WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: codemonkeys-hipaa-forms (Used by 724 domains)

HIPAA FORMS – Add HIPAA Compliant Webforms to Your WordPress Website

👤 codemonkeys 📦 v3.2.0 🔗 Plugin Homepage

The HIPAA FORMS plugin allows you to create web forms using Caldera Forms or Gravity Forms just like you would a simple contact form. A simple checkbox next to the form within the plugin admin interface instantly takes over your form, appends the form with a HIPAA Compliant badge and signature field where users can sign by dragging their mouse or with their finger on touch screens, and upon submit encrypts the data and pushes it to the HIPAA FORMS Service API which then stores it within a HIPAA Compliant storage solution.

Users with login credentials and the appropriate user roles (administrator or hipaa) can then log into your WordPress administrator dashboard and search/view the submitted forms and even generate an encrypted and password protected PDF file of the form which can then be printed or saved to a hard drive.

Here’s how the HIPAA FORMS Service and integrated WordPress plugin secures the protected health information of your forms:
1. On submit the entire form is encrypted requiring 2 separate keys to decrypt.
2. Once the form data is encrypted it sends the encrypted data to the HIPAA FORMS Service API where it remains encrypted on a HIPAA Compliant storage solution.
3. When someone with login credentials logs into your WordPress administrator dashboard with either and administrator or hipaa user role that user can then go to the HIPAA FORMS plugin interface and view the forms that have been submitted. While you can view the decrypted forms here the data never actually leaves the HIPAA FORMS Service servers, you’re simply pulling them from the api, decrypting and viewing in your browser, the data never actually touches your hosting server.
4. The only way the data can leave the HIPAA FORMS Service servers is if you click the “generate pdf” button and create an encrypted password protected pdf file. At this point you can print or save the pdf to your hard drive but since the pdf remains encrypted and password protected the form data remains safe in transit.
5. Once you close the pdf generation window the pdf file is then destroyed on the HIPAA FORMS Service server removing any chance of a bad actor gaining access to the file.
6. Each time a user accesses the HIPAA FORMS plugin admin interface a log entry is created and stored on the HIPAA FORMS Service which you can review at any time from the HIPAA FORMS plugin interface. This is required by HIPAA Regulations to ensure any potential data breach can be back-traced.
7. Since the form data is encrypted and remains on the HIPAA FORMS Service database we ensure that protected data can not be tampered with and changed by anyone.
8. Both a SSL certificate and a BAA agreement between the user and Code Monkeys LLC (the company that developed and maintains the HIPAA FORMS Service and WordPress plugin) is required. The ability to submit or view forms is disabled until both of these requirements have been met.

NEW IN V1.5.5:
Version 1.5.5 is our first “major” update to the plugin since releasing it. This update includes an improved user interface and the following specific form settings:
1. Option to show/hide the signature field
2. Option to specify a success message or a redirect url after a form is submitted
3. Option to set who can see the submitted forms with the following options:
A. All users with admin/hipaa user role
B. Only specific users
C. Only a specific doctor/user selected within a form (ie. Patient selects a specific doctor in a form, only that doctor will see the submitted form). NOTE: Admins see all forms regardless of settings.

While we believe we’ve made the entire process as simple as possible we also understand that there may be questions or issues sometimes that the user needs addressed. Given the urgency and importance of a service such as this we’ve built a complete support ticket system directly into the HIPAA FORMS WordPress plugin interface to allow the users to submit and track support tickets without ever needing to leave their own administrator dashboard. The HIPAA FORMS Service team at Code Monkeys LLC strives to respond to tickets within 1 business day. Users can also call Code Monkeys LLC directly for support between 9am and 5pm CST.

NOTE: A subscription-based license key to access the HIPAA FORMS Service API is required from https://www.hipaaforms.online in order to submit and view forms (a free version is available, no credit card required). Your website must also have SSL enabled (url should show https://).

Web Designer Friendly

We know that the owners or board members of dental clinics, health clinics, hospitals and insurance agencies aren’t the ones that will be implementing this service. It’s YOU, the web designers and developers that have the task of finding a solution and making it work.

Our initial primary goal was to build a solution for our own website builds so we’ve done everything we can to make the installation, setup and implementation of this service as seamless and efficient as possible. If you can build a contact form with Caldera Forms you can build HIPAA Compliant web forms with our service, in fact once you have the plugin setup and build the form all you really need to do is check a box and your form is instantly compliant.

We also want to ensure that YOU have the knowledge and ability to protect both yourself and your client. While we require your client to sign a BAA agreement with us we don’t require that the web designer/developer have a BAA in place but we STRONGLY recommend it. A BAA agreement protects your client, not you or us but it is actually REQUIRED according to HIPAA Regulations and without the BAA in place your client is not in compliance and may be violating both federal and state privacy laws. While YOU may not have a legal obligation to have a BAA in place with your client, as your client’s technical expert on all thing relating to their website have a moral obligation to make your client aware that a BAA agreement should be in place between you and them.

If you’re not an agency or freelance but work on the website directly for a company you should still ensure that your company has a BAA agreement in place for all employees and any 3rd party IT professionals that may have access to protected health information. Fines for violating HIPAA Regulations can be in the six figures and your company could be out of business leaving you looking for a new job if your company is not compliant.

Regardless of if you’re an agency, freelancer or work directly for a company that takes protected private health information, if you have any questions or need help with anything relating to compliance or how to put a BAA agreement in place between yourself and your client please don’t hesitate to submit a support ticket or give us a call.

