Your Medical Practice's Website and Email Might Be a HIPAA Violation
If your practice uses a Gmail address, has a contact form on your website, or lets patients email you to schedule appointments, there is a real chance you are handling patient information in a way that does not meet HIPAA requirements.
Most providers do not find out until there is a complaint, a breach, or an audit. By then, the fines are already on the table.
This is not about alarming you. It is about closing gaps that are genuinely easy to miss and surprisingly common in small and mid-sized practices.
What HIPAA Actually Protects (And Why It Extends to Your Website)
HIPAA protects Protected Health Information, which the law defines as any information that can identify a patient and relates to their health condition, the care they received, or the payment for that care.
Most providers think of PHI as medical records, test results, or prescription history. Those are obvious examples. But the definition is broader than that.
PHI can include:
- A patient’s name combined with the name of your practice
- An email address linked to a medical appointment
- A phone number paired with a request for a prescription refill
- A date of birth combined with a reason for a visit
- An IP address if it can be tied to health-related activity on your site
That last one catches people off guard. When a patient fills out a contact form on your site asking about an upcoming procedure, several things happen simultaneously: their name and message are transmitted, their IP address is logged, and depending on how your site is built, that data may pass through third-party services with no HIPAA agreement in place.
None of that requires a breach for a violation to exist. The violation is in the handling.
The Gmail Problem
A personal Gmail address is not HIPAA compliant. Full stop.
Google does not sign a Business Associate Agreement for free consumer Gmail accounts. A BAA is a contract required under HIPAA that obligates a vendor to protect PHI and handle any breaches appropriately. Without one, using Gmail to communicate with patients about their care - scheduling, referrals, billing questions, follow-ups - creates a direct HIPAA exposure.
Google Workspace, the paid version, can be made HIPAA compliant, but only if:
- You have an active, signed BAA with Google
- You have properly configured the security settings Google requires
- Staff are trained on what can and cannot be sent through it
Most small practices using Google Workspace have not completed all three of those steps. They assume the paid account is automatically compliant. It is not.
The same problem applies to Yahoo Mail, personal Outlook.com accounts, AOL, and any other consumer email service. None of them will sign a BAA because their products are not designed for regulated data.
If your practice email ends in @gmail.com, @yahoo.com, @hotmail.com, or any personal domain, it is time to fix that before a patient complaint prompts a regulator to fix it for you.
Your Contact Form Is a Transmission of PHI
A standard website contact form collects a patient’s name, phone number or email, and a message. If that message includes anything health-related - and it almost always does, because that is why patients are contacting a medical practice - the form just collected PHI.
Where that PHI goes next is where most practices have a problem.
The typical setup sends the form submission directly to the practice’s email inbox. If that inbox is a Gmail account or another non-compliant service, you have a chain of non-compliant data handling from the moment the patient hits submit.
Even if your email is compliant, the form itself may not be. Most standard contact forms:
- Do not encrypt data at rest before transmitting it
- Route through form platforms or plugins that have no BAA in place
- Store submissions in a database managed by a third party that has never been evaluated for HIPAA compliance
- Pass data through analytics or tracking scripts embedded on the same page
Popular tools like Contact Form 7, WPForms, and Gravity Forms are widely used on healthcare websites and are not HIPAA compliant out of the box. Some offer HIPAA-compatible configurations with additional setup and cost. Many sites using them have never made those changes.
Appointment Scheduling Tools Have the Same Problem
If your website links patients to a scheduling tool, that tool is handling PHI the moment a patient enters their name, reason for visit, and contact information.
Tools like standard Calendly, Acuity Scheduling, or a basic Google Form intake sheet are not HIPAA compliant by default. Some offer HIPAA-compatible tiers with a BAA. Most small practices link to the free version or a plan that does not include one.
If a patient can book an appointment on your site and the tool managing that does not have a BAA with your practice, that is an exposure point.
Tracking Scripts and Analytics Are a Risk You May Not Have Considered
Standard Google Analytics and Facebook Pixel both collect data about website visitors, including what pages they viewed and in some configurations their IP addresses.
If a patient visits a page on your site titled “HIV Treatment” or “Addiction Recovery Services” and then submits a contact form, their IP address may be associated with that page visit and captured by a third-party analytics platform with no HIPAA agreement in place.
This is an area that has seen significant regulatory and legal activity. A federal court ruling in American Hospital Association v. Becerra vacated HHS guidance that had broadly treated any IP address visiting a public healthcare webpage as PHI. Simply landing on your homepage is not, by itself, a violation.
The line moves when a user takes action. The moment a visitor submits a contact form, initiates an appointment request, or logs into a patient portal, their identity becomes actively linked to a clinical query. At that point, any tracker capturing that interaction is capturing PHI - and doing so without authorization if no BAA is in place with the analytics provider.
What HIPAA Compliance Actually Requires for a Medical Website
A HIPAA-compliant website is not just one with an SSL certificate. That is a baseline, not a complete standard.
A compliant setup requires:
Encrypted data transmission and storage. Any form that collects patient information needs to transmit it over encrypted channels and store it in a system that maintains that encryption.
Business Associate Agreements with every vendor that touches PHI. Your hosting provider, your form platform, your scheduling tool, your email provider, and any analytics tool that could capture identifiable visitor data all need BAAs if PHI passes through them.
Access controls and audit logs. Only authorized staff should be able to access patient communications, and there should be a record of who accessed what.
Staff training. A technically compliant system operated by untrained staff is still a liability. Sending an unencrypted email with patient details because it was faster defeats the technical controls.
