The short answer: SurveyMonkey can be used in a HIPAA-compliant way only when your organization is on a plan for which SurveyMonkey signs a business associate agreement (BAA), historically an enterprise-tier arrangement, and only when HIPAA features are enabled and the surveys are designed with discipline. Free and standard self-serve plans come with no BAA, which means no protected health information (PHI) may flow through them.

Patient surveys sit closer to PHI than most teams assume, so the boundaries deserve a careful walk-through.

Why Survey Data Is PHI

Under the Privacy Rule, individually identifiable health information held or transmitted by a covered entity is protected, and the identifier framework (45 CFR 164.514) counts names, emails, phone numbers, and dates alongside the obvious clinical fields. A patient satisfaction survey linked to a respondent's contact details is health information twice over: the answers describe a care experience, and the respondent list itself reveals who receives care from your organization.

Anonymity is harder than it looks. A survey with no name field can still identify respondents through email invitation tracking, IP collection, appointment-date questions, or small-cell demographics at a small practice. If your organization can reasonably re-identify a response, treat it as identifiable.

That makes the survey vendor a business associate under 45 CFR 164.502(e) whenever identifiable patient data flows through it, and the covered entity must execute a BAA before that happens (45 CFR 164.308(b)). The contract, not the vendor's security page, is the deciding element; our explainer on business associate agreements covers why.

Where SurveyMonkey Stands

SurveyMonkey has offered HIPAA-oriented capability as an enterprise feature: BAA execution plus account settings intended for sensitive data handling. Two practical consequences follow:

  • Free, Advantage, and standard team plans: no BAA; patient-identifiable surveys cannot run through them. This mirrors the consumer-tool pattern across the "is X HIPAA compliant" series.
  • Enterprise arrangements: ask SurveyMonkey directly whether a BAA is available for your contract, execute it before any patient data flows, and confirm which account features are part of the covered configuration. Plan structures change; the executed document in your compliance file is the fact that matters.

With a BAA in place, the standard limits still apply. Coverage follows the corporate account, not the person, so a staff member's personal SurveyMonkey login is outside the agreement entirely. And a BAA is not a compliance program: your risk analysis (45 CFR 164.308(a)(1)), access controls, and training remain your obligations.

Design Rules for Covered Patient Surveys

If you run patient surveys on a covered enterprise account, design does the rest of the work:

  1. Collect minimum necessary data. Every identifier you skip is exposure you never create. If the workflow does not require names, do not collect them.
  2. Keep invitations clean. Survey invitations travel by email or text, and those channels have their own rules. Invitation bodies should be logistics-only, no conditions, no visit reasons, consistent with the Security Rule's transmission-risk analysis (45 CFR 164.312(e)).
  3. Restrict result access by role, and know who can export raw responses.
  4. Set retention. Survey responses containing patient experience data should follow your record retention rules, not live indefinitely in a vendor console.
  5. Cover the workflow in your risk analysis and vendor inventory, like every other system touching PHI.

The Texting Alternative for Patient Feedback

For the most common healthcare survey, the post-visit satisfaction pulse, a full survey platform is often more machinery than the job needs. A one-question SMS survey, sent through a patient communication platform under BAA, reaches patients on the channel they already answer and collects the signal that matters: was this visit good, and if not, why not.

The mechanics favor text: response friction is a single reply rather than a link, a form, and a submit button, and unhappy responses can route straight to a staff queue for same-day service recovery. Consent rules are the same as all patient texting, prior express consent under the TCPA (47 U.S.C. 227), documented and honored. Our guide to patient satisfaction SMS surveys covers question design, timing, and escalation in full.

The practical division of labor for many organizations: SMS pulses for routine satisfaction and service recovery, and a covered enterprise survey platform for the occasional deep instrument, annual patient experience research, community health assessments, where branching logic and long forms earn their complexity.

The Decision Framework

  • Any patient survey on a free or standard SurveyMonkey plan: stop; no BAA exists. Export what you must retain, delete the rest, document the remediation, and assess notification duties under the Breach Notification Rule (45 CFR Part 164, Subpart D) with your privacy officer.
  • Enterprise account with an executed BAA and disciplined design: covered patient surveys are achievable, and the platform is a reasonable choice for complex instruments.
  • Routine satisfaction measurement: run it as a consented SMS pulse on covered communication infrastructure, and reserve the survey platform for research-grade needs.
  • Truly anonymous community surveys with no patient identifiers, no tracked invitations, and no re-identification path sit outside PHI, but validate the "truly" before relying on it.

