Free Resource · No email required

HIPAA Website Risk Checklist

Technical self-assessment for healthcare practices

Most healthcare website compliance issues come from standard tools and default configurations — not deliberate negligence. This checklist helps you spot the exposures most commonly found during technical audits, across 26 specific items grouped into 5 sections.

How to use it: Work through each section honestly. If you are unsure about any item, treat it as a "No" — unverified is not the same as compliant. Print this page to PDF from your browser if you want a copy.

Request Free Audit
Your progress 0 of 26 items checked
01

Tracking & Third-Party Exposure

02

Forms & Patient Data Handling

03

Security & Infrastructure Controls

04

Privacy & Regulatory Alignment

05

Internal Controls & Accountability

Interpreting your results

If any item is marked "No" or "Unsure," your website may be exposing patient data through a common misconfiguration. Most compliance gaps on healthcare websites come from the same handful of patterns — tracking pixels, non-BAA forms, analytics capturing URL parameters, missing state-law notices. None of them require malicious intent to create liability.

Recent enforcement trends

  • In 2025, Aspen Dental agreed to an $18.5 million class action settlement related to tracking technologies on its website.
  • The HHS Office for Civil Rights (OCR) has issued direct guidance stating that tracking technologies capturing patient-related interactions without a BAA constitute a violation — regardless of intent.
  • Enforcement actions have repeatedly cited missing BAAs with common vendors: analytics providers, form services, chat widgets, and hosting platforms.
  • State-level laws — Washington MHMDA, California CMIA/CCPA, Texas HB 300, New York SHIELD — extend exposure beyond federal HIPAA. Several allow patients to sue the practice directly, without a regulator.

Many of these patterns come from tools set up without compliance in mind: analytics copied from a marketing agency's template, a chat widget added by a well-intentioned office manager, a plugin installed years ago and never reviewed.

Next step

A structured technical audit:

  • maps every tracker, cookie, form, and third-party tool on your site
  • identifies which pose actual compliance risk under HIPAA and your state's privacy law
  • delivers a prioritized remediation plan — the material issues first
Request Free Audit

Free report delivered as a PDF to your email within 3–5 business days. No commitment.