Planned For Next Major Release

  1. Finish form-specific history interface

Currently In Development Premium Add-Ons

  1. Secure file upload
  2. Secure save for later ability
  3. Appointment manager
  4. Improved Notes Interface/Functionality
  5. Patient Communication Portal (Virtual Visit/HouseCall)
    A) Real-Time 2-Way Messaging
    B) Patient Access to Submitted Forms
    C) Video E-Visit
DomainExposuresHeadersLast Checked
u*p*o.com F 2026-05-03 14:01:38
s*a*i*p*a*t*c*u*g*r*.com (WP 6.9.4) F 2026-05-03 14:00:12
h*r*o*c*r*s.org C 2026-05-03 13:20:05
a*a*a*h*e*e*t*r.org (WP 6.9.4) 🔓 F 2026-05-03 10:38:26
e*n*e*t*o*m*.com F 2026-05-03 08:41:30
d*t*m*h*e*e*.com F 2026-05-03 08:21:30
d*s*i*o.com F 2026-05-03 06:31:29
w*k*s*i*e.com F 2026-05-03 05:19:36
p*t*o*h*p*o*e*o*.com F 2026-05-03 02:55:49
d*r*b*c*a*e*l*e.com F 2026-05-03 02:21:14
p*l*s*d*d*n*a*.com (WP 6.9.4) F 2026-05-02 23:06:05
w*y*e*e*l*h*a*e*.org C 2026-05-02 22:46:14
o*h*i*.org F 2026-05-02 22:22:53
s*o*c*n*a*e*a*i*s.com (WP 6.9.4) F 2026-05-02 22:01:40
m*i.associates (WP 6.9.4) F 2026-05-02 19:52:16
d*n*m*e*g*a*e*.com F 2026-05-02 19:43:56
d*n*o*i*e*s*o*.com (WP 6.9.4) F 2026-05-02 18:56:40
b*k*r*o*l*m*n.com D 2026-05-02 18:16:53
b*k*r*h*l*o*a*-*h*l*c*.com D 2026-05-02 18:08:34
p*s*a*m*a*i*y*e*l*e*s.com F 2026-05-02 17:06:30
p*s*a*.com F 2026-05-02 16:53:16
d*m*z*h*r*.com F 2026-05-02 16:43:43
d*m*n*l*a*e*l*e*s.com F 2026-05-02 15:48:55
p*a*r*e*e*o*e*y.com F 2026-05-02 15:01:44
d*l*n*d*r*.com (WP 6.9.4) 🔓 F 2026-05-02 14:57:29
m*u*t*i*l*n*p*d*.com (WP 6.7.5) F 2026-05-02 13:55:26
d*k*m*a*r*c*m*r*a*.com F 2026-05-02 13:42:15
n*t*r*p*t*i*m*d*c*n*d*l*t*.com F 2026-05-02 13:13:38
f*g*t*p*k*.com F 2026-05-02 13:07:38

Top 50 Plugins

Plugin Count
elementor 1,800,450
contact-form-7 1,770,416
elementor-pro 1,049,481
woocommerce 816,578
revslider 617,763
jetpack 467,002
js_composer 432,362
wp-rocket 334,096
essential-addons-for-elementor-lite 293,692
gravityforms 267,060
complianz-gdpr 256,646
cookie-law-info 231,313
instagram-feed 228,088
google-site-kit 222,053
sitepress-multilingual-cms 221,190
google-analytics-for-wordpress 214,049
header-footer-elementor 210,208
elementskit-lite 206,911
bluehost-wordpress-plugin 190,775
gutenberg 162,337
gutenberg-core 159,507
cookie-notice 151,371
the-events-calendar 131,527
litespeed-cache 130,994
wpforms-lite 129,550
gtranslate 127,925
astra-sites 119,573
popup-maker 116,091
woocommerce-payments 112,960
tablepress 109,187
coblocks 99,539
honeypot 97,392
astra-addon 95,313
duracelltomi-google-tag-manager 93,533
wp-smushit 93,516
all-in-one-seo-pack 93,320
LayerSlider 91,657
bb-plugin 90,822
premium-addons-for-elementor 86,880
megamenu 86,508
akismet 86,074
cleantalk-spam-protect 83,880
mailchimp-for-wp 83,756
woocommerce-gateway-stripe 83,116
ml-slider 81,034
fusion-builder 79,664
borlabs-cookie 79,520
ewww-image-optimizer 79,050
wp-pagenavi 78,797
formidable 78,063

Top 50 Themes

Theme Count
hello-elementor 615,573
Divi 510,726
astra 423,626
flatsome 133,744
Avada 124,341
generatepress 119,948
pub 109,942
oceanwp 83,460
kadence 78,474
enfold 71,844
salient 66,714
twentytwentyfour 58,958
h4 56,410
twentyseventeen 56,190
bb-theme 55,281
cocoon-master 52,095
betheme 51,820
blocksy 50,688
dt-the7 46,160
twentytwentyfive 43,814
neve 39,351
Avada-Child-Theme 37,622
gox 33,449
woodmart 33,292
bridge 32,878
twentytwentyone 32,115
lightning 31,449
twentytwenty 30,045
swell 28,597
Impreza 26,441
bricks 26,019
sydney 25,643
twentytwentythree 24,026
Newspaper 23,472
voxel 22,440
twentytwentytwo 19,980
epik-redesign 19,270
kubio 19,178
uncode 19,113
sinatra 18,819
twentysixteen 18,221
storefront 17,869
pro 17,861
Total 14,730
extendable 14,595
yith-wonder 14,041
hello-theme-child-master 13,356
themify-ultra 12,983
yootheme 12,936
factory-templates-4 12,927