Online Form Design Best Practices

Tuesday, October 2nd, 2018

Most businesses and organizations today use online forms to collect customer information. The same applies to healthcare companies. But, healthcare companies need to abide by stringent regulations concerning PHI or Protected Health Information under HIPAA.

So, it is of the utmost importance for such organizations to follow certain best practices when designing these forms. Let’s take a look at a few of them.


First and foremost, the data that is filled into the form must be secured when being transmitted, processed and stored. One way to do that is via encryption. Encryption secures form data by making it unreadable to those who do not have the access. This typically includes the browser and server.

SSL is one of the encryption options you can consider. It stands for Secure Sockets Layer and it’s basically a type of security protocol that secures the connection between sender and receiver. So, when data is transmitted, only the sender and receiver will have access to it. No third party can intercept and retrieve the data.

So, SSL encryption allows you to secure the submitted data during transmission.

You can make the data even more secure by adding an authentication layer. What that means is that only people who are authorized to view the data will be able to do so. This can go a long way in preventing unauthorized access.

Protect Yourself from Bots

Bots are automated programs that go poking around the Internet, looking for information, looking for system vulnerabilities, and looking for ways to send spam, among other things.  It is extremely common for such bots to automatically fill out and submit online forms … often with garbage or with spam.

Recipe: Completely Secure Collection of Web Form Data using SSL and PGP or S/MIME

Tuesday, March 17th, 2009

The situation: your organization needs to collect information from clients through from(s) on your web site, but that information is sensitive. So, you need to be absolutely sure that the information is transferred from the users of your web site to you in as secure a fashion as possible. This means that

  1. no one but you (or optionally your authorized staff) can intercept or read the information,
  2. the information is never stored insecurely anywhere
  3. the information cannot be modified without your knowledge

Why would this high level of security and privacy be necessary? There are many cases where they are essential; some of these include:

Receive Secure Web Form Submissions in a Secure Email

Thursday, January 15th, 2009

You collect private information on your website. Whether it’s health information that needs to be HIPAA-compliant, credit card numbers, or other confidential data, you need an easy and transparent way to protect the privacy of your visitors, from start to finish.


LuxSci provides a secure web form for your website. Information is encrypted and emailed to you directly, so that you can access everything in your own email, but know that the data was secure from input to delivery.

