HIPAA Compliant Website: The Complete 2026 Guide

If your website collects any patient information, even through a simple contact form, HIPAA may already apply to you. A form that asks for a name and a reason for a visit can count as protected health information the second someone clicks submit.

For most providers, this is not welcome news. You went into practice to help people, not to study privacy law. A HIPAA-compliant website is possible with the right approach, and you do not have to navigate the requirements alone. ComplyAssistant, with 25+ years of experience, helps healthcare organizations understand and manage HIPAA requirements, including guidance around website compliance. 

A HIPAA-compliant website is not something you buy once and forget. It is one piece of a wider compliance program: your risk analysis, vendor agreements, and policies. This guide covers both, with real examples and a checklist you can use today.

Ready to Simplify HIPAA Compliance?

Our intuitive HIPAA compliance software helps you stay secure, meet all regulations, and streamline your processes. Get started today and stay compliant with ease!

What Is a HIPAA-Compliant Website?

A HIPAA-compliant website protects the health information people share with you online. It collects, sends, and stores patient data in a way that meets the rules set by the Health Insurance Portability and Accountability Act, known as HIPAA. The law asks covered organizations to protect electronic protected health information, ePHI, using three types of safeguards.

Compliant vs. Merely “Secure-Looking”

A padlock icon in the browser bar feels reassuring, but it does not make your site compliant. It only shows that traffic between the visitor and your site is encrypted. It says nothing about who can read the data once it arrives, whether your host signed the right agreement, or whether you wrote down your security decisions.

Think of a solo therapist with a tidy website and a working contact form. The site looks safe. But if that form emails client details to a personal Gmail account with no agreement in place, the practice is not compliant. Looking secure and being compliant are two different things.

The Three Safeguard Categories: Administrative, Physical, Technical

HIPAA groups its protections into three types of safeguards, and a compliant website depends on all three working together.

Safeguard type

What it covers

How it shows up on your website

Administrative

People, policies, procedures, and training

Risk analysis, staff training, deciding who can view form data, signed vendor agreements

Physical

Protection of buildings, servers, and devices

Secure data centers, locked server rooms, device controls (usually handled by your host)

Technical

Technology that guards ePHI

Encryption, access controls, unique logins, audit logs, multi-factor sign-in

The administrative column is where many providers fall short, and it is the part regulators look at closely.

Why No Platform Is HIPAA Compliant Out of the Box

There is no website builder or content system that is HIPAA compliant the moment you install it. Not WordPress, not Wix, not any of them. Compliance comes from how the platform is set up, hosted, and managed, plus the agreements you sign with the companies involved. A tool can support compliance when the right pieces are in place, but it never carries compliance for you.

Does Your Website Need to Be HIPAA Compliant?

Not every healthcare website has to follow HIPAA. A site that only lists your services, address, and office hours, with no way to submit health details, usually falls outside the rules. The question is whether your website touches protected health information at all. To answer it, you need to know what counts as PHI, then check how your site handles it.

What HIPAA Protects: PHI and ePHI, the 18 Identifiers in Plain English

Protected health information, or PHI, is any information that can identify a person and connects to their health, care, or payment for care. When that information is created, sent, or stored electronically, it becomes ePHI.

HIPAA lists 18 types of identifiers that can make information identifiable. Common ones that show up on websites include:

  • Names, home address, and ZIP code details
  • Phone and fax numbers and email addresses
  • Dates tied to a person, such as a birth date or appointment date
  • Social Security numbers and medical record numbers
  • Full-face photos
  • Web addresses, IP addresses, and device identifiers


That last group surprises people. An IP address or a device ID can count as an identifier when it is linked to health information. So a visitor filling out a form about a medical concern can create PHI even without typing their full name.

Do You Collect, Transmit, or Store PHI?

The simplest way to check whether HIPAA applies is to ask three questions. If you answer yes to any of them, your website needs to be compliant.

