Search this site

Practice website compliance guide · September 24, 2026

HIPAA-compliant website: what applies to a practice site, page by page.

No website is HIPAA compliant by itself, and no builder, host, or badge can make it so. HIPAA regulates the practice, if it is a covered entity, and the vendors that handle protected health information for it. The website question is narrower and answerable: which pages and tools can see information about a visitor's health, and does every vendor that receives it have a business associate agreement and a permission to receive it?

This guide walks that question page by page, using the HHS, CMS, Google, and FTC documents as they read on September 24, 2026. It is general information, not legal advice.

Walk your own site

Four questions, in order, for every page type.

Answer them for the practice first, then for each kind of page. Both outcomes are shown so the path can be followed on paper or in a meeting with the privacy officer.

  1. 01

    Is the practice a HIPAA covered entity?

    CMS lists health plans, clearinghouses, and health care providers who submit HIPAA transactions, such as claims, electronically. Doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies that bill that way are covered.

    If yes

    The HIPAA Rules apply to protected health information the site collects or passes to a vendor. Go to question 2.

    If no

    HIPAA may not apply, but other law can, including the FTC Act and, for health apps and similar products, the FTC Health Breach Notification Rule. Confirm the status with counsel using the CMS decision tool rather than assuming it.

    CMS: Are You a Covered Entity?
  2. 02

    Does the page sit behind a login?

    Patient portals, telehealth rooms, and account-based bill pay are user-authenticated pages. HHS says tracking technologies on those pages generally have access to protected health information.

    If yes

    Only vendors that have signed a business associate agreement and have a Privacy Rule permission may receive data from these pages, and the pages must meet the Security Rule. Marketing pixels do not belong here.

    If no

    Go to question 3. The login and registration pages themselves are public, but HHS treats credentials or registration details typed there as individually identifiable health information.

    HHS OCR: Use of Online Tracking Technologies
  3. 03

    Can the visitor type or select something about themselves on this page?

    Appointment requests, symptom checkers, contact forms, and portal login or registration pages all collect what a person enters. HHS gives the example of a tracker picking up an email address or the reason for seeking care on an appointment page.

    If yes

    That entry is a disclosure of protected health information to any tool that sees it. The form processor, scheduler, chat tool, analytics tag, and ad pixel each need a business associate agreement and a permission, or they come off the page.

    If no

    Go to question 4.

    HHS OCR: Use of Online Tracking Technologies
  4. 04

    Does the page address a condition, treatment, or provider that a visitor could be reading about for their own care?

    This is the part a court changed. On June 20, 2024, the U.S. District Court for the Northern District of Texas, in American Hospital Association v. Becerra, vacated the bulletin to the extent it said HIPAA is triggered when a tracker connects an IP address with a visit to an unauthenticated public page about specific health conditions or health care providers. HHS says it is evaluating its next steps.

    If yes

    Keep a named list of every third-party script on condition, procedure, and physician pages, with a reason for each and a way to remove it in one change. The order narrowed federal guidance. It did not change the rest of the bulletin, the practice's own privacy promises, or what the page says about the person reading it.

    If no

    General pages such as hours, directions, careers, and policies are the pages HHS itself uses as examples where trackers do not see protected health information. Standard analytics can run there, on a documented list.

    HHS OCR bulletin, court-order notice at the top

Not sure about question one? CMS publishes a covered entity decision tool for providers, plans, and clearinghouses.

Page by page

What a third-party script can see on each kind of practice page.

The same tag behaves differently on a careers page and on a scheduling page. This is the table to walk with whoever manages the practice's tag manager.

Practice page types, what a third-party script can see, what the HHS bulletin says, and the build decision
Page typeWhat a script can seeWhat HHS saysBuild decision
Hours, directions, careers, policiesPage address, IP address, device detailsHHS example: a visit to a job-postings or visiting-hours page does not disclose PHI, even if the visitor could be identified.Analytics may run from a documented script list.
Condition and procedure pagesA page address that names the condition, plus IP address and deviceThe passage covering an IP address plus a visit to these pages was vacated on June 20, 2024. HHS is evaluating next steps.Named, justified, removable scripts only. No ad pixels or session replay by default.
Physician and location pagesWhich provider or office the visitor looked atThe same vacated passage covered public pages listing health care providers.Same named-script rule as condition pages.
Appointment request or online schedulingName, email, phone, reason for the visit, requested dateA tracker collecting an email address or the reason for seeking care here is disclosing PHI, and the HIPAA Rules apply.Scheduler under a business associate agreement. No third-party trackers on the form or its confirmation page.
Contact formWhatever the form asks, and whatever people type anywayIndividually identifiable health information collected on a regulated entity's site generally is PHI.Ask for contact details only, say not to include medical details, and route submissions to a processor that signs a business associate agreement.
Symptom checker or quizSymptoms and answers the visitor entersHHS says trackers on a public page with a symptom-checker tool may have access to PHI, such as symptoms entered for a health analysis.Leave it off a marketing site unless the tool is covered and has a clinical owner.
Portal login and registrationCredentials, name, email addressInformation entered there is individually identifiable health information. Trackers that collect it are disclosing PHI.No third-party trackers on login or registration pages.
Patient portal after loginDiagnoses, prescriptions, messages, billingTracking on user-authenticated pages generally has access to PHI.Covered vendors only, with Security Rule access, audit, and encryption controls.
Online bill payName, account, amounts owedPayment for health care is part of the definition of individually identifiable health information.Review the payment vendor's role with counsel before launch. No marketing trackers on payment pages.

