HIPAA Compliance for Therapist Websites

Your Contact Form Is Probably a HIPAA Violation

Most therapy websites were built by someone who didn't understand the rules. Here's what compliance actually requires — and how to fix it without rebuilding everything.

HIPAA compliant therapy website design and development

The Part Nobody Explains Clearly

Your website becomes subject to HIPAA the moment a prospective client types something like 'I'm struggling with anxiety' into your contact form. That message — their name plus a mental health concern — is Protected Health Information under federal law.

A standard contact form on Squarespace, Wix, or basic WordPress sends that data through unencrypted email. No Business Associate Agreement. No secure routing. Just an open pipe to your inbox.

That's the violation. And it happens on thousands of therapy websites right now.

The good news: it's fixable. The bad news: most web designers don't know it's a problem.

We do — because building for regulated professionals is the work, not a footnote.

Unencrypted contact form data exposure on therapy websites
The Real Requirements

HIPAA Compliance on a Therapy Website Is Four Things

01 Encrypted Data — In Transit and At Rest +
Every form submission containing client information must be encrypted while it travels across the internet (SSL/TLS) and encrypted while it sits on a server. HTTPS on your domain is not enough on its own — the tools collecting the data must encrypt it too.
02 A Signed Business Associate Agreement (BAA) With Every Tool That Touches PHI +
A BAA is a federal contract. It means the vendor — your form builder, your scheduling tool, your email platform — formally accepts legal responsibility for protecting any patient data that passes through their system. If a vendor won't sign one, you cannot legally use their tool for patient intake. Standard Google Forms, Squarespace forms, and Mailchimp won't sign BAAs. Full stop.
03 No Standard Analytics or Tracking Pixels +
Google Analytics is non-compliant on therapy websites. Google explicitly refuses to sign a BAA for GA, and its mechanics — IP capture, behavioral tracking, cross-site profiling — constitute unauthorized disclosure of PHI when used on pages where users are seeking mental health care. The FTC fined BetterHelp $7.8 million for exactly this. Meta Pixel carries the same risk. We build with HIPAA-safe analytics alternatives (Fathom or Plausible) that don't touch PHI.
04 Access Controls +
Only authorized personnel should be able to access form submissions or patient data through the website. Shared logins, public staging URLs with real data, and unsecured admin panels are all exposure points.
HIPAA compliant contact form and BAA protection for therapy websites
How We Handle It

Built Compliant From Day One — Not Patched After the Fact

When we build a therapy website, compliance isn't a checklist we run at the end. It's baked into the architecture.

Every contact form uses a BAA-backed provider — JotForm Healthcare, HIPAAtizer, or FormDr — with secure, encrypted routing that bypasses standard email entirely. Submissions go to a compliant, access-controlled inbox, not an open Gmail account.

Scheduling integrations use tools that sign BAAs — SimplePractice, Jane App, or equivalent — so the booking flow doesn't create a liability the moment someone selects a service type.

Your analytics runs on Fathom: real traffic data, zero PHI capture, no BAA required because it never touches patient information.

The Astro framework we build on is fast, clean, and doesn't carry the plugin bloat that creates additional attack surfaces on WordPress installs.

We're not a law firm and this is not legal advice. What we build is designed to keep you clear of the most common, most serious compliance gaps — the ones that result in real enforcement actions.

Real Client

Built for a Relationship Therapist in San Antonio

A relationship therapist in San Antonio came to us with a practice growing by word of mouth but no real web presence. Her existing setup had the standard problems — a template site, a basic contact form, no analytics she could trust, and a Psychology Today profile that was producing less every month.

The compliance audit turned up three exposure points before we wrote a single line of copy: an unencrypted contact form, a Google Analytics tag on a page listing her specialties, and a scheduling embed from a tool that had never signed a BAA.

We rebuilt her web presence with compliant infrastructure throughout — a BAA-backed contact form, HIPAA-safe analytics with zero PHI capture, and a scheduling integration from a provider that signs. Then we solved a harder problem: how do you build a marketing system for a therapist who can't use testimonials, can't share client stories, and needs every content decision to clear an ethical review?

The answer was a fictional column — invented couple scenarios with real clinical insight, clearly labeled as composite, zero patient exposure. We added a non-diagnostic self-assessment quiz to the homepage. Average dwell time after launch: 5–7 minutes.

Compliant infrastructure doesn't cost you visibility — it's what let Google trust the site enough to show it. Ninety days after launch:

+58%

Month-over-month traffic growth

Page One

Average Google position (8.9) across her ranking queries

5.3%

Search click-through rate — roughly double the norm for those positions

−18%

Bounce rate, and falling

Compliant and findable aren't a trade-off. Built right, they're the same build.

