Practice sites that carry no patient data, on purpose.
Marketing sites for practices, clinics, and health systems, built on a structured clinical-content model: services, conditions, providers, locations, accepted insurance, and FAQs. We mark them up with MedicalBusiness, Physician, and MedicalProcedure schema, build to WCAG 2.2 AA, and harden the transport, and we deliberately keep the whole thing out of PHI scope. This is the public face of your practice, the part patients actually use to find and choose you, and the safest version of it holds no patient data at all.
// no website is HIPAA compliant on its own; compliance is an organizational posture across your whole practice. A marketing site strengthens that posture best by staying clean: out of PHI scope, carrying no patient data, with tracker discipline on every public page.
> The public site holds no patient data.
> That is what keeps it simple to run safely.
The public face of the practice, built to stay clean.
A practice marketing site is the part patients meet first. It tells them what you treat, who treats it, where you are, whether you take their insurance, and what to expect. That is real work, and it deserves real engineering, but it does not require protected health information. The single most important decision we make on a healthcare marketing site is to keep it out of PHI scope entirely, so the largest and most public surface of your web presence carries no patient data and stays simple to run safely.
We build that surface on a structured clinical-content model rather than a pile of flat pages. Services connect to the conditions they address, providers connect to the conditions they treat and the locations they practice at, and procedures are described as procedures. On top of that structure we layer MedicalBusiness, Physician, and MedicalProcedure schema, so search engines and the AI tools patients increasingly use can describe you accurately instead of guessing. The content model is what keeps the site legible to those systems and maintainable for your team.
The rest is discipline that most generic articles skip. We serve everything over TLS, harden the Content Security Policy, and build to WCAG 2.2 AA from the start. And we hold tracker discipline even on public health-topic pages, because a careless pixel can still create exposure after the 2024 court ruling narrowed but did not erase the risk. If a page would ever need to collect health information, that is a separate, deliberately engineered project, not something we bolt onto the brochure site.
What this page is, and is not
A clean line keeps a marketing site safe and simple.
- It is the public marketing layer, kept out of PHI scope
- It is a structured clinical-content model, not flat pages
- It carries no patient data and needs no BAA on its own
- It is not a patient portal, which handles real ePHI
- It is not an intake form, which is a Secure Forms project
Structured clinical content, marked up properly.
A practice site is more legible when its content is modeled, not just typed. We build services, conditions, providers, locations, accepted insurance, and FAQs as a connected structure, so a provider links to what they treat and where, a service links to the conditions it addresses, and a procedure is described as a procedure rather than a paragraph.
On top of that structure we add MedicalBusiness, Physician, and MedicalProcedure schema. That is how search engines and AI tools describe your practice accurately instead of guessing, and it is the difference between a site that merely exists and one that is actually understood by the systems patients use to find care.
// the structure does the work; the schema makes it legible
What is included
- A structured clinical-content model for services and conditions
- Provider, location, and accepted-insurance pages done properly
- Procedures described and linked to the providers who do them
- FAQs structured so they answer the questions patients actually ask
- MedicalBusiness, Physician, and MedicalProcedure schema
- Schema mapped to the content model, not pasted on top
- Accurate descriptions for search engines and AI tools
- A model your team can extend as services change
Out of PHI scope, with tracker discipline.
The marketing site holds no patient data, and that is deliberate. Keeping the public layer out of PHI scope is the single biggest thing that makes a healthcare site simple to run safely, because the data you never collect is the data you never have to protect, log, or account for in a contract. We serve everything over TLS and harden the Content Security Policy so the surface is both clean and locked down.
The nuance most generic articles miss is that even public health-topic pages need tracker discipline. After American Hospital Association v. Becerra, a bare unauthenticated page about a condition is no longer automatically a HIPAA event, but a careless analytics or advertising pixel can still create exposure. More than 100 million dollars in pixel-tracking settlements have landed since 2023, so we keep the marketing layer clean rather than assuming the ruling makes it a free-for-all.
If you have an existing site whose trackers have never been audited, the full cleanup is our Tracking and Analytics Governance work. On a new build, we simply hold the discipline from the start.
What is included
- Deliberately kept out of PHI scope, carrying no patient data
- TLS everywhere and a hardened Content Security Policy
- Tracker discipline even on public health-topic pages
- No careless analytics or advertising pixel on condition pages
- A clear boundary: anything that collects PHI is a separate project
- An honest read on the Becerra ruling, not a free-for-all
- Fast, hand-built pages your team can maintain and extend
- A surface simple to run safely because it holds no patient data
Model the content, then keep the surface clean.
We start with the structure of the practice, build it into a clinical-content model, mark it up, and make it accessible. Throughout, we hold the line that keeps it safe: no patient data on the public site, and tracker discipline on every page. The result is a site that is accurate, legible to the systems patients use, and simple to run.
// structure first, schema and accessibility on top, PHI kept out entirely
- Model the practiceWe map your services, conditions, providers, locations, accepted insurance, and FAQs into a structured clinical-content model. The structure decides how everything connects, so a provider links to what they treat and where, and a service links to the conditions it addresses, rather than living as disconnected pages.
- Build and mark it upWe hand-build the pages on that model and layer MedicalBusiness, Physician, and MedicalProcedure schema mapped to it. The schema is tied to the content rather than pasted on top, so search engines and AI tools describe your practice accurately instead of guessing.
- Make it accessibleWe build to WCAG 2.2 AA from the start: keyboard access, color contrast, alt text, labeled fields, and accurate captions, with conformance documentation you can keep on file. Building to WCAG 2.2 AA also satisfies the WCAG 2.1 AA that Section 1557 and the ADA reference.
- Harden and keep PHI outWe serve everything over TLS, harden the Content Security Policy, and confirm the whole site stays out of PHI scope. Anything that would collect health information is split off into a Secure Forms project rather than weakening the clean marketing layer.
- Hold tracker disciplineWe keep analytics and advertising pixels disciplined even on public health-topic pages, because the Becerra ruling narrowed but did not erase the risk. On an existing site we audit the trackers; on a new build we hold the line from the first page.
Frequently asked questions
Related services
A marketing site is the clean public layer of healthcare web. These are the neighboring pieces, from the surfaces that genuinely handle patient data to the upkeep that keeps the whole thing current.
Further reading: What "HIPAA-compliant" actually means for a website (and what it does not).
Building or rebuilding a practice site and want it done cleanly?
Tell us about your services, providers, and locations. We will give you a straight read on a structured clinical-content model, the schema and accessibility that make it legible, and exactly how we keep the whole public site out of PHI scope.