Soli
Compliance Guide

Using Google Forms for patient intake

A candid, step-by-step look at what it takes to use Google Forms under HIPAA — and the structural gaps that remain for therapy practices.

Small practices gravitate to Google Forms because it is free, familiar, and fast. The honest answer to “Is it HIPAA compliant?” is: it canbe part of a compliant workflow, but only after meaningful configuration work — and structural gaps remain even then. This guide spells out each step and is direct about where Google Forms falls short for therapy intake.

A BAA is necessary, not sufficient

Google does offer a Business Associate Addendum (BAA), and Google Forms iscovered under it — listed as part of Google Drive in Google's “HIPAA Included Functionality” alongside Docs, Sheets, and Slides. Older articles sometimes claim Forms is excluded; the current position is that it is covered as part of Drive on an eligible paid plan with an accepted BAA.

Signing the BAA, however, does notmake your setup compliant. A BAA is a legal contract that assigns responsibility — it configures nothing and adds none of the access controls, audit trails, or safeguards the Security Rule demands. Compliance requires an eligible plan, an accepted BAA, correct configuration, and your own administrative and physical safeguards (policies, training, risk analysis, access reviews). Drop any layer and you are exposed, BAA or not. Misconfigured forms remain one of the most frequent causes of HIPAA violations.

Step-by-step: getting Google Forms HIPAA-ready

1

Get on an eligible paid Google Workspace plan

Free @gmail.com accounts have no BAA and can never be HIPAA compliant. You need paid Google Workspace. Business Starter and Business Standard can technically sign the BAA but lack Vault, advanced security, and retention controls. Business Plus or Enterprise is the realistic floor for a defensible setup because those tiers add Vault for retention and eDiscovery, stronger endpoint management, and Data Loss Prevention.

2

Accept the BAA in the Admin console

Sign in as a super administrator, then navigate to Admin console → Account → Account settings → Legal and compliance → Security and Privacy Additional Terms. Open the Google Workspace/Cloud Identity HIPAA Business Associate Amendment, click Review and Accept, answer the three covered-entity questions, and confirm. Screenshot the acceptance screen for your compliance files — electronic acceptance is as legally binding as a signed paper copy.

3

Lock down organization-wide sharing

In the Admin console, restrict Drive external sharing so response spreadsheets stay inside your organization and disable "anyone with the link" sharing for the org unit that handles intake.

4

Build the form with "minimum necessary" in mind

Collect only the PHI you actually need. Avoid open-ended free-text fields that invite over-disclosure and confirm responses flow exclusively into your controlled Workspace environment.

5

Control where responses land — and who sees them

Route responses to a single, access-controlled Google Sheet. The core limitation: anyone with editor access sees every response. There is no per-field or per-record role separation. Share the sheet only with the smallest group of named staff who have a documented need to access intake data.

6

Keep notifications and receipts internal

Turn off response receipts to respondents and any notification that emails response data to personal or external addresses. Emailed response summaries are a classic uncontrolled PHI disclosure.

7

Disable risky add-ons

Third-party Forms and Sheets add-ons fall outside Google’s BAA. Restrict Marketplace add-on installation across the organization and remove any add-on that touches response data.

8

Turn on Data Loss Prevention

On Business Standard and above, set up DLP rules under Security → Data protection to detect and flag PHI patterns exiting your environment.

9

Set retention and recovery

With Vault (Business Plus and Enterprise), define retention rules and legal holds on response data. Document your data lifecycle so it holds up in an audit.

10

Do the non-technical HIPAA work

A BAA and proper configuration do not substitute for a documented risk analysis, written policies, workforce training, periodic access reviews, and a breach response plan. Those administrative and physical safeguards are your responsibility, not Google’s.

Where Google Forms still falls short

Even fully configured, Google Forms was not designed for clinical intake. Consider the residual risk you are accepting:

No per-response audit trail. Workspace logs file-level access, not which staff member viewed a specific intake record. That gap is material in an OCR audit.

No role-based or minimum-necessary enforcement. Editor access exposes all responses. You cannot scope visibility by sensitivity or by patient.

No field-level encryption. Google can technically access the data. This is not zero-knowledge; you are relying on their controls and your own configuration.

No built-in consent capture or identity-bound e-signatures. Clinical intake and consent workflows require more than a checkbox to withstand scrutiny.

Receipts and add-ons leak easily. The default conveniences are the same features that cause uncontrolled disclosures.

None of this makes Google Forms unusable. It means you carry real residual risk and own the full configuration and oversight burden.

The honest comparison

Every step above, side by side with what the same task looks like on a platform built for mental health intake.

Step to handle therapy intakeGoogle FormsSoli Forms
Choose / upgrade to an eligible paid planRequired (Business Plus or Enterprise realistically)Not needed — purpose-built for healthcare
Locate and accept a BAAManual via super-admin in Admin consoleIncluded on every paid plan
Configure org-wide sharing restrictionsManual admin workOn by default
Restrict who can see responsesNot possible per-record — all or nothingRole-based access built in
Prevent receipts / notifications leaking PHIManualEncrypted by design
Disable non-covered add-onsManual admin workNot applicable
Per-response audit trailNot availableBuilt in
Field-level / zero-knowledge encryptionNot availableDefault — encrypted on device
Consent capture & identity-bound e-signaturesBuild it yourselfBuilt in
Retention / eDiscoveryHigher plan tier + manual setupBuilt in
Your own policies, training, risk analysisStill requiredStill required

Bottom line

Google Forms can be one piece of a compliant workflow if you follow every step above and accept its structural limits. Soli Formseliminates most of that checklist because it was purpose-built for mental health intake — encrypted on device, role-aware, audit-logged, with a BAA on every paid plan.

This article is educational and is not legal advice. Consult a qualified HIPAA professional about your specific practice before relying on any tool to handle protected health information.