Trustform Digital
All articles

Compliance

What Is a HIPAA-Compliant Website? A Guide for Dental and Medical Practices

By Jody Hartwell· May 11, 2026· 9 min read
What Is a HIPAA-Compliant Website? A Guide for Dental and Medical Practices

"HIPAA compliant" gets thrown around a lot. Here is what it actually means for a practice website, when it applies, and what makes a site genuinely safe.

If you run a dental or medical practice, you have almost certainly been told that your website needs to be "HIPAA compliant." It is one of the most common phrases in healthcare marketing, and also one of the most misunderstood. Some vendors use it as a selling point without explaining what it means. Others wave it away entirely. Both leave you exposed.

This guide explains, in plain English, what HIPAA actually is, when it applies to a website, and what genuinely makes a practice website HIPAA-conscious. No legalese, no scare tactics. Just what a practice owner needs to understand to ask the right questions and protect the trust patients place in you.

What HIPAA actually is

HIPAA is the Health Insurance Portability and Accountability Act, a federal law first passed in 1996. For the purposes of your website, two parts of it matter most: the Privacy Rule, which governs how protected health information can be used and shared, and the Security Rule, which sets standards for protecting that information when it is stored or transmitted electronically. You can read the government's own overview on the HHS.gov HIPAA site.

HIPAA applies to two kinds of organizations. Covered entities are healthcare providers, health plans, and clearinghouses. Your practice is almost certainly a covered entity. Business associates are the outside companies that handle protected health information on your behalf, which can include your web host, your form software, your email provider, and sometimes the person who builds and maintains your site. The details for both are laid out on the HHS guidance for professionals.

What counts as protected health information

Protected health information, or PHI, is any information that connects a person to their health, care, or payment for care. On a practice website, PHI shows up more often than people expect:

  • A patient's name and phone number submitted alongside a reason for their visit.
  • An appointment request that mentions a symptom, condition, or procedure.
  • A new-patient intake form with medical history, insurance, or medications.
  • A message through a contact form that says "I think I chipped a tooth" and includes contact details.
  • Anything uploaded to a patient portal, from x-rays to insurance cards.

The moment your website collects information like this, you are handling PHI, and HIPAA considerations apply to how that data moves and where it lands.

Is a website even covered by HIPAA?

This is where the nuance lives, and where a lot of confusion comes from. Not every page on the internet is subject to HIPAA. A simple brochure site that only lists your services, hours, and a phone number does not itself collect PHI, so the law is not really engaged by the marketing content alone.

But most practice websites do more than that. They have an appointment request form, a contact form, a chat widget, or a patient portal. They often connect to scheduling, email, or practice-management systems. The instant a visitor can type health-related information into your site, or your site talks to a system that stores it, you have crossed from "brochure" into "handling PHI," and the Security Rule's expectations come with it.

The question is not whether your website is HIPAA compliant in the abstract. It is whether every place a patient's information travels is protected.

What makes a website HIPAA-conscious

There is no single switch that makes a site compliant. It is a series of practical safeguards working together. Here are the ones that matter most for a practice.

Encryption in transit (HTTPS everywhere)

Every page, and especially every form, should load over HTTPS so that information is encrypted as it travels between the patient's browser and your server. This is the baseline, and the HIPAA Security Rule treats transmission security as a core safeguard. If any part of your site still loads over plain HTTP, that is a red flag.

Where form data actually goes

This is the safeguard most often gotten wrong. Many websites are set up to simply email form submissions to the front desk. Standard email is not encrypted end to end, which means a patient's health details can travel and sit in inboxes in the clear. A HIPAA-conscious setup delivers submissions to encrypted, access-controlled storage, not a plain email blast. Ask specifically: when a patient submits a form, where does that data go, and is it encrypted the whole way?

Business Associate Agreements (BAAs)

Any outside vendor that touches PHI on your behalf should sign a Business Associate Agreement, a contract that legally binds them to protect that data. That can include your hosting provider, your form or scheduling tool, and your email service. If a vendor cannot or will not sign a BAA, they should not be handling patient information, no matter what their marketing says.