Standing Up a Covered Survey Program, Step by Step

If an enterprise agreement is genuinely in place, the remaining work is procedural. A repeatable sequence keeps each new instrument inside the lines:

  1. Execute the agreement first, and file it. The signed document, with its date and scope, belongs in the compliance file next to your other vendor agreements, not in an account manager's inbox.
  2. Confirm the covered configuration. Ask which account settings the agreement assumes, then verify them in the console rather than trusting the default state of a new workspace.
  3. Add the workflow to your vendor inventory and risk analysis under 45 CFR 164.308(a)(1), the same way any other system touching patient data is recorded.
  4. Write the question set against a purpose statement. Decide what decision the results will drive, then keep only the questions that serve it. Every identifier you skip is exposure you never create.
  5. Decide the identification model deliberately. Fully anonymous, pseudonymous with a key held inside your own systems, or identified. Each is defensible; drifting between them is not.
  6. Restrict roles before launch. Set who can view aggregate results, who can view individual responses, and who can export raw data, then check the export permission specifically, because it is the one that leaves the platform.
  7. Design the invitation separately from the survey. Invitation bodies carry logistics only, consistent with the Security Rule's transmission-risk analysis (45 CFR 164.312(e)).
  8. Set retention and a disposal date so responses follow your record retention rules instead of living indefinitely in a vendor console.
  9. Pilot on staff, then a small patient cohort, and read the raw output before scaling. Free-text fields are where unplanned clinical detail arrives.
  10. Review annually. Plans, features, and staff change. Re-verify the agreement scope and the account settings on a schedule.

Anonymity Edge Cases That Break Quietly

  • Tracked invitation links. A unique link per recipient re-identifies every response, no matter what the survey page says. Anonymity and per-recipient tracking cannot both be true.
  • Small cells. At a single-provider practice, "which provider did you see" plus a visit week identifies the respondent by inference. Small populations defeat anonymity faster than any field does.
  • Open text boxes. Patients volunteer names, conditions, and phone numbers in free-text fields. If a survey has one, treat the response set as potentially identifiable regardless of design intent.
  • Metadata. IP capture, device fingerprints, and precise submission timestamps can support re-identification even with every visible field stripped.
  • Reidentified follow-up. Service recovery requires knowing who was unhappy. A workflow that promises anonymity and then follows up individually has contradicted itself, so choose one design and say so plainly in the invitation.
  • Third-party survey research. Vendors running patient experience research on your behalf are business associates too, and their subcontractors need to be inside the chain.
  • Substance use disorder programs. Records covered by 42 CFR Part 2 carry consent requirements stricter than HIPAA, so surveys touching those programs need their own analysis rather than the general patient survey template.

What to Ask a Survey or Messaging Vendor

The questions worth asking before any patient survey launches, as a procurement checklist rather than legal advice:

  1. Will you sign a business associate agreement for the specific plan we are purchasing, and may we read it first?
  2. Which features are inside the agreement, and which integrations, panels, or analytics add-ons are excluded?
  3. Can individual response export be restricted by role, and is that action logged?
  4. What identifiers does the platform collect by default, including IP and device data, and can each be disabled?
  5. How long are responses retained, and can we set automatic deletion on our own schedule?
  6. Which subcontractors process response data, and in which regions is it stored?
  7. What audit logs are available to us directly, without filing a support request?
  8. How are results returned to us at contract end, and on what timeline is our data deleted?

For teams comparing form and survey tools generally, the same analysis applies vendor by vendor; see our companion piece on whether Google Forms is HIPAA compliant.

Frequently Asked Questions

Does SurveyMonkey sign a BAA?

SurveyMonkey has offered BAA coverage as an enterprise-tier feature, not on free or standard self-serve plans. Confirm availability for your specific contract with their sales team and execute the agreement before any patient-identifiable survey launches.

Can I run an anonymous patient survey on a free SurveyMonkey plan?

Only if it is genuinely anonymous: no names, no tracked email invitations, no IP or metadata collection that permits re-identification, and no small-population questions that identify by inference. If your organization could reasonably link a response to a patient, the survey is identifiable and needs covered infrastructure.

Are patient satisfaction responses PHI?

When linked to an identifiable respondent by a covered entity, yes: they describe a care experience tied to a person. Even the respondent list alone reveals who receives care from your organization, which is identifiable health information in itself.

Should survey invitations be sent by text?

Text invitations reach patients faster than email, and with prior express consent under the TCPA they are fully workable. Keep the invitation body logistics-only and send it through a platform with a signed BAA, since the recipient list is patient data.

What is the simplest compliant way to measure patient satisfaction?

A one-question SMS pulse after visits, run on a patient communication platform with a signed BAA included, documented consent, and escalation routing for unhappy replies. Reserve full survey platforms for complex research instruments where branching and long forms are genuinely needed.

Does a signed patient authorization let us survey patients on any platform?

No. Authorization and vendor coverage answer different questions. An authorization can permit a use or disclosure of PHI; it does not make an uncovered vendor an acceptable place to process it. You still need a business associate agreement with whoever handles the data.

Can we survey patients about a specific condition or treatment?

On covered infrastructure, yes, and clinical quality work often requires it. Two cautions apply: a condition-specific respondent list is a more sensitive disclosure than a general one, so access controls matter more, and programs governed by 42 CFR Part 2 have consent rules of their own that a general patient survey process does not satisfy.

Feedback on the Channel Patients Answer

FRANSiS runs post-visit SMS pulses with a signed BAA included, documented consent, and an AI Powered Helper routing unhappy replies to your team the same day. Contact us to start measuring patient experience where patients actually respond.