HIPAA and website builders

Choosing a website builder for a medical practice

The compliance risk in a clinic website is almost never the builder. It is what the finished site collects, which scripts it loads, and — increasingly — what an AI tool invented while writing it. Here is how to evaluate that, and where ClinicSite stands.

General information, not legal advice. Your compliance officer or counsel should sign off on decisions about your practice.

The framing that saves you a great deal of trouble

There is no certified category called a HIPAA compliant website builder, because HIPAA certifies nothing. Once you accept that, the decision gets much easier.

HIPAA obligations attach to information, not to software. So the useful question is not “is this builder compliant” — a question with no defensible answer — but does the website this builder produces receive individually identifiable health information at all?

There are only two honest answers, and they lead to different projects.

Answer one

No — the site handles no PHI

A brochure site: services, clinicians, hours, insurance, location, phone number. Visitors get in touch by calling or emailing. Nothing patient-identifiable is collected, stored or transmitted by the website, so there is no PHI for HIPAA to govern on that surface. This is the position most small practices should want, and most do not realise is available to them.

Answer two

Yes — the site collects patient information

Intake forms, a symptom box, a portal, an appointment request naming a condition, a chat widget that stores transcripts. Now you need a business associate agreement with the builder and with every subprocessor in the path — form vendor, chat vendor, email service, storage — plus a risk analysis, access controls, audit logging, and a breach response plan.

Most practices choose answer two by accident

Nobody sits down and decides to take on business associate relationships. It happens because the website template shipped with a contact form, the form field said “How can we help?”, and a patient typed three sentences about their symptoms into it. The obligation arrived with the default settings. The full requirements guide covers how to unwind that.

What to demand from any builder you are evaluating

Seven questions. The answers separate vendors quickly.

  1. Will the finished site collect patient information? If forms are included, where do submissions go, who stores them, for how long, and who can read them?
  2. Is form data ever emailed in plain text? This remains the single most common way clinical detail escapes, and it is often hidden in a default notification setting.
  3. What third-party scripts load on the published site? Analytics, advertising pixels, session recording and chat widgets on pages that reveal a patient relationship are the area drawing the most scrutiny in healthcare. Can you turn them off, and are they off by default?
  4. Is HTTPS applied to every page, or only the pages with forms on them?
  5. Will you sign a BAA, and who are your subprocessors? A vendor that cannot name its own subprocessors cannot meaningfully sign one.
  6. If AI generates the content, what stops it inventing facts? Ask this one specifically and listen closely to the answer. See below.
  7. What do you decline to claim? A vendor with no edges is a vendor you have not finished evaluating.

The newer risk: an AI builder that makes things up

This is not a HIPAA question, but it belongs on the same page, because it is the failure mode most likely to actually harm a practice this year.

Point a general-purpose AI website builder at a medical practice and it will produce something polished within seconds. It will also, unprompted and with complete confidence, write a biography for a dentist who does not work there, list four insurance plans the practice does not accept, quote a price nobody set, and compose a warm five-star testimonial signed by a patient who does not exist.

For a restaurant that is an embarrassment. For a healthcare practice it is a patient arriving for treatment they believe is covered, a credential claim you cannot support, and advertising content about a regulated service that is simply false.

ClinicSite’s generator is constrained against exactly this. It is instructed to use only facts found on the site it was given, never to invent providers, prices, insurers or contact details, and to omit a section entirely rather than fabricate its contents. If your current site does not name its clinicians, the generated site has no team section. If it lists no insurers, there is no insurance section.

The visible cost is that drafts from a thin source site look sparse next to a competitor that filled the same page with invention. We think that is the correct trade for a medical practice, and we would rather explain it than quietly make the other choice. See what actually gets built.

Where ClinicSite stands

Mechanism rather than adjectives, so you can check it against your own requirements.

