HIPAA-Compliant Marketing

HIPAA-Compliant Intake Forms for Therapy Practices (2026)

The FTC's action against Cerebral should be required reading for every therapy practice owner: a mental-health company's intake and marketing data flowed into ad platforms and loosely secured systems, and the consequences included penalties, mandated overhauls, and a public record no practice wants. Add HHS enforcement like URMC's $2.85M settlement over marketing-data handling, and the message for 2026 is plain — mental-health intake data is treated as the most radioactive PHI there is, and regulators know exactly where to look for it: your website's contact form.

Because here's the uncomfortable truth about therapy websites. The moment a prospective client types "struggling with panic attacks since my divorce" into your "How can we help?" field and adds their name and phone number, you are holding protected health information about a mental-health condition. Where that submission lands determines whether you're compliant — before a clinician ever says hello.

What makes therapy intake different

Generic "HIPAA form" advice underestimates the therapy-specific stakes:

Presenting concerns are diagnosis-adjacent PHI. A dermatology form that says "rash" is sensitive; a therapy form that says "suicidal thoughts," "drinking again," or "my teenager is self-harming" is in a different category — the kind of disclosure that ruins lives if breached, and the kind courts and regulators weigh heaviest. If your form invites free-text presenting concerns (and it should — it helps triage), the storage architecture behind it must be beyond reproach.

Consent has layers most verticals never touch. Therapy intake typically needs: consent to treat; telehealth-specific informed consent if you deliver care virtually; guardian consent and minor-assent handling for adolescent clients (with state-specific rules about what minors can consent to themselves); and clear communication-preference consent — some clients cannot safely receive texts or voicemails at home, so "how may we contact you?" is a safety question, not a marketing one. And remember the special status of psychotherapy notes under HIPAA: nothing in your marketing or intake stack should ever be within reach of clinical process notes.

The Good Faith Estimate is part of intake now. Under the No Surprises Act, self-pay and uninsured clients are entitled to a Good Faith Estimate of charges. The practical implication for your forms: collect insurance/self-pay status at intake, and build the GFE delivery into your new-client workflow rather than scrambling per client. A well-designed intake flow makes GFE compliance a template, not a chore.

A crisis disclaimer is non-negotiable. Your web form is not monitored 24/7. Every therapy intake form needs visible language directing people in crisis to 988 or emergency services — both an ethical duty and a liability shield.

Where the form data goes is the whole ballgame

Most therapy websites run on WordPress, and most WordPress forms store every submission in the site's own database. Walk the consequences: your web host (no BAA) is storing mental-health PHI; everyone with wp-admin access — the SEO contractor, the old web developer — can read presenting concerns; every backup copies it all again; and a garden-variety WordPress hack becomes a reportable mental-health data breach.

The architecture we run for therapy clients eliminates the category of risk instead of managing it:

  • Submissions never exist in WordPress. On submit, the entry POSTs server-to-server from the web server to app.pilotpractice.com — a HIPAA-compliant platform under a signed BAA, with field-level encryption and access logging. Nothing is written to the WordPress database. The website is a pass-through, not a datastore. (Full technical breakdown: Is Gravity Forms HIPAA Compliant?)
  • Each site authenticates with its own bearer token, so submissions are verifiably from your site, and one site's credential can be revoked without touching anything else.
  • Passwords are structurally unstorable. Clients sometimes paste portal passwords into free-text fields. Three independent layers — an ingest block, a model-level cast strip, and a retroactive scrub of historical records — make it impossible for a password to persist. Not a policy; a property of the system.
  • Spam never becomes a record. Bot submissions are screened out before they reach the CRM, so your PHI system contains clients, not junk with fabricated crisis language.
  • Scheduling lands in your actual EHR. Our booking widget integrates with 30+ EHR/EMR systems — including the platforms therapy practices actually run — so a new-client booking creates the appointment and chart in your real system, with date-of-birth collection enforced where the EHR requires it. No standalone calendar to reconcile (why that matters).

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

The ungated checklist: therapy intake audit

Run this today — no email gate, no sales call required.

  1. Submit a test entry, then check your WordPress form-entries screen. If the test appears there, mental-health PHI is stored in your website database right now.
  2. Read your "reason for visit" field. If it invites clinical detail (good for triage), confirm the storage behind it is BAA-covered and encrypted.
  3. Check the crisis language. Is 988 / emergency-services guidance visible on the form itself?
  4. Verify communication-preference capture. Can clients say "no voicemails, no texts" — and does your system actually honor it?
  5. Check minor-client handling. Does your intake distinguish guardian consent from adolescent self-consent per your state's rules?
  6. Confirm telehealth consent is collected before the first virtual session, not after.
  7. Map your GFE workflow. Does intake capture self-pay status, and does a Good Faith Estimate go out on a defined trigger?
  8. List every system that receives a copy — notification emails, Zapier, spreadsheets. Each is a business associate; each needs a BAA.
  9. Check your ad-platform surface. No pixel or third-party script should run on intake or booking pages — a special disaster for mental health (therapy ads done right).
  10. Confirm the BAA chain end to end: forms platform, CRM, email/SMS reminders, host.

Design notes that lift conversion without lifting risk

Fewer fields, more clients: name, contact method + preference, presenting-concern text box, insurance/self-pay, and how they found you. Everything else belongs in the clinical intake after the relationship exists. Make the concern field optional and prompt gently ("Share as much or as little as you like"). Offer online booking alongside the form — many therapy clients, especially for anxiety-adjacent concerns, will book a slot at 11 p.m. but will never make a phone call.

The do-marketing answer

A compliant intake form is table stakes; a full caseload comes from the system around it: service pages for each specialty and population, fast follow-up on every inquiry (therapy clients contact 2–3 practices and go with whoever answers first), compliant reminders that cut no-shows, and attribution that shows which channel fills which clinician's schedule — all without a byte of PHI reaching an ad platform.

That's what PilotPractice runs for therapy and behavioral-health practices: the website, the server-to-server intake, the EHR-integrated booking, and the marketing — under one BAA, with SOC 2 and HIPAA controls documented at trust.pilotpractice.com. The complete playbook is in our 2026 HIPAA-compliant marketing guide, or book a demo and we'll audit your current intake flow live.


PilotPractice security & compliance documentation: trust.pilotpractice.com

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI