email notifications, integrations, logs, and backups using invented test data.
- 3
Choose the destination
Confirm the agreements and safeguards for the selected service before patient information moves.
- 4
Test and retire
Check access and delivery, compare records, then retire the old form according to the retention plan.
A form review you can hand to your team
| Question | What to record |
|---|---|
| Where do answers land? | Named system and account owner |
| Who can read them? | Staff roles and integrations |
| What appears in alerts? | Prefer a generic “new submission” notice |
| How long are copies kept? | Approved retention and backup policy |
Use invented test information. Do not paste real submissions into an audit request.
Before you decide
What does a BAA actually cover?
A business associate agreement (BAA) sets responsibilities for handling protected health information. It does not make a workflow compliant by itself. Review every service that receives, transmits, or stores that information, including integrations, logs, and backups. The practice and its service providers each have responsibilities.
Do we have to replace FormDr or Jotform?
You may be able to keep the service your team already knows. The useful question is whether the account, agreement, settings, and connected apps fit the information you collect. Replacing a tool before checking those things can create extra work without resolving the underlying problem.
We would review the current setup first. If a clearer website link, tighter access, or a change to notifications is enough, that can become the scope of the work. A full replacement makes sense when the existing workflow cannot meet the agreed requirements.
Should old entries be deleted immediately?
Keep the old records available until the practice has confirmed what must be retained and that the new destination contains the required information. An export can look successful while missing attachments or other parts staff need later.
The transition plan should say who checks completeness, where retained records live, and when old copies can be removed. We can help coordinate those checks; deletion then follows the practice-approved schedule and the vendor’s retention limits.
Sources & further reading
- HHS: cloud services, business associates, and risk analysis
- FormDr: features and included BAA
- Jotform: receiving a BAA for a HIPAA-enabled account
Vendor features and terms can change. Confirm the requirements for your account before making a change.