HIPAA and your practice website: what actually applies

A marketing site is usually not a HIPAA problem, until it collects the wrong thing or loads the wrong script. Here is where the line sits.

The GrowMyCare team7 min read

This article is general information, not legal advice. HIPAA is fact-specific and the consequences of getting it wrong are significant. Talk to a healthcare attorney about your particular situation.

Most practice owners hold one of two beliefs about HIPAA and their website, and both are wrong. Either the whole site is treated as a compliance minefield where nothing can be published, or it is assumed that marketing is exempt and anything goes.

The reality is narrower and more useful: a marketing website is generally not subject to HIPAA until it touches protected health information. What matters is knowing exactly where that line is.

What counts as protected health information

PHI is individually identifiable health information held or transmitted by a covered entity. The key word is identifiable, it is the combination of a person’s identity with something about their health.

A name and email address on a contact form asking about your services is generally not PHI. The same name and email attached to a message describing symptoms is.

This is why the boundary is drawn at what your forms invite, not merely what you intend to collect.

Contact forms: the most common mistake

An open-ended field labelled “How can we help?” on a medical practice site will receive clinical detail. Patients describe symptoms because that is what they are thinking about. Once that arrives in your inbox through an ordinary form service, PHI has been transmitted through a system you likely have no Business Associate Agreement with.

Two ways to handle it:

Keep the marketing form non-clinical. Ask for name, contact details and a general enquiry, and state explicitly on the form not to include health details. This is the approach we take on the form on this site.

Or use a compliant form provider. If you genuinely need clinical detail before a visit, that form belongs in a HIPAA-compliant platform covered by a signed BAA, not a general website form tool.

The failure mode is having neither: an open clinical field flowing into an ordinary inbox.

Analytics and tracking pixels

This is where the most significant enforcement activity has occurred, and where most practices have exposure without realising it.

When a visitor lands on a page about a specific condition and an advertising pixel fires, that third party receives the page URL along with an identifier. The combination can constitute a disclosure of PHI, the inference being that this identifiable person was researching that condition.

Practical guidance:

  • Do not put advertising or social media pixels on pages about specific conditions or treatments
  • Prefer privacy-respecting analytics that do not use cookies or build cross-site profiles
  • If you use conventional analytics, exclude condition-specific pages and disable any feature that captures form contents or full URLs with parameters
  • Audit what is actually loading, chat widgets and review tools frequently include tracking nobody agreed to

Reviews and testimonials

You cannot confirm a treatment relationship publicly without authorisation. That constrains two things.

Responding to reviews. Never confirm, deny, or discuss any clinical detail, including confirming that the person was a patient. Acknowledge generally and move it offline.

Publishing testimonials. A patient testimonial naming the person and their treatment is a disclosure. It needs written HIPAA authorisation, which is a specific document, not a verbal agreement or a casual reply to an email.

There is a second constraint that has nothing to do with HIPAA: the FTC’s rule on consumer reviews and testimonials makes fabricated testimonials federally actionable with civil penalties. Both rules point the same way, real testimonials, properly authorised in writing, or none.

Business Associate Agreements

A BAA is required with any vendor that creates, receives, maintains or transmits PHI on your behalf. For a typical practice website, ask about it for:

  • Form and intake providers, if the forms collect anything clinical
  • Scheduling systems that store appointment reasons
  • Hosting, if PHI is ever stored on the server
  • Email providers, if patients email clinical information
  • Any developer or agency with access to systems containing PHI

A vendor that will not sign a BAA is telling you something useful.

The practical summary

A marketing website that publishes information about your practice, collects only non-clinical enquiries and loads no advertising trackers on condition pages is generally straightforward.

Exposure comes from four places, and they are all avoidable:

  1. Open-ended clinical fields flowing into non-compliant systems
  2. Advertising and analytics trackers on condition-specific pages
  3. Testimonials published without written authorisation
  4. Review responses that confirm a treatment relationship

Fix those four and the website side of HIPAA is mostly handled. Then talk to an attorney about the rest of your operation, which is where the harder questions live.

Find out what is costing you patients

Fifteen minutes on a call. We look at your current site and rankings live and tell you what we'd fix first, whether or not you hire us.

Book a free 15-min call