Does Gravity Forms enable HIPAA compliance?

Gravity Forms, a widely used WordPress plug-in designed to create online forms, has stated that it can be HIPAA-compliant, but it does not come pre-configured with HIPAA compliance features. Instead, it offers functionalities that can be used to develop forms that adhere to HIPAA standards, as long as users take specific precautions and comply with essential security protocols.


According to Gravity Forms, data collected through its plug-in is stored in tables within the user's WordPress database, which is hosted by the user’s chosen hosting provider. Gravity Forms then uses the existing infrastructure provided by WordPress to ensure that the collected data is securely stored within the user’s database environment. This approach ensures that the data remains under the user’s control and within the parameters of their selected hosting provider. 


Keep in mind that Gravity Forms states, “By default, [t]he data collected by Gravity Forms is not encrypted during storage. If required, encryption of data at rest would need to be provided by an add-on or the custom code.” Because Gravity Forms has stated that it does not host or store collected form data on your behalf and that it does not sign Business Associate Agreements, you must do this with your website host or data services provider.

Product details

Company Logo

Product description

Gravity Forms is a WordPress plug-in that lets you create forms to place on your website.

This web page was updated on November 01, 2023.

Disclaimer:

Readers should perform their own research before making the final decision. The information on the Jform HIPAA Compliance Checker does not constitute official healthcare or legal advice. Jform is not liable for any damage or liabilities arising out of or connected in any manner with this platform.

만약 귀하가 틀리거나 불완전하고 부정확한 정보를 보면 아래의 폼을 작성하는 것으로 수정을 요청하십시오.

Request Correction
JForm 엔터프라이즈

Jform 엔터프라이즈로 전문적인 솔루션을 가지세요

Jform 엔터프라이즈가 어떻게 귀하의 조직에 혜택을 주는지 알아보세요. 쉽게 자동화하고 협업하거나 조정하십시오.