Web Development • HIPAA-Aware Healthcare Web • SEO • AI Search Optimization (407) 409-8383   |   [email protected]
Healthcare Website Development

Practice sites that carry no patient data, on purpose.

Marketing sites for practices, clinics, and health systems, built on a structured clinical-content model: services, conditions, providers, locations, accepted insurance, and FAQs. We mark them up with MedicalBusiness, Physician, and MedicalProcedure schema, build to WCAG 2.2 AA, and harden the transport, and we deliberately keep the whole thing out of PHI scope. This is the public face of your practice, the part patients actually use to find and choose you, and the safest version of it holds no patient data at all.

// no website is HIPAA compliant on its own; compliance is an organizational posture across your whole practice. A marketing site strengthens that posture best by staying clean: out of PHI scope, carrying no patient data, with tracker discipline on every public page.

OUT OF PHI SCOPE CLINICAL CONTENT MODEL WCAG 2.2 AA
The overview

The public face of the practice, built to stay clean.

A practice marketing site is the part patients meet first. It tells them what you treat, who treats it, where you are, whether you take their insurance, and what to expect. That is real work, and it deserves real engineering, but it does not require protected health information. The single most important decision we make on a healthcare marketing site is to keep it out of PHI scope entirely, so the largest and most public surface of your web presence carries no patient data and stays simple to run safely.

We build that surface on a structured clinical-content model rather than a pile of flat pages. Services connect to the conditions they address, providers connect to the conditions they treat and the locations they practice at, and procedures are described as procedures. On top of that structure we layer MedicalBusiness, Physician, and MedicalProcedure schema, so search engines and the AI tools patients increasingly use can describe you accurately instead of guessing. The content model is what keeps the site legible to those systems and maintainable for your team.

The rest is discipline that most generic articles skip. We serve everything over TLS, harden the Content Security Policy, and build to WCAG 2.2 AA from the start. And we hold tracker discipline even on public health-topic pages, because a careless pixel can still create exposure after the 2024 court ruling narrowed but did not erase the risk. If a page would ever need to collect health information, that is a separate, deliberately engineered project, not something we bolt onto the brochure site.

What this page is, and is not

A clean line keeps a marketing site safe and simple.

  • It is the public marketing layer, kept out of PHI scope
  • It is a structured clinical-content model, not flat pages
  • It carries no patient data and needs no BAA on its own
  • It is not a patient portal, which handles real ePHI
  • It is not an intake form, which is a Secure Forms project
The content model

Structured clinical content, marked up properly.

A practice site is more legible when its content is modeled, not just typed. We build services, conditions, providers, locations, accepted insurance, and FAQs as a connected structure, so a provider links to what they treat and where, a service links to the conditions it addresses, and a procedure is described as a procedure rather than a paragraph.

On top of that structure we add MedicalBusiness, Physician, and MedicalProcedure schema. That is how search engines and AI tools describe your practice accurately instead of guessing, and it is the difference between a site that merely exists and one that is actually understood by the systems patients use to find care.

// the structure does the work; the schema makes it legible

What is included

  • A structured clinical-content model for services and conditions
  • Provider, location, and accepted-insurance pages done properly
  • Procedures described and linked to the providers who do them
  • FAQs structured so they answer the questions patients actually ask
  • MedicalBusiness, Physician, and MedicalProcedure schema
  • Schema mapped to the content model, not pasted on top
  • Accurate descriptions for search engines and AI tools
  • A model your team can extend as services change
The clean surface

Out of PHI scope, with tracker discipline.

The marketing site holds no patient data, and that is deliberate. Keeping the public layer out of PHI scope is the single biggest thing that makes a healthcare site simple to run safely, because the data you never collect is the data you never have to protect, log, or account for in a contract. We serve everything over TLS and harden the Content Security Policy so the surface is both clean and locked down.

The nuance most generic articles miss is that even public health-topic pages need tracker discipline. After American Hospital Association v. Becerra, a bare unauthenticated page about a condition is no longer automatically a HIPAA event, but a careless analytics or advertising pixel can still create exposure. More than 100 million dollars in pixel-tracking settlements have landed since 2023, so we keep the marketing layer clean rather than assuming the ruling makes it a free-for-all.

If you have an existing site whose trackers have never been audited, the full cleanup is our Tracking and Analytics Governance work. On a new build, we simply hold the discipline from the start.

What is included

  • Deliberately kept out of PHI scope, carrying no patient data
  • TLS everywhere and a hardened Content Security Policy
  • Tracker discipline even on public health-topic pages
  • No careless analytics or advertising pixel on condition pages
  • A clear boundary: anything that collects PHI is a separate project
  • An honest read on the Becerra ruling, not a free-for-all
  • Fast, hand-built pages your team can maintain and extend
  • A surface simple to run safely because it holds no patient data
How we work

Model the content, then keep the surface clean.

