Healthcare websites & HIPAA basics
What healthcare providers need to know about building a trustworthy website that handles patient information responsibly.
- Difficulty
- Beginner
Your website is often the first place a potential patient encounters your practice. It needs to convey trust, make it easy to book or contact you, and — critically — handle any patient information in a way that respects the law.
This guide covers what a healthcare website typically needs, what HIPAA means for your web presence, and the features we most commonly build for healthcare clients.
Quick summary
Healthcare websites must balance approachability with strict rules around patient data. If HIPAA applies to your practice, any form, chat widget, or booking system that collects patient health information falls under it. We build these systems with business associate agreements and compliant tooling in place. Read this guide, then see our deeper HIPAA explainer at HIPAA for websites.
We are not lawyers
This guide reflects our practical experience building healthcare websites. It is not legal advice. HIPAA compliance involves your entire organization, not just your website. Always consult a qualified healthcare attorney or compliance officer for your specific situation.
What healthcare websites need to do
Patients visiting your site want to answer a few questions quickly:
- Are you accepting new patients?
- What does the practice specialize in?
- How do I book an appointment or get in touch?
- Are you covered by my insurance?
- Can I trust you?
A healthcare website that answers these questions clearly — without jargon, with real photos and bios, and with an easy path to contact — converts visitors into patients. Everything else is secondary.
Typical website goals
| Goal | What we build |
|---|---|
| New patient acquisition | Clear service pages, call-to-action on every page |
| Appointment booking | Online scheduling widget (HIPAA-compliant where needed) |
| Patient trust | Provider bios, credentials, patient testimonials |
| Existing patient info | Patient portal links, forms, after-visit summaries |
| Local SEO | Location pages, Google Business Profile integration |
Compliance & legal considerations
What HIPAA means for your website
HIPAA (the Health Insurance Portability and Accountability Act) is a US federal law that protects patient health information. The parts relevant to your website are:
Protected Health Information (PHI) — any information that could identify a patient and relates to their health condition, treatment, or payment. A name combined with an appointment date is PHI. A contact form asking about symptoms is PHI.
Business Associate Agreement (BAA) — if a third-party tool processes PHI on your behalf (an email platform, a booking system, a chat tool), you need a signed BAA with that vendor. Not every vendor offers one. We only use HIPAA-eligible tools in healthcare projects, and we handle the BAA paperwork with you.
Where this commonly catches practices off-guard:
- Standard contact forms — a general "contact us" form where someone describes their symptoms is collecting PHI. It needs to be handled by a HIPAA-compliant form and email provider.
- Live chat widgets — many general-purpose chat tools will not sign a BAA. We check each vendor's current terms and use one that will.
- Analytics and advertising trackers — a tracking script sends information about what a visitor looked at to the company that supplies it. On a healthcare site that can amount to disclosing patient information to a vendor you have no BAA with. HHS's Office for Civil Rights has published guidance specifically on tracking technologies (linked at the end of this guide), and it is worth reading before you add any tracker.
- Email notifications — appointment confirmation emails sent through non-BAA providers are a violation if they include health details.
- Online reviews & testimonials — you cannot publicly disclose that someone is your patient, even to respond to a review, without written authorization.
Don't assume your booking tool is compliant
Plenty of popular scheduling tools will not sign a BAA at all, and others only offer one on a specific plan. Vendors change these terms, so we check what a tool actually offers today — in writing — before we put it anywhere near patient information.
State-level rules
Medical privacy rules vary by state, and some add obligations on top of HIPAA. California, for example, has its own Confidentiality of Medical Information Act (Civil Code Part 2.6), which says a provider of health care "shall not disclose medical information regarding a patient of the provider of health care ... without first obtaining an authorization," subject to its own list of exceptions. Your compliance officer or attorney can tell you which state rules apply to you; we build to accommodate whatever they specify.
