Your website is where patients type things.
A page about frames is marketing. A page that takes an appointment request is something else. The difference matters, and most practice websites are built as though it doesn't — which is how patient details end up somewhere nobody meant to send them.

Does HIPAA apply to my practice website?
Parts of it, on some pages. A plain marketing page usually isn't handling protected health information. But the moment your site takes an appointment request, asks a patient why they are coming in, or links into a portal, it is touching information you have to be careful with — and any advertising or analytics code running on those same pages can pass details to companies you never signed anything with. We build the site so those paths are closed by default. We are not your HIPAA compliance program, and we do not sell you one.
Book A 30-Minute Call- Encrypted on every visit, from the first one
- No tracker loads until a visitor agrees to it
- Forms ask for as little as possible on purpose
- 37 security checks re-run every month
Almost every problem we find is one of these three.
None of them are exotic. They are ordinary settings that nobody was paid to think about when the site was built.
Leak one
The tracking code on the appointment page
An advertising pixel on a page about dry eye tells that advertiser somebody was reading about dry eye. On a page where a patient requests an appointment, it can carry more than that. Practices did not choose this — the marketing agency added a tag and moved on.
- The government warned health care providers about this in a 2022 notice and updated it in 2024
- A federal court struck part of that guidance down in June 2024, so the official line is narrower now than it was
- The lawsuits did not narrow. Tracking cases against providers have run past $100 million in settlements since 2023.
What we do. No advertising or analytics tracker loads until the visitor says yes, and none of them run on a page that takes an appointment request. That is a build decision, not a setting somebody has to remember.
The four rules that reach your site →
Leak two
The form that asks too much
Whatever you ask a patient for, you are now responsible for. Plenty of practice websites ask for symptoms, insurance ID numbers or a reason for the visit on a public form, and then email it around in plain text.
- Our appointment form asks for a name, a way to reach you and a preferred time. Nothing clinical.
- Submissions travel encrypted and land in named inboxes, not a shared catch-all
- If a patient needs to tell you something medical, the form tells them to call — because a phone line is the right place for it
Leak three
The plumbing nobody looks at
These are the settings that tell a patient's browser what to trust and what to block. They are invisible, they are free, and on the real practice site we audited, three of the core ones were simply missing.
- Encrypted from the very first request, not after a redirect
- Security headers switched on, so a browser can stop injected code and hijacked clicks
- Cookies flagged so they cannot travel unprotected
- The server does not announce its software and version to anyone who asks
- No staff email addresses left sitting on public pages for scammers to harvest
Every month
Then it gets re-checked
Security is not a thing you finish. Plug-ins update, certificates expire, somebody adds a tag. So the same checks run again every month and a person reads the result.
- 37 security checks re-run monthly
- Accessibility re-checked in the same pass — 244 items
- You get told what changed, in English
About those "new HIPAA security rules."
If a vendor has told you that your practice is already out of compliance with new HIPAA security requirements, here is the actual state of play as of August 2026 — and it is not what that email said.

It is still a proposal.
The government published a big proposed rewrite of the HIPAA Security Rule in January 2025. Comments closed that March. No final rule has been issued. The target date has already slipped more than once, and provider groups have asked for it to be withdrawn outright. A proposal is not law and cannot be enforced against you.
The current rule still applies.
The HIPAA Security Rule that exists today has not gone anywhere, and the most commonly cited failure in government investigations is still the same one it has always been — not having done a proper risk analysis.
And the breaches are real.
2025 set a record for large health care data breaches, with 772 reported. The regulation is contested. The exposure is not.
What we do, and what we don't.
"HIPAA compliant website" is a phrase used loosely by a lot of vendors. We are going to be specific instead.
Build it so the risky paths are closed.
Encryption on every request. Security headers on. Cookies flagged properly. No tracker before consent, and none at all on pages that take appointment requests. Forms that ask for the minimum and route to named inboxes over an encrypted connection. No staff addresses left exposed. Then 37 security checks re-run every month, with a person reading the result and telling you what changed. This is what "HIPAA-aware" means and it is the honest version of the phrase.
Sell you a compliance program.
We do not tell you your practice is HIPAA compliant — that covers your staff, your training, your devices, your vendors and your risk analysis, and a website is one small part of it. We do not act as your compliance officer. We do not give legal or privacy advice. And we will not hand you a certificate that says you are protected, because that certificate would not be worth anything. If you need a HIPAA risk analysis, get one from somebody who does that for a living.
More on this page's topic
Is a marketing website covered by HIPAA?
Can I run Google Analytics or a Facebook pixel on my practice site?
Are the new HIPAA security requirements in force yet?
Will you sign a business associate agreement?
What actually gets checked every month?
What if a patient sends medical details through the contact form anyway?
See what's actually on your site right now.
Independent practices only · $0 until you're live · no contract · 37 security checks every month