HIPAA, Privacy & Security

Your website is where patients type things.

A page about frames is marketing. A page that takes an appointment request is something else. The difference matters, and most practice websites are built as though it doesn't — which is how patient details end up somewhere nobody meant to send them.

A patient information form on a clipboard beside a padlock symbol.
The decisions that matter here are made before a patient types a single character.
Short answer

Does HIPAA apply to my practice website?

Parts of it, on some pages. A plain marketing page usually isn't handling protected health information. But the moment your site takes an appointment request, asks a patient why they are coming in, or links into a portal, it is touching information you have to be careful with — and any advertising or analytics code running on those same pages can pass details to companies you never signed anything with. We build the site so those paths are closed by default. We are not your HIPAA compliance program, and we do not sell you one.

Book A 30-Minute Call
  • Encrypted on every visit, from the first one
  • No tracker loads until a visitor agrees to it
  • Forms ask for as little as possible on purpose
  • 37 security checks re-run every month
Three Places It Leaks

Almost every problem we find is one of these three.

None of them are exotic. They are ordinary settings that nobody was paid to think about when the site was built.

A patient information form on a clipboard beside a padlock symbol. Leak one

The tracking code on the appointment page

An advertising pixel on a page about dry eye tells that advertiser somebody was reading about dry eye. On a page where a patient requests an appointment, it can carry more than that. Practices did not choose this — the marketing agency added a tag and moved on.

  • The government warned health care providers about this in a 2022 notice and updated it in 2024
  • A federal court struck part of that guidance down in June 2024, so the official line is narrower now than it was
  • The lawsuits did not narrow. Tracking cases against providers have run past $100 million in settlements since 2023.

What we do. No advertising or analytics tracker loads until the visitor says yes, and none of them run on a page that takes an appointment request. That is a build decision, not a setting somebody has to remember.

The four rules that reach your site →
A practice receptionist handing a card across the front desk to a patient. Leak two

The form that asks too much

Whatever you ask a patient for, you are now responsible for. Plenty of practice websites ask for symptoms, insurance ID numbers or a reason for the visit on a public form, and then email it around in plain text.

  • Our appointment form asks for a name, a way to reach you and a preferred time. Nothing clinical.
  • Submissions travel encrypted and land in named inboxes, not a shared catch-all
  • If a patient needs to tell you something medical, the form tells them to call — because a phone line is the right place for it
What we collect and why →
A clinician holding a direct ophthalmoscope close to a patient's eye during an examination. Leak three

The plumbing nobody looks at

These are the settings that tell a patient's browser what to trust and what to block. They are invisible, they are free, and on the real practice site we audited, three of the core ones were simply missing.

  • Encrypted from the very first request, not after a redirect
  • Security headers switched on, so a browser can stop injected code and hijacked clicks
  • Cookies flagged so they cannot travel unprotected
  • The server does not announce its software and version to anyone who asks
  • No staff email addresses left sitting on public pages for scammers to harvest
See these findings on a live site →
A clinician in scrubs holding a tablet that shows accessibility icons, including a wheelchair symbol and a sign-language symbol. Every month

Then it gets re-checked

Security is not a thing you finish. Plug-ins update, certificates expire, somebody adds a tag. So the same checks run again every month and a person reads the result.

  • 37 security checks re-run monthly
  • Accessibility re-checked in the same pass — 244 items
  • You get told what changed, in English
What's included, and what it costs →
You May Have Had This Email

About those "new HIPAA security rules."

If a vendor has told you that your practice is already out of compliance with new HIPAA security requirements, here is the actual state of play as of August 2026 — and it is not what that email said.

A clinician explaining a document to a seated patient across a desk.
We would rather tell you nothing is due than sell you a deadline that isn't there.

It is still a proposal.

The government published a big proposed rewrite of the HIPAA Security Rule in January 2025. Comments closed that March. No final rule has been issued. The target date has already slipped more than once, and provider groups have asked for it to be withdrawn outright. A proposal is not law and cannot be enforced against you.

The current rule still applies.

The HIPAA Security Rule that exists today has not gone anywhere, and the most commonly cited failure in government investigations is still the same one it has always been — not having done a proper risk analysis.

And the breaches are real.

2025 set a record for large health care data breaches, with 772 reported. The regulation is contested. The exposure is not.

We build the website to a careful standard because it is the right way to build it — not because of a deadline that hasn't been set. If that costs us a sale to somebody with a scarier email, we can live with it.

Straight About This

What we do, and what we don't.

"HIPAA compliant website" is a phrase used loosely by a lot of vendors. We are going to be specific instead.

What we do

Build it so the risky paths are closed.

Encryption on every request. Security headers on. Cookies flagged properly. No tracker before consent, and none at all on pages that take appointment requests. Forms that ask for the minimum and route to named inboxes over an encrypted connection. No staff addresses left exposed. Then 37 security checks re-run every month, with a person reading the result and telling you what changed. This is what "HIPAA-aware" means and it is the honest version of the phrase.

What we don't

Sell you a compliance program.

We do not tell you your practice is HIPAA compliant — that covers your staff, your training, your devices, your vendors and your risk analysis, and a website is one small part of it. We do not act as your compliance officer. We do not give legal or privacy advice. And we will not hand you a certificate that says you are protected, because that certificate would not be worth anything. If you need a HIPAA risk analysis, get one from somebody who does that for a living.

Questions, Answered

More on this page's topic

Is a marketing website covered by HIPAA?
Usually not on its own. HIPAA covers protected health information, and a page describing your dry eye service is not that. It changes when the site starts collecting things — an appointment request, a form asking why the patient is coming in, a portal link. Those pages need to be treated differently from the ones about frames, and on most practice websites they aren't.
Can I run Google Analytics or a Facebook pixel on my practice site?
Many practices do, and it is exactly where the trouble has been. The government warned providers about tracking technology in 2022 and updated that warning in 2024; a federal court then struck down part of it in June 2024, so the official position is narrower than it was. The private lawsuits did not narrow — health care tracking cases have run past $100 million in settlements since 2023. Our build loads no tracker until a visitor agrees, and none on appointment pages.
Are the new HIPAA security requirements in force yet?
No. The government proposed a major update to the HIPAA Security Rule in January 2025 and has not finalized it. The target date has slipped more than once and provider groups have asked for it to be withdrawn. If somebody has emailed you saying your practice is already out of compliance with new HIPAA security rules, that is not accurate. The existing Security Rule does still apply.
Will you sign a business associate agreement?
Talk to us about your specific situation and we will tell you honestly whether one is warranted and what it would cover. What we will not do is hand you a signed form and let you treat it as proof that your practice is compliant. A BAA describes a relationship. It is not a compliance program and it is not a shield.
What actually gets checked every month?
37 security checks and 244 accessibility items, across every page. Certificates, headers, cookie flags, exposed information, mixed content, and whether anything new got added to the site since last time. A person reads the output and you get a plain-English note about what changed and what was fixed.
What if a patient sends medical details through the contact form anyway?
The form is written to steer them to the phone for anything clinical, and it does not ask for it. But patients do what patients do. Submissions travel encrypted and go to named inboxes rather than a shared mailbox, so if it happens, it lands in the smallest number of hands it can. How your practice then handles it is part of your own procedures.
Built Careful, Checked Monthly

See what's actually on your site right now.

Independent practices only · $0 until you're live · no contract · 37 security checks every month