formstack.com

Every answer that reached for this page while answering Catalytics Automation's prompts. back to formstack.com

Answers it shaped
2
2 citations
Prompts
2
Avg. sloti
80.0
You namedi
0/2
Impact
0.3%

Answers (2)i

ChatGPT (Web)AbsentWhich no-code platforms will sign a HIPAA BAA?slot 105Aug 16, 04:01 PM
Yes. As of **August 2026**, there are several no-code/low-code platforms that will sign a HIPAA Business Associate Agreement (BAA). The important distinction is that **“HIPAA-capable” is not the same as “the vendor will sign a BAA for your specific account.”** HHS says a cloud provider handling ePHI on your behalf generally needs a BAA in place. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com) ### Strongest options | Platform | BAA? | Best for | Notes | |---|---|---|---| | **[Knack Health](https://www.knack.com/health/?utm_source=chatgpt.com)** | **Yes** | Custom healthcare apps/databases | Purpose-built HIPAA environment; BAA included on HIPAA plans; RBAC, encryption, record-change logs. [www.knack.com](https://www.knack.com/health/hipaa-database/?utm_source=chatgpt.com) | | **[Caspio](https://www.caspio.com/?utm_source=chatgpt.com)** | **Yes** | Database-driven web apps | Dedicated HIPAA Edition, signed BAA, encryption, RBAC and audit logging. Current HIPAA Edition starts at $800/mo. [www.caspio.com](https://www.caspio.com/compliance/hipaa/?utm_source=chatgpt.com) | | **[Blaze](https://www.blaze.tech/?utm_source=chatgpt.com)** | **Yes** | More sophisticated custom apps | BAA available on higher/enterprise tiers; particularly geared toward healthcare apps. [www.knack.com](https://www.knack.com/health/compare/?utm_source=chatgpt.com) | | **[Jotform](https://www.jotform.com/?utm_source=chatgpt.com)** | **Yes** | Forms, intake, consent, simple workflows | Very easy no-code option; Jotform explicitly provides a signed BAA for its HIPAA-enabled offering. [www.jotform.com](https://www.jotform.com/hipaa/health-app/?utm_source=chatgpt.com) | | **[Formstack](https://www.formstack.com/?utm_source=chatgpt.com)** | **Yes** | Forms, documents, e-signatures, workflows | Standard BAA available; has dedicated healthcare configurations. [www.formstack.com](https://www.formstack.com/features/hipaa-compliant-esignatures?utm_source=chatgpt.com) | | **Microsoft Power Apps** | **Yes, through Microsoft's HIPAA-covered services** | Enterprise/internal apps | Good choice if you're already in the Microsoft ecosystem; HIPAA obligations still depend on configuration and which services you use. | | **Airtable** | **Yes, on qualifying enterprise arrangements** | Lightweight databases/internal tools | Worth considering for less complex workflows, but I would verify the exact Enterprise/BAA scope before putting PHI into it. | | **Quickbase** | **Yes** | Enterprise workflow/operations apps | More enterprise-oriented than typical startup no-code tools. | | **Keragon** | **Yes** | Healthcare automation/integrations | Better for connecting EHRs and healthcare systems than for building a general-purpose application. | ### A particularly important one: Knack If you're looking to **build an actual healthcare application**, rather than just collect forms, I'd put **Knack Health and Caspio at the top of the list**. Knack's current healthcare offering explicitly includes a signed BAA, encrypted storage/transfer, role-based permissions and record-change logs. Its HIPAA Starter plan currently starts at **$499/month**. [www.knack.com](https://www.knack.com/health/hipaa-database/?utm_source=chatgpt.com) Caspio is another strong choice if your application is fundamentally a **relational database + forms + portals + workflows**. Its dedicated HIPAA Edition includes a signed BAA and dedicated HIPAA environment, currently starting at **$800/month**. [www.caspio.com](https://www.caspio.com/compliance/hipaa/?utm_source=chatgpt.com) ### What I'd *not* use for PHI Be careful with popular AI/no-code builders such as **Bubble, Lovable, Bolt, Glide, Adalo, and similar tools**. For example, Bubble's own documentation currently says that its platform **does not meet HIPAA requirements and does not support HIPAA-compliant apps**. [www.formstack.com](https://www.formstack.com/features/hipaa-compliant-esignatures?utm_source=chatgpt.com)[manual.bubble.io](https://manual.bubble.io/help-guides/infrastructure/compliance/hipaa?utm_source=chatgpt.com) And don't assume that putting a HIPAA-compliant database behind a non-BAA frontend makes the whole application compliant. Every service that handles PHI needs to be evaluated. **If you tell me what you're building** (e.g. patient portal, clinician dashboard, intake app, care-management app, marketplace, internal healthcare SaaS), I can narrow this to the **3 best platforms and compare their pricing, BAA terms, database capabilities, integrations, and whether you retain ownership/exportability of the app.