What to Check Right Now

The Five Most Common Violations on Therapy Websites

01 Standard contact forms +
Squarespace, Wix, and default WordPress forms route data through unencrypted email. If your form has a free-text message field, you have exposure.
02 Google Analytics on clinical pages +
If GA is running on your services pages, specialties pages, or any page where someone might indicate they're seeking mental health care, you have a compliance problem. Google will not sign a BAA for GA.
03 Facebook or Meta Pixel +
Retargeting pixels track and transmit behavioral data — including which clinical conditions a user was researching — to third-party advertising networks. This is an unauthorized disclosure of PHI.
04 Scheduling tools without BAAs +
Acuity Scheduling (standard plan), Calendly, and Google Calendar don't sign BAAs. If your booking tool collects any health-related information, it needs one.
05 Responding to Google reviews in a way that confirms someone is a patient +
A public reply like 'Thanks for the kind words — I'm glad our sessions are helping' is a HIPAA violation. It confirms the reviewer is a patient. Your review policy needs to be explicit and your responses need to be templated carefully.
Compliance in Practice

The One-Star Review That Could Have Become a Write-Up

An angry former patient left our client a one-star review. She did what almost every therapist does: started typing a reply.

We stopped her before she hit post. Any response that engaged with the reviewer — even a polite one — risked confirming a patient relationship in public. That's not a PR problem. That's a reportable HIPAA violation.

Instead, we ran the protocol: drafted a compliant response and reviewed it with her compliance officer, who signed off — then made the strategic call not to engage at all. We flagged the review to Google for removal on compliance grounds and rebuilt her rating the legitimate way: a steady cadence of real reviews from her local community. Back to 4 stars within a week. No write-up. No exposure. No spam-looking review blast.

Most web designers would have let her hit post. They wouldn't have known there was anything wrong with it.

Common HIPAA compliance violations on therapy websites
Questions

Compliance Questions We Get Every Time

Does HIPAA apply to my website if I don't do insurance billing? +
Yes. HIPAA applies to any covered entity — which includes any healthcare provider who transmits health information electronically, regardless of billing model. Private-pay therapists are covered entities.
Is the SimplePractice website builder HIPAA compliant? +
SimplePractice's built-in website is covered under their BAA, which handles the compliance baseline. The limitation isn't compliance — it's SEO capability. SimplePractice templates can't compete in a real local search market. They rank poorly, don't support custom schema, and can't be customized at the level needed to outrank directories and competitors.
Can I use a standard Gmail for form submissions if the form is compliant? +
No. Even if the form itself encrypts the data in transit, routing submissions to a standard Gmail account breaks the chain. Gmail will not sign a BAA. Compliant form providers route submissions to their own secure, encrypted inboxes — separate from your personal email.
What's the actual risk if I don't fix these? +
Civil penalties range from $100 to $50,000 per violation, with annual caps up to $1.5 million. Enforcement has escalated significantly — GoodRx was fined $1.5M for tracking pixels, BetterHelp $7.8M for Meta Pixel use. Independent practitioners aren't exempt.
Do you guarantee HIPAA compliance? +
We build to the standard as we understand it and use tools with established compliance records. We're not a HIPAA auditing firm and this isn't legal advice — we recommend consulting a healthcare attorney or compliance specialist for a formal certification. What we can tell you is that we understand the actual requirements well enough to avoid the common, serious violations that most web designers miss entirely.
Recommended Start

The Practice Build

$1,800 flat. You own everything.

Founding pricing. 3 build slots left at $1,800 — then $1,999 for the next five, then $2,200 standard. Slots count across every build we take, not just practice sites.

A complete, compliant web presence for your practice, delivered in 14 days:

  • Custom Astro build — 6–7 pages (Home, About, 2–3 specialty pages, Rates, Contact)
  • HIPAA-compliant contact form (BAA-backed provider) — no exposure from day one
  • Privacy-first analytics (no Google Analytics, no pixels)
  • Google Business Profile claimed, categorized, and optimized
  • Keyword architecture baked into the structure — every page targets a real search
  • Schema markup, mobile-first, sub-second load times
  • Full ownership handoff: your domain, your content, your code. Cancel nothing to keep it.

$500 deposit locks your build slot. Balance at launch.

We take a small number of builds at a time, so each one gets built properly rather than quickly. Once the founding slots fill, the price steps up permanently.

Lock a Build Slot — $500 Deposit

Fully refundable until your kickoff call.

Not sure yet? Start with the free scan below ↓
After Launch

The Launch Period

$900/month, one to three months

Your site goes live unproven. We publish the content, post to your Google Business Profile, watch the data, and tune what underperforms. It ends with a baseline, a content plan, and the site running. Not a retainer — a finish line.

Book a Free Call — 30 Minutes

After the handover, content packages start at $600 a month if you'd rather we kept writing. No minimum term.

Free Compliance Scan

Find Out What Your Current Site Is Exposing — Free

Drop your website below. Within 24 hours you'll get a human-written scan of your site's compliance and visibility gaps — unencrypted forms, tracking pixels on clinical pages, mobile failures, and whether Google can actually find you. No call required. No pitch attached.

One email with your scan. That's it. No drip sequence, no list.