  1. 1

    Published sites cannot collect patient data

    Every published site runs under a content security policy that blocks form submission and outbound network calls outright. This is structural, not a toggle. Visitors contact you by tapping your phone number or email link.
  2. 2

    No third-party scripts on your site

    No analytics, no advertising pixels, no session recording, no tag manager. The one exception is the website assistant if you enable it, which widens the policy by a single known origin.
  3. 3

    HTTPS on every page, automatically

    Certificates are issued when your domain resolves to us and renewed without intervention. There is no partially-secured site to end up with.
  4. 4

    Hosted on Microsoft Azure

    Sites, dashboard and generation all run on Azure infrastructure. More detail on the hosting page.
  5. 5

    Content generated from your real facts only

    The generator omits rather than invents. No fabricated clinicians, insurers, prices or testimonials.
  6. 6

    EMR credentials encrypted and isolated

    If you connect your EMR, credentials are encrypted at rest with AES-256-GCM and bound to your clinic, the sync runs in an isolated worker with its own restricted database role, and row-level security applies to the synced records.

And what we do not claim

Written down here so you never have to infer it from silence.
CapabilityStatusWhat that means
HIPAA certificationNot yetNo vendor has one. There is no HIPAA certification scheme. Treat any claimed badge as a warning sign.
SOC 2 reportNot yetWe do not publish one. If your procurement requires it, raise that early.
Business associate agreementPartialNot a self-serve document. If you intend to connect an EMR, talk to us first — contact page.
Patient intake formsNot yetPublished sites cannot submit forms. This is why they carry no PHI, and it is a real limitation if you need web intake.
Patient portalNot yetNot a ClinicSite feature. You can link to the portal you already run.
Uptime SLANot yetWe publish no uptime commitment and will not imply one.
Structured data markup on generated sitesNot yetGenerated sites ship clean semantic HTML and inherited meta tags, but emit no machine-readable business schema today.

Frequently asked questions

Is there such a thing as a HIPAA compliant website builder?
Not as a certified category, no. HIPAA has no certification scheme, so no builder can hold a HIPAA badge. What a builder can honestly offer is a site that handles no protected health information at all, or a signed business associate agreement covering the PHI it does handle. Anything sold in between those two positions deserves a hard question.
Can I build a clinic website without any HIPAA exposure?
Yes, and it is the simplest position to be in. A site that publishes your services, clinicians, hours, insurance and phone number, and that invites contact by phone or email rather than by web form, receives no protected health information. There is nothing to safeguard, nothing to disclose in a breach, and no subprocessor to chase for an agreement.
Does ClinicSite sign a business associate agreement?
For the website itself the question does not usually arise, because a published ClinicSite site does not collect patient information. It becomes the right question if you plan to connect an EMR, since that syncs appointment and clinician records onto the platform. Contact us before connecting anything and we will discuss it directly rather than making a blanket claim here.
Why can't I add a patient intake form to my ClinicSite site?
Published sites run under a content security policy that blocks form submission outright, so it is a structural property rather than a setting. That is the reason the sites carry no PHI risk, and it is also a genuine limitation. If web-based intake is essential to how your practice runs, ClinicSite is not the right fit today and we would rather you knew that now.
What about the AI chatbot — does it collect health information?
It is instructed not to. The assistant answers only from your published practice information, refuses clinical questions and redirects them to your team, is told not to collect or store personal health information, and hands off to a human when it cannot help. It is scoped as a website assistant, not an intake tool or a triage system.
Will you claim to be HIPAA compliant?
No. We publish no HIPAA certification and no SOC 2 report, and we do not describe the product as HIPAA compliant. We describe the specific mechanisms — no data collection on published sites, HTTPS everywhere, Azure hosting, tenant-bound encryption of EMR credentials — and let you evaluate them against your own requirements.
How is this different from using a general website builder?
Two things. General builders will happily generate a plausible clinician biography, a list of accepted insurers, and a testimonial, none of which are true — a nuisance for a bakery and a serious problem for a medical practice. And they ship with forms, analytics and tracking scripts enabled by default, which is precisely the surface that has drawn regulatory attention on healthcare sites.

See what your clinic site could look like

Paste your current website address. You get a full generated replacement to look at — free, no account, no card.

Free preview · no card · previews are deleted after 7 days