← All guides

Website · Patient information

Does your practice website need HIPAA hosting?

Before paying for a hosting upgrade, find out what it needs to cover. Your website, forms, email, and booking service may handle different information.

What are you buying when you buy “HIPAA hosting”?

You ask whether your practice website is set up properly. Someone recommends a more expensive hosting plan. It sounds reassuring, but does that plan cover the form, the email notification, or the booking tool?

If nobody explains which information the host handles, you cannot tell whether the upgrade solves the problem. You might pay for a new server while patient answers keep flowing through the same unrelated services.

Start with what the website receives.

A site publishing hours and biographies has a different job from an application receiving patient histories. Many practices use a public website that links to a separately managed patient portal.

HHS says a cloud provider maintaining electronic protected health information can be a business associate even when it cannot read encrypted records. The provider’s role depends on the information it handles, not the marketing name of its plan.

HHS cloud-computing guidance

The lock icon does not answer the whole question.

HTTPS protects a connection in transit. It does not tell you who can open the dashboard, what an email notification contains, or whether a backup includes submissions.

Ask the person proposing hosting to name the services receiving sensitive information. Include forms, email delivery, storage, backups, and connected tools. Each should have a clear purpose and an accountable owner.

Ask for a plan tied to your practice.

A useful proposal explains what stays on the public site, where patients complete intake, who manages access, and what gets tested. It identifies the agreements and safeguards for services handling protected information.

“BAA available” means an agreement can be obtained for eligible use. Confirm the right account is covered and the configuration fits the workflow. Buy against that documented plan.

Your next steps

  1. 1

    Separate the jobs

    List public pages, booking, intake, email, records, and analytics.

  2. 2

    Draw the route

    Include network intermediaries, integrations, logs, and backups that may handle patient information.

  3. 3

    Check each service

    Verify eligible features, the applicable agreements, access controls, and recovery arrangements.

  4. 4

    Verify before launch

    Use invented test records to test permissions and data destinations. Record what was checked and who owns ongoing reviews.

Three different checks

Three different checks
LabelWhat it means
BAA availableThe vendor offers an agreement for eligible use
Agreement verifiedThe correct account and relationship are covered
Configuration checkedThe actual workflow has been reviewed and tested

These are review stages, not badges awarded to any account on this page. No single stage proves overall compliance.

Before you decide

What does a BAA actually cover?

A business associate agreement (BAA) sets responsibilities for handling protected health information. It does not make a workflow compliant by itself. Review every service that receives, transmits, or stores that information, including integrations, logs, and backups. The practice and its service providers each have responsibilities.

Is every AWS or Google service covered?

Coverage applies to particular services and terms, rather than everything sold under a company’s name. AWS publishes an eligible-service list, and Google Workspace lists its included functionality. A third-party add-on needs its own review even when it connects to a covered service.

For a proposed setup, we name the actual services and integrations on the diagram. That lets the practice check the right agreements and settings before patient information starts moving through them.

Does a public website automatically avoid HIPAA obligations?

A public page may be simple, but the services loaded on it can still send information elsewhere. For example, a booking link, a form, or a tracking script can introduce a data flow that is not obvious from reading the page. Avoiding storage on the website does not answer what those services receive.

We look at the actual behavior and document the destinations. That gives your responsible advisers a concrete setup to assess and helps us decide what should remain on the public site.

Sources & further reading

Vendor features and terms can change. Confirm the requirements for your account before making a change.