We start with the structure of the practice, build it into a clinical-content model, mark it up, and make it accessible. Throughout, we hold the line that keeps it safe: no patient data on the public site, and tracker discipline on every page. The result is a site that is accurate, legible to the systems patients use, and simple to run.

// structure first, schema and accessibility on top, PHI kept out entirely

  1. Model the practiceWe map your services, conditions, providers, locations, accepted insurance, and FAQs into a structured clinical-content model. The structure decides how everything connects, so a provider links to what they treat and where, and a service links to the conditions it addresses, rather than living as disconnected pages.
  2. Build and mark it upWe hand-build the pages on that model and layer MedicalBusiness, Physician, and MedicalProcedure schema mapped to it. The schema is tied to the content rather than pasted on top, so search engines and AI tools describe your practice accurately instead of guessing.
  3. Make it accessibleWe build to WCAG 2.2 AA from the start: keyboard access, color contrast, alt text, labeled fields, and accurate captions, with conformance documentation you can keep on file. Building to WCAG 2.2 AA also satisfies the WCAG 2.1 AA that Section 1557 and the ADA reference.
  4. Harden and keep PHI outWe serve everything over TLS, harden the Content Security Policy, and confirm the whole site stays out of PHI scope. Anything that would collect health information is split off into a Secure Forms project rather than weakening the clean marketing layer.
  5. Hold tracker disciplineWe keep analytics and advertising pixels disciplined even on public health-topic pages, because the Becerra ruling narrowed but did not erase the risk. On an existing site we audit the trackers; on a new build we hold the line from the first page.
Questions, answered honestly

Frequently asked questions

No. No website is HIPAA compliant on its own, and a marketing site least of all. Compliance is an organizational posture across your whole practice: administrative, physical, and technical safeguards working together, plus signed agreements, a Security Risk Analysis, workforce training, and breach procedures. What a marketing site can do is strengthen that posture instead of undermining it, and the cleanest way it does that is by carrying no patient data at all. We build the technical layer and keep it out of PHI scope; your practice owns the posture that no vendor can sell.

Because the safest patient data is the data the site never collects. A practice marketing site exists to help people find you, understand your services and conditions, see your providers and locations, check your accepted insurance, and read your FAQs. None of that requires protected health information. By deciding deliberately that the public site holds no patient data, we keep the largest and most public surface of your web presence simple to run safely and outside the reach of a Business Associate Agreement. If a page would need to collect health information, that is a Secure Forms and Intake project, engineered around that data rather than bolted onto the brochure site.

We mark the site up with MedicalBusiness, Physician, and MedicalProcedure schema, mapped to a structured clinical-content model of services, conditions, providers, locations, and procedures. That structure does real work. It lets search engines and AI tools describe your practice accurately rather than guessing, it ties a provider to the conditions they treat and the locations they practice at, and it keeps the content model consistent as you add services. The schema is not decoration; it is how a clinical site stays legible to the systems patients increasingly use to find care.

They can. American Hospital Association v. Becerra vacated only the unauthenticated-page theory in 2024, so a bare public page about a condition is no longer automatically a HIPAA event. That is not the same as a free-for-all. A careless analytics or advertising pixel on a health-topic page can still create exposure, and more than 100 million dollars in pixel-tracking settlements have landed since 2023. We keep the marketing layer clean with deliberate tracker discipline rather than assuming the ruling removed the risk. For the full cleanup of an existing site, that is our Tracking and Analytics Governance work.

We build to WCAG 2.2 AA, which also satisfies the WCAG 2.1 AA that HHS Section 1557 and Section 504 require, with keyboard access, color contrast, alt text, labeled fields, and accurate captions. Be clear on the hedge: we build to WCAG, but legal Section 1557 and ADA conformance also depends on your organization's ongoing process and content, because a conformant site can drift the moment someone uploads an unlabeled PDF. The deadlines are extended: Section 1557 requires WCAG 2.1 AA by May 11, 2027 for organizations with 15 or more employees and May 10, 2028 for smaller ones, and DOJ ADA Title II lands April 26, 2027 and 2028 on the same split.

Either. Plenty of practices have a site that looks fine but is built on a flat content model, carries trackers nobody audited, or quietly collects intake into a non-covered inbox. We can rebuild it on a structured clinical-content model, harden the transport and Content Security Policy, audit the trackers, and confirm what stays out of PHI scope. We will also tell you honestly when your current site is good enough and a smaller piece of work, such as a tracking cleanup or an accessibility pass, serves you better than a full rebuild.

Yes. We hand-build the pages on a content model your team can read and extend, and we document how the structured content, the schema, and the accessibility posture fit together. You own the code and the configuration. The point of a structured clinical-content model is that adding a new service, provider, or location is a known, repeatable edit rather than a one-off rebuild, so the site stays accurate as the practice changes without us in the loop for every update.

Building or rebuilding a practice site and want it done cleanly?

Tell us about your services, providers, and locations. We will give you a straight read on a structured clinical-content model, the schema and accessibility that make it legible, and exactly how we keep the whole public site out of PHI scope.