Chykalophia Docs
Industries

Healthcare websites & HIPAA basics

What healthcare providers need to know about building a trustworthy website that handles patient information responsibly.

Difficulty
Beginner

Your website is often the first place a potential patient encounters your practice. It needs to convey trust, make it easy to book or contact you, and — critically — handle any patient information in a way that respects the law.

This guide covers what a healthcare website typically needs, what HIPAA means for your web presence, and the features we most commonly build for healthcare clients.

Quick summary

Healthcare websites must balance approachability with strict rules around patient data. If HIPAA applies to your practice, any form, chat widget, or booking system that collects patient health information falls under it. We build these systems with business associate agreements and compliant tooling in place. Read this guide, then see our deeper HIPAA explainer at HIPAA for websites.

We are not lawyers

This guide reflects our practical experience building healthcare websites. It is not legal advice. HIPAA compliance involves your entire organization, not just your website. Always consult a qualified healthcare attorney or compliance officer for your specific situation.

What healthcare websites need to do

Patients visiting your site want to answer a few questions quickly:

  • Are you accepting new patients?
  • What does the practice specialize in?
  • How do I book an appointment or get in touch?
  • Are you covered by my insurance?
  • Can I trust you?

A healthcare website that answers these questions clearly — without jargon, with real photos and bios, and with an easy path to contact — converts visitors into patients. Everything else is secondary.

Typical website goals

GoalWhat we build
New patient acquisitionClear service pages, call-to-action on every page
Appointment bookingOnline scheduling widget (HIPAA-compliant where needed)
Patient trustProvider bios, credentials, patient testimonials
Existing patient infoPatient portal links, forms, after-visit summaries
Local SEOLocation pages, Google Business Profile integration

What HIPAA means for your website

HIPAA (the Health Insurance Portability and Accountability Act) is a US federal law that protects patient health information. The parts relevant to your website are:

Protected Health Information (PHI) — any information that could identify a patient and relates to their health condition, treatment, or payment. A name combined with an appointment date is PHI. A contact form asking about symptoms is PHI.

Business Associate Agreement (BAA) — if a third-party tool processes PHI on your behalf (an email platform, a booking system, a chat tool), you need a signed BAA with that vendor. Not every vendor offers one. We only use HIPAA-eligible tools in healthcare projects, and we handle the BAA paperwork with you.

Where this commonly catches practices off-guard:

  • Standard contact forms — a general "contact us" form where someone describes their symptoms is collecting PHI. It needs to be handled by a HIPAA-compliant form and email provider.
  • Live chat widgets — many general-purpose chat tools will not sign a BAA. We check each vendor's current terms and use one that will.
  • Analytics and advertising trackers — a tracking script sends information about what a visitor looked at to the company that supplies it. On a healthcare site that can amount to disclosing patient information to a vendor you have no BAA with. HHS's Office for Civil Rights has published guidance specifically on tracking technologies (linked at the end of this guide), and it is worth reading before you add any tracker.
  • Email notifications — appointment confirmation emails sent through non-BAA providers are a violation if they include health details.
  • Online reviews & testimonials — you cannot publicly disclose that someone is your patient, even to respond to a review, without written authorization.

Don't assume your booking tool is compliant

Plenty of popular scheduling tools will not sign a BAA at all, and others only offer one on a specific plan. Vendors change these terms, so we check what a tool actually offers today — in writing — before we put it anywhere near patient information.

State-level rules

Medical privacy rules vary by state, and some add obligations on top of HIPAA. California, for example, has its own Confidentiality of Medical Information Act (Civil Code Part 2.6), which says a provider of health care "shall not disclose medical information regarding a patient of the provider of health care ... without first obtaining an authorization," subject to its own list of exceptions. Your compliance officer or attorney can tell you which state rules apply to you; we build to accommodate whatever they specify.