  • Do you collect PHI? You do if patients enter health details through contact forms, intake forms, appointment requests, live chat, or patient portals.
  • Do you transmit PHI? You do if your site sends health information by email, form submission, or messaging, including to your own team.
  • Do you store PHI? You do if health information is stored on a server, database, or backup connected to your website.


A dental office that lets patients request appointments online is collecting and transmitting PHI. A clinic with a patient portal is doing all three.

Covered Entity vs. Business Associate: Which Are You?

HIPAA splits the organizations it covers into two groups, and where you fall changes your duties:

  • Covered entities are healthcare providers, health plans, and clearinghouses. A therapy practice, a dental office, and a medical group are all covered entities.
  • Business associates are companies that handle PHI for a covered entity, such as a billing company, a cloud host, or a form tool.


Both groups have to protect PHI. If you are a covered entity, you are also responsible for making sure the business associates you work with meet the rules, and that responsibility is put in writing through an agreement we cover shortly.

Which Parts of Your Site Need Compliance, and Which Pages Don’t

You may not need to rebuild your whole website. Only the parts that collect, send, or store PHI have to be compliant, so the rest can stay as they are.

Picture a physical therapy clinic. Its “About Us” page, service list, and staff bios do not handle PHI, so they carry no HIPAA duties. But its online intake form and payment page do. Protect those specific parts rather than move the whole site to costly hosting you may not need. Just be careful, because adding one small feature, like a symptom checker, can pull a page into HIPAA territory.

What HIPAA Requires: The Privacy, Security, and Breach Notification Rules

HIPAA is built on a set of rules. Three of them shape how your website should work: the Privacy Rule, the Security Rule, and the Breach Notification Rule.

The Privacy Rule and Its Website Implications

The Privacy Rule sets the ground rules for how PHI can be used and shared, and it gives patients rights over their own information. For your website, this means collecting only the health information you actually need, telling patients how their data is used through a privacy notice, and having a way to honor patient requests, such as asking to see or correct their information.

The Security Rule and Technical Safeguards for ePHI

The Security Rule matters most for a website because it covers ePHI. It asks covered organizations to protect electronic health information with administrative, physical, and technical safeguards. On the technical side, that points to access controls, unique user logins, audit logs, and encryption.

One detail is worth knowing. Under the current rule, encryption is an “addressable” item, which means you must use it where reasonable or write down why you chose an equal alternative. In early 2025, the Department of Health and Human Services proposed changes that would make encryption and multi-factor sign-in required, remove that flexibility, and add regular vulnerability scans and yearly testing. As of now, this is still a proposed rule, not final, and the current rule stays in force. Including encryption and multifactor sign-in is considered a best practice in the healthcare industry. Implementing these controls now is recommended for your organization’s overall protection and will save you a step when the proposed HIPAA Security updates are announced in 2027. 

The Breach Notification Rule (The 60-Day Clock, the 500+ HHS Reporting List)

If PHI is exposed, the Breach Notification Rule tells you what to do next:

  • Tell affected individuals without unreasonable delay, and no later than 60 days after you discover the breach.
  • If a breach affects 500 or more people, notify HHS within that same 60-day window and alert prominent local media.
  • Report breaches affecting fewer than 500 people to HHS once a year.

Penalties for a Non-Compliant Site: Tiered Fines and Real Enforcement Examples

HIPAA fines are grouped into four tiers based on how much the organization knew and whether it fixed the problem. The figures below took effect on January 28, 2026, and rise each year with inflation.

Tier

What it means

Fine per violation

Tier 1

You did not know and could not reasonably have known

$145 to $73,011

Tier 2

Reasonable cause, not willful neglect

$1,461 to $73,011

Tier 3

Willful neglect, fixed within 30 days

$14,602 to $73,011

Tier 4

Willful neglect, not fixed

$73,011 to $2,190,294

11 Steps to Build a HIPAA-Compliant Website 

Work through these steps in order, and lean on your host and vendors for the technical lifting.

