WhatsApp Us

Healthcare websites for US practices · PHI handled on purpose, not by accident

HIPAA compliant website design that keeps patient data out of the wrong places

HIPAA compliant website design starts with one question: where does protected health information travel once a patient clicks “Submit”? BtechWaleTech is three freelance developers in India who build practice websites so that intake data lands only in services covered by your business associate agreements, ad and analytics tags stay off patient pages, and every login leaves an audit trail. Compliance stays your practice's responsibility, signed off by your own counsel; the build gives you the technical footing. Brochure sites start at US$150; custom encrypted intake starts at US$900. See how this differs from a general medical practice website.

  • Practice website fromUS$150 · 1–2 weeks
  • Condition and service pages at scaleFrom US$300 · 3–5 weeks
  • Custom encrypted intake or portalFrom US$900 · 6–12 weeks
  • Where PHI is storedOnly in services you hold a BAA with
  • BillingUSD · wire, Wise, PayPal
  • After launch2 months free fixes, then from US$120/mo
  • PHI mapped before design
  • BAA-covered vendors only
  • No pixels on patient pages
  • Encrypted intake forms
  • Audit logs and MFA
  • Sites from US$150
  • You own every account

Three freelance developers in India · WhatsApp replies 7 days a week · calls in US Eastern mornings

  • 3Freelance developers, all reachable directly
  • 0Ad or analytics tags on pages that collect PHI
  • 2Working days to an itemised quote
  • 2Months of free fixes after launch

The short answer

What makes a website design HIPAA compliant?

A HIPAA compliant website design keeps protected health information inside vendors that sign a business associate agreement, encrypts forms in transit and at rest, limits access with unique logins and audit logs, and keeps third-party tracking off pages that handle PHI. We build practice sites from US$150 and custom encrypted intake from US$900; your counsel confirms compliance.

Building a patient app too? Read our page on HIPAA compliant app development. For accessibility duties that sit alongside privacy, see ADA compliant website design.

Last updated

HIPAA-aware website builds with us, at a glance
Good fitUS clinics, therapists, dental and specialty practices, home care and health startups
First deliverableA PHI flow map: every field, where it goes, who can see it
HostingYour own cloud or form vendor account, under a BAA you sign with them
TrackingAnalytics only on public pages, reviewed tag by tag
Our access to PHINone needed: we build and test with dummy records
Starting pricesSites from US$150; custom intake or portal from US$900
Who signs off complianceYour practice and its counsel or compliance officer

What the build covers

Pieces of a HIPAA compliant website design project we take on

Each item is scoped around one idea: PHI should only ever reach systems your practice controls and has a business associate agreement for.

Why choose us

Healthcare template platform, general web designer or a small remote team

Three common routes US practices take. None is automatically right; the question is who maps the PHI and who holds the agreements.

Healthcare template platform, general web designer or a small remote team
Question Healthcare template platform General web designer BtechWaleTech
Who signs a BAA with you Often the platform itself, on certain plans Usually nobody; forms may go to plain email Your hosting and form vendors sign; we design around them
Design freedom Limited to the platform's themes High High, custom layout and content
Tracking review Depends on platform defaults Rarely considered Tag-by-tag review before launch
Where data lives Platform's servers Wherever the plugin sends it Your own accounts, listed in the handover
Ownership if you leave Content export varies Usually yours Domain, code, hosting and accounts are yours
Custom intake logic What the platform offers Plugin-dependent Built to your workflow, from the starting price quoted
Communication Support tickets Local meetings possible WhatsApp and video calls, US Eastern mornings
Legal sign-off Your counsel Your counsel Your counsel, with our PHI flow map to review

If you want one vendor to host everything and sign one BAA, a healthcare platform can be simpler; we are a better fit when you need custom design or workflow and are comfortable holding the vendor agreements yourself.

Pricing

What HIPAA compliant website design costs with us

The starting prices below apply to US practices. A public practice site that collects no PHI, or routes it straight into a HIPAA-eligible form service you subscribe to, starts at US$150. A larger site with dozens of condition, treatment and location pages starts at US$300. Custom encrypted intake, consent capture or a patient portal front end is software work and starts at US$900. Your own subscriptions (BAA-tier hosting, form service, secure email) are billed to you by those vendors and are listed in the quote so nothing is hidden. Every figure is a starting point; the itemised quote arrives in about two working days and nothing is billed before you approve it in writing.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is HIPAA compliant website design?