Always recommended

  • Provider bios with credentials and photos
  • Clear specialty and service pages
  • Prominent phone number and location
  • Online appointment request or booking
  • Insurance accepted (even a partial list)
  • Patient forms available to download or fill online
  • Accessible design (the ADA covers doctors' offices and private hospitals, and a separate HHS rule applies if you receive federal funding — see below)

Often recommended

  • Telehealth booking separate from in-person
  • Multi-location pages with unique SEO per location
  • Patient portal link (to your EHR system)
  • Blog or health education content
  • Before/after gallery (only with a signed HIPAA authorization — get legal sign-off)
  • Video introductions from providers

Tech & integrations we use

The right tools depend on your specialty and patient volume. Here are the categories and our typical choices:

CategoryOptions we work with
Appointment schedulingJane App, Spruce Health, or another tool that will sign a BAA
Patient intake formsJotform, Cognito Forms — on a plan that includes a BAA
TelehealthDoxy.me, Spruce Health
Email platformGoogle Workspace or Microsoft 365, with a BAA in place
AnalyticsA privacy-first tool, or analytics configured so it never sees patient information

We will not point a form, a booking flow, or an email notification at a vendor that will not give you a BAA. That rules out the free tiers of several popular marketing and CRM tools, so we check each vendor's current terms at the start of the project rather than assuming.

Common pitfalls

  • Launching with a generic contact form. Any form asking about conditions, medications, or symptoms is PHI. We scope this from day one.
  • Using stock photos of "doctors." Patients want to see your real team. Generic stock undermines trust immediately.
  • Ignoring mobile. A large share of patients will find you on a phone, and many will never open your site on a desktop. Your booking flow has to work perfectly on a small screen.
  • Forgetting accessibility. Two separate rules are in play. The ADA covers doctors' offices and private hospitals as places open to the public; the Department of Justice "does not have a regulation setting out detailed standards" for private businesses, but points to WCAG as helpful guidance. Separately, if your practice receives federal financial assistance from HHS, its Section 504 rule requires your web content to meet WCAG 2.1 Level A and AA — from 11 May 2027 if you have fifteen or more employees, and from 10 May 2028 if you have fewer, unless you can show that compliance would cause a fundamental alteration or undue burdens. Building to WCAG 2.1 AA now covers both, and it is the right thing to do for your patients either way.
  • Review responses that confirm someone is a patient. Never confirm or deny a patient relationship publicly online.

Common questions

Do I need a BAA with every tool on my site?

Only tools that process or store PHI need a BAA. A tool that never touches patient data — like your WordPress theme or a cookie consent banner — does not. The key question is: can this tool see or store information that identifies a patient and relates to their health? If yes, you need a BAA.

Is my existing website HIPAA-compliant?

Most websites built by general web agencies are not. Common issues include unencrypted contact forms, standard email notifications, and analytics tools without proper configuration. We offer a compliance review as part of any healthcare project.

Can we collect patient testimonials and publish them?

Yes — but only with a signed, written HIPAA authorization. The rule spells out what a valid authorization has to contain: a specific description of the information to be used, who may use it, who it may be disclosed to, the purpose, an expiration date or event, and the patient's signature and date. It also has to tell the patient how to revoke it. We can provide template language, but your attorney should review it.

What about the HIPAA 'right of access' — do we need a patient portal?

No — the right of access is about giving a patient a copy of their records when they ask, not about running a portal. Where a portal exists it is usually part of your EHR (electronic health records) system rather than your website, and your website just needs to link to it clearly. We integrate with whatever EHR you use.

We're a wellness business (yoga, massage, nutrition) — does HIPAA apply?

HIPAA applies to "covered entities" and their business associates. A covered entity is a health plan, a healthcare clearinghouse, or — in the rule's words — "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Those covered transactions are mostly insurance and billing ones, which is why many wellness businesses are not covered entities: if you never bill insurance electronically, HIPAA may not reach you. If you do, you likely are covered. Ask your attorney, and note that other privacy laws can still apply either way.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page