Do Therapist Websites Need to Be HIPAA Compliant?
Where the line actually sits and which of your tools need a BAA.
If you’ve been building or thinking about your therapist website, you’ve probably run into this question at least once: does my therapy practice website need to be HIPAA compliant?
Maybe someone in a therapist Facebook group mentioned it. Maybe you Googled it and got seventeen conflicting answers. Maybe you’ve just been vaguely anxious about it for months, not entirely sure what would even happen if it wasn’t.
Let’s start off with a clear answer and one that doesn’t require a law degree or two hours of reading dense federal regulations.
The short answer is: your website itself doesn’t need to be HIPAA compliant, but certain things you put on it do.
If you go through and remove every place on your website where visitors can input information, no contact forms, no comment sections, no schedulers, your website almost certainly stays outside HIPAA’s reach. Direct people to call, email, or use your EHR’s booking link instead and you’ve sidestepped the complexity entirely.
The longer answer is more nuanced, and understanding the nuance is what actually protects you. Keep reading for the full picture
A HIPAA Refresher
HIPAA (the Health Insurance Portability and Accountability Act) is the US federal law that sets extra protections for the personal information of people who are receiving healthcare services.
If you’re a therapist in private practice in the US, you are a covered entity under HIPAA. That means you are legally required to protect your clients’ privacy, and by extension, the tools and vendors you use to run your practice can carry legal responsibility for how they handle that information.
The data HIPAA specifically protects is called Protected Health Information, or PHI. The key concept is this: health information becomes PHI when it can be connected to a specific person. A general blog post about anxiety is not PHI. A therapy note that includes a client’s name, date of birth, and reason for treatment absolutely is.
The identifiers most likely to come up in website-related work include names, email addresses, phone numbers, appointment dates, and any description of someone’s mental health or reasons for seeking therapy.
Your Website Is a Marketing Tool, Not a Practice Management Tool
Here’s the framing that makes everything else make sense: your therapist website is a marketing tool, not a practice management tool. Think of it as a bridge into your practice. Its job is to help the right people find you, understand what you offer, and feel safe enough to take that first step toward reaching out.
Think of it as existing on one side of a line. On the outside of that line is your public-facing marketing presence: who you are, how you help, what it’s like to work with you. That’s your website. On the inside of that line is your practice: your clients, their records, their communications with you, their care.
The moment someone goes from being a website visitor to being your client, they cross that line, and once they cross it, a different level of digital security applies. The bridge has done its job. Now you’re in practice management territory, and that’s where the real HIPAA work lives.
Your website lives entirely on the outside. As long as it’s doing that job without collecting or storing sensitive health information, it operates outside HIPAA’s strictest requirements.
So What Could Trigger HIPAA on a Website?
HIPAA applies to your website the moment it starts to collect, transmit, or store PHI. The most common elements that trigger HIPAA on a therapist website are contact forms, schedulers, and client portals. The tricky part is that even a simple contact form can collect PHI without you realizing it, because you can’t control what people write in a free-text message field. Most people reaching out to a therapist will share something personal.
How to Think Through HIPAA for Your Website
So what do you actually need to do? Here’s how I’d think through it:
If your website is purely informational (content pages, an about page, a blog) and you’re directing people to contact you by phone or through your EHR’s booking link, your website has minimal HIPAA exposure. You’re essentially using it as a brochure, which is exactly what it is.
If you have a contact form, the questions to ask are: Where are those submissions going? Is the form transmitting data securely? Is the email receiving them from a provider with a BAA? If the answer to any of those is unclear or no, it’s worth exploring secure form options through Hushmail, Simple Practice, or similar.
If you have a scheduler embedded on your site, whether it needs to be HIPAA-compliant is a gray area that depends on how it’s used and how much risk you’re comfortable taking on. It’s worth getting more information on schedulers if you’re unsure. That said, the safest path is no scheduler or one that’s compliant.
If you want clients to be able to message you or access documents through your site, use your EHR’s client portal. Link to it, but keep the actual secure communication inside the compliant system.
Think of your website as the bridge between someone finding you and actually becoming your client. Your job is to make that bridge beautiful and welcoming. But once someone goes from curious visitor to person reaching out, the systems on the other side need to be ready to receive them securely. That means your email, your scheduler, and anything else that touches their information once they’ve made contact.
Some Less Obvious Things to Know About
The more familiar risks are things like: a contact form that collects health information, an unsecured scheduler, a client portal built into the website. But there are a few less obvious risks that almost never come up in the standard HIPAA-for-therapists conversation, and they’re worth knowing about.
Your Blog Comments Are Collecting Data
If you have a blog and you’ve enabled comments, you have a form on your website that anyone can fill out. A reader could write something personal about their mental health in a comment.
Those submissions are typically stored directly in your website’s database, on your hosting server, without any of the protections that a HIPAA-compliant tool would provide. If you’re not actively using your comment section, it’s worth turning it off.
Your Contact Form Data Doesn’t Just Go to Your Inbox
Standard contact form plugins process submissions through your server before sending them to your email. Many also store every submission in a database on your server, meaning there’s a growing record of everything anyone has ever sent you, sitting in your hosting environment.
And when the sending process fails (which it does), many plugins log the error, including the full contents of the failed submission, along with the client’s name, email, and message. Your website administrator may get notified of those errors automatically, seeing information they never intended to see through a completely routine technical process.
People Who Work On Your Website Can Access It All
If you ever hand credentials to a web developer or maintenance person to fix something, it’s worth thinking carefully about what else those credentials open up. A WordPress admin login is usually contained to the website.
But if that same login also gives access to your email, your hosting account where form submissions are stored, or anything that could surface client data, that’s an access problem, even if the person on the other end is completely trustworthy.
