End-To-End Form Encryption (HIPAA compliance)

Hi Dev Team et. al,

Would it be possible to add end-to-end encryption on individual forms that require an access code (set by an administrator) to view submission data? Maybe it could be combined with this wishlist, Make the forms HIPAA compliant - #4 by Max , and others dealing with compliance to Data Protection Regulations?

  • :speaking_head::loudspeaker:Community please up vote :white_check_mark:

Thanks in advance :busts_in_silhouette::busts_in_silhouette::busts_in_silhouette:……

Kind regards,

mw :technologist:t4:

2 Likes

Hi there, @Master_Web :waving_hand:

Thank you for the feedback!

While we don’t have any certificates to prove HIPAA compliance, I’d like to say that we take privacy measures very seriously. We store encrypted information from the froms on protected server disks in Google Cloud Platform.

By clicking the Submit button the user agrees to share their data, which is accessible only by the widget owner and is not processed by Elfsight in any manner. Additionally, you can include a Consent checkbox in your widget settings to ask the users for their consent before they submit the data.

However, I agree that it would be great to make our forms HIPAA-compliant, and we’ll try to consider this opportunity in the future :slightly_smiling_face:

1 Like

Thank you, Max :sparkles:.

I do think if the forms were to become GDPR-compliant, or compliant to a stronger Global Data Protection Framework/Regulation that includes HIPAA compliance, that would be even better. Maybe, I should have stated this from the initial post. I just wasn’t sure if there were any other wishlist requests for other Global Data Protection Frameworks/Regulations.

Smalls businesses (SMB) in particular need the ease of staying compliant, and proving they are compliant wherever they are trying to operate on a Global Scale. So as it relates to End-To-End encryption of individual forms, and being able to use an access code (known only to an SMB administrator), my preference is for at least GDPR compliance, HIPAA only covers Health data in the US - https://hipaauniversity.com/blog/hipaa-vs-gdpr-what-sets-them-apart/

And, while I’m sure Elfsight takes privacy seriously, there are use cases for SMBs that require an extra layer of Data Protection, especially when using third party services. In the end, it’s just a wish, as I prefer to use Elfsight Forms, rather than another.

  • :speaking_head::loudspeaker: Community, please :prayer_beads:up vote :white_check_mark: this feature.

Also, please check out all the Other Wishlist features I’m championing :gem_stone: , add your comments, and up vote them too :white_check_mark:

Thanks in advance :busts_in_silhouette::busts_in_silhouette::busts_in_silhouette:……

Kind regards,

mw :technologist:t4:

1 Like

I completely got your point, thank you for such a detailed comment!

We’ll keep this idea in mind and try to consider it in the future, especially if it gets more votes :slightly_smiling_face:

1 Like