Recommended features
Always recommended
- Provider bios with credentials and photos
- Clear specialty and service pages
- Prominent phone number and location
- Online appointment request or booking
- Insurance accepted (even a partial list)
- Patient forms available to download or fill online
- Accessible design (the ADA covers doctors' offices and private hospitals, and a separate HHS rule applies if you receive federal funding — see below)
Often recommended
- Telehealth booking separate from in-person
- Multi-location pages with unique SEO per location
- Patient portal link (to your EHR system)
- Blog or health education content
- Before/after gallery (only with a signed HIPAA authorization — get legal sign-off)
- Video introductions from providers
Tech & integrations we use
The right tools depend on your specialty and patient volume. Here are the categories and our typical choices:
| Category | Options we work with |
|---|---|
| Appointment scheduling | Jane App, Spruce Health, or another tool that will sign a BAA |
| Patient intake forms | Jotform, Cognito Forms — on a plan that includes a BAA |
| Telehealth | Doxy.me, Spruce Health |
| Email platform | Google Workspace or Microsoft 365, with a BAA in place |
| Analytics | A privacy-first tool, or analytics configured so it never sees patient information |
We will not point a form, a booking flow, or an email notification at a vendor that will not give you a BAA. That rules out the free tiers of several popular marketing and CRM tools, so we check each vendor's current terms at the start of the project rather than assuming.
Common pitfalls
- Launching with a generic contact form. Any form asking about conditions, medications, or symptoms is PHI. We scope this from day one.
- Using stock photos of "doctors." Patients want to see your real team. Generic stock undermines trust immediately.
- Ignoring mobile. A large share of patients will find you on a phone, and many will never open your site on a desktop. Your booking flow has to work perfectly on a small screen.
- Forgetting accessibility. Two separate rules are in play. The ADA covers doctors' offices and private hospitals as places open to the public; the Department of Justice "does not have a regulation setting out detailed standards" for private businesses, but points to WCAG as helpful guidance. Separately, if your practice receives federal financial assistance from HHS, its Section 504 rule requires your web content to meet WCAG 2.1 Level A and AA — from 11 May 2027 if you have fifteen or more employees, and from 10 May 2028 if you have fewer, unless you can show that compliance would cause a fundamental alteration or undue burdens. Building to WCAG 2.1 AA now covers both, and it is the right thing to do for your patients either way.
- Review responses that confirm someone is a patient. Never confirm or deny a patient relationship publicly online.
Common questions
Do I need a BAA with every tool on my site?
Only tools that process or store PHI need a BAA. A tool that never touches patient data — like your WordPress theme or a cookie consent banner — does not. The key question is: can this tool see or store information that identifies a patient and relates to their health? If yes, you need a BAA.
Is my existing website HIPAA-compliant?
Most websites built by general web agencies are not. Common issues include unencrypted contact forms, standard email notifications, and analytics tools without proper configuration. We offer a compliance review as part of any healthcare project.
Can we collect patient testimonials and publish them?
Yes — but only with a signed, written HIPAA authorization. The rule spells out what a valid authorization has to contain: a specific description of the information to be used, who may use it, who it may be disclosed to, the purpose, an expiration date or event, and the patient's signature and date. It also has to tell the patient how to revoke it. We can provide template language, but your attorney should review it.
What about the HIPAA 'right of access' — do we need a patient portal?
No — the right of access is about giving a patient a copy of their records when they ask, not about running a portal. Where a portal exists it is usually part of your EHR (electronic health records) system rather than your website, and your website just needs to link to it clearly. We integrate with whatever EHR you use.
We're a wellness business (yoga, massage, nutrition) — does HIPAA apply?
HIPAA applies to "covered entities" and their business associates. A covered entity is a health plan, a healthcare clearinghouse, or — in the rule's words — "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Those covered transactions are mostly insurance and billing ones, which is why many wellness businesses are not covered entities: if you never bill insurance electronically, HIPAA may not reach you. If you do, you likely are covered. Ask your attorney, and note that other privacy laws can still apply either way.
Related guides
- HIPAA for websites — the full guide
- Compliance — all the rules that touch a website
- ADA & WCAG: web accessibility compliance
- Web accessibility basics
- Local SEO basics
- Data privacy basics for your business
- Working with contact forms
- Accepting payments online
Need a hand?
Learn more
- HHS: HIPAA for Professionals — the official US Department of Health & Human Services HIPAA resource
- HHS: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates — the Office for Civil Rights bulletin on analytics and pixel trackers. Read the note at the top: in June 2024 a federal court vacated the part of this bulletin that treated an IP address plus a visit to a public page about a health condition as enough to trigger HIPAA, and HHS says it is "evaluating its next steps". The rest of the bulletin still stands
- ADA.gov: Guidance on Web Accessibility and the ADA — the Department of Justice's own guidance on websites and the ADA
Last updated