Access controls and audit trails

Only the people who need patient information should be able to reach it, each with their own login, and the system should keep a record of who accessed what. This limits both accidental exposure and the damage if a single account is ever compromised.

Analytics and tracking pixels

This one surprises people. Standard analytics and advertising trackers can quietly transmit information about what a visitor does on your site to third parties. HHS has published guidance warning that, on healthcare sites, these tracking technologies can end up sharing PHI without proper agreements in place. On pages that collect patient information, tracking has to be configured carefully, or kept off entirely. When in doubt, review the HHS professional guidance.

Data minimization

The safest data is the data you never collected. Forms should ask for what you genuinely need to serve the patient and nothing more. Every extra field is one more piece of sensitive information to protect.

Common misconceptions

  • "The padlock means my site is HIPAA compliant." The padlock only means the connection is encrypted. That is necessary, but it is a small part of the whole picture.
  • "My host says they are HIPAA compliant, so I am covered." Compliant infrastructure is a good start, but compliance depends on how the whole site is configured, whether BAAs are signed, and how data is handled day to day.
  • "There is an official HIPAA certification." There is not. The government does not certify or approve websites as HIPAA compliant. Any badge claiming otherwise is marketing, not a legal seal.
  • "HIPAA does not apply to a small practice." It applies regardless of size. A solo practice is just as much a covered entity as a large group.

A practical checklist: what to ask your web person

You do not need to become a compliance expert. You need a builder who takes this seriously and can answer plainly. Bring these questions:

  1. Does every page, and every form, load over HTTPS?
  2. When a patient submits a form, exactly where does that data go, and is it encrypted the entire way?
  3. Are form submissions stored in secure, access-controlled storage, or just emailed to the front desk?
  4. Which vendors touch patient data, and have they signed Business Associate Agreements?
  5. How is analytics or ad tracking handled on pages that collect patient information?
  6. Who can access submitted patient data, and is that access logged?

If the answers are vague, that tells you something. A security-minded partner will welcome these questions, because they have already thought them through. You can see how we approach this on our security and compliance page, and there is a companion guide on what HIPAA means for forms, analytics, and chat if you want to go deeper on those specifics.

Built in, not bolted on

HIPAA is not a badge you buy or a box you check once. It is a set of habits and safeguards that protect the trust your patients hand you the moment they type their name into your website. Getting it right does not have to be complicated, but it does have to be intentional, built in from the start rather than bolted on later.

If you are not sure where your current site stands, that is worth finding out. You can book a free call to talk it through, or get a tailored recommendation for your specific practice. No pressure, and no jargon.

Share this article

Email

Jody Hartwell

Jody writes about building secure, modern, HIPAA-conscious websites and better patient experiences for dental, medical, and legal practices.

Trustform Digital

Secure, HIPAA-conscious websites that book more patients

We design fast, secure websites and local SEO for dental, medical, and legal practices, built and protected by a CISSP-certified developer. From dental website design and medical practice websites to local SEO and HIPAA-conscious patient tools, we build around exactly what your practice needs.

Why practices choose Trustform Digital

We design secure, HIPAA-conscious websites and local SEO for dental, medical, and legal practices, built and protected by a certified security professional, so the right patients can find you and reach out with confidence.

Security-first, by default

Built by a CISSP-certified developer with AWS and Google Cloud credentials. Encrypted forms, HIPAA-conscious setup, and secure managed hosting are the baseline, not an upsell.

One expert, start to finish

You work directly with the person building your site. Nothing is outsourced, there are no handoffs, and no rotating account managers.

Built to book more patients

Fast, mobile-first websites and local SEO designed to turn Google searches into booked patients and consultations, not just a pretty page.

You own everything

Your website, your domain, and your content are yours. No lock-in, no proprietary traps, no hostage situations, ever.

What we build