Source for every row: the HHS OCR bulletin on online tracking technologies, including the court-order notice at its top. HHS last reviewed its content on June 26, 2024.

Business associate agreements

Ask each vendor one question: will it touch PHI, and will it sign?

HHS says a vendor that creates, receives, maintains, or transmits protected health information for the practice is a business associate whether or not an agreement exists, and that signing one does not make a vendor a business associate if it does not meet the definition. The role decides, not the paperwork.

Website host, database, or cloud storage

Becomes a business associate: When the site stores electronic PHI: saved form submissions, a portal, uploaded files.

HHS says a cloud provider that stores ePHI is a business associate even if the data is encrypted and it holds no key. The conduit exception covers transmission-only services, not storage.

HHS: HIPAA and cloud computing

Form processor, scheduler, or chat

Becomes a business associate: When a visitor can submit identifiable health information through it.

HHS's own example: a clinic website that sends appointment details and an IP address to a tracking vendor makes that vendor a business associate, and an agreement is required.

HHS OCR tracking bulletin

Web analytics

Becomes a business associate: When the tag can receive PHI from the pages it runs on.

Google says it does not offer business associate agreements for Google Analytics, that HIPAA-regulated customers must not expose PHI to it, and that authenticated pages should not carry its tags.

Google: HIPAA and Google Analytics

Advertising and social pixels

Becomes a business associate: When the pixel runs on a page that can reveal PHI.

HHS says disclosing PHI to tracking vendors for marketing without a HIPAA-compliant authorization is an impermissible disclosure.

HHS OCR tracking bulletin

Email and office suite

Becomes a business associate: When staff email or store PHI in it, including form notifications.

Google offers a business associate amendment for listed Workspace services, which an administrator must accept before PHI is used. Third-party add-ons are not covered by it.

Google Workspace: HIPAA compliance

Customer data platform

Becomes a business associate: When the practice wants measurement from tools that will not sign an agreement.

HHS describes a route: a data platform that signs a business associate agreement de-identifies the tracking data and passes only de-identified data on.

HHS OCR tracking bulletin

Shortcuts that do not work

What a banner, a badge, or a promise cannot do.

  • A cookie banner is not an authorization

    HHS says banners that ask visitors to accept or reject cookies do not constitute a valid HIPAA authorization.

    HHS OCR tracking bulletin
  • A privacy-policy sentence is not a permission

    HHS says the Privacy Rule does not permit disclosures to a tracking vendor just because the privacy policy or terms of use announce them.

    HHS OCR tracking bulletin
  • A vendor's promise to strip PHI later is not enough

    HHS says it is insufficient for a tracking vendor to agree to remove or de-identify PHI after receiving it. The agreement and the permission have to exist before the disclosure.

    HHS OCR tracking bulletin
  • A compliance seal is not compliance

    In its first Health Breach Notification Rule case, announced February 1, 2023, the FTC said GoodRx displayed a seal falsely suggesting HIPAA compliance. GoodRx agreed to a $1.5 million civil penalty.

    FTC: GoodRx enforcement action
  • Encryption does not end a vendor's role

    A host that stores encrypted ePHI without the key is still a business associate, according to HHS. Encryption lowers risk. It does not replace the agreement or the Security Rule.

    HHS: HIPAA and cloud computing
  • No government certificate exists

    HHS says the Office for Civil Rights does not endorse, certify, or recommend specific technology or products. A vendor badge is the vendor's own claim.

    HHS: HIPAA and cloud computing

When the practice is not a covered entity

Outside HIPAA is not outside the law.