HIPAA compliant website design is the practice of planning and building a healthcare website so that any protected health information it touches is handled the way the HIPAA Privacy, Security and Breach Notification Rules expect. It is less about how the site looks and more about where data flows.

A website is never “HIPAA compliant” on its own. Compliance is a property of your whole organisation: policies, risk analysis, training, vendor agreements and the systems you run. The site is one of those systems. What the build can do is remove easy mistakes, such as a contact form that emails symptoms in plain text, or an advertising pixel sitting on an appointment page, and put the right technical safeguards in place for the pieces that genuinely need PHI.

So when a practice asks us for HIPAA compliant website design, we start by separating the site into two zones. The public zone is marketing: services, providers, locations, blog posts, insurance lists. The PHI zone is anything where a patient types or uploads information about their health, identity or care. The public zone can use normal hosting and careful analytics. The PHI zone needs vendors under a business associate agreement, encryption, access control and logs. Keeping the zones apart is the single design decision that makes everything else manageable.

Does my practice website need to be HIPAA compliant?

If your practice is a HIPAA covered entity and the website collects, stores or transmits PHI, then yes, that part of the site falls under your HIPAA obligations. If the site only publishes information and never receives patient details, the HIPAA exposure is much smaller, though tracking tools can still create risk.

Covered entities are health plans, health care clearinghouses and health care providers that conduct certain standard transactions electronically, such as billing insurance. Most US clinics, dentists, therapists and chiropractors who bill insurers fit that description. Vendors that handle PHI on their behalf are business associates and have their own obligations.

The practical test is simple. Walk through your own site as a patient would and write down every point where you can type something: contact form, appointment request, new-patient paperwork, chat widget, review request, newsletter sign-up, payment page. For each, ask whether a person could reasonably enter health or identity details. A “Request an appointment” form that asks for date of birth and reason for visit clearly collects PHI. A newsletter box that asks only for an email address, on a page with no condition content, usually does not. That list becomes the scope of your HIPAA compliant website design project.

  • Covered entity plus PHI on the site: HIPAA safeguards apply to that part
  • Covered entity, information-only site: focus on tracking and forms that might invite PHI
  • Not a covered entity (for example, a wellness app sold direct to consumers): look at FTC and state health-data rules instead

When does a website form collect PHI?

A form collects PHI when it links individually identifiable information, such as a name, email, phone number or IP address, with information about a person's health, care or payment for care, and it is received by or for a covered entity. A name plus “reason for visit” is PHI; a name alone on a general enquiry often is not.

The trouble is that patients do not read form labels carefully. A plain “Message” box on a dermatology site will eventually receive a description of a rash and a photo request. That is why HIPAA compliant website design treats open text boxes as PHI-capable by default. Either the form is built to handle PHI properly, or it is worded and structured so patients are steered away from sharing it (“Please don't include medical details here; we will call you back”).

We prefer the honest route: if a practice genuinely needs clinical information before a visit, build the secure form and route it correctly, rather than pretending patients will follow a disclaimer. If the practice only needs a call-back, strip the form to name, phone and preferred time, and keep it on a page without condition-specific context. Fewer fields means less PHI, less risk and a shorter form that more patients actually finish.

Clearly PHI

Intake questionnaires, symptom descriptions, insurance member IDs, uploaded referrals, medication lists, appointment requests with a reason for visit.

Often PHI in practice

Free-text message boxes, chat widgets, forms on condition-specific pages, patient portal login and registration pages.

Usually not PHI

Job applications, vendor enquiries, a newsletter email field on a general page, anonymous feedback without identifiers.

Which vendors need a BAA in a HIPAA compliant website design?

Any vendor that creates, receives, stores or transmits PHI for your practice needs a business associate agreement with you. For a website, that usually means the hosting or cloud provider for the PHI zone, the form or intake service, secure email, scheduling, chat and any analytics or tag tool that could see PHI.

Hosting surprises people. HHS guidance on cloud computing and HIPAA says a cloud service provider that stores electronic PHI is a business associate even if it only holds encrypted data and lacks the encryption key. The narrow “conduit” exception covers transmission-only services with transient access, not a server that keeps your forms.

