Healthcare web that does not become the weak link.
Six pieces cover the whole span of healthcare on the web, and each has its own page to go deeper: HIPAA-aware practice sites kept out of PHI scope, custom patient portals wired to your EHR, encrypted intake, Section 1557 accessibility, tracking governance, and ongoing security upkeep. Take one, or take the set. We are candid about the line throughout. We own the code, the configuration, and the safeguards; your practice owns the compliance posture that no vendor can sell. The goal is simple: a healthcare site that strengthens your posture instead of undermining it.
// no website is HIPAA compliant on its own; compliance is an organizational posture across your whole practice. We build the technical layer to be HIPAA-aware, and we draw a clean line between what we own and what only your organization, your policies, and your signed agreements can carry.
> We build the site so it is HIPAA-aware.
> Compliance lives at the organization level.
Healthcare web is mostly discipline, not magic.
Most of what makes a healthcare site safe is not exotic engineering. It is deciding deliberately where protected health information is allowed to flow, and refusing to let it leak anywhere a contract and a risk analysis have not accounted for. That discipline runs through all six pieces below, from a public marketing site to a portal, from encrypted intake to tracking cleanup and ongoing upkeep. We encrypt everything in transit, we keep the public marketing layer out of PHI scope so it carries no patient data, and we route anything that does collect health information through infrastructure a covered vendor will sign a Business Associate Agreement for. The work is care, not cleverness.
The framing matters as much as the code. Compliance is organizational, so a web team's job is to make the website HIPAA-aware, strengthening your posture rather than becoming the part of it that fails. We hold a clean dividing line throughout: we own the technical layer, and your practice owns what only an organization can carry. Anyone who sells you the website as the whole answer is selling you something that does not exist.
Some of this is regulated ground where the facts are real and the hype is thick. The HHS Security Rule, the OCR online-tracking bulletin, the 2024 court decision in American Hospital Association v. Becerra, the December 2024 proposed Security Rule update, and Section 1557 are all genuine. We state them plainly and we never dress them up with invented numbers or guarantees. Where a rule is proposed rather than in force, we say so.
The line we hold
Every healthcare engagement runs on the same clean division of responsibility.
- We own the code, config, integration, and documentation
- We own MFA, encryption, audit logging, CSP, and consent enforcement
- We own WCAG conformance and the conformance documentation
- You own executing BAAs and your Security Risk Analysis
- You own workforce training and breach determination
Map the PHI, then build around it deliberately.
We start by finding where health information actually flows, then we keep as much of your site as we can out of that flow entirely. What must touch PHI gets the full set of safeguards. What does not, stays simple. The result is a site that is easier to run safely because most of it never carries patient data in the first place.
// the marketing layer stays clean, the portal carries the weight
- Map where PHI flowsWe trace every place health information could enter, move through, or rest in your site, from an intake form to a portal message to a stray analytics tag. That map decides everything else. Most of a practice site can be kept out of PHI scope, and knowing exactly which parts cannot is the foundation of a safe build.
- Keep the marketing layer cleanThe public site (services, conditions, providers, locations, accepted insurance, FAQs) is built on a structured clinical-content model and deliberately carries no patient data. That keeps the largest, most public surface simple to run safely and far outside the reach of a Business Associate Agreement.
- Engineer the PHI surfacesWhere health information genuinely must be handled, we build the full technical layer: TLS everywhere, mandatory MFA, role-based access control, encryption in transit and at rest, tamper-evident audit logging, a hardened Content Security Policy, and EHR integration over FHIR R4 and US Core where a portal needs it.
- Gate the vendors and the trackersPHI is only allowed to reach infrastructure a covered vendor will sign a BAA for. We inventory tags and trackers, remove or server-side proxy anything that leaks health information, and enforce consent across the whole stack so a pixel never becomes the channel that hands data to a vendor you have no agreement with.
- Document and maintainWe hand over the technical layer documented: what is encrypted, what is logged, how consent is enforced, and how the accessibility posture was verified. From there an optional retainer keeps the patching, scans, drift checks, and monitoring current as dependencies age and the rules move.
Six pieces, one honest posture
Each one is its own page with the detail, the safeguards, and what is included. Start wherever your practice sits, or read them in order.
// Not sure where to begin? Start with Healthcare Website Development if you are building a new site, or a Tracking or Accessibility audit if you already have one. Or just tell us the problem and we will point you to the right piece.
Frequently asked questions
Related services
This hub is the healthcare-specific layer on top of our core web work. If you want the same hand-built craft without the healthcare safeguards, start with Web Development. For the search and the AI sides of the same practice, the other hubs are here.
Further reading: What "HIPAA-compliant" actually means for a website (and what it does not).
Building or fixing a healthcare site and want it done honestly?
Tell us what you are working with. We will give you a straight read on what stays out of PHI scope, what needs the full technical layer, and exactly where the line sits between what we build and what your practice has to own.