HIPAA and Practice Websites

A website cannot be “HIPAA compliant” on its own.

Compliance belongs to the covered entity, not to a page. What a practice website can do is stay out of the way: collect no protected health information, route booking and intake into the secure systems you already use, and avoid the tracking that has drawn most of the enforcement attention. That is how TMN builds every healthcare site.

0
PHI on the marketing site
4
Healthcare practices built
$2.2K+
Practice sites from
Hand-coded
No template builder
The Actual Rule

What HIPAA actually covers.

A plain-language orientation, not legal advice. Your privacy officer and counsel govern your obligations, and this page is written to help you ask them better questions.

01

It governs entities, not files

HIPAA applies to covered entities and their business associates. There is no certification that makes a website compliant, and any vendor selling you a “HIPAA compliant website” badge is selling a badge. What exists is a set of obligations your practice carries, and vendors who either help or hinder.

02

Protected health information is the line

PHI is health information tied to an identifiable person. A page describing a treatment is marketing. A form where a patient types symptoms, insurance details, or an appointment reason alongside their name is a different category entirely, and it changes what has to be true about where that data lands.

03

Business associate agreements

Any vendor that creates, receives, maintains, or transmits PHI on your behalf generally needs a BAA with you. That is why intake belongs in a platform that will sign one, and why a generic contact form emailing your inbox is the wrong place for clinical detail.

04

Tracking technologies drew the scrutiny

Third-party analytics and advertising pixels on patient-facing pages have been the subject of significant federal attention and litigation in recent years, because they can transmit identifiers alongside health-related browsing. Your practice decides its risk posture here, in writing, with counsel.

The Build

How TMN builds around it.

The design goal is simple: the marketing site should never become a system of record.

01

No PHI collected on the site

Marketing forms stay minimal: name, email, and a reason to reach out. Clinical intake, history, and insurance detail belong in your platform, not in a form on a brochure page.

02

Intake routes to your systems

Scheduling and intake link or embed into the secure, HIPAA-compliant platform your practice already uses and already has a BAA with, when that is included in the approved scope. Your privacy officer and vendors govern that side.

03

Analytics you choose deliberately

TMN's default is privacy-friendly, cookieless analytics rather than advertising pixels on patient-facing pages. If your practice wants different tooling, that becomes a documented decision rather than a default nobody reviewed.

04

Clinical content stays yours

Treatment pages are drafted for your review and published only after your clinical approval. On LumiClinics, that included a SPRAVATO page reproducing the manufacturer's required safety information word for word.

05

Crisis resources handled correctly

988 and local crisis lines are placed where someone in distress can find them, worded so the site never reads as a substitute for emergency care.

06

Hand-coded, few moving parts

Every plugin is another vendor touching your site. A hand-coded static site has a smaller surface to reason about than a plugin stack that updates itself on someone else's schedule.

Built by us

Healthcare practices, publicly credited.

Live sites on client domains that credit TMN, so you can check the work rather than take a claim.

01

LumiClinics

Psychiatry and therapy practice in Northbrook, Illinois, serving patients statewide by telehealth. Named providers, plain-language insurance, one direct intake path, and regulated treatment content. Case study.

02

Training Wheels ABA

Pediatric ABA therapy group with 3 clinic locations in Austin, Texas. Insurance clarity including Medicaid, simple tour scheduling, and hiring pages that support clinician recruiting. Case study.

03

Smitha Reddy MD

Rheumatology and functional medicine practice in San Diego, built credential-forward with the patient path routed to the affiliated care organization. Case study.

FAQ

What practice owners ask first.

01

Is my website HIPAA compliant?

A website is not compliant or non-compliant by itself. Your practice is the covered entity, and the question is whether your site and its vendors help you meet your obligations. If your site collects no PHI and routes intake to a platform you have a BAA with, you have removed the most common problem. Confirm your own posture with your privacy officer.

02

Can a contact form be HIPAA compliant?

A simple name-and-email form that does not ask for clinical detail is ordinary business contact. The risk starts when a form invites symptoms, diagnoses, insurance identifiers, or appointment reasons, because that content then has to live somewhere appropriate. TMN keeps marketing forms minimal and sends clinical intake to your platform.

03

What about Google Analytics and Meta pixels?

Third-party tracking on patient-facing pages has drawn substantial federal scrutiny and litigation, because identifiers can travel alongside health-related browsing. TMN defaults to privacy-friendly, cookieless analytics. If you want other tools, that should be a decision your practice makes with counsel, documented rather than assumed.

04

Do you sign a BAA?

TMN builds and maintains the marketing site and does not process patient records, so in the standard arrangement there is no PHI for TMN to touch. If a project scope would put TMN in contact with PHI, that needs to be identified up front and papered correctly before the work starts.

05

How much does a HIPAA-aware practice website cost?

The same as any TMN build: $2,250 Starter Refresh, $3,750 Full Site Rebuild, $5,000+ Custom Studio Build. Keeping PHI off the site is an architecture decision, not an upcharge. See full pricing detail, a live practice build, or how to verify any of this.

06

Is this legal advice?

No. This page is a plain-language orientation to help you ask your privacy officer and counsel better questions. They govern your obligations, and nothing here substitutes for their review of your specific practice.

Ready to get started?

Tell us about your operation. We’ll put together a free custom homepage so you can see the direction before committing. No retainer. No pressure.