Many vendors offer BAAs, but often only on specific plans or for specific services within their platform, so read the list of covered services rather than the marketing page. The agreement has to be between the vendor and your practice. We do not sign BAAs, and we do not need to: we design the site so that PHI flows only into your BAA-covered accounts, and we build and test with dummy records. If a feature would require us to see real patient data, we flag it and you decide how to handle it with your counsel.

  • Cloud hosting or database for intake data
  • HIPAA-eligible form or e-signature service
  • Secure email or messaging used for patient replies
  • Online scheduling and reminder tools
  • Live chat or chatbot on pages patients use
  • Customer data platforms or analytics that may receive PHI

What did the HHS tracking technology guidance say, and what did the 2024 court ruling change?

The HHS Office for Civil Rights bulletin on online tracking technologies explains that pixels, cookies and similar tools can disclose PHI to vendors. In June 2024 a federal court vacated one part of it, the part treating IP address plus a visit to an unauthenticated public page about a health condition as enough to trigger HIPAA.

According to the HHS bulletin on tracking technologies, tracking on user-authenticated pages such as patient portals and telehealth platforms generally has access to PHI, and the practice must make sure disclosures are permitted and put a BAA in place with the tracking vendor. The bulletin also says consent banners that ask users to accept cookies are not a valid HIPAA authorization, and that a vendor promising to strip or de-identify PHI after receiving it is not sufficient.

The court decision, American Hospital Association v. Becerra in the Northern District of Texas on June 20, 2024, declared unlawful and vacated the guidance to the extent it said HIPAA is triggered when an online technology connects an IP address with a visit to an unauthenticated public page about specific health conditions or providers. HHS notes it is evaluating next steps. The rest of the bulletin still stands: portals, login and registration pages, appointment tools and symptom checkers remain places where tracking can reach PHI.

For design, that means a condition page with no form is lower risk than it looked in 2023, but an appointment page, login page or intake flow still needs tracking kept out unless a BAA covers the vendor.

Can you use Google Analytics or a Meta Pixel on a HIPAA compliant website?

You can use analytics on public marketing pages with care, but keep ad pixels and general analytics off patient portals, login and registration pages, intake forms and appointment flows unless the vendor signs a BAA. Most mainstream ad and analytics tools do not offer one, so the safe default is to exclude them from the PHI zone.

In a HIPAA compliant website design we handle this at the template level rather than by memory. The PHI-zone layout simply does not load the tag manager, so a marketer adding a new pixel next year cannot accidentally put it on the intake page. On public pages, we configure analytics to avoid collecting form contents, strip query strings that could carry identifiers and avoid event names that describe conditions (“booked_oncology_consult” tells a vendor too much).

Measuring bookings is still possible. One approach is to count completions inside your own BAA-covered system and report totals, not individuals. Another, described in the HHS bulletin, is a customer data platform vendor that signs a BAA, de-identifies the data and passes only de-identified information on to tools that will not sign one. The trade-off is less granular ad attribution. Most practices find that acceptable once they see the risk on the other side.

  • PHI zone: no tag manager, no pixels, no session recording, no third-party chat without a BAA
  • Public zone: analytics configured without form capture or identifying parameters
  • Conversion data: aggregate counts from your own system, or a BAA-covered data platform
  • Every tag documented with its purpose and owner in the handover pack

How to build encrypted intake forms for a practice website

In HIPAA compliant website design, an encrypted intake form sends answers over TLS straight to a BAA-covered database or form service, stores them encrypted at rest, and notifies staff that a new submission exists without putting the answers in the email. Staff then read the submission after logging in.

That last point matters more than it sounds. The most common leak we find in practice websites is not hacking; it is a form plugin that emails the full submission, date of birth and symptoms included, to a shared inbox on an ordinary email plan. Changing the notification to “New intake received, sign in to view” removes the problem without changing the patient experience at all.

On a custom build, the form posts to an API running in your own cloud account under that provider's BAA. The database encrypts data at rest, backups are encrypted too, and files such as insurance card photos go to private storage with short-lived signed links. Each staff member signs in with their own account and multi-factor authentication, and every view or export is logged. On a vendor build, we embed the HIPAA-eligible form service, check that your plan includes the BAA, and make sure the form loads without your site's analytics on the same page.

Either way, we minimise fields first. If you do not use a question in the visit, do not ask it online.

