HIPAA-Compliant Intake Forms: When Your Practice Needs a BAA
Does HIPAA apply to your med spa or salon? What the Security Rule requires of intake forms, what a Business Associate Agreement covers, and how to evaluate form vendors.
Somewhere between "we should go digital" and "which app should we use," every med spa or clinic owner hits the same question: does this need to be HIPAA compliant? The honest answer is more useful than the scary one — HIPAA applies to some beauty and wellness businesses and not others, the rules for intake forms are concrete rather than mystical, and the single clearest signal a software vendor takes any of it seriously is whether they will sign a Business Associate Agreement.
Here's how to work out where you stand, what HIPAA actually requires of your intake forms, and what a BAA does.
Does HIPAA even apply to your practice?
HIPAA covers two groups: covered entities — healthcare providers who transmit health information electronically for insurance billing, plus health plans and clearinghouses — and their business associates, the vendors who handle patient data on their behalf.
In practice, for the beauty and wellness world:
- Med spas with a medical director, nurse injectors, or any medical treatments are usually in scope — and should operate as if they are even in edge cases. Neurotoxin injections, filler, IV therapy, and prescription-strength treatments are medical services, and the client records behind them look exactly like protected health information (PHI).
- Chiropractors, medical estheticians working under a provider, and any practice billing insurance are almost always covered entities.
- Independent lash techs, tattoo artists, hair stylists, and spray tan studios are generally not covered entities. HIPAA likely doesn't bind them — but state privacy laws do, clients expect medical-grade care for health disclosures anyway, and the intake form asking about allergies, medications, and skin conditions deserves the same protection whether or not a federal statute technically requires it.
The pragmatic rule most attorneys give: if your intake form asks health questions, handle it like PHI. Compliance you don't strictly need is a selling point; compliance you needed and skipped is an incident.
What HIPAA requires of intake forms and client records
HIPAA's Security Rule doesn't name specific products — it names safeguards. Applied to consent and intake forms, the ones that matter:
- Encryption in transit and at rest. The form travels from the client's phone to storage over an encrypted connection (TLS), and sits encrypted on disk (AES-256 is the standard worth asking for by name).
- Access controls. Staff see client records only after authenticating, ideally with per-employee accounts — so you can tell who accessed what, and shut off one person's access without changing everyone's password.
- Audit trails. A record of who created, viewed, or changed a record, and when. For consent forms specifically, an immutable log — one that shows a signature hasn't been altered since signing — is the difference between a defensible record and a PDF someone could have edited.
- Retention and disposal. Records kept as long as your state requires (often six or more years for medical records), and actually deletable when the retention period ends.
- Minimum necessary. Collect what the treatment requires, not everything you can think of. A leaner intake form is both better UX and better compliance.
Notice what's not on the list: paper. Ironically, the filing cabinet fails several of these tests — no access log, no encryption, no way to prove a page wasn't swapped. A well-built digital system isn't a compliance risk compared to paper; it's the fix.
What a BAA is, and why vendors dodge it
A Business Associate Agreement is a contract in which a vendor that touches PHI on your behalf — your forms app, your cloud storage, your email provider if records flow through it — commits to HIPAA's safeguards, breach notification duties, and liability. If you're a covered entity, using a vendor to store patient intake forms without a BAA is itself a HIPAA violation, no breach required.
This is where general-purpose form builders quietly fall down. Many popular tools either refuse to sign BAAs, reserve them for enterprise tiers at several times the price, or sign one but still route your data through analytics and marketing trackers. When you evaluate any forms vendor, the questions are short:
- Will you sign a BAA, and on which plan?
- Where is the data stored, and is it encrypted at rest?
- Is there an audit trail on signatures and record changes?
- Do third-party trackers or SDKs see client data?
- Can I export or delete records to meet retention rules?
A vendor who answers those five plainly is rare enough to shortlist.
How Consentify handles it
Consentify was built for exactly this gap — practices that need medical-grade record handling without hospital-chain software. Client submissions are encrypted with AES-256 at rest and TLS in transit; encryption keys on the device live in hardware (the iPhone/iPad Secure Enclave). Every signature and later amendment lands in a tamper-proof, timestamped audit trail. There are no third-party analytics or ad SDKs in the app — client data isn't shared with trackers, period. The full detail is on the security page.
A BAA is included on the Elite and Empire plans and signed electronically right in the app — no enterprise sales call, no paperwork round-trip. For practices below that tier, or outside HIPAA's scope entirely, the same encryption and audit protections apply to every plan including the free one; the BAA is the contractual layer on top. See pricing for the current plan lineup.
And because compliance is only real if the forms get used, the client experience stays simple: clients sign on their own phone via QR code or link — no app, no account — or on the practice iPad at the front desk, with legally binding e-signatures under the ESIGN Act.
FAQ
I'm a solo esthetician. Do I need HIPAA-compliant forms?
If you don't bill insurance and aren't working under a medical provider, you're likely not a HIPAA covered entity. But your intake forms still collect sensitive health information covered by state privacy and consumer-protection laws — and clients don't grade on jurisdiction. Using a system with encryption and access controls costs you nothing extra and removes the question entirely.
Is emailing a filled-out intake form HIPAA compliant?
Standard email is not encrypted end-to-end and is one of the most common sources of HIPAA complaints. The safer pattern is the one modern form tools use: the client fills the form in a secure browser session, the record lands directly in encrypted storage, and email carries at most a link or a confirmation — not the health data itself.
Does signing a BAA make my practice HIPAA compliant?
No. A BAA covers the vendor's side. Your practice is still responsible for its own safeguards — training staff, controlling who has access, using device passcodes, and having basic policies. A good vendor shrinks the checklist; it doesn't finish it.
How long do I need to keep signed consent forms?
HIPAA requires six years for compliance documentation, and state medical-record laws often require six to ten years for treatment records (longer for minors). Check your state's rule, and make sure your forms system can actually retain — and then delete — records on that schedule.
This article is general information for practice owners, not legal advice. For decisions about your specific obligations, talk to a healthcare attorney in your state.