Compliance
What Is a HIPAA-Compliant Website? A Guide for Dental and Medical Practices

"HIPAA compliant" gets thrown around a lot. Here is what it actually means for a practice website, when it applies, and what makes a site genuinely safe.
If you run a dental or medical practice, you have almost certainly been told that your website needs to be "HIPAA compliant." It is one of the most common phrases in healthcare marketing, and also one of the most misunderstood. Some vendors use it as a selling point without explaining what it means. Others wave it away entirely. Both leave you exposed.
This guide explains, in plain English, what HIPAA actually is, when it applies to a website, and what genuinely makes a practice website HIPAA-conscious. No legalese, no scare tactics. Just what a practice owner needs to understand to ask the right questions and protect the trust patients place in you.
What HIPAA actually is
HIPAA is the Health Insurance Portability and Accountability Act, a federal law first passed in 1996. For the purposes of your website, two parts of it matter most: the Privacy Rule, which governs how protected health information can be used and shared, and the Security Rule, which sets standards for protecting that information when it is stored or transmitted electronically. You can read the government's own overview on the HHS.gov HIPAA site.
HIPAA applies to two kinds of organizations. Covered entities are healthcare providers, health plans, and clearinghouses. Your practice is almost certainly a covered entity. Business associates are the outside companies that handle protected health information on your behalf, which can include your web host, your form software, your email provider, and sometimes the person who builds and maintains your site. The details for both are laid out on the HHS guidance for professionals.
What counts as protected health information
Protected health information, or PHI, is any information that connects a person to their health, care, or payment for care. On a practice website, PHI shows up more often than people expect:
- A patient's name and phone number submitted alongside a reason for their visit.
- An appointment request that mentions a symptom, condition, or procedure.
- A new-patient intake form with medical history, insurance, or medications.
- A message through a contact form that says "I think I chipped a tooth" and includes contact details.
- Anything uploaded to a patient portal, from x-rays to insurance cards.
The moment your website collects information like this, you are handling PHI, and HIPAA considerations apply to how that data moves and where it lands.
Is a website even covered by HIPAA?
This is where the nuance lives, and where a lot of confusion comes from. Not every page on the internet is subject to HIPAA. A simple brochure site that only lists your services, hours, and a phone number does not itself collect PHI, so the law is not really engaged by the marketing content alone.
But most practice websites do more than that. They have an appointment request form, a contact form, a chat widget, or a patient portal. They often connect to scheduling, email, or practice-management systems. The instant a visitor can type health-related information into your site, or your site talks to a system that stores it, you have crossed from "brochure" into "handling PHI," and the Security Rule's expectations come with it.
The question is not whether your website is HIPAA compliant in the abstract. It is whether every place a patient's information travels is protected.
What makes a website HIPAA-conscious
There is no single switch that makes a site compliant. It is a series of practical safeguards working together. Here are the ones that matter most for a practice.
Encryption in transit (HTTPS everywhere)
Every page, and especially every form, should load over HTTPS so that information is encrypted as it travels between the patient's browser and your server. This is the baseline, and the HIPAA Security Rule treats transmission security as a core safeguard. If any part of your site still loads over plain HTTP, that is a red flag.
Where form data actually goes
This is the safeguard most often gotten wrong. Many websites are set up to simply email form submissions to the front desk. Standard email is not encrypted end to end, which means a patient's health details can travel and sit in inboxes in the clear. A HIPAA-conscious setup delivers submissions to encrypted, access-controlled storage, not a plain email blast. Ask specifically: when a patient submits a form, where does that data go, and is it encrypted the whole way?
Business Associate Agreements (BAAs)
Any outside vendor that touches PHI on your behalf should sign a Business Associate Agreement, a contract that legally binds them to protect that data. That can include your hosting provider, your form or scheduling tool, and your email service. If a vendor cannot or will not sign a BAA, they should not be handling patient information, no matter what their marketing says.
Access controls and audit trails
Only the people who need patient information should be able to reach it, each with their own login, and the system should keep a record of who accessed what. This limits both accidental exposure and the damage if a single account is ever compromised.
Analytics and tracking pixels
This one surprises people. Standard analytics and advertising trackers can quietly transmit information about what a visitor does on your site to third parties. HHS has published guidance warning that, on healthcare sites, these tracking technologies can end up sharing PHI without proper agreements in place. On pages that collect patient information, tracking has to be configured carefully, or kept off entirely. When in doubt, review the HHS professional guidance.
Data minimization
The safest data is the data you never collected. Forms should ask for what you genuinely need to serve the patient and nothing more. Every extra field is one more piece of sensitive information to protect.
Common misconceptions
- "The padlock means my site is HIPAA compliant." The padlock only means the connection is encrypted. That is necessary, but it is a small part of the whole picture.
- "My host says they are HIPAA compliant, so I am covered." Compliant infrastructure is a good start, but compliance depends on how the whole site is configured, whether BAAs are signed, and how data is handled day to day.
- "There is an official HIPAA certification." There is not. The government does not certify or approve websites as HIPAA compliant. Any badge claiming otherwise is marketing, not a legal seal.
- "HIPAA does not apply to a small practice." It applies regardless of size. A solo practice is just as much a covered entity as a large group.
A practical checklist: what to ask your web person
You do not need to become a compliance expert. You need a builder who takes this seriously and can answer plainly. Bring these questions:
- Does every page, and every form, load over HTTPS?
- When a patient submits a form, exactly where does that data go, and is it encrypted the entire way?
- Are form submissions stored in secure, access-controlled storage, or just emailed to the front desk?
- Which vendors touch patient data, and have they signed Business Associate Agreements?
- How is analytics or ad tracking handled on pages that collect patient information?
- Who can access submitted patient data, and is that access logged?
If the answers are vague, that tells you something. A security-minded partner will welcome these questions, because they have already thought them through. You can see how we approach this on our security and compliance page, and there is a companion guide on what HIPAA means for forms, analytics, and chat if you want to go deeper on those specifics.
Built in, not bolted on
HIPAA is not a badge you buy or a box you check once. It is a set of habits and safeguards that protect the trust your patients hand you the moment they type their name into your website. Getting it right does not have to be complicated, but it does have to be intentional, built in from the start rather than bolted on later.
If you are not sure where your current site stands, that is worth finding out. You can book a free call to talk it through, or get a tailored recommendation for your specific practice. No pressure, and no jargon.
Share this article
Jody Hartwell
Jody writes about building secure, modern, HIPAA-conscious websites and better patient experiences for dental, medical, and legal practices.
Trustform Digital
Secure, HIPAA-conscious websites that book more patients
We design fast, secure websites and local SEO for dental, medical, and legal practices, built and protected by a CISSP-certified developer. From dental website design and medical practice websites to local SEO and HIPAA-conscious patient tools, we build around exactly what your practice needs.