Secure hosting for HIPAA compliant website design

For HIPAA compliant website design, host the public marketing site wherever it performs best, and host the PHI zone in a cloud or vendor account that signs a BAA and offers encryption, access control and logging. Splitting the two keeps the expensive, locked-down environment small.

The HIPAA Security Rule's technical safeguards in 45 CFR 164.312 name the controls to plan for: access control with unique user identification, an emergency access procedure, automatic logoff, encryption and decryption, audit controls, integrity protections, person or entity authentication, and transmission security. Some are labelled required and some addressable, which means you assess whether they are reasonable and appropriate and document the decision. That assessment is your practice's job; our job is to make each control available and switched on by default.

In practice, a typical PHI zone we build runs in the practice's own cloud account: a small API, an encrypted managed database, private file storage, a web application firewall, and centralised logs retained for the period your policies set. The public site can be a static build on a content delivery network, which is fast, cheap and has no database to breach. Both live in accounts your practice owns, so the credentials, the BAA and the billing relationship all sit with you, not with us.

Access control and audit logs in a HIPAA compliant website design

Every HIPAA compliant website design with a back office should give each staff member a named account, require multi-factor authentication, grant only the access each role needs, and log who viewed, changed or exported PHI. Shared logins make audit trails useless.

The workflow side is where HIPAA compliant website design meets daily clinic life. Front-desk staff might see new intake submissions but not billing notes; a clinician sees full questionnaires for their own patients; the practice manager can export. We model those roles in plain language with you before building them, because a permission scheme that is too strict gets bypassed with shared passwords, and one that is too loose defeats the purpose.

Audit logs should answer three questions quickly: who opened this record, when, and from where. We write logs to storage that ordinary staff accounts cannot edit, set automatic logoff after a period of inactivity you choose, and include a simple screen for the practice manager to review recent access. For offboarding, the admin panel has a one-click “disable user” action, so an employee who leaves on Friday cannot sign in on Saturday. Documentation of these settings goes into your compliance file.

How much does a HIPAA compliant website cost?

With us, a practice website starts at US$150, a content-heavy site with many condition and location pages starts at US$300, and custom encrypted intake or a portal front end starts at US$900. Your BAA-tier vendor subscriptions are separate and paid directly to those vendors.

The cost of HIPAA compliant website design depends less on page count and more on how much PHI the site handles. Four drivers move the quote most. First, whether you use an off-the-shelf HIPAA-eligible form service or need custom intake logic. Second, how many staff roles and permissions the back office needs. Third, integrations, for example sending intake data to your EHR through its API. Fourth, how much existing tracking and plugin clutter needs to be audited and removed from your current site.

Across the market, quotes vary widely, partly because some providers price in the ongoing platform subscription and others price only the build. When comparing, ask each one to list which vendors will hold PHI, who signs the BAA with each, and what you pay monthly after launch. A lower build price with PHI flowing through an uncovered plugin is not cheaper in any sense that matters. For general practice site budgets, our page on what a small business website costs covers the non-health baseline.

How to choose a developer for HIPAA compliant website design

Choose a developer who can explain, in writing, where every piece of PHI goes on your future site, which vendor holds it and who signs the BAA. If the answer is vague or “our hosting is HIPAA compliant”, keep looking.

Good questions to ask: Will you need access to real patient data during the build? (The answer should usually be no.) Which tags will load on the intake page? How are form notifications worded? Where are backups stored and are they encrypted? What happens to logs, and for how long? Who owns the cloud account? Can you give me a data-flow diagram my counsel can review?

Red flags are just as telling. Be wary of anyone who calls their work “HIPAA certified” without explaining what that means and who issued it, promises that a consent banner solves tracking, installs a chat widget without asking about BAAs, or keeps the hosting account in their own name. Also be wary of the opposite extreme: a developer who refuses to build any form at all and tells you to use phone calls only, when a properly scoped secure form would serve patients better. A sensible partner explains the trade-offs and leaves the legal judgement to your counsel.

Beyond HIPAA: FTC, state health-data laws and accessibility

HIPAA is not the only rule that shapes HIPAA compliant website design for a US health business. Non-covered health apps and services may fall under the FTC Health Breach Notification Rule, some states have their own consumer health-data laws, and the ADA applies to the websites of businesses open to the public.