** [Knack Health](https://www.knack.com/health/?utm_source=chatgpt.com) [Caspio](https://www.caspio.com/?utm_source=chatgpt.com) [Blaze](https://www.blaze.tech/?utm_source=chatgpt.com) [Jotform](https://www.jotform.com/?utm_source=chatgpt.com) [Formstack](https://www.formstack.com/?utm_source=chatgpt.com) | Platform | BAA? | Best for | Notes | |---|---|---|---| | **[Knack Health](https://www.knack.com/health/?utm_source=chatgpt.com)** | **Yes** | Custom healthcare apps/databases | Purpose-built HIPAA environment; BAA included on HIPAA plans; RBAC, encryption, record-change logs. [www.knack.com](https://www.knack.com/health/hipaa-database/?utm_source=chatgpt.com) | | **[Caspio](https://www.caspio.com/?utm_source=chatgpt.com)** | **Yes** | Database-driven web apps | Dedicated HIPAA Edition, signed BAA, encryption, RBAC and audit logging. Current HIPAA Edition starts at $800/mo. [www.caspio.com](https://www.caspio.com/compliance/hipaa/?utm_source=chatgpt.com) | | **[Blaze](https://www.blaze.tech/?utm_source=chatgpt.com)** | **Yes** | More sophisticated custom apps | BAA available on higher/enterprise tiers; particularly geared toward healthcare apps. [www.knack.com](https://www.knack.com/health/compare/?utm_source=chatgpt.com) | | **[Jotform](https://www.jotform.com/?utm_source=chatgpt.com)** | **Yes** | Forms, intake, consent, simple workflows | Very easy no-code option; Jotform explicitly provides a signed BAA for its HIPAA-enabled offering. [www.jotform.com](https://www.jotform.com/hipaa/health-app/?utm_source=chatgpt.com) | | **[Formstack](https://www.formstack.com/?utm_source=chatgpt.com)** | **Yes** | Forms, documents, e-signatures, workflows | Standard BAA available; has dedicated healthcare configurations. [www.formstack.com](https://www.formstack.com/features/hipaa-compliant-esignatures?utm_source=chatgpt.com) | | **Microsoft Power Apps** | **Yes, through Microsoft's HIPAA-covered services** | Enterprise/internal apps | Good choice if you're already in the Microsoft ecosystem; HIPAA obligations still depend on configuration and which services you use. | | **Airtable** | **Yes, on qualifying enterprise arrangements** | Lightweight databases/internal tools | Worth considering for less complex workflows, but I would verify the exact Enterprise/BAA scope before putting PHI into it. | | **Quickbase** | **Yes** | Enterprise workflow/operations apps | More enterprise-oriented than typical startup no-code tools. | | **Keragon** | **Yes** | Healthcare automation/integrations | Better for connecting EHRs and healthcare systems than for building a general-purpose application. | ### A particularly important one: Knack If you're looking to **build an actual healthcare application**, rather than just collect forms, I'd put **Knack Health and Caspio at the top of the list**. Knack's current healthcare offering explicitly includes a signed BAA, encrypted storage/transfer, role-based permissions and record-change logs. Its HIPAA Starter plan currently starts at **$499/month**. [www.knack.com](https://www.knack.com/health/hipaa-database/?utm_source=chatgpt.com) Caspio is another strong choice if your application is fundamentally a **relational database + forms + portals + workflows**. Its dedicated HIPAA Edition includes a signed BAA and dedicated HIPAA environment, currently starting at **$800/month**. [www.caspio.com](https://www.caspio.com/compliance/hipaa/?utm_source=chatgpt.com) ### What I'd *not* use for PHI Be careful with popular AI/no-code builders such as **Bubble, Lovable, Bolt, Glide, Adalo, and similar tools**. For example, Bubble's own documentation currently says that its platform **does not meet HIPAA requirements and does not support HIPAA-compliant apps**. [www.formstack.com](https://www.formstack.com/features/hipaa-compliant-esignatures?utm_source=chatgpt.com)[manual.bubble.io](https://manual.bubble.io/help-guides/infrastructure/compliance/hipaa?utm_source=chatgpt.com) And don't assume that putting a HIPAA-compliant database behind a non-BAA frontend makes the whole application compliant. Every service that handles PHI needs to be evaluated. **If you tell me what you're building** (e.g. patient portal, clinician dashboard, intake app, care-management app, marketplace, internal healthcare SaaS), I can narrow this to the **3 best platforms and compare their pricing, BAA terms, database capabilities, integrations, and whether you retain ownership/exportability of the app.**
