The HIPAA-compliant form builder built for lead gen.
SOC 2 Type II certified. HIPAA compliance with signed BAA on Pro and above. GDPR, PIPEDA, and TCPA ready. AES-256 encryption, TLS 1.3, and US data residency — not as add-ons. As defaults.
HIPAA-compliant form builder with signed BAA.
When your lead gen forms ask about health conditions, current coverage, prescriptions, or any Protected Health Information, HIPAA compliance is required — not optional. MakeForms is purpose-built for healthcare lead gen with the technical and administrative safeguards HIPAA mandates.
TCPA compliance with TrustedForm on every submission.
The Telephone Consumer Protection Act requires written prior express consent before making telemarketing calls. $1,500 minimum fine per unconsented call. For lead gen agencies running outbound campaigns, every call to a form-generated lead needs a defensible consent record. MakeForms generates that record automatically.
SOC 2 Type II certified — independently audited annually.
SOC 2 Type II is a third-party audit of MakeForms' security controls over a sustained period — not a point-in-time snapshot. It covers security, availability, and confidentiality. The audit is conducted annually by an independent CPA firm.
EU and Canadian data compliance built in.
MakeForms supports data residency in the EU (Frankfurt) and Canada (Montreal) for customers subject to GDPR or PIPEDA. Select your data region during onboarding. Data never leaves your selected region.
Security built into the infrastructure.
Not bolt-on compliance. MakeForms was built HIPAA-first with security controls at every layer of the stack.
AES-256 at rest
All data encrypted at rest using AES-256. Tenant-isolated keys — your account's data uses encryption keys that are unique to your tenant, not shared across customers.
TLS 1.3 in transit
All data in transit encrypted with TLS 1.3. TLS 1.0 and 1.1 disabled. Certificate pinning on all API endpoints. HSTS enforced on all domains.
Zero-trust access
MakeForms employees access production systems only through MFA-enforced VPN with just-in-time provisioning. No persistent access to customer data. Access requests logged and audited.
AWS with VPC isolation
All infrastructure runs on AWS inside isolated Virtual Private Clouds. No shared compute between tenants. Security groups enforced at the instance level.
99.9% uptime SLA
Multi-AZ deployment. Automated failover. Daily backups with 30-day retention. Point-in-time recovery available on Enterprise.
Pen testing + CVE monitoring
Annual third-party penetration tests. CVE monitoring on all dependencies. Security patches deployed within 24 hours of CVE publication for critical vulnerabilities.
Immutable audit logs
All access to PHI fields, form exports, and admin actions logged immutably. Logs retained 12 months. CloudTrail enabled across all AWS accounts.
Secure SDLC
SAST scanning on every pull request. Dependency vulnerability scanning in CI/CD pipeline. Code review required before production deployments. No direct production pushes.
Ready to review the BAA?
The MakeForms Business Associate Agreement uses standard HHS-aligned terms. Most compliance teams approve it the same day. Available on Pro and above. Request it during onboarding or contact your account manager.
Common questions
Does MakeForms sign a HIPAA Business Associate Agreement?
Is MakeForms SOC 2 Type II certified?
Where is my data stored?
How does MakeForms handle TrustedForm for TCPA compliance?
Does MakeForms share my data with third parties?
Is the MakeForms security documentation available?
Built for compliance-first lead gen. Ready when your legal team is.
Book a 15-minute compliance demo. We'll walk through the BAA, PHI field setup, TrustedForm configuration, and data residency options. Bring your compliance officer.