The FTC says its Health Breach Notification Rule covers vendors of personal health records and related entities not covered by HIPAA, and that July 2024 amendments make clear that makers of health apps and connected devices must comply. The Washington Attorney General describes the state's My Health My Data Act as protecting consumer health data outside HIPAA's scope, with main provisions effective March 31, 2024 for most businesses and June 30, 2024 for small businesses, and a requirement to link a consumer health data privacy policy from the homepage.

Accessibility is the other half of a patient-friendly site. The Department of Justice's March 2022 guidance says the ADA's requirements apply to goods and services that public accommodations offer on the web. We build forms with proper labels, keyboard support and readable error messages, which also cuts form abandonment. Our accessibility-focused website page and California privacy page go deeper. None of this is legal advice; your counsel decides which rules apply to you.

HIPAA compliant website design with a team in India: how it works from the US

From the US, you work with us through video calls in your Eastern morning, which is our evening, plus WhatsApp or Slack in between. Quotes and invoices are in USD, paid by wire, Wise or PayPal. The key difference on health projects is that we are set up to never need your patients' data.

India is nine and a half hours ahead of US Eastern time during daylight saving and ten and a half in winter, so an 8:30 a.m. call in Chicago or New York is early evening for us; Pacific clients usually take early calls. Your practice creates the cloud account, form service and domain registrar login, signs the BAAs with those vendors, and invites us with limited roles. We deploy into your environment using test data only; production PHI appears only after launch, inside your accounts, visible to your staff.

The first two weeks look like this. Days one and two: you send your current site, forms and workflow notes; we return questions and, about two working days later, an itemised quote. Week one after approval: we produce the PHI flow map and tag inventory, you review it with your compliance lead, and we agree which forms stay, go or change. Week two: wireframes of the public pages and the intake flow, the cloud environment skeleton, and the first staging link you can click through. Contract terms, confidentiality and ownership are set out in the written quote; defaults are on our terms page. We don't visit clinics, and invoices come from India.

Does HIPAA compliant website design hurt SEO or AI-search visibility?

A HIPAA compliant website design can still rank well. Search visibility comes from public content, page speed and local signals, none of which require PHI. The only change is how you measure results.

Condition, treatment, provider and location pages are public and should be written for patients: what the treatment is, who it suits, what to expect, insurance accepted, how to book. We add structured data for the practice and its locations, keep pages fast (Google's web.dev guidance treats an LCP of 2.5 seconds or less, INP of 200 milliseconds or less and CLS of 0.1 or less at the 75th percentile as good), and link each service to its booking route. Google Search Console reports queries and clicks in aggregate and does not need tags on patient pages, which makes it a natural fit.

AI assistants such as Google's AI Overviews and chat-based search tend to quote short, self-contained answers from clear pages. Provider bios with real credentials, plain-English FAQ blocks and consistent practice details across your site and Google Business Profile help. For ongoing work, see our local SEO service, and ask us how to keep review requests free of health details.

Worked example: a hypothetical two-location physical therapy practice in Denver

Say a physical therapy practice with clinics in Denver and Aurora wants online new-patient intake and better search visibility. This is an illustrative scenario, not a past client.

Their current site runs a page builder with a contact form that emails every submission, injury details included, to a shared inbox, and an ad pixel loaded on every page, including the appointment request. The PHI flow map shows three problem points: the form email, the pixel on the booking page, and a chat widget whose vendor has no BAA.

The plan splits the site. The public side is rebuilt as a static site with provider bios, condition pages for back pain, sports injuries and post-surgical rehab, and a page per clinic. That part is quoted from our US$300 line because of the number of pages. The intake side becomes a custom form in the practice's own cloud account under the provider's BAA, with file upload for referral letters, staff roles for front desk and therapists, and audit logs; that portion starts from US$900. The chat widget is removed, the pixel is limited to public pages, and bookings are counted as monthly totals from the intake system.

The practice's compliance consultant reviews the flow map before build, which is how HIPAA compliant website design should always run: counsel reviews the plan, not just the finished site. After launch, staff read intakes after signing in, and no health details travel by email.

HIPAA compliant website design launch checklist

Before go-live, confirm that every PHI path ends in a BAA-covered service, that no tracking loads in the PHI zone, and that your staff can sign in, view and export only what their role allows. Then have your counsel or compliance officer review the documentation.

