Website Design

HIPAA for Websites: EVERYTHING You Need to Know to Stay Compliant and Avoid Fines

Most healthcare websites are quietly violating HIPAA through tracking pixels and unprotected forms. Here’s what triggers a violation and the five-step playbook to fix it.

Use AI to summarize this article

Is Your Healthcare Website Breaking HIPAA? Here's What's Actually Triggering It

I've built over 100 websites for healthcare companies at MMG Studio, and almost every one of them started the same way. A founder or marketing lead comes to us with a site that already has Google Analytics running, a Meta Pixel installed, and a contact form collecting names and phone numbers. Nobody flagged it as a problem, because on the surface, nothing looks wrong. No one's stealing data. No one's hacking the site. It just looks like a normal marketing setup.

That's exactly the problem. HIPAA violations on websites rarely look like a data breach. They look like a normal marketing stack running in an environment it was never built for. And I've watched even smart, careful teams walk straight into it, including one of our own clients early on, a pharmacy tech company that needed an NABP certification badge. That certification came with a mandatory HIPAA check, and it was the first time we discovered we were in violation of several requirements without knowing it. It didn't turn into a lawsuit, but it was close enough to change how we build every healthcare site since.

Free playbook

HIPAA compliance doesn't have to slow down your launch.

Get the 5-step playbook healthcare marketing teams use to launch a compliant site without the guesswork or the legal back and forth.

Get the free playbook

What HIPAA Actually Protects, and Why Most Marketers Get It Wrong

HIPAA, the Health Insurance Portability and Accountability Act of 1996, exists to protect what's called protected health information, or PHI. The part almost everyone misunderstands is that health information alone is not PHI. Identifying information alone is not PHI either.

It's the combination of the two that creates the violation. "Depressive symptoms" is just a phrase. "John Smith" is just a name. But "John Smith has depressive symptoms" is protected health information, and that pairing is what triggers HIPAA.

PHI covers the categories you'd expect: full names, email addresses, phone numbers, home addresses, dates of birth, social security numbers, insurance IDs. But it also covers something most marketing teams never think about, which is URL structure. If your site is organized well from an SEO standpoint, your URLs already reveal the nature of the services someone is looking at. A visit to a page like /services/oncology tells you something about that visitor's health, whether you meant it to or not.

The Two Types of HIPAA Violations Your Website Can Commit

There are two categories worth understanding, because they show up in almost every healthcare marketing stack.

Context violations happen when PHI itself gets captured and sent somewhere it shouldn't go. If a patient fills out a contact form, that data usually flows to a third party server. If you don't have a signed business associate agreement, known as a BAA, with whoever is storing that data, you're in violation. Most marketing teams don't have one.

Intent violations are more subtle. These happen when you're tracking behavior that reveals health interest, even without a form submission. Someone visiting a page about oncology services is revealing something about their health just by being there. If any pixel or analytics tool is tracking that page, you have a violation. A compliant cookie consent setup that requires opt in before visiting sensitive pages is one way around this, though I'll be honest, it's one of the more confusing gray areas in the entire framework.

The tools most likely to cause this problem are ones you probably already have installed: Meta Pixel, Google Analytics, Hotjar, Intercom, LinkedIn Insight tags, and TikTok Pixel. These aren't obscure tools. They're standard on most business websites, which is exactly why healthcare sites get caught off guard.

Real Settlements That Prove This Isn't Theoretical

Two cases from 2023 show how this plays out at scale.

GoodRx settled a class action lawsuit for 25 million dollars after disclosing prescription data. The platform had Meta Pixel and Google Analytics 4 active on pages tied to specific medications, and that data was shared with advertisers. Someone researching a drug that signals a health condition had that information passed along without their knowledge. That's a textbook intent violation.

BetterHelp, the online therapy platform that sponsored Joe Rogan's podcast for years, settled for 7.8 million dollars. The cause was Facebook and Snapchat pixels running across their ad platforms. Mental health data is one of the most protected categories under HIPAA, which made this a fairly straightforward case for regulators.

If you're running a two to ten million dollar healthcare company, I understand the instinct to think this only applies to platforms like these. It doesn't. We've worked with mid market clients who ran into this exact contention, just at a smaller scale with fewer headlines attached.

There's No HIPAA Certification, and Any Badge Claiming Otherwise Is Fake

I want to be direct about this because it matters. There is no such thing as a HIPAA compliance certification for a website. If you see a HIPAA compliant badge in an agency's footer or on a healthcare site, it isn't real. Certifications exist for staff training, not for websites, and they don't apply in this context.

What makes HIPAA frustrating is that there's no pass or fail metric. Your job, and mine, is risk reduction. Not a badge. Not a checkbox. The goal is getting as close to the framework's intent as possible and treating it as an ongoing responsibility, not a one time fix.

The Five Step Playbook to Bring Your Website Into Compliance

Here's the process we run on every healthcare build, broken down so you can run it yourself.

Step one: map your data flows. Before touching a single script, answer four questions. Does your site collect names alongside anything that could reveal health information? Do you have a patient portal, scheduler, or intake form? What third party tools are currently active on your site? What do your URL structures reveal about visitor intent? Document the answers in one place, not just your privacy policy.

Step two: audit your script inventory. Open your tag manager or source code and write down every script that fires. Google Search Console and Google Lighthouse both make this easier. Pay close attention to Meta Pixel, Google Analytics, Hotjar, Intercom, LinkedIn Insight tags, and TikTok Pixel, since these are the most common culprits we find on client sites. If you have the budget, tools like FreshPaint act as a proxy layer that strips PHI before it reaches Google Analytics. Full Story, Heap, and similar server side tracking providers offer the same kind of protection at an enterprise price point.

Step three: lock down your forms. Standard contact forms are the most common failure point, and the fix is straightforward. Use a CRM or form tool that's HIPAA compliant by design, such as HubSpot or Zoho, or work with a provider willing to sign a BAA with you.

Step four: get your BAAs in order. A business associate agreement is a legal contract between a covered entity and any vendor handling PHI on its behalf. Your checklist should cover your hosting provider, whether that's AWS, Google Cloud, Cloudflare, or a service like Hostinger or GoDaddy, along with your form tool, CRM, email platform, analytics tools, and chat integrations. Get signed BAAs before launch, or work with an agency that opens this conversation for you from the start.

Step five: publish and maintain your privacy framework. You need a notice of privacy practices, which is legally mandated if your client qualifies as a covered entity. The HHS website provides a free template with no email required. Your cookie consent banner needs to be prominent enough that a visitor can't reasonably claim they never saw it. Your privacy policy itself needs to stay current on every tracking technology in use, what data is collected, how it's stored, and what rights users have. We've used Termageddon for this on client sites, and it auto updates based on what's actually running on the website, which removes a lot of the manual upkeep.

Treat This as an Ongoing Responsibility, Not a Launch Task

The companies that got fined weren't careless. They just didn't build compliance into how they operate day to day. That's the real lesson here. HIPAA compliance isn't a box you check once during a website launch and forget about. It's a standard you maintain as your stack changes, as new tools get added, and as your content grows.

If you want the full checklist version of this playbook, including the tool by tool breakdown and BAA request templates, grab the free HIPAA compliant website playbook. No email required.

And if you're evaluating whether your site's design and structure are actually built to support this kind of compliance long term, take a look at our high converting websites visual swipe file for examples of what that looks like done right.