Using Google Forms for patient intake
A candid, step-by-step look at what it takes to use Google Forms under HIPAA — and the structural gaps that remain for therapy practices.Small practices gravitate to Google Forms because it is free, familiar, and fast. The honest answer to “Is it HIPAA compliant?” is: it canbe part of a compliant workflow, but only after meaningful configuration work — and structural gaps remain even then. This guide spells out each step and is direct about where Google Forms falls short for therapy intake.
A BAA is necessary, not sufficient
Google does offer a Business Associate Addendum (BAA), and Google Forms iscovered under it — listed as part of Google Drive in Google's “HIPAA Included Functionality” alongside Docs, Sheets, and Slides. Older articles sometimes claim Forms is excluded; the current position is that it is covered as part of Drive on an eligible paid plan with an accepted BAA.
Signing the BAA, however, does notmake your setup compliant. A BAA is a legal contract that assigns responsibility — it configures nothing and adds none of the access controls, audit trails, or safeguards the Security Rule demands. Compliance requires an eligible plan, an accepted BAA, correct configuration, and your own administrative and physical safeguards (policies, training, risk analysis, access reviews). Drop any layer and you are exposed, BAA or not. Misconfigured forms remain one of the most frequent causes of HIPAA violations.
Step-by-step: getting Google Forms HIPAA-ready
Get on an eligible paid Google Workspace plan
Free @gmail.com accounts have no BAA and can never be HIPAA compliant. You need paid Google Workspace. Business Starter and Business Standard can technically sign the BAA but lack Vault, advanced security, and retention controls. Business Plus or Enterprise is the realistic floor for a defensible setup because those tiers add Vault for retention and eDiscovery, stronger endpoint management, and Data Loss Prevention.
Accept the BAA in the Admin console
Sign in as a super administrator, then navigate to Admin console → Account → Account settings → Legal and compliance → Security and Privacy Additional Terms. Open the Google Workspace/Cloud Identity HIPAA Business Associate Amendment, click Review and Accept, answer the three covered-entity questions, and confirm. Screenshot the acceptance screen for your compliance files — electronic acceptance is as legally binding as a signed paper copy.
Lock down organization-wide sharing
In the Admin console, restrict Drive external sharing so response spreadsheets stay inside your organization and disable "anyone with the link" sharing for the org unit that handles intake.
Build the form with "minimum necessary" in mind
Collect only the PHI you actually need. Avoid open-ended free-text fields that invite over-disclosure and confirm responses flow exclusively into your controlled Workspace environment.
Control where responses land — and who sees them
Route responses to a single, access-controlled Google Sheet. The core limitation: anyone with editor access sees every response. There is no per-field or per-record role separation. Share the sheet only with the smallest group of named staff who have a documented need to access intake data.
Keep notifications and receipts internal
Turn off response receipts to respondents and any notification that emails response data to personal or external addresses. Emailed response summaries are a classic uncontrolled PHI disclosure.
Disable risky add-ons
Third-party Forms and Sheets add-ons fall outside Google’s BAA. Restrict Marketplace add-on installation across the organization and remove any add-on that touches response data.
Turn on Data Loss Prevention
On Business Standard and above, set up DLP rules under Security → Data protection to detect and flag PHI patterns exiting your environment.
Set retention and recovery
With Vault (Business Plus and Enterprise), define retention rules and legal holds on response data. Document your data lifecycle so it holds up in an audit.
Do the non-technical HIPAA work
A BAA and proper configuration do not substitute for a documented risk analysis, written policies, workforce training, periodic access reviews, and a breach response plan. Those administrative and physical safeguards are your responsibility, not Google’s.
Where Google Forms still falls short
Even fully configured, Google Forms was not designed for clinical intake. Consider the residual risk you are accepting:
No per-response audit trail. Workspace logs file-level access, not which staff member viewed a specific intake record. That gap is material in an OCR audit.
No role-based or minimum-necessary enforcement. Editor access exposes all responses. You cannot scope visibility by sensitivity or by patient.
No field-level encryption. Google can technically access the data. This is not zero-knowledge; you are relying on their controls and your own configuration.
No built-in consent capture or identity-bound e-signatures. Clinical intake and consent workflows require more than a checkbox to withstand scrutiny.
Receipts and add-ons leak easily. The default conveniences are the same features that cause uncontrolled disclosures.
None of this makes Google Forms unusable. It means you carry real residual risk and own the full configuration and oversight burden.
The honest comparison
Every step above, side by side with what the same task looks like on a platform built for mental health intake.
| Step to handle therapy intake | Google Forms | Soli Forms |
|---|---|---|
| Choose / upgrade to an eligible paid plan | Required (Business Plus or Enterprise realistically) | Not needed — purpose-built for healthcare |
| Locate and accept a BAA | Manual via super-admin in Admin console | Included on every paid plan |
| Configure org-wide sharing restrictions | Manual admin work | On by default |
| Restrict who can see responses | Not possible per-record — all or nothing | Role-based access built in |
| Prevent receipts / notifications leaking PHI | Manual | Encrypted by design |
| Disable non-covered add-ons | Manual admin work | Not applicable |
| Per-response audit trail | Not available | Built in |
| Field-level / zero-knowledge encryption | Not available | Default — encrypted on device |
| Consent capture & identity-bound e-signatures | Build it yourself | Built in |
| Retention / eDiscovery | Higher plan tier + manual setup | Built in |
| Your own policies, training, risk analysis | Still required | Still required |
Bottom line
Google Forms can be one piece of a compliant workflow if you follow every step above and accept its structural limits. Soli Formseliminates most of that checklist because it was purpose-built for mental health intake — encrypted on device, role-aware, audit-logged, with a BAA on every paid plan.
This article is educational and is not legal advice. Consult a qualified HIPAA professional about your specific practice before relying on any tool to handle protected health information.