  • PHI flow map approved, listing every field and destination
  • Signed BAAs on file for hosting, forms, email, scheduling and chat vendors
  • Tag inventory: no pixels, session replay or tag manager on PHI pages
  • TLS everywhere; data and backups encrypted at rest
  • Form notifications contain no PHI
  • Named staff accounts with MFA; automatic logoff configured
  • Audit logs enabled, protected from edits and reviewed on a schedule
  • Accessible labels, keyboard navigation and clear error messages on forms
  • Privacy policy and notice of privacy practices linked where patients expect them
  • Incident contact and steps written down for your team

HHS breach rules under 45 CFR 164.408 set different reporting routes for breaches involving 500 or more individuals and those involving fewer, which is one more reason to keep PHI paths short and logged. Ready to check your current site against this list? Send it via our contact page.

Vendors

Website components, PHI exposure and whether a BAA is needed

A starting map for your own review. Your counsel decides the final position for each vendor.

Website components, PHI exposure and whether a BAA is needed
ComponentCan it receive PHI?BAA with the vendor?How we build it
Static public pages on a CDN Normally noUsually not neededNo forms that invite health details; fast static hosting
Intake or appointment form YesYesHIPAA-eligible form service or custom API in your BAA-covered cloud
Database and file storage for submissions YesYes, even if encryptedEncrypted at rest, private buckets, signed links
Form notification email Yes, if it includes answersNeeded if PHI is sentNotification only: “new submission, sign in to view”
Patient portal login page YesNeeded for any tracking vendorNo analytics or pixels loaded on the page
Live chat or chatbot OftenYes, if patients use itOnly vendors that sign one, or removed
Analytics on public pages Lower risk after June 2024Review per pageNo form capture, no identifying parameters

Cost

HIPAA compliant website design cost by scope

Starting prices in USD. Vendor subscriptions under a BAA are paid by your practice directly.

HIPAA compliant website design cost by scope
ScopeTypical contentsStarts atTimeline
Information-only practice site Services, providers, locations, call-back form without health fieldsUS$1501–2 weeks
Practice site plus HIPAA-eligible form service Same site with vendor intake forms embedded and styledUS$1502–3 weeks
Content-heavy practice site Dozens of condition, treatment and location pagesUS$3003–5 weeks
Custom encrypted intake Your own forms, roles, audit logs, file uploadsUS$9006–10 weeks
Patient portal front end Login, messages, documents via your EHR's APIUS$9008–12 weeks
Monthly care Patching, form tests, log reviewUS$120/moOngoing

Safeguards

Security Rule technical safeguards and what the build provides

Standards named in 45 CFR 164.312. The build makes each control available; your risk analysis decides how you apply it.

Security Rule technical safeguards and what the build provides
StandardWhat it asks forWhat we build
Access control Unique user IDs, emergency access, automatic logoff, encryptionNamed accounts, break-glass admin, idle timeout, encryption on by default
Audit controls Record and examine activity in systems with ePHITamper-resistant logs of views, edits and exports
Integrity Protect ePHI from improper alteration or destructionVersioned records, restricted delete, backup checks
Person or entity authentication Verify users are who they claimMulti-factor sign-in for every staff account
Transmission security Guard ePHI sent over networks; encryption where appropriateTLS on every endpoint, no PHI in email or URLs

Healthcare websites across the US

Where US practices ask us about HIPAA compliant website design

We work remotely with practices in every state. These metros show the kinds of health organisations that typically need careful PHI handling on their websites.

  • Houston, Texas

    Home to the Texas Medical Center, the metro has many specialty clinics and imaging centres that need intake forms and referral uploads handled inside BAA-covered systems.

  • Boston, Massachusetts

    Hospital-affiliated practices and health startups here often arrive with compliance teams already involved, wanting a clear data-flow map before any design work begins.

  • Nashville, Tennessee

    A centre for healthcare management businesses, where multi-site physician groups want consistent practice websites with shared intake rules across many locations.

  • Rochester, Minnesota

    With Mayo Clinic nearby, independent practices and patient-services businesses compete for visibility and need sites that treat patient enquiries carefully.

  • Cleveland, Ohio

    Specialty practices and home health providers in the region look for websites where referrals and new-patient paperwork stay off ordinary email.

  • Philadelphia, Pennsylvania

    Dense with teaching hospitals and outpatient groups, the city has many practices modernising old sites with plugin forms that email PHI in plain text.

  • Baltimore, Maryland

    Behavioural health clinics and specialty groups want online intake with strong access control, because the information patients share is especially sensitive.