What Happens When a Practice Gets It Wrong
The Office for Civil Rights enforces HIPAA and has the authority to issue fines ranging from $145 to $73,011 per violation, depending on the level of negligence, up to $2,190,294 per calendar year per violation category. Those figures reflect the HHS annual inflation adjustment published January 28, 2026 and remain the definitive penalty standard for the year.
For a small practice, a single investigation can result in a settlement that is painful even at the lower end of the penalty scale. The corrective action plans that often accompany settlements can require years of monitoring and reporting.
State attorneys general can pursue additional penalties under state law. And beyond the regulatory consequences, a known breach damages patient trust in a way that takes much longer to recover from than a fine.
The practices that end up in front of regulators are not always the ones that had a sophisticated breach. Many were flagged because a former patient filed a complaint about how their information was handled - a contact form submission that ended up somewhere it should not have, an email forwarded to a non-secure account, an intake form left in an unencrypted plugin database.
What to Do About It
The good news is that most of these gaps are fixable, and the fixes are not as complex as HIPAA’s reputation suggests.
Email first. If your practice runs on consumer email, switching to a properly configured HIPAA-compliant email provider is the most immediate change to make. Options with BAA availability include Microsoft 365 for healthcare and Google Workspace with a signed BAA and compliant configuration. Your IT provider or technology partner should be able to help verify the setup.
Audit your website forms. Walk through every form on your site. Identify where the submission data goes, what platform manages it, and whether that platform has a BAA in place. If it does not, the form needs to be rebuilt or replaced.
Review your scheduling and intake tools. Check the terms of service and plan level for any scheduling tool linked from your site. Confirm a BAA exists.
Remove or replace tracking scripts. If your site runs Google Analytics or Facebook Pixel, evaluate whether those tools are capturing data in a way that creates risk. HIPAA-compliant analytics alternatives exist that do not send data to third parties without appropriate agreements.
Document everything. HIPAA compliance is not a one-time event. It requires a record of what you have in place, when you reviewed it, and how it is maintained.
If you are a healthcare provider who is not sure where your website currently stands on any of these points, that is exactly the kind of technical assessment we help with at Corespark. We build websites for healthcare providers that are designed with these requirements in mind from the start - secure forms, compliant data handling, and a setup that does not put your practice at risk. A conversation about your current setup costs nothing. Schedule a technical review here.
Frequently Asked Questions
Is Gmail HIPAA compliant for a medical practice?
No. Free personal Gmail accounts are not HIPAA compliant because Google does not sign a Business Associate Agreement for them. Google Workspace can be configured for HIPAA compliance, but only with a signed BAA and proper security settings. Most small practices using Google Workspace have not completed this process.
Can a patient email a doctor about their care?
A patient can initiate email communication and assume the risk of an unencrypted channel. However, the practice is still responsible for how it handles, stores, and responds to that communication on its end. Replying to a patient through a non-compliant email system creates HIPAA liability regardless of how the conversation started.
Is a contact form on a medical website a HIPAA risk?
Yes. If a patient submits a contact form that includes their name and anything health-related, that submission is PHI. The form platform, the destination inbox, and any third-party services the data passes through all need to be evaluated for HIPAA compliance. Most standard contact forms are not configured with this in mind.
What is a Business Associate Agreement?
A BAA is a contract required under HIPAA between a healthcare provider and any vendor that handles PHI on their behalf. Without one, using a service to store, transmit, or process patient information creates a compliance violation regardless of how secure the service technically is.
Does HIPAA apply to small medical practices?
Yes. HIPAA applies to all covered entities - which includes any healthcare provider that transmits health information electronically - regardless of the size of the practice. Small practices are not exempt and are subject to the same penalties as larger organizations.
Can website analytics be a HIPAA violation?
Yes. The HHS Office for Civil Rights has clarified that tracking pixels and analytics tools on healthcare websites can capture PHI, including IP addresses associated with health condition pages or service inquiries. Using tools like Google Analytics or Facebook Pixel without proper safeguards on a healthcare website creates risk.
What is the penalty for a HIPAA violation?
The Office for Civil Rights can issue fines ranging from $145 to $73,011 per violation depending on the level of negligence, up to $2,190,294 per calendar year per violation category - figures set by the HHS inflation adjustment published January 28, 2026. State attorneys general may pursue additional penalties. Corrective action plans following investigations can require years of ongoing compliance monitoring.
What makes a medical practice website HIPAA compliant?
A compliant medical website requires encrypted data transmission and storage, Business Associate Agreements with every vendor that touches patient data, access controls limiting who can view patient communications, audit logging, and staff training. An SSL certificate is a baseline requirement, not a complete compliance standard.
Sources
- U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule. hhs.gov/hipaa
- U.S. Department of Health and Human Services, Office for Civil Rights. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates. Bulletin, December 2022. hhs.gov/hipaa/for-professionals/privacy/guidance
- U.S. District Court for the Northern District of Texas. American Hospital Association v. Becerra. Civil Action No. 4:23-cv-01110-P (ruling vacating the unauthenticated-page portion of HHS tracking guidance).
- U.S. Department of Health and Human Services. Annual Civil Monetary Penalties Inflation Adjustment. 45 CFR Part 102. Published January 28, 2026.
- U.S. Department of Health and Human Services. Health Insurance Portability and Accountability Act of 1996 (HIPAA). hhs.gov/hipaa
Need a technology partner in the Yadkin Valley?
Corespark helps local small businesses in NC and VA with tech strategy, web development, and more.
Talk to Corespark →