Your Contact Form Is Probably a HIPAA Violation
Most therapy websites were built by someone who didn't understand the rules. Here's what compliance actually requires — and how to fix it without rebuilding everything.
The Part Nobody Explains Clearly
Your website becomes subject to HIPAA the moment a prospective client types something like 'I'm struggling with anxiety' into your contact form. That message — their name plus a mental health concern — is Protected Health Information under federal law.
A standard contact form on Squarespace, Wix, or basic WordPress sends that data through unencrypted email. No Business Associate Agreement. No secure routing. Just an open pipe to your inbox.
That's the violation. And it happens on thousands of therapy websites right now.
The good news: it's fixable. The bad news: most web designers don't know it's a problem.
We do — because building for regulated professionals is the work, not a footnote.
HIPAA Compliance on a Therapy Website Is Four Things
01 Encrypted Data — In Transit and At Rest +
02 A Signed Business Associate Agreement (BAA) With Every Tool That Touches PHI +
03 No Standard Analytics or Tracking Pixels +
04 Access Controls +
Built Compliant From Day One — Not Patched After the Fact
When we build a therapy website, compliance isn't a checklist we run at the end. It's baked into the architecture.
Every contact form uses a BAA-backed provider — JotForm Healthcare, HIPAAtizer, or FormDr — with secure, encrypted routing that bypasses standard email entirely. Submissions go to a compliant, access-controlled inbox, not an open Gmail account.
Scheduling integrations use tools that sign BAAs — SimplePractice, Jane App, or equivalent — so the booking flow doesn't create a liability the moment someone selects a service type.
Your analytics runs on Fathom: real traffic data, zero PHI capture, no BAA required because it never touches patient information.
The Astro framework we build on is fast, clean, and doesn't carry the plugin bloat that creates additional attack surfaces on WordPress installs.
We're not a law firm and this is not legal advice. What we build is designed to keep you clear of the most common, most serious compliance gaps — the ones that result in real enforcement actions.
Built for a Relationship Therapist in San Antonio
A relationship therapist in San Antonio came to us with a practice growing by word of mouth but no real web presence. Her existing setup had the standard problems — a template site, a basic contact form, no analytics she could trust, and a Psychology Today profile that was producing less every month.
The compliance audit turned up three exposure points before we wrote a single line of copy: an unencrypted contact form, a Google Analytics tag on a page listing her specialties, and a scheduling embed from a tool that had never signed a BAA.
We rebuilt her web presence with compliant infrastructure throughout — a BAA-backed contact form, HIPAA-safe analytics with zero PHI capture, and a scheduling integration from a provider that signs. Then we solved a harder problem: how do you build a marketing system for a therapist who can't use testimonials, can't share client stories, and needs every content decision to clear an ethical review?
The answer was a fictional column — invented couple scenarios with real clinical insight, clearly labeled as composite, zero patient exposure. We added a non-diagnostic self-assessment quiz to the homepage. Average dwell time after launch: 5–7 minutes.
Compliant infrastructure doesn't cost you visibility — it's what let Google trust the site enough to show it. Ninety days after launch:
+58%
Month-over-month traffic growth
Page One
Average Google position (8.9) across her ranking queries
5.3%
Search click-through rate — roughly double the norm for those positions
−18%
Bounce rate, and falling
Compliant and findable aren't a trade-off. Built right, they're the same build.
The Five Most Common Violations on Therapy Websites
01 Standard contact forms +
02 Google Analytics on clinical pages +
03 Facebook or Meta Pixel +
04 Scheduling tools without BAAs +
05 Responding to Google reviews in a way that confirms someone is a patient +
The One-Star Review That Could Have Become a Write-Up
An angry former patient left our client a one-star review. She did what almost every therapist does: started typing a reply.
We stopped her before she hit post. Any response that engaged with the reviewer — even a polite one — risked confirming a patient relationship in public. That's not a PR problem. That's a reportable HIPAA violation.
Instead, we ran the protocol: drafted a compliant response and reviewed it with her compliance officer, who signed off — then made the strategic call not to engage at all. We flagged the review to Google for removal on compliance grounds and rebuilt her rating the legitimate way: a steady cadence of real reviews from her local community. Back to 4 stars within a week. No write-up. No exposure. No spam-looking review blast.
Most web designers would have let her hit post. They wouldn't have known there was anything wrong with it.
Compliance Questions We Get Every Time
Does HIPAA apply to my website if I don't do insurance billing? +
Is the SimplePractice website builder HIPAA compliant? +
Can I use a standard Gmail for form submissions if the form is compliant? +
What's the actual risk if I don't fix these? +
Do you guarantee HIPAA compliance? +
The Practice Build
$1,800 flat. You own everything.
Founding pricing. 3 build slots left at $1,800 — then $1,999 for the next five, then $2,200 standard. Slots count across every build we take, not just practice sites.
A complete, compliant web presence for your practice, delivered in 14 days:
- ✓ Custom Astro build — 6–7 pages (Home, About, 2–3 specialty pages, Rates, Contact)
- ✓ HIPAA-compliant contact form (BAA-backed provider) — no exposure from day one
- ✓ Privacy-first analytics (no Google Analytics, no pixels)
- ✓ Google Business Profile claimed, categorized, and optimized
- ✓ Keyword architecture baked into the structure — every page targets a real search
- ✓ Schema markup, mobile-first, sub-second load times
- ✓ Full ownership handoff: your domain, your content, your code. Cancel nothing to keep it.
$500 deposit locks your build slot. Balance at launch.
We take a small number of builds at a time, so each one gets built properly rather than quickly. Once the founding slots fill, the price steps up permanently.
Fully refundable until your kickoff call.
Not sure yet? Start with the free scan below ↓The Launch Period
$900/month, one to three months
Your site goes live unproven. We publish the content, post to your Google Business Profile, watch the data, and tune what underperforms. It ends with a baseline, a content plan, and the site running. Not a retainer — a finish line.
After the handover, content packages start at $600 a month if you'd rather we kept writing. No minimum term.
Find Out What Your Current Site Is Exposing — Free
Drop your website below. Within 24 hours you'll get a human-written scan of your site's compliance and visibility gaps — unencrypted forms, tracking pixels on clinical pages, mobile failures, and whether Google can actually find you. No call required. No pitch attached.
Got it.
Your scan lands in your inbox within 24 hours — written by a person, not a robot.
Form hiccup — email us directly at [email protected]
One email with your scan. That's it. No drip sequence, no list.
Also From This Section