HTTPS Is a Start, Not the Whole Answer
You may have heard that your website needs to have a little padlock icon in the browser bar. That’s called HTTPS, and yes, your site does need it. But having that padlock doesn’t mean your website is fully secure or HIPAA-ready. It just means the information is protected while it’s traveling from your visitor’s browser to your website. What happens to it after it arrives is a separate question entirely, and that’s where the other considerations in this article come in.
What About The Deeper Technical Stuff?
The basic building blocks of your website, including where it’s hosted, what it looks like, what platform it’s built on, don’t need to be HIPAA compliant on their own. That’s because none of them are involved in collecting or storing your clients’ personal information. They’re just the foundation your website sits on and are not the systems that handle sensitive data.
At Empathysites, for example, we’re a website design and maintenance service. We don’t provide a BAA (Business Associate Agreement), and neither does our hosting, because an Empathysite is a marketing tool.
The BAA: What It Is and When You Actually Need One
A Business Associate Agreement, or BAA, is a contract between you (the covered entity) and a vendor (the business associate) that establishes the vendor’s responsibility to handle PHI in accordance with HIPAA.
BAAs are required when you’re using a tool that handles PHI on your behalf.
Examples:
- Email. Standard Gmail does not offer a BAA. Google Workspace does, but you have to activate it; it doesn’t happen automatically. Hushmail and Paubox are popular HIPAA-compliant email options that come with BAAs.
- Contact forms. If you want a secure contact form, options like Hushmail’s web forms or other HIPAA-compliant form tools come with BAAs.
- Scheduling software. EHRs like SimplePractice and TherapyNotes are built with HIPAA compliance in mind.
- Telehealth platforms. Any platform you use for video sessions needs a BAA.
What does not require a BAA: your website design service, your web host (in most cases, when the site is a marketing tool only), and your website platform.
What If You’re Not Sure You’re Compliant?
The good news is that HIPAA violations rarely come from an investigator actively monitoring therapist websites. They typically surface through client complaints, data breaches, or audits triggered by something else entirely.
That said, when they do come up, the consequences are worth understanding: civil penalties for unintentional violations can range from $100 to $50,000 per violation and even a single investigation creates financial strain through fines, legal fees, and remediation costs. For a solo practice, getting this set up correctly is time well spent. And beyond the financial side, your reputation is built on trust and confidentiality which is worth protecting too.
Frequently Asked Questions
Does my therapist website need to be HIPAA compliant?
Your website itself, used as a marketing tool, generally does not need to meet the full HIPAA compliance standard. HIPAA requirements apply when a system collects, transmits, or stores Protected Health Information. A website that presents your services, shares your bio, and publishes a blog is not doing any of those things. The compliance requirement kicks in when you add elements that allow clients to input personal or health information, like contact forms, schedulers, or intake tools.
Do I need a BAA for my website?
In most cases, no. A Business Associate Agreement is required when a vendor is handling PHI on your behalf. Your website design service and your web host are not handling PHI if your site is a marketing tool only, so a BAA is typically not needed for those. You do need a BAA for the tools that touch client data: your email provider, any contact forms that store submissions, your scheduler, your telehealth platform, and any practice management software.
Is Squarespace (or Wix, or WordPress) HIPAA compliant?
These platforms are website builders, not healthcare data systems. None of them offer a BAA as part of their standard service, and they’re not designed to handle PHI. That’s fine, because your website doesn’t need to be a healthcare data system. Use them to build your marketing presence, and route any actual client communication through tools that are purpose-built for healthcare.
Is Gmail HIPAA compliant for therapists?
Standard Gmail, the free consumer version, is not appropriate for client communication because Google does not offer a Business Associate Agreement for it. Google Workspace (the paid business version) can be used in a HIPAA-compliant way, but you have to actively sign the BAA with Google and configure your account correctly. It doesn’t happen automatically. Alternatives like Hushmail and Paubox are built specifically for healthcare and come with BAAs included.
What actually happens if a therapist has a HIPAA violation?
HIPAA violations are typically discovered through client complaints, data breaches, or audits triggered by other events. Civil penalties for unintentional violations can range from $100 to $50,000 per violation. Beyond the financial penalties, there’s the cost of legal fees, remediation, and the reputational impact to a practice that depends on trust. Most violations come from using standard tools that seem perfectly reasonable without realizing they weren’t designed with healthcare privacy requirements in mind.
Do contact forms on therapist websites need to be HIPAA compliant?
Most people reaching out to a therapist will share something personal, and once a submission combines a name or email with any health-related information, it’s likely PHI. A secure form through a HIPAA-compliant provider like Hushmail is the safer choice.
Putting It All Together: It’s More Manageable Than It Looks
When your therapist website is used as a marketing tool it does not need to be HIPAA compliant in the full sense. What needs to be HIPAA compliant are the tools that touch PHI: your email, your contact forms if you use them, your scheduler, and any client-facing systems.
The most important thing you can do is understand where the line is between your public-facing marketing presence and your client-facing practice operations and make sure the tools on each side of that line are appropriate to the work they’re doing.
Your website’s job is to be a welcoming bridge into your practice. Let it do that job. Just make sure that once someone crosses it, the systems waiting on the other side are ready to receive them securely.
Read These Next: Related Guides
- The Complete Guide to Contact Forms for Therapist Websites: the risks, the options, and how to decide what’s right for your practice
- The Ultimate Guide to HIPAA Compliant Email for Therapists: BAAs, provider comparisons, and how to set yourself up correctly
- How to Add a Scheduler to Your Therapist Website: what to look for in a scheduling tool and how to embed it on your site
- How to Add a Client Portal to Your Therapist Website: how to add your client portal to your website in the most effective ways possible