HIPAA and Health Data
Effective August 24, 2026
No business associate agreement is offered through independent signup, and a checkbox, privacy notice, encryption setting, or generated “HIPAA” label does not make a workflow HIPAA compliant.
Examples of prohibited PHI include patient identifiers combined with diagnoses, symptoms, medications, treatment, insurance, billing, appointment, or other individually identifiable health information. If your proposed use may involve regulated health data, stop collection and contact SkyGridobe@gmail.com for a written eligibility review.
No PHI is a product rule, not a promise that every accidental submission falls outside every privacy law for health data. Consumer health, breach notification, biometric, children's, and general privacy laws may protect health information even when HIPAA does not. Do not use WebFormafy for symptom screening, diagnoses, treatment, medication, insurance, patient appointments, reproductive health, mental health, or other workflows involving health status without prior written approval.
If PHI or other prohibited health data is submitted accidentally, stop further collection, do not copy it into email or support tickets, preserve only the minimum information needed for a security/legal assessment, and contact support immediately. Deletion, notification, and incident steps will be determined from the actual data, location, contracts, and applicable law.
HIPAA enablement, if offered in the future, requires a documented risk analysis and risk management program, appropriate contracts and BAAs, approved subprocessors, access and audit controls, workforce procedures, handling for incidents and breaches, contingency testing, and written authorization from platform security and legal owners.