Does a Therapist Website Need to Be HIPAA Compliant?

A therapist website only needs to be HIPAA compliant if it collects, stores, or transmits protected health information (PHI). So, does a therapist website need to be HIPAA compliant? Most therapy sites do not handle PHI and therefore do not require full compliance. However, if your site includes forms, portals, or messaging that involve client health data, compliance is necessary.
What counts as PHI on a website?
Protected health information (PHI) includes any data that can identify a client and relate to their health, treatment, or payment. Examples are intake forms with medical history, secure messaging with clients, or payment portals tied to services rendered.
If your website never touches this kind of data, it is not subject to HIPAA. A simple informational site with your bio, services, and contact email does not require compliance.
Common website features and HIPAA
Many therapy websites include contact forms, appointment requests, or newsletters. These are generally safe if they do not ask for or store health-related details. For example, a form that only collects a name, email, and preferred contact time does not involve PHI.
| Feature | Involves PHI? | HIPAA Required? |
|---|---|---|
| Basic contact form (name, email, phone) | No | No |
| Intake form with medical history | Yes | Yes |
| Secure client portal | Yes | Yes |
| Blog or service descriptions | No | No |
| Online payment (no health details) | No | No |
| Encrypted messaging with clients | Yes | Yes |
When a standard website is enough
For most private practices, a well-built public website serves as a digital brochure. It shares your approach, specialties, and how to reach you. These sites do not need HIPAA safeguards because they do not handle sensitive client data.
We build therapist websites that are professional, easy to update, and designed to attract local clients. Hosting, security updates, and edits are included in the monthly fee, so you can focus on your practice.
When you do need HIPAA compliance
If your website includes any feature where clients submit or access health information, HIPAA applies. This could be an online intake form, a portal for test results, or a chat system for therapy sessions.
In these cases, you need a HIPAA Compliant Website Design for Therapists. This involves encryption, access controls, audit logs, and a Business Associate Agreement (BAA) with your web host and any third-party tools.
Any vendor that touches PHI on your site must sign a Business Associate Agreement. This includes your web host, form service, or messaging platform.
What HIPAA compliance entails for a website
A compliant site must protect data in transit and at rest. This means SSL encryption, secure servers, and strict access controls. All forms and portals must be built to prevent unauthorized access.
You also need policies for data retention, breach notification, and client rights like access to their records. These are operational requirements, not just technical ones.
Alternatives to a fully compliant website
Instead of building PHI-handling features into your site, many practices use separate HIPAA-compliant tools. For example, you might direct clients to a secure third-party portal for intake forms or messaging.
This keeps your public website simple and non-compliant, while still offering the functionality clients need. It also reduces your compliance burden, as the third-party vendor handles most of the requirements.
Services like SimplePractice, TherapyNotes, or Doxy.me are designed for HIPAA compliance. Linking to these from your site is often easier than building compliance into your own website.
How to decide what your practice needs
Start by listing every way your website interacts with clients. Note which interactions involve health information. If none do, a standard site is sufficient.
If you do need PHI features, consider whether a third-party tool or a fully compliant website is the better fit for your practice size and budget.
Assess your website’s needs
- List all client-facing features (forms, chat, portals, payments).
- Identify which features involve PHI.
- Determine if a third-party tool can handle PHI features.
- Consult a compliance expert if unsure.
Keeping your site secure and updated
Even non-compliant sites need basic security. SSL certificates, regular updates, and strong passwords protect against common threats. These are standard with our plans and included in the monthly fee.
For compliant sites, security is more rigorous, but the same principle applies: ongoing maintenance is essential. We handle updates and monitoring so you do not have to.
How it works
If you need a website that handles PHI, here is how to approach it.
- 1Audit your needs
Decide which features require PHI and whether they belong on your site or a third-party platform.
- 2Choose a compliant host
Select a hosting provider that offers BAAs and meets HIPAA technical requirements.
- 3Build with security in mind
Use encrypted forms, secure logins, and access controls for any PHI-related features.
- 4Document policies
Create and post your privacy policy, breach notification plan, and client rights information.
- 5Sign BAAs
Ensure every vendor that touches PHI signs a Business Associate Agreement.
- 6Maintain and monitor
Regularly update software, review logs, and test security measures to stay compliant.
Frequently asked questions
Can i add a contact form to my therapy website without HIPAA compliance?
Yes, if the form only collects non-PHI data like name, email, and phone number. Avoid asking for medical history, symptoms, or treatment details unless the form is HIPAA compliant.
Do i need a business associate agreement with my web designer?
Only if your web designer or host will have access to PHI. For a standard informational site, a BAA is not necessary.
What is the difference between a HIPAA compliant and non-compliant website?
A compliant website includes technical, physical, and administrative safeguards for PHI, such as encryption and access controls. A non-compliant site lacks these but is sufficient if no PHI is involved.
Can i use Google forms on my therapy website?
Google Forms is not HIPAA compliant by default. If you use it to collect PHI, you would need a BAA with Google, which is not typically available for standard accounts.
Is a password-protected page on my website HIPAA compliant?
Not necessarily. Password protection alone does not meet HIPAA requirements. You also need encryption, audit logs, and other safeguards.
How do i know if my current website is HIPAA compliant?
Review whether it handles PHI and if it has the required safeguards, such as encryption and BAAs with vendors. If unsure, consult a HIPAA compliance expert.