Step 1: Start With a Documented Risk Analysis

Before you change a single setting, look at where your risk actually is. A security risk analysis is a written review of how PHI flows through your website, where it could be exposed, and what you will do about it. This step goes first because it tells you what the rest of your work should focus on, and it is the very thing regulators ask to see. If you cannot show a written risk analysis, you are not compliant, no matter how good your technology looks.

Step 2: Choose HIPAA-Compliant Hosting and Sign a BAA

Your website needs to live on hosting built for health data, with encrypted storage, access controls, monitoring, backups, and secure data centers. Just as important, the host must sign a Business Associate Agreement, or BAA. This written contract makes the host accept its own HIPAA duties and share responsibility for your data. Without a signed BAA, storing PHI with any provider breaks the rules, even if the servers are secure.

Step 3: Enforce HTTPS With TLS/SSL Encryption (Data in Transit)

Every page that touches PHI should load over HTTPS, not plain HTTP. HTTPS uses a security protocol called TLS (you will also see it called SSL) to scramble data as it travels between the visitor and your server. Without it, anyone sitting between the user and your site could read what passes through, including the health details a patient just typed.

Step 4: Secure Your Forms and Data Collection With Encrypted, Compliant Form Tools

Standard contact forms are not built for health data. If a patient can enter symptoms, medications, or insurance details, you need a HIPAA compliant form tool that encrypts the information and comes with a signed BAA. 

Step 5: Encrypt Data at Rest (Secure Storage)

Encryption in transit protects data while it moves. Encryption at rest protects it while it sits on a server or in a backup, and you want both. When stored PHI is encrypted, a stolen file or breached server is far less useful to an attacker, since the data cannot be read without the key. Limit that key, and the stored data, to the people who truly need it.

Step 6: Lock Down Access: Unique User IDs, Role-Based Controls, MFA

Not everyone on your team needs to see everything. Give each person a unique login, and set permissions by role so staff only reach the data their job requires. Add multi-factor sign-in, often shown as MFA, which asks for a second step beyond a password, such as a code from a phone app. Review who has access from time to time, and remove logins the moment someone leaves.

Step 7: Use HIPAA-Compliant Email and Secure Messaging

Regular email services like standard Gmail or Outlook are not compliant for sending PHI on their own. If your website triggers emails with health details, those messages need encrypted, HIPAA-ready email backed by a BAA with the provider. The same care applies to any chat or messaging feature that carries patient information.

Step 8: Add Firewalls/WAF, Monitoring, and Audit Logging

Good protection watches for trouble and keeps records. A firewall and a web application firewall (WAF) that filters web traffic help block attacks before they reach your site. Monitoring alerts you to strange activity, and audit logs record who accessed what and when. Those logs help you catch problems and prove your diligence if you are ever reviewed, and HIPAA expects records like these to be kept for six years.

Step 9: Back Up Data Offsite With Proper Retention, Plus a Disaster-Recovery Plan

Data can be lost to a cyberattack, a hardware failure, or a simple mistake. Regular backups, stored securely in a separate location, let you recover without losing patient records or halting your practice. Encrypt those backups too, and have a written plan for restoring them. A backup you have never tested is a promise you have not checked.

Step 10: Set Secure Data Disposal and Retention Rules

Holding onto PHI forever adds risk with no benefit. Decide how long you need to keep information, and delete it securely when it is no longer needed. Secure disposal means the data cannot be pulled back later, so for digital records that involves proper wiping or destruction, not just dragging a file to the trash.

Step 11: Publish Required Policies and Consent 

A compliant website is also honest with its visitors. A few documents should be easy to find on your site:

  • A Privacy Policy explaining how you handle data
  • A Notice of Privacy Practices describing patients’ rights over their PHI
  • Terms of Use for your website
  • A cookie or consent notice if your site uses tracking tools


Write them in language patients can actually read.

Can WordPress, Webflow, Wix, or Squarespace Support a HIPAA Compliant Website?

