Why every medical and dental practice needs to take digital compliance seriously now
August 31, 2026
August 2026
/
Ask most independent practices about HIPAA and they will point to the EHR and the signed patient forms. The website rarely comes up. That is the gap. The booking tools, forms, chat, and marketing tags on a practice site handle protected health information every day, and the enforcement and litigation that used to target only large health systems now reaches practices of every size.
Compliance is not just a big-system problem
A solo dentist and a hospital network run on the same third-party tools: an online scheduler, a contact form, a review widget, a chatbot, an analytics tag, an advertising pixel. Every one of those can collect a name, a condition, an appointment reason, or an identifier. At the practice level nobody vetted them against HIPAA, because the assumption is that compliance lives inside the clinical software, not the marketing site.
Where PHI actually leaks on a practice website
- Online booking and intake forms that route patient details through a vendor with no business associate agreement.
- Advertising and analytics pixels on appointment and condition pages, quietly sending health context to platforms that never signed a BAA.
- Chatbots and review tools that log whatever a patient types, including symptoms and medications.
Why now
Three forces have converged. A wave of tracking-pixel litigation has named healthcare organizations specifically. Regulators have issued clear guidance that marketing trackers on patient-facing pages are in scope. And patients are more aware than ever of how their health data is handled. The practices being pursued are not only the giants. Enforcement follows the exposure, and the exposure is everywhere a tool touches patient data.
A privacy policy PDF is not compliance
Many practices believe a HIPAA notice on the website closes the loop. It does not. Compliance is about what the site actually does with data, not what a document says it does. A polished policy over a site that leaks PHI to an ad platform is not a defense.
What to do about it
The work is straightforward and far cheaper than a breach: inventory every tool and tag on the site, put a business associate agreement in place for anyone handling patient data, configure analytics to exclude identifiers and health context, and separate marketing measurement from the systems that hold PHI. For a practice, this is a small project. For one that skips it, the first demand letter is not.
Agency 39A builds compliance into how a healthcare site works from the start, because for a practice, trust is the product, and a site that visibly protects patient data is part of earning it.
Ready to start a conversation about digital transformation?
Speak with our team and discuss your digital transformation.
Learn How our Pathfinder™ process Can improve your website
Schedule a meeting with our strategy team and we’ll show you how Pathfinder™ leads to project success.
Learn more about our fractional growth offering
Connect with our team to explore how a Fractional Growth Team can accelerate your marketing, UX, and digital execution, without the delays or costs of traditional models.
Curious how your site stacks up?
We’ll show you what’s working, what’s not, and where you’re leaving opportunities on the table.
Turn AI Search Into a Competitive Advantage.
See how your site can be structured to earn visibility in generative results and convert high-intent traffic into action.
Episode details
Ask most independent practices about HIPAA and they will point to the EHR and the signed patient forms. The website rarely comes up. That is the gap. The booking tools, forms, chat, and marketing tags on a practice site handle protected health information every day, and the enforcement and litigation that used to target only large health systems now reaches practices of every size.
Compliance is not just a big-system problem
A solo dentist and a hospital network run on the same third-party tools: an online scheduler, a contact form, a review widget, a chatbot, an analytics tag, an advertising pixel. Every one of those can collect a name, a condition, an appointment reason, or an identifier. At the practice level nobody vetted them against HIPAA, because the assumption is that compliance lives inside the clinical software, not the marketing site.
Where PHI actually leaks on a practice website
- Online booking and intake forms that route patient details through a vendor with no business associate agreement.
- Advertising and analytics pixels on appointment and condition pages, quietly sending health context to platforms that never signed a BAA.
- Chatbots and review tools that log whatever a patient types, including symptoms and medications.
Why now
Three forces have converged. A wave of tracking-pixel litigation has named healthcare organizations specifically. Regulators have issued clear guidance that marketing trackers on patient-facing pages are in scope. And patients are more aware than ever of how their health data is handled. The practices being pursued are not only the giants. Enforcement follows the exposure, and the exposure is everywhere a tool touches patient data.
A privacy policy PDF is not compliance
Many practices believe a HIPAA notice on the website closes the loop. It does not. Compliance is about what the site actually does with data, not what a document says it does. A polished policy over a site that leaks PHI to an ad platform is not a defense.
What to do about it
The work is straightforward and far cheaper than a breach: inventory every tool and tag on the site, put a business associate agreement in place for anyone handling patient data, configure analytics to exclude identifiers and health context, and separate marketing measurement from the systems that hold PHI. For a practice, this is a small project. For one that skips it, the first demand letter is not.
Agency 39A builds compliance into how a healthcare site works from the start, because for a practice, trust is the product, and a site that visibly protects patient data is part of earning it.