industry·7 min read·

Medical & Dental Practices: HIPAA-Aware Website Setup

Most 'HIPAA-compliant website' marketing is half-true. Here's the actual scope of what's required and what to actually do.

What HIPAA does and doesn't require

HIPAA covers Protected Health Information (PHI). Your marketing site usually doesn't process PHI.

PHI shows up the moment you accept patient forms, secure messaging, intake info, insurance details, or appointment requests with health context.

When PHI is involved, you need encryption in transit and at rest, access controls, audit logs, and Business Associate Agreements (BAAs) with every vendor that touches it.

Practical setup

HIPAA-eligible hosting (AWS, GCP, Azure, with BAA signed).

TLS on every page.

Forms that submit to a HIPAA-compliant backend with BAA.

No form submissions sent to plain Gmail, use a BAA-covered system.

Two-factor authentication on every admin login.

FAQ

No, they will not sign a BAA. Same for most consumer-grade tools.

Want this done for you?

Book a free 30-minute audit. We'll show you exactly how to apply this to your business.

Book a free audit