Website · Patient information
Does your practice website need HIPAA hosting?
Before paying for a hosting upgrade, find out what it needs to cover. Your website, forms, email, and booking service may handle different information.
What are you buying when you buy “HIPAA hosting”?
You ask whether your practice website is set up properly. Someone recommends a more expensive hosting plan. It sounds reassuring, but does that plan cover the form, the email notification, or the booking tool?
If nobody explains which information the host handles, you cannot tell whether the upgrade solves the problem. You might pay for a new server while patient answers keep flowing through the same unrelated services.
Start with what the website receives.
A site publishing hours and biographies has a different job from an application receiving patient histories. Many practices use a public website that links to a separately managed patient portal.
HHS says a cloud provider maintaining electronic protected health information can be a business associate even when it cannot read encrypted records. The provider’s role depends on the information it handles, not the marketing name of its plan.
The lock icon does not answer the whole question.
HTTPS protects a connection in transit. It does not tell you who can open the dashboard, what an email notification contains, or whether a backup includes submissions.
Ask the person proposing hosting to name the services receiving sensitive information. Include forms, email delivery, storage, backups, and connected tools. Each should have a clear purpose and an accountable owner.
Ask for a plan tied to your practice.
A useful proposal explains what stays on the public site, where patients complete intake, who manages access, and what gets tested. It identifies the agreements and safeguards for services handling protected information.
“BAA available” means an agreement can be obtained for eligible use. Confirm the right account is covered and the configuration fits the workflow. Buy against that documented plan.
Your next steps
- 1
Separate the jobs
List public pages, booking, intake, email, records, and analytics.
- 2
Draw the route
Include network intermediaries, integrations, logs, and backups that may handle patient information.
- 3
Check each service
Verify eligible features, the applicable agreements, access controls, and recovery arrangements.
- 4
Verify before launch
Use invented test records to test permissions and data destinations. Record what was checked and who owns ongoing reviews.
Three different checks
| Label | What it means |
|---|---|
| BAA available | The vendor offers an agreement for eligible use |
| Agreement verified | The correct account and relationship are covered |
| Configuration checked | The actual workflow has been reviewed and tested |
These are review stages, not badges awarded to any account on this page. No single stage proves overall compliance.
Before you decide
What does a BAA actually cover?
A business associate agreement (BAA) sets responsibilities for handling protected health information. It does not make a workflow compliant by itself. Review every service that receives, transmits, or stores that information, including integrations, logs, and backups. The practice and its service providers each have responsibilities.
Is every AWS or Google service covered?
Coverage applies to particular services and terms, rather than everything sold under a company’s name. AWS publishes an eligible-service list, and Google Workspace lists its included functionality. A third-party add-on needs its own review even when it connects to a covered service.
For a proposed setup, we name the actual services and integrations on the diagram. That lets the practice check the right agreements and settings before patient information starts moving through them.
Does a public website automatically avoid HIPAA obligations?
A public page may be simple, but the services loaded on it can still send information elsewhere. For example, a booking link, a form, or a tracking script can introduce a data flow that is not obvious from reading the page. Avoiding storage on the website does not answer what those services receive.
We look at the actual behavior and document the destinations. That gives your responsible advisers a concrete setup to assess and helps us decide what should remain on the public site.
Sources & further reading
- HHS: cloud services, business associates, and risk analysis
- AWS: eligible services and shared responsibility
- Google Workspace: HIPAA agreements and configuration
- Google Workspace: HIPAA included functionality
Vendor features and terms can change. Confirm the requirements for your account before making a change.