  • Atlanta, Georgia

    Fast-growing multi-location dental, dermatology and urgent care groups need scalable location pages and a single secure intake route behind them.

  • Tampa, Florida

    Retiree-heavy communities keep demand high for cardiology, orthopaedic and home care practices that need accessible, large-text forms with careful data handling.

  • Phoenix, Arizona

    Growing physical therapy, chiropractic and med spa businesses want booking funnels that measure results without sending patient details to ad platforms.

  • Denver, Colorado

    Sports medicine, rehab and mental health practices across the Front Range need intake forms, referral uploads and privacy-safe conversion tracking.

  • Seattle, Washington

    Health and wellness businesses here also weigh Washington's My Health My Data Act, which reaches consumer health data outside HIPAA.

  • San Diego, California

    Life-science startups and specialty clinics want patient-facing sites that respect both HIPAA-style safeguards and California privacy requirements.

  • New York, New York

    Private practices and therapy groups across the boroughs need fast mobile sites, secure new-patient forms and clear separation of marketing from clinical data.

How it works

How HIPAA compliant website design runs with us, step by step

  1. Send your site and forms

    Share your current website, every form you use and a short note on your intake workflow. We reply with questions, usually the same day, and flag obvious PHI leaks straight away.

  2. Get the itemised quote

    About two working days later you receive a USD quote that separates the public site, the PHI zone and your own vendor subscriptions. Nothing is billed before written approval.

  3. Approve the PHI flow map

    We document every field, destination, tag and vendor. You and your compliance lead review it, sign BAAs with the chosen vendors and invite us with limited roles.

  4. Build with dummy data

    Public pages and the secure intake are built in your accounts using test records only. You click through staging builds each week on a call in your morning.

  5. Pre-launch checks

    We run the launch checklist together: tag scan, notification test, role tests, logging, accessibility and speed. Findings are fixed before any patient sees the site.

  6. Launch and hand over

    You receive the flow map, tag inventory, vendor list and admin guide. Free fixes run for two months, then optional care plans start at the listed monthly price.

Questions

HIPAA compliant website design: questions US practices ask

What is a HIPAA compliant website?

It is a website whose handling of protected health information fits within a covered entity's HIPAA program: PHI goes only to vendors under a business associate agreement, data is encrypted in transit and at rest, access is limited and logged, and tracking tools stay off pages that handle PHI. The website supports compliance; the practice itself is responsible for it.

Does every medical practice website need to be HIPAA compliant?

Any part of a covered entity's website that collects, stores or sends PHI must be handled under HIPAA. A site that only publishes information and never receives patient details has far less exposure, although tracking tools and open message boxes can still create risk. Map every form and tag first; that list shows how much of the site needs safeguards.

How much does HIPAA compliant website design cost?

With our team, practice websites start at US$150, larger content sites at US$300, and custom encrypted intake or portal front ends at US$900. Vendor subscriptions that include a business associate agreement, such as hosting or a form service, are billed to your practice directly and listed in the quote. The amount of PHI handled drives cost more than page count.

Is a contact form on a medical website PHI?

It can be. A form that pairs a name, email, phone number or IP address with health details, such as a reason for visit, is PHI when a covered entity receives it. Open message boxes invite patients to share symptoms, so either build the form to handle PHI properly or keep it to a call-back request on a general page.

Do I need a business associate agreement with my web host?

If the host stores PHI, such as form submissions or uploads, yes. HHS guidance says a cloud provider that stores electronic PHI is a business associate even when it holds only encrypted data without the key. A host serving only public marketing pages with no PHI generally is not in that position, which is why we split the two.

Will your team sign a BAA with our practice?

No. We design the site so we never need access to real patient data: PHI flows only into hosting, form and email services that sign BAAs directly with your practice, and we build and test with dummy records. If a requested feature would require us to handle live PHI, we raise it early so you can decide with your counsel.

Can I use Google Analytics on a HIPAA website?

Use it carefully on public marketing pages, configured to avoid form contents and identifying parameters, and keep it off patient portals, login and registration pages, intake forms and appointment flows unless the vendor signs a BAA. For bookings, count completions inside your own BAA-covered system and report totals instead of sending individual events to analytics.

Is the Meta Pixel allowed on a healthcare website?