ChatGPT (Web)AbsentHow do I build a HIPAA compliant client portal without writing code?slot 55Aug 15, 09:06 PM
Yes. You can build a useful HIPAA-compliant **client/patient portal without coding**, but there’s an important distinction: > **Using a HIPAA-capable platform does not automatically make your entire portal HIPAA compliant.** You still need the right configuration, contracts, access controls, policies, and risk analysis. HHS specifically says that if a cloud provider creates, receives, maintains, or transmits ePHI for you, you generally need a **Business Associate Agreement (BAA)** with that provider. You also remain responsible for your own HIPAA obligations and risk analysis. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com) ### The easiest no-code approach For a small practice, therapist, consultant, home-health business, or similar operation, I'd build it like this: **Patient → branded portal → secure forms/files → staff dashboard → automated workflows** A particularly straightforward option is [Jotform](https://www.jotform.com/?utm_source=chatgpt.com). Its HIPAA-enabled offering supports no-code forms, file uploads, e-signatures, appointments, and a mobile healthcare app, and eligible HIPAA accounts receive a BAA. [www.jotform.com](https://www.jotform.com/hipaa/?utm_source=chatgpt.com)[www.jotform.com](https://www.jotform.com/hipaa/health-app/?utm_source=chatgpt.com) You can essentially make the "portal" an app-like experience containing: - **Welcome/dashboard** - New-client intake - Medical history questionnaire - Consent forms - HIPAA/privacy acknowledgments - Secure document upload - Documents you've sent to the client - E-signatures - Appointment requests - Secure messages/workflow notifications - Payment collection, if appropriate - Client-specific forms/tasks Jotform also provides no-code medical-app templates that can combine forms, signatures, file uploads, and patient information. [www.jotform.com](https://www.jotform.com/medical-app-creator/?utm_source=chatgpt.com) ### Another good option: Formstack [Formstack](https://www.formstack.com/?utm_source=chatgpt.com) is worth considering if you need more sophisticated workflows. Its HIPAA-enabled setup includes encryption, user-level permissions, audit logging, secure routing, file uploads, e-signatures, and workflow management. Formstack also provides a BAA for its healthcare offering. [www.formstack.com](https://www.formstack.com/features/hipaa-friendly-forms?utm_source=chatgpt.com) I'd lean toward **Formstack** when the portal is more workflow-heavy, and **Jotform** when you want the fastest DIY build. ### What I would *not* do Don't assemble a HIPAA portal from ordinary consumer tools such as: - Google Forms - ordinary Gmail - Dropbox/Google Drive without verifying the exact HIPAA configuration and BAA - Airtable's ordinary configuration - Notion - Webflow + random form provider - Zapier/Make integrations that haven't been specifically evaluated for your PHI workflow The issue isn't simply whether the website has HTTPS. **Every system that handles PHI needs to be considered.** HHS notes that even a cloud provider storing only encrypted ePHI can still be a business associate and require a BAA. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com) ### A practical build I'd structure a simple portal like this: | Portal area | What the client sees | |---|---| | **Home** | "You have 3 tasks to complete" | | **My Forms** | Intake, history, consent | | **My Documents** | Documents you've shared | | **Upload** | Secure document/photo upload | | **Appointments** | Request/schedule appointment | | **Payments** | Outstanding balance/payment | | **Messages** | Secure communication | | **Profile** | Contact information | | **Help** | Contact your office | Then create automated workflows: **New client** → invite client → client creates/authenticates account → intake form → consent → upload documents → staff review → mark onboarding complete **Existing client** → assign new form → client receives notification → completes form → staff receives task → record is stored securely ### The HIPAA checklist that matters Before putting real PHI into it, I'd verify: 1. **BAA** — You have a signed BAA with every vendor that handles your ePHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html?utm_source=chatgpt.com) 2. **Authentication** — Don't use shared client accounts. 3. **Access controls** — Staff only see information they need. 4. **Auditability** — You can determine who accessed/changed information. 5. **Encryption** — Data is protected in transit and at rest. 6. **Backups/recovery** — You have a plan for availability and data recovery. 