HIPAA Compliant Website Design

Most healthcare websites are not HIPAA compliant, and most owners have never been told. If your site collects anything from a patient, these are the parts that have to be right.

Get a free compliance audit Talk to us

The short version

A Website Becomes a HIPAA Problem the Moment It Collects Something

A brochure site with no forms carries little risk. The moment there is an appointment request, a contact form asking about symptoms, a patient portal login, or a chat widget, protected health information is in play and the rules apply.

$137,886 minimum annual penalty tier for wilful neglect left uncorrected
Per record breach notification obligations scale with the number of individuals affected
Your host without a signed BAA, standard hosting is not compliant no matter how the site is built

What we build

The Five Things That Have to Be Right

Each of these is a place we have found real healthcare sites failing.

Hosting

A Signed Business Associate Agreement

If your host can access servers holding patient data, they are a business associate and need a signed BAA. Most budget shared hosting will not sign one. This is the single most common failure, and no amount of good development fixes it.

Forms

Encrypted Submission and Storage

A form that emails patient details in plain text is a breach waiting to be discovered. Submissions need encryption in transit and at rest, restricted access, and a retention policy that actually deletes things.

Notice

A Published Notice of Privacy Practices

A covered entity describing its services online needs an NPP published and reachable. Most healthcare sites we audit do not have one. We draft it and publish it properly rather than linking a PDF nobody can open on a phone.

Tracking

Analytics That Never See Patient Data

Third-party trackers on pages behind a patient login, or on pages revealing a condition, can disclose PHI to a vendor you never signed an agreement with. We configure analytics so it measures traffic without ever touching identifiable data.

The fifth is access control: who on your team can read form submissions, whether that is logged, and what happens when somebody leaves. It is the least visible of the five and the most often ignored.

Why us

We Already Do This Work

Our founder has spent 2+ years working part-time as a developer for a US healthcare web company, building and maintaining freestanding emergency-room and hospital websites. Compliance is not a checklist we downloaded, it is the environment those sites are built in.

  • Notices of Privacy Practices drafted and published
  • Forms rebuilt with encrypted submission and controlled access
  • Tracking reconfigured so no patient data reaches a third party
  • Hosting moved where a BAA can actually be signed
  • Advertising claims reviewed against state and federal rules
Get a free compliance audit

What we are not

We are not attorneys, and we do not certify compliance. Nobody building a website can. What we do is know where the exposure sits, build so that it is avoided, and route the judgement calls to your compliance advisor.

Any agency promising you "HIPAA certified" hosting or a "HIPAA compliant" plugin is selling something that does not exist. Compliance is how the whole system is operated, not a product you buy.

FAQ

HIPAA and Websites: Common Questions

Is WordPress HIPAA compliant?

WordPress itself is neither compliant nor non-compliant, because compliance is a property of the whole system rather than the software. A WordPress site can be run compliantly with the right hosting, a signed BAA, encrypted forms, controlled access, and correct tracking. The same site on standard shared hosting with a plain-text contact form is not.

Does a brochure site with no forms need to be HIPAA compliant?

If it collects nothing from patients, the exposure is low. But a Notice of Privacy Practices is still expected of a covered entity describing its services online, and most sites acquire a form eventually. It is far cheaper to build it right than to retrofit after a form appears.

Can we keep using Google Analytics?

Usually yes, with care. The risk is tracking on pages that reveal health information about an identifiable person, such as anything behind a patient login or a page tied to a specific condition. We configure analytics to exclude those contexts so you keep your traffic data without disclosing anything.

Our current host says they are HIPAA compliant. Is that enough?

Ask them to sign a Business Associate Agreement. If they will not, the claim is marketing rather than a legal position. The signed BAA is what actually matters, and it is a short conversation that tells you where you stand.

How much does this cost?

It depends entirely on what is already in place. Some sites need a notice published and a form rebuilt. Others need to move hosting. The free audit tells you which, and we quote from there with no obligation.

Find Out Where You Stand

A free audit covering hosting, forms, notices, and tracking, with a plain list of what needs fixing.

Get a free compliance audit