HIPAA forms that refuse to leak
Every form builder gates HIPAA behind a top tier and allows one BAA per account. Then it invites you to connect Zapier, which signs no BAA at all. Minnato puts the compliance boundary at the practice — and blocks patient data from reaching any vendor that hasn't signed.
The compliance boundary is the practice, not the account
An agency with sixty client practices cannot use a one-BAA-per-account tool compliantly at any price. Their only compliant option is sixty separate subscriptions.
A BAA per practice
Each covered entity gets its own agreement, its own encryption key, its own audit scope and its own destruction path. One practice leaving never touches another's data.
The blind agency role
Your team administers forms, sites and branding without ever seeing patient data — enforced in the database, not the interface. So the agency isn't a business associate and doesn't need sixty BAAs of its own.
The gate
A practice cannot collect patient information until its agreement is countersigned. Not a warning banner — the submission is refused.
Egress control
Patient data cannot reach a vendor without a BAA. The notification still fires, with every PHI field removed, so your automations keep working.
Tracker-safe by construction
Forms render on their own origin with no third-party requests at all — no fonts, no CAPTCHA, no analytics. Signed attestation reports prove it.
Provable destruction
Each practice's data is encrypted under its own key. Destroy the key and their records are unrecoverable, with everyone else's untouched.
What the incumbents actually offer
Verified from published pricing and terms, August 2026.
| Typical form builder | Minnato | |
|---|---|---|
| BAAs per account | One | One per practice |
| HIPAA tier | Top plan only | Every paid plan |
| Blocks PHI to uncovered vendors | No — markets Zapier | Refuses it |
| Third-party requests on the form | Fonts, CAPTCHA, analytics | None |
| Collects agreements for you | No workflow | Send, sign, countersign |
| Per-practice data destruction | Manual, unprovable | Cryptographic |
Security you can check rather than trust
Every claim on this page is enforced somewhere a reviewer can inspect.
Isolation defended three times
Row-level security in the database, the practice bound into the ciphertext, and an encryption context that makes AWS KMS itself refuse a cross-practice decryption. Any one holds if the others fail.
Append-only audit trail
Every read of patient data recorded with who, what, when and from where. Retained six years, exportable per practice, and impossible to alter — including by us.
US-only, verified in transit
Patient data never leaves the region, and the database connection verifies the server certificate rather than merely encrypting to whoever answers.
See it against your own sites
We'll scan every practice site you manage and show you which ones are sending patient data to vendors that never signed a BAA. It takes a day and costs nothing.