Get Your Free Audit →

Marketing

What Makes a Medical Website HIPAA Compliant

A HIPAA problem on a practice website is almost never the website. It is the tracking, the forms and the vendors behind it. Here is where the exposure actually sits.

Efferent Media is a Long Island digital marketing agency, family owned and based in Lindenhurst since 2011. Articles here describe published platform policy and our own measured results. They are marketing guidance, not legal advice.

On this page

Most conversations about HIPAA and websites focus on the wrong layer. The markup is rarely the problem. The problem is what the page loads, what the forms collect, and who else receives it.

A practice site can be beautifully built, fully encrypted, and still be the source of a reportable exposure.

The short version

HIPAA concerns protected health information, which is health information tied to an identifiable person. On a website, that combination shows up in more places than people expect:

  • A contact form that asks what the patient is coming in for
  • A chat widget that stores a transcript
  • An appointment request that names a procedure
  • Analytics that record the URL of a treatment page alongside an identifier
  • An advertising pixel that fires on a page a patient reached because of a condition

The last two are where most practices are actually exposed, and neither involves anyone typing anything.

Tracking is the real exposure

When a standard analytics or advertising tag fires on a page about a specific treatment, it can transmit the page URL, a persistent identifier, and sometimes an IP address to a third party. If that page indicates why the person is there, the combination can constitute protected health information leaving your control.

The uncomfortable part is that several of the largest advertising platforms will not sign a Business Associate Agreement. Without one, sending them that data is not something you can consent your way out of.

Practical consequences for a practice website:

Keep browser advertising tags off pages with health intent. Treatment pages, consultation pages, anything with a form where a patient describes a problem. Top-of-funnel pages are a different question.

Do not build remarketing audiences from treatment page visitors. An audience defined as "people who viewed the knee replacement page" is a list of people with an implied condition.

Do not upload patient lists for ad targeting. Customer Match from a patient roster is exactly what it looks like.

Know what your chat widget retains. Many store full transcripts with the vendor by default.

Forms and where they send data

A form is only as compliant as its destination. The questions to ask:

  1. Where does the submission actually go? An email inbox is usually not an appropriate destination for health details.
  2. Who is the vendor, and will they sign a BAA? If the answer is no, that vendor cannot receive PHI, regardless of how secure the connection is.
  3. Does the form ask more than it needs? The cheapest compliance improvement available is usually removing a field. A form that asks for a name, a phone number and a preferred time carries far less risk than one asking what is wrong.
  4. Is the confirmation email safe? A confirmation that names the procedure has just sent PHI over plain email.

The things that matter less than people think

HTTPS. Necessary, universal, and not sufficient. Encryption in transit says nothing about who receives the data at the other end.

A compliance badge. There is no certifying body. A badge is a graphic.

A privacy policy. Required and useful, and it does not make a non-compliant data flow compliant. It describes what you do; it does not change it.

Hosting matters, but not the way it is sold

Where the site is hosted matters only if PHI is stored there. A brochure site with no forms and no tracking has little to store. A site collecting appointment requests does, and the hosting provider becomes a business associate.

Not every host will sign a BAA. Some explicitly will not. Checking that before you build is far cheaper than moving afterwards.

A short audit you can run today

  • Open a treatment page and look at what loads in the network tab. Every third-party domain is a recipient.
  • Open each form and read the fields as if you were the person filling them in. Would a regulator call any answer health information?
  • List every vendor that touches a form submission. For each, ask whether a BAA exists.
  • Check your advertising accounts for any audience built from site behavior on treatment pages.

Most practices find something in under an hour. It is almost always tracking, and it is almost always fixable without touching the design.

Start Here

See Where Your Own Leads Are Leaking.

Get Your Free Audit →