A cash-pay clinic, a wellness brand, or a practice app may fall outside HIPAA. The Federal Trade Commission's Health Breach Notification Rule requires vendors of personal health records and related entities to notify consumers after a breach of unsecured health information. The FTC finalized changes on April 26, 2024 that apply the rule to health apps and similar technologies not covered by HIPAA, count an unauthorized disclosure as a breach, and require notice to the FTC at the same time as individuals for breaches of 500 or more people, no later than 60 calendar days after discovery. On September 9, 2026, the FTC withdrew its 2021 policy statement on health apps as obsolete, because the 2024 rule already covers them.

Privacy promises carry weight on their own. On March 2, 2023, the FTC announced a proposed order requiring BetterHelp to pay $7.8 million after it shared email addresses, IP addresses, and health questionnaire answers with Facebook, Snapchat, Criteo, and Pinterest for advertising, having promised to keep them private.

The website's share of the work

What a build can do, and what it cannot.

LA Digital Systems designs practice websites with these decisions made before launch. The other half belongs to the practice, its counsel, and its vendors, and no page on this site claims or certifies HIPAA compliance for any site, vendor, or integration.

The build can

  • List every third-party request each page type makes, with an owner and a reason, and keep that list with the release.
  • Keep the first message to contact details and say plainly not to send medical details.
  • Ship login, registration, form, and confirmation pages with no third-party trackers.
  • Choose the host, form processor, and scheduler after confirming which of them will sign a business associate agreement.
  • Make any script removable in one change, so a new ruling does not mean a rebuild.
  • Load each page type after launch and record which third-party requests fire, instead of trusting the tag manager.

The build cannot

  • Decide whether the practice is a covered entity.
  • Sign a business associate agreement on the practice's behalf.
  • Perform the Security Rule risk analysis the practice owns.
  • Make a vendor compliant, or make a noncompliant tool safe with a banner.
  • Replace the practice's counsel or privacy officer.

The HIPAA Security Rule update HHS proposed on December 27, 2024 is still a proposal; HHS says the current Security Rule remains in effect. To see the public side of a route-first practice structure, inspect the Innovative Urology example. It shows public information architecture and patient routes. It does not prove HIPAA compliance, and nothing here claims it does.

HIPAA-compliant website questions

Short answers, with the source behind each one.

01

Does a website need to be HIPAA compliant?

HIPAA applies to covered entities and their business associates, not to websites as such. If the practice is a covered entity, protected health information its site collects or passes to vendors falls under the HIPAA Rules. HHS says that when tracking on a public page has no access to that information, as on many hours or careers pages, its use is not regulated by the HIPAA Rules.

02

How do you make a website HIPAA compliant?

You make the practice's handling of the site's data compliant. Walk each page type, remove or cover every tool that can see protected health information with a business associate agreement and a Privacy Rule permission, protect stored ePHI under the Security Rule, and include the website in the practice's risk analysis. No builder, host, or badge does this on its own.

03

How can I tell whether my practice website is HIPAA compliant?

There is no certificate to look for, because HHS does not certify products. Open each page type with the browser's network panel and list every third-party request. Match each vendor to a signed business associate agreement, or remove it from pages that can reveal health information. Confirm the forms and scheduler are covered, the login pages carry no trackers, and the risk analysis names the site.

04

Can Google be HIPAA compliant?

It depends on the product. Google says it does not offer business associate agreements for Google Analytics and that HIPAA-regulated customers must not expose protected health information to it. For Google Workspace and Cloud Identity, Google offers a business associate amendment covering listed services, which an administrator must accept before using PHI. Third-party add-ons are outside that agreement.

05

Is a cookie consent banner enough for tracking pixels?

No. HHS says website banners that ask users to accept or reject cookies do not constitute a valid HIPAA authorization. If a pixel can receive protected health information, the vendor needs a business associate agreement and a permission, or the individual's HIPAA-compliant authorization, before the disclosure.

06

Did the 2024 court ruling end the HHS tracking guidance?

No. The June 20, 2024 order in American Hospital Association v. Becerra vacated one part: the position that an IP address combined with a visit to an unauthenticated page about specific conditions or providers triggers HIPAA. The guidance on logged-in pages, forms, scheduling, login and registration pages, and mobile apps remains on the HHS page, which says HHS is evaluating its next steps.

07

Does a brochure site with no forms need HIPAA-compliant hosting?

If the site stores no electronic protected health information, the host may never handle any. Once form submissions, uploads, or portal data are stored on the host or its database, HHS treats that host as a business associate, even when the data is encrypted and the host has no key.

Where the design work lives

Build the practice site with the script list written first.

The page inventory, build paths, and release checks for a practice site are on the medical and healthcare website design page. The public intake route remains intentionally unavailable while routing and operating boundaries are finalized, so nothing on this site asks for personal or medical information.