I’ve run into this too.
I had a client that needed to collect HIPAA protected data. Putting their marketing site into scope for HIPAA was not a sane choice. Their EMR vendor didn’t have any options that didn’t require migrating to a new EMR offering in order to create/publish/accept forms. All the other options were clunky and required a lot more work and niche expertise or training in those applications.
So we went with Google Forms. They already used Google Workspace and had executed the HIPAA addendum to the terms.
That lasted less than a year. The physicians and patients were both put off by the fact that it was a Google Form and it looked unprofessional.
They’re back to posting PDFs on their website.