Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Is Your Website HIPAA-Compliant?

By Vijay Choksi on August 1, 2022
Email this postTweet this postLike this postShare this post on LinkedIn
Stethoscope and Laptop Computer. Laptop computers and other kinds of mobile devices and communications technologies are of increasing importance in the delivery of health care. Photographer Daniel Sone
National Cancer Institute, Unsplash

If you are a HIPAA-covered entity or business associate, you likely know that patient PHI may only be created, received, maintained, and transmitted as permitted by the HIPAA Security Rule and the HIPAA Privacy Rule.  Yet you may not have focused on your company’s website as a place where PHI is collected and transmitted.  If you are subject to HIPAA, you should continually assess your website data practices.  As described in this blog post, you should make sure third-party trackers like Meta Pixel are not accessing and disclosing data behind the scenes.  But common customer-facing tools should not be overlooked.  Common ways in which PHI may be collected and transmitted include:

  • Live Chat
  • Patient Portals
  • Online Patient Forms
  • Online Scheduling Tools
  • Reviews and Testimonials
  • Email
  • Online loyalty Programs

The HIPAA Privacy Rule requires that entities that create, receive, maintain, and/or transmit PHI take specific measures to protect it. For example, if your company keeps individually identifiable medical information on a server, that server must be encrypted and secure. Transmitting PHI includes sending information via email, text, web forms or other types of digital messaging. Storing PHI includes storing information in apps, data centers, etc. If your company website collects, stores, or transmits PHI and does not take reasonable measures to secure that data, it may violate HIPAA.

To begin remediating risks, companies should:

  • Purchase and implement an SSL certificate for the company website
  • Ensure all web forms on the company website are encrypted and secure
  • Only send emails containing PHI through encrypted email servers
  • Partner with web hosting companies that are HIPAA-compliant and have processes for protecting PHI
  • Execute BAAs with third parties that have access to PHI (including web hosting companies)
  • Ensure that PHI is only accessible by authorized individuals within your company
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    HIPAA & Health Information Technology
  • Organization:
    Fox Rothschild LLP

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo