You cannot copy content of this website, your IP is being recorded.

How To Make Existing Healthcare Practice Website HIPAA Compliant

How To Make Existing Healthcare Practice Website HIPAA Compliant

Making an existing healthcare website HIPAA compliant requires securing every touchpoint where Protected Health Information (PHI)—including patient names, email addresses, phone numbers, IP addresses paired with health searches, and appointment details—is collected, transmitted, stored, or analyzed. An existing healthcare website usually does not need to be rebuilt from scratch to improve HIPAA compliance. But simply adding SSL, a privacy policy, a cookie banner, or a “HIPAA-compliant form” is not enough.

The practical objective is to identify every place where PHI/ePHI can be created, collected, transmitted, stored, or disclosed, then secure those workflows and ensure the vendors touching that information are contractually and technically appropriate.

As of 2026, HHS states that the current HIPAA Security Rule remains in effect; proposed modifications to strengthen the Security Rule have not replaced the existing rule.

Start With the Website Data Flow

For a medical, dental, healthcare practice, example data flow could like this:

Website ComponentTypical HIPAA ConcernWhat To Do
Contact formPatient may enter symptoms, diagnosis, treatment requestUse secure PHI-capable form/service + appropriate BAA
Appointment requestIdentity + healthcare requestTreat as potentially PHI + appropriate BAA
Patient portal/loginVery high PHI exposureIsolate and tightly control tracking/scripts + appropriate BAA
Live chat/chatbotPatients disclose health informationHIPAA-compliant vendor + appropriate BAA
SMS/textingAppointment/health informationHIPAA-compliant workflow and vendor + appropriate BAA
Email notificationsPHI can be sent into ordinary inboxesAvoid sending PHI in ordinary notification emails + appropriate BAA
Call trackingCall recordings/numbers may contain PHIReview vendor and BAA requirements + appropriate BAA
Google AnalyticsData may be disclosed externallyEvaluate configuration and what data is transmitted
Google Ads tagsAdvertising identifiers/trackingRemove or isolate from PHI-sensitive workflows
Meta PixelThird-party disclosure riskGenerally keep away from PHI-sensitive pages/workflows
Session replay/heatmapsMay capture forms or patient behaviorDisable on sensitive areas unless appropriately controlled
Embedded schedulingPatient/appointment informationReview data flow and vendor relationship
CRMStores leads that may contain health informationAppropriate safeguards + BAA when BA relationship exists
Hosting/CDNMay maintain/transmit website data/logsDetermine whether ePHI reaches provider
WordPress pluginsCan send data to external vendorsInventory and minimize
BackupsMay contain form/database PHIEncrypt and access-control
Website administratorsCan potentially access PHILeast privilege, MFA, logging
Marketing agencyMay access leads, forms or analyticsDetermine whether agency is a business associate