HIPAA and Your Website: What Most Designers Don't Think About
A lot of website advice wasn't written with HIPAA in mind.
Most designers are working with online businesses where the biggest concerns are clear messaging, strong visuals, and getting people to take the next step. Those things matter for a healthcare practice, too. But there's a layer underneath all of it that most designers don't think about: protecting patient information and making sure the way your website is set up doesn't quietly create HIPAA risk you didn't realize you were taking on.
This is something I think about for every project. Not because I'm a HIPAA expert — I'm not, and you should always work with someone qualified for legal guidance specific to your practice. But after years of working in healthcare, I've learned where the risks tend to show up, and most of them aren't where providers expect.
A quick disclaimer before we go further: I'm not a lawyer or HIPAA compliance expert. You're legally responsible for your practice's HIPAA compliance, and anything I share here is general awareness, not legal advice. When in doubt, consult someone qualified.
Most providers don't realize HIPAA applies to their website at all
This is the gap I run into most often. Providers think of HIPAA as something that lives inside the practice — paperwork, the portal, conversations behind closed doors. The website feels like marketing, separate from the clinical side of things. So when something on the website creates HIPAA risk, it tends to come as a surprise.
Here's what actually matters: most websites don't need to be fully HIPAA-compliant in the sense of being built on a special locked-down platform. What matters is how protected health information is collected and where it goes once it's collected.
Where the real risks are
The places to pay attention are anywhere a patient might submit personal or health information. Contact forms that ask for health details, scheduling tools that capture appointment information tied to a specific concern, intake forms, questionnaires, client portals.
This is why I always recommend keeping anything that touches PHI inside your HIPAA-compliant system — your EHR or practice management platform — rather than collecting it through your website's built-in tools. Most of the platforms my clients use (Jane, SimplePractice, Acuity, Mindbody, ChiroHD, and more) offer embeddable forms or scheduling that connect to your site without bringing PHI onto the website itself. Either embedding directly or linking out to the secure portal works. Both keep the protected information where it belongs.
For general inquiries — someone asking about availability, pricing, or whether you might be a good fit — a standard Squarespace contact form is usually fine. The key is what that form is doing. A form that asks general questions and says "we'll get back to you" or "we'll call you to schedule" is a different thing than a form that captures health details or completes an appointment booking. The form copy should also remind people not to share specific health information in their message, since some patients will try to.
The thank you page matters too
After someone submits a form, they land on a thank you page. That page should do exactly what it says: thank them, confirm the message was sent, and give them an expectation of when to expect a reply. It shouldn't ask for additional information or capture anything beyond what was already collected.
Small detail, but worth getting right.
Confirmation emails and calendar invites
Anything automated that goes out to a patient — confirmation emails, calendar invites, appointment reminders — should be coming from your HIPAA-compliant system, not from your regular email or Google Calendar. This is one of the cleanest ways to handle the issue: if you use the right tool for the right task, most of the risk takes care of itself.
The thing nobody warns providers about: Google reviews
This is where I see otherwise careful providers run into HIPAA issues without realizing it.
When someone leaves a Google review and you reply, every word of that reply is public. And here's the part many providers don't realize: even confirming that someone is a patient is itself a HIPAA violation. Even if they identified themselves in the review. Even if the review is glowing. The mere fact that someone is your patient is protected health information, and confirming it from your side is a disclosure.
This is real, not theoretical. The Office for Civil Rights has imposed fines on practices for exactly this — replies that referenced a patient's care, confirmed their relationship to the practice, or expanded on details the patient mentioned in the review. Fines have ranged from $10,000 to $50,000 in recent years.
The mistakes providers make when responding to their own reviews tend to look like this:
They confirm the person is a patient by name. The patient may have already done that themselves, but you confirming it from your side is still a disclosure.
They reference what the patient came in for. Even if the patient mentioned their diagnosis or condition in the review, replying with "so glad we could help with your shoulder" or "thanks for trusting us with your son's care" is you confirming or expanding on PHI.
They mention other family members. "Tell your husband we said hi" sounds friendly. It also confirms that the husband is also a patient.
They get personal in ways that feel warm and inadvertently violate the privacy a patient is entitled to.
A safe response thanks someone for their feedback in general terms, invites them to reach out directly if there's anything more to discuss, and stops there. No specifics, no confirmation of the relationship, no expanding on anything the patient mentioned.
If it feels impersonal? Yes. That's the point. The warmth and personal connection belongs in your relationship with the patient, not in a public reply that thousands of people could see. If you want to thank them more personally, do it in person the next time they're in for an appointment, or with a note. The public reply is just a placeholder.
One thing not to do: stop replying to reviews entirely. Google rewards engaged business profiles, and consistent replies signal to both Google and prospective patients that your practice is active and attentive. A generic, HIPAA-safe reply still does that work. The goal isn't to disappear from your reviews. It's to reply in a way that's safe for both you and the patient.
This is one of the places where having someone behind the keyboard who isn't client-facing can help. A practice administrator or someone in a marketing role who doesn't know the patients personally is less likely to slip into the kind of warm, personal reply that creates risk.
A few other things worth knowing
A privacy policy is required, and it's your responsibility to make sure yours covers your practice.
Avoid photos that accidentally show patient information. A photo of your space that includes a patient's name on a screen or paperwork visible in the background is a real issue. It's worth checking every photo before it goes on your site or social media.
Why I bring this up
Most designers won't ask any of these questions. They'll build the site, set up the forms, and hand it off without thinking about whether any of it could create HIPAA exposure for you. That's not because they're careless — it's because they're not used to working in a context where it matters.
It does matter. I'm not a HIPAA specialist, but knowing where these risks tend to show up is just part of how I think about building a website for a health and wellness practice. It's not a separate process or a specialty service. It's just paying attention to a layer that most designers don't.
If you're already working with someone and not sure whether your current setup is HIPAA-aware, that's a fair question to ask.