Keep ad pixels away from any page where PHI can be collected, such as appointment requests, intake forms and portal logins. HHS says cookie consent banners are not a valid HIPAA authorization, so a banner does not fix a pixel on a booking page. Public pages carry less risk after the June 2024 court ruling, but review each one.

What did the 2024 court ruling change about HHS tracking guidance?

On June 20, 2024, a federal court in Texas vacated the part of the HHS tracking bulletin saying HIPAA is triggered when a technology links an IP address with a visit to an unauthenticated public page about health conditions or providers. Guidance on patient portals, login pages, appointment tools and symptom checkers remains, and HHS said it was evaluating next steps.

How are HIPAA intake forms encrypted?

Answers travel over TLS to a BAA-covered form service or a database in your own cloud account, where they are encrypted at rest along with backups and uploaded files. Staff receive a notification that a submission exists, then sign in with multi-factor authentication to read it. The answers themselves never travel by ordinary email.

How long does HIPAA compliant website design take?

An information-only practice site takes one to two weeks, and a larger content site three to five. Custom encrypted intake or a portal front end usually takes six to twelve weeks, depending on roles, integrations and review time. Your own steps, such as signing vendor BAAs and compliance review of the flow map, also affect the schedule.

Can a healthcare website rank well if it avoids tracking pixels?

Yes. Rankings come from useful public content, speed, structured data and local signals, not from pixels. Google Search Console reports search performance in aggregate without tags on patient pages, and bookings can be counted inside your own system. You lose some ad-attribution detail, not organic visibility.

Should I use a healthcare website platform or a custom build?

A healthcare platform that hosts everything and signs one BAA can be simpler if its templates suit you. A custom build fits when you need your own design, workflow or integrations and are comfortable holding separate agreements with a cloud provider and form vendor. Ask any option which systems hold PHI and who signs each agreement.

Does HIPAA apply to therapists' and counsellors' websites?

If the therapist is a covered entity, for example because they bill insurance electronically, PHI collected through the website falls under HIPAA. Mental health intake is especially sensitive, so we keep forms short, route them to BAA-covered services and avoid chat widgets without agreements. Our therapist website page covers the rest of the design side.

What about health apps or wellness businesses not covered by HIPAA?

They may fall under other rules. The FTC says its Health Breach Notification Rule covers vendors of personal health records not covered by HIPAA, including health app makers after July 2024 amendments, and states such as Washington have consumer health-data laws. Your counsel should confirm which rules apply before we design data flows.

Who is responsible for HIPAA compliance, the developer or the practice?

The practice, as the covered entity, is responsible for its HIPAA compliance, including risk analysis, policies, training and vendor agreements. Vendors that handle PHI carry their own business associate duties. A developer who never touches PHI provides technical safeguards and documentation; your counsel or compliance officer confirms the whole picture.

Can you fix our existing site instead of starting a new HIPAA compliant website design?

Often, yes. We start with a PHI flow audit that lists every form, tag and widget, then recommend targeted fixes: rewording form notifications, removing pixels from booking pages, swapping a chat vendor, or moving intake to a BAA-covered service. If the platform itself blocks those fixes, we explain why a rebuild would cost less over time.

How do I pay a team in India from the US?

You receive an itemised quote in USD and pay approved milestones by bank wire, Wise or PayPal. Invoices come from India. Your accountant can advise how to record them; we do not give tax advice. Nothing is billed before you approve the quote in writing.

What time are calls with your team?

Most calls happen in your morning. India is nine and a half hours ahead of US Eastern time in summer and ten and a half in winter, so an 8:30 a.m. Eastern call is early evening for us. West Coast practices usually take early calls, and WhatsApp messages get replies seven days a week.

Who owns the website, hosting and data?

Your practice. You register the domain, open the cloud and form accounts, sign the BAAs with those vendors and invite us with limited access. The code goes into a repository you own. At the end we hand over documentation and remove our access, so patient data never sits in accounts outside your control.

What happens after launch?

Fixes are free for two months after launch. After that, care plans start at US$120/mo and cover security patches, dependency updates, monthly form tests and a review of logs and tags, since new marketing tools have a habit of creeping onto pages they should not be on. You can also take maintenance in-house using the handover pack.

Next step

Send us your site and every form on it

Share your website address and intake workflow on WhatsApp. We point out where patient data could leak, then send an itemised USD quote with the PHI flow map plan in about two working days.