7 HIPAA Violations Hiding on Your Practice Website Right Now
Most practice websites have at least one HIPAA violation the owner doesn't know about. Here are 7 common ones with the exact regulation each one breaks.
Most HIPAA enforcement actions don’t target large hospital systems. A review of recent OCR enforcement data shows that the majority of fines and settlements involve organizations far smaller than the headline-grabbing cases suggest. The most frequently cited violation? Inadequate risk analysis — which appeared in 13 of 20 recent enforcement actions.
Source: HHS.gov, Compliance Enforcement Data; Shook, Hardy & Bacon, “OCR Enforcement Activity,” March 2025
Your practice website is part of that risk analysis. Here are seven violations we find on the majority of practice websites we audit — with the specific HIPAA provision each one breaks.
1. Contact Forms Not Designed for PHI
Standard contact forms on WordPress, Squarespace, and Wix may use HTTPS for transport, but they aren’t designed for handling Protected Health Information. Form submissions are often forwarded via unencrypted email, stored without encryption at rest, and processed by vendors without BAA coverage. If a patient includes their name and reason for visit — “I’d like to schedule an appointment for anxiety treatment” — that PHI is being handled by systems with no HIPAA safeguards.
Regulation: 45 CFR § 164.312(e)(1) requires transmission security for electronic PHI, including encryption where appropriate.
2. Google Analytics Capturing Patient Browsing Behavior
When a patient visits your “Services” page and then fills out a form, Google Analytics links their browsing history to their identity. That combination is PHI, and Google has not signed a BAA with your practice.
Regulation: 45 CFR § 164.502(a) prohibits disclosure of PHI to entities without a BAA. HHS issued a specific bulletin on tracking technologies confirming this interpretation.
3. Shared Hosting Without a BAA
Most shared hosting providers (GoDaddy, Bluehost, HostGator) do not sign Business Associate Agreements. If any patient data touches your server — even through a contact form submission that’s temporarily stored — you need a BAA with your hosting provider.
Regulation: 45 CFR § 164.308(b)(1) requires covered entities to have BAAs with all business associates who may access PHI.
4. No Encryption at Rest for Form Submissions
If your contact form plugin stores submissions in a standard database without encryption, every stored message containing health information is unprotected PHI at rest. Many WordPress form plugins (Contact Form 7, WPForms) store submissions this way by default.
Regulation: 45 CFR § 164.312(a)(2)(iv) requires encryption and decryption mechanisms for electronic PHI.
5. Third-Party Scheduling Without BAA Coverage
Scheduling widgets that collect patient names, contact information, and appointment types are processing PHI. If your scheduling vendor hasn’t signed a BAA with you, every booking is an unprotected disclosure to a third party.
Regulation: 45 CFR § 164.502(e) requires that disclosures to business associates be governed by a BAA.
6. Patient Testimonials Without Proper Authorization
Publishing a patient review on your website with their name and treatment type requires a HIPAA-specific authorization — not just a verbal “sure, you can use that.” A signed HIPAA authorization form under 45 CFR § 164.508 is legally distinct from a general marketing consent.
Regulation: 45 CFR § 164.508 requires written authorization for use of PHI for marketing purposes.
7. No Access Controls on Backend Systems
If your website admin panel, hosting control panel, or form submission dashboard can be accessed without multi-factor authentication, you have an access control gap. This is especially common on WordPress sites where the admin login is at the default /wp-admin URL with no MFA.
Regulation: 45 CFR § 164.312(d) requires person or entity authentication. MFA is not yet mandatory under current rules, but it is increasingly expected by OCR and would become required under proposed Security Rule updates.
In 2024, 742 healthcare data breaches were reported to OCR, with 276.8 million records exposed — the worst year on record. The average cost of a healthcare data breach reached $4.88 million per incident.
Source: HIPAA Journal, “Healthcare Data Breach Statistics — Updated for 2026”
The pattern: Most practice owners assume HIPAA applies to their EHR and patient records, not their website. But any website feature that collects, transmits, or stores patient information is subject to the same rules. If you haven’t audited your website for these violations, you likely have at least one.
How Many of These 7 Violations Are on Your Site?
We've audited dozens of practice websites. The average has 3 or more of these violations. Want to know your number? Our free Report Card checks all seven.
Get Your Free Report CardIf you run a practice in this space, see how we build for Mental Health Practices.
Related Industries
Go deeper on specific violations
- The FTC Warned 130 Hospitals About Google Analytics. Your Practice Website Is Next. →
- Squarespace and Wix Will Never Be HIPAA-Compliant. Here's Why. →
- 55% of HIPAA Fines Hit Small Practices. Here's What That Means for Yours. →
- 77% of Patients Start on Google. Is Your Practice Website Losing Them? →
- Your Contact Form Is Probably a HIPAA Violation →