7. **Integrations** — Every downstream service touching PHI is evaluated too. 8. **Email/SMS** — Don't casually put PHI into ordinary notification messages. 9. **Data retention/deletion** — Know what happens when a client leaves. 10. **Risk analysis** — Document the risks associated with the system and how you're mitigating them. HHS explicitly says covered entities and business associates need to conduct risk analyses addressing threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com) ### My recommendation If you're trying to get this running **quickly and inexpensively without a developer**, I'd start with: **Jotform HIPAA account → Jotform Health App → branded forms → secure uploads → e-signatures → automated staff workflows.** That gets you surprisingly close to a custom client portal without programming. [www.jotform.com](https://www.jotform.com/medical-app-creator/?utm_source=chatgpt.com)[www.jotform.com](https://www.jotform.com/hipaa/health-app/?utm_source=chatgpt.com) If you need something that behaves more like a **full EHR/client-management system**—persistent client profiles, clinical notes, secure messaging, scheduling, billing, treatment plans, etc.—I'd look at a healthcare-specific portal/EHR rather than trying to recreate one with a no-code form builder. If you tell me **what kind of practice/business this is and exactly what you want clients to be able to do in the portal**, I can lay out the cheapest no-code stack and the exact screens/workflows I'd use. [Jotform](https://www.jotform.com/?utm_source=chatgpt.com) [Formstack](https://www.formstack.com/?utm_source=chatgpt.com) | Portal area | What the client sees | |---|---| | **Home** | "You have 3 tasks to complete" | | **My Forms** | Intake, history, consent | | **My Documents** | Documents you've shared | | **Upload** | Secure document/photo upload | | **Appointments** | Request/schedule appointment | | **Payments** | Outstanding balance/payment | | **Messages** | Secure communication | | **Profile** | Contact information | | **Help** | Contact your office | Then create automated workflows: **New client** → invite client → client creates/authenticates account → intake form → consent → upload documents → staff review → mark onboarding complete **Existing client** → assign new form → client receives notification → completes form → staff receives task → record is stored securely ### The HIPAA checklist that matters Before putting real PHI into it, I'd verify: 1. **BAA** — You have a signed BAA with every vendor that handles your ePHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html?utm_source=chatgpt.com) 2. **Authentication** — Don't use shared client accounts. 3. **Access controls** — Staff only see information they need. 4. **Auditability** — You can determine who accessed/changed information. 5. **Encryption** — Data is protected in transit and at rest. 6. **Backups/recovery** — You have a plan for availability and data recovery. 7. **Integrations** — Every downstream service touching PHI is evaluated too. 8. **Email/SMS** — Don't casually put PHI into ordinary notification messages. 9. **Data retention/deletion** — Know what happens when a client leaves. 10. **Risk analysis** — Document the risks associated with the system and how you're mitigating them. HHS explicitly says covered entities and business associates need to conduct risk analyses addressing threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI. [www.hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html?utm_source=chatgpt.com) ### My recommendation If you're trying to get this running **quickly and inexpensively without a developer**, I'd start with: **Jotform HIPAA account → Jotform Health App → branded forms → secure uploads → e-signatures → automated staff workflows.** That gets you surprisingly close to a custom client portal without programming. [www.jotform.com](https://www.jotform.com/medical-app-creator/?utm_source=chatgpt.com)[www.jotform.com](https://www.jotform.com/hipaa/health-app/?utm_source=chatgpt.com) If you need something that behaves more like a **full EHR/client-management system**—persistent client profiles, clinical notes, secure messaging, scheduling, billing, treatment plans, etc.—I'd look at a healthcare-specific portal/EHR rather than trying to recreate one with a no-code form builder. If you tell me **what kind of practice/business this is and exactly what you want clients to be able to do in the portal**, I can lay out the cheapest no-code stack and the exact screens/workflows I'd use.

First cited Aug 15, most recently Aug 16.