HIPAA Website Risk Checklist
Technical self-assessment for healthcare practices
Most healthcare website compliance issues come from standard tools and default configurations — not deliberate negligence. This checklist helps you spot the exposures most commonly found during technical audits, across 26 specific items grouped into 5 sections.
How to use it: Work through each section honestly. If you are unsure about any item, treat it as a "No" — unverified is not the same as compliant. Print this page to PDF from your browser if you want a copy.
Tracking & Third-Party Exposure
Forms & Patient Data Handling
Security & Infrastructure Controls
Privacy & Regulatory Alignment
Internal Controls & Accountability
Interpreting your results
If any item is marked "No" or "Unsure," your website may be exposing patient data through a common misconfiguration. Most compliance gaps on healthcare websites come from the same handful of patterns — tracking pixels, non-BAA forms, analytics capturing URL parameters, missing state-law notices. None of them require malicious intent to create liability.
Recent enforcement trends
- In 2025, Aspen Dental agreed to an $18.5 million class action settlement related to tracking technologies on its website.
- The HHS Office for Civil Rights (OCR) has issued direct guidance stating that tracking technologies capturing patient-related interactions without a BAA constitute a violation — regardless of intent.
- Enforcement actions have repeatedly cited missing BAAs with common vendors: analytics providers, form services, chat widgets, and hosting platforms.
- State-level laws — Washington MHMDA, California CMIA/CCPA, Texas HB 300, New York SHIELD — extend exposure beyond federal HIPAA. Several allow patients to sue the practice directly, without a regulator.
Many of these patterns come from tools set up without compliance in mind: analytics copied from a marketing agency's template, a chat widget added by a well-intentioned office manager, a plugin installed years ago and never reviewed.
Next step
A structured technical audit:
- maps every tracker, cookie, form, and third-party tool on your site
- identifies which pose actual compliance risk under HIPAA and your state's privacy law
- delivers a prioritized remediation plan — the material issues first
Free report delivered as a PDF to your email within 3–5 business days. No commitment.