Providers often ask which platform is “the HIPAA compliant one.” The honest answer is that none of them are compliant by default, but some support a compliant setup better than others.

WordPress: Compliant Only When Hosted, Hardened, and Configured Correctly

WordPress is common in healthcare, and it can support a compliant website when set up with care. Compliance depends on HIPAA-ready hosting, tightened server settings, encrypted storage, secure forms, access controls, logging, and signed BAAs. WordPress gives you the flexibility to build a compliant site, but that flexibility means the work is yours to do, or your host’s.

Webflow, Wix, Squarespace, and Other SaaS Builders: BAA Availability and Shared-Infrastructure Limits

Hosted website builders are easy to use, but most were not made for health data. Many will not sign a BAA; they run on shared systems you cannot fully control, and they limit the backend security you can put in place. If your site collects PHI, these platforms are often a poor fit as the place where that data lands, though they can still work well for pages that carry no health information.

The Embed Approach: Dropping Compliant Components Into a Non-Compliant Marketing Site

You do not always have to choose between a pretty marketing site and a compliant one. A popular approach is to keep your public pages on the builder you like and handle PHI through a separate HIPAA-ready tool that you embed into the page. Take a small clinic that loves its Squarespace site: instead of rebuilding everything, it drops in a HIPAA compliant intake form and scheduling tool from a vendor that signs a BAA. The marketing pages stay simple, and the health data flows through a service built to protect it.

How to Choose a HIPAA-Compliant Web Host

Since your host carries much of the technical load, choosing the right one is one of the most important decisions you will make.

Hosted vs. Self-Hosted: Control vs. Overhead

You can pay a provider to handle the secure setup for you, or you can run your own servers and manage the security yourself.

  • Managed HIPAA hosting hands the heavy lifting to a provider. You give up some control, but you avoid buying and maintaining your own security stack. This suits most small and midsize practices.
  • Self-hosting gives you full control, but it demands real technical skill and constant upkeep. It fits organizations with strong in-house IT teams.


For most healthcare providers, managed hosting is the practical choice.

What a Compliant Host Must Provide (Encryption, Access Controls, Logging, Audited Data Centers)

Whatever you choose, the host should clearly offer a set of protections:

  • Encryption for data at rest and in transit
  • Access controls and support for unique logins
  • Activity logging and monitoring
  • Secure, regularly reviewed data centers
  • Reliable backups and recovery options


If a provider cannot clearly explain how it delivers these, keep looking.

Certifications That Signal the Real Thing: SOC 2 Type II, HITRUST CSF, ISO 27001

Certifications are a useful shortcut for judging a host’s security, because they show that an outside auditor has checked the provider against a recognized standard. Watch for SOC 2 Type II, HITRUST CSF, and ISO 27001. These do not automatically make your website compliant, but they are a strong sign that the host takes security seriously.

The Questions to Ask and the BAA Red Flags Before You Sign

Before you commit, ask a few direct questions:

  • Will you sign a BAA? If a provider hesitates or refuses, walk away.
  • What certifications do you hold, and how recent are they?
  • How do you handle encryption, backups, and monitoring?
  • Do your own subcontractors sign BAAs with you?


That last point matters. Your web developer is a business associate, and the vendors they rely on are too, so make sure the agreements reach all the way down the chain.

Administrative Safeguards: Risk Analysis, Policies, Training, and Incident Response

Here is the part most website guides skip, and it is the part regulators focus on. Your technology can be flawless, but without the administrative side, you are still exposed.

Documented Risk Analysis and Risk Management

A risk analysis is not a one-time checkbox. It is an ongoing review of where PHI could be at risk, followed by real steps to reduce those risks, all written down. If OCR ever reviews your organization, this is usually the first document they ask for, so a written, up-to-date risk analysis is your strongest shield.

Written Policies and Procedures

Policies turn good intentions into consistent action. They tell your team how to handle PHI, who can access what, and what to do when something goes wrong. A healthcare policy management tool makes it easier to create, share, and update these documents and to prove that staff have read them.

Workforce Security and Privacy Training

Your people are your first line of defense and often your biggest risk. A staff member who reuses a weak password or clicks a bad link can undo strong technology in seconds. Regular training keeps privacy and security front of mind, so keep it simple, keep it frequent, and record who completed it.

An Incident Response and Breach Plan

Even careful organizations face incidents. What separates a manageable event from a disaster is having a plan ready before you need it. Your plan should spell out who does what when a problem appears, how you will contain it, and how you will meet the notification deadlines we covered earlier.

Managing BAAs and Vendor Risk as an Ongoing Program

Signing a BAA is the start, not the finish. You should know every vendor that touches your PHI, keep their agreements current, and check that they are actually protecting your data. This gets hard as the list grows, so a vendor risk management approach keeps every agreement and review in one place instead of scattered across inboxes.

Why Documentation Is the First Thing OCR Asks For After a Breach

There is a lesson in nearly every enforcement case. Organizations that could show their risk analysis, policies, training records, and agreements were treated very differently from those that could not. Documentation is the difference between “here is our proof” and “trust us,” and only one of those holds up under review.

Your HIPAA Compliant Website Checklist

Use this checklist to see where your website stands. Treat any gap as a task to schedule.

Technical Controls

  • HTTPS with TLS on every page that handles PHI
  • Encryption for stored data and backups
  • Firewall and web application firewall in place
  • Unique logins and multi-factor sign-in for anyone who accesses PHI
  • Activity monitoring and audit logs kept for six years
  • Secure, tested offsite backups


Administrative Controls

  • A current, written security risk analysis
  • Signed BAAs with your host, form tool, email provider, and other vendors
  • Written policies and procedures for handling PHI
  • Regular staff training with completion records
  • A written incident response and breach plan


Required Website Policies

  • Privacy Policy
  • Notice of Privacy Practices
  • Terms of Use
  • Cookie or consent notice, if you use tracking tools


Review and Maintenance for Audit Readiness

  • A schedule to reassess your risk analysis and controls
  • A record of new pages, features, or vendors added over time
  • Evidence, such as logs and training records, ready to show if reviewed

How to Audit Your Existing Website for HIPAA Compliance

If your site is already live, you do not need to start over. You need to find out where it stands and close any gaps.

A Step-by-Step Self-Assessment

Start with a simple, honest review of your own site:

  • Confirm your BAAs are signed and current with every vendor
  • Review your hosting and server settings
  • Test that encryption is on for data in transit and at rest
  • Check who has access, and remove logins that are no longer needed
  • Look over your posted policies and consent notices
  • Make sure logging and monitoring are running


Write down what you find, because the list becomes your plan for what to fix first.

Common Gaps Organizations Discover

When practices run this review, a few problems show up over and over:

  • Exposed staging or test versions of the site that are visible to the public
  • Cloud storage that was set up quickly and left open
  • Contact or intake forms that are not encrypted
  • Missing BAAs with a form tool, email service, or analytics provider
  • Old accounts still active after someone left the team


Any one of these can lead to a breach, so finding them yourself is far better than having an attacker or a regulator find them for you.

How ComplyAssistant Helps You Manage HIPAA Website Compliance

Everything above points to one truth: a compliant website is one part of a wider compliance program. The risk analysis, the BAAs, the policies, and the records are what keep you protected and what a website has to prove you have. This is exactly the work ComplyAssistant is built to manage.

ComplyAssistant is a healthcare-focused governance, risk, and compliance company that has served providers for more than two decades. Health systems and hospital associations rely on its software and services to keep their compliance programs organized and audit-ready.

  • Risk Register– record website risks alongside the rest of your organization, track them over time, and produce the documentation on demand.
  • Vendor Risk Management and BAA Tracking – keep every BAA and vendor check-in in one place, so nothing slips through the cracks as your list of partners grows.
  • Policy Management – build and update your policies, send them to your team, and show that staff have read and acknowledged them.
  • Audit Management –deliver audit results in a clear portal rather than a pile of spreadsheets, so you can see where you stand and prove it quickly.
  • HIPAA Consultants and Virtual CISO Services – honest reviews, gap analysis, and a clear plan to fix what needs fixing, tailored to your organization.


Talk to our team, and we will look at where your site stands today and give you a plan for closing the gaps. 

Wrapping Up!

Building a HIPAA compliant website comes down to two things working together. First, the site itself: secure hosting, encryption, protected forms, tight access, and clear policies. Second, the program around it: a written risk analysis, signed vendor agreements, trained staff, and records you can show.

The program is what keeps you compliant when a regulator asks questions or a breach tests your defenses. Start with your risk analysis, close your gaps one by one, and keep your documentation current. 

FAQs About HIPAA Compliant Website

What Is a HIPAA Compliant Website?

A HIPAA compliant website protects the health information people share with you online. It collects, sends, and stores patient data using safeguards that meet HIPAA’s rules, such as encryption, access controls, secure hosting, and signed vendor agreements. It also sits within a wider compliance program that includes a risk analysis, written policies, and staff training.

Do I Need One if I Only Have a Contact Form?

Possibly, yes. If your contact form asks for health details, like symptoms, conditions, or medications, then it collects protected health information, and HIPAA applies. If the form only gathers a name and a general message with no health context, the risk is lower, but many providers protect it anyway to stay safe.

Is WordPress HIPAA Compliant?

WordPress is not compliant on its own, but it can support a compliant website when it is set up correctly. That means HIPAA-ready hosting, encrypted storage, secure forms, access controls, activity logs, and signed BAAs. The platform gives you the flexibility, but the security work is still yours to complete.

Do I Need a BAA With My Web Host and Form Tools?

Yes. Any company that stores, sends, or can access your PHI is a business associate and must sign a Business Associate Agreement. That includes your web host, your form tool, your email provider, and often your web developer. Without a signed BAA, sharing PHI with that vendor breaks the rules, even if their systems are secure.

How Much Does a HIPAA Compliant Website Cost?

The cost varies widely based on your setup. Managed HIPAA hosting, encrypted form tools, and secure email each carry a monthly fee, and expert reviews add to the total. The bigger picture is that a compliant program almost always costs far less than a single HIPAA fine or the fallout from a breach.

Are Wix, Squarespace, and Webflow HIPAA Compliant?

These builders are usually not a good fit for pages that handle PHI. Many will not sign a BAA, they run on shared systems, and they limit backend security. They can still work well for your marketing pages, and you can handle PHI through a separate HIPAA-ready tool that you embed into the site.

How Do I Make My Existing Website HIPAA Compliant?

Start with a risk analysis to find where PHI flows and where it is exposed. Then confirm your hosting and BAAs, turn on encryption in transit and at rest, secure your forms, lock down access, and post the right policies. Review who has access, fix any gaps you find, and keep your documentation current so you can prove your work.

Ken Reiher

After more than 20 years of consulting and management experience in healthcare, I understand how quickly things can shift. My prior work in revenue cycle, finance, corporate compliance and auditing helped me appreciate the importance of building relationships to develop strategies and facilitate required change. In my current role as VP of Operations for ComplyAssistant, I wear quite a few hats, managing business operations, supporting consulting engagements, assisting with product development and supporting client engagement. I enjoy working directly with clients, listening to their needs, and working hand-in-hand with the software development team to create solutions that work for the modern needs of security and compliance in healthcare and other verticals. I received my BS and MBA degrees from Fairleigh Dickinson University Madison. And, I’m honored in my role to contribute to various industry publications, and to be affiliated with HIMSS (NJ, NY, Delaware Valley and National), NJPCA, NJAMHAA and HFMA (NJ and National).