HIPAA eCommerce

12-Step HIPAA-Compliant Website Checklist for 2023

Updated  |  11 min read
Key Takeaways
  • Following a HIPAA website checklist ensures legal compliance with HIPAA regulations, which is mandatory for all healthcare providers.
  • It helps protect patient privacy by ensuring that appropriate security measures are in place, such as encryption and secure login procedures.
  • Following a HIPAA compliance checklist also helps healthcare providers prevent data breaches and protects a care provider's reputation.
  • Compliance with a HIPAA risk assessment checklist is essential for safeguarding patients' sensitive health information and avoiding legal and financial consequences.

Understanding What HIPAA Means for Your Site

Every medical practice, clinic, pharmacy, nursing home, and healthcare provider must adhere to HIPAA rules when they have an online presence that transfers medical information. Healthcare organizations failing to do so could lead to substantial fines from the government.

Even worse, you'll lose the trust of your patients and ruin your good reputation. Customers trust their health to physicians and caregivers, and they want to feel just as confident that their health information is in good hands. That's why you need to invest in a robust HIPAA-compliant website if you plan to transfer or store electronic protected health information, or ePHI.

A HIPAA security requirements checklist can be used by a security officer.

Duty of Care for HIPAA Compliance

Covered entities are companies subject to HIPAA regulations. This encompasses doctors, pharmacies, and nursing homes that transfer medical information, often referred to as electronic medical records (EMR), electronic health records (EHR), or (electronic) protected health information (PHI or ePHI). Covered entities also include health insurance companies, HMOs, government agencies that subsidize health care (Medicare), and military and veterans' organizations.

A HIPAA audit is performed by the Office for Civil Rights (OCR), a division of Health and Human Services (HHS).

Sharing this information has become an important part of modern healthcare, but compliance also creates a burden for medical providers. We can't stress this enough: Covered entities bear the final responsibility for their compliance with all HIPAA guidelines and regulations.

Here we offer a free HIPAA-compliant website checklist so you can be prepared for HIPAA requirements for your website.

12-Step HIPAA Checklist

Hipaa checklist.

1. Create a HIPAA-Compliant Website Checklist

The first step in a HIPAA-compliant checklist is creating a list that serves needs specific to your company. Having a plan in place for HIPAA-compliant website design and hosting is one of the most important business objectives you'll ever pursue. Don't approach this haphazardly; you need to have a personalized HIPAA-compliant checklist to ensure you meet every HIPAA standard.

2. Research Healthcare Industry Needs

When considering the needs of your website, you must first consider the HIPAA laws in place that affect every healthcare provider and then personalize your plan to comply. Simple, unsecured websites are no longer an option and often suffer HIPAA violations, even if you just include a contact form for patients to fill out. Be sure to find trusted information so that you can find an IT partner familiar with compliance.

3. Determine If HIPAA Is Necessary

Next, you need to determine if your data fits the description you'd find on a HIPAA-compliant requirements checklist at all. HIPAA-compliant websites are only necessary if it is used to collect, store, process, display, or transmit ERM/EHR/PHI. HIPAA does not cover physical health records or electronic records that are stored in a single location with no means of web transfer.

Because HIPAA was designed to improve healthcare by providing easy access to information, there aren't many computer systems in the medical industry that don't require strict compliance.


Looking for a HIPAA-Compliant Website?

We can help there, too. We developed HIPAA-compliant eCommerce that is customizable to your needs. Check it out to get started!

HIPAA compliant website solution.

4. Learn HIPAA Website Basics

Before you understand how to make your website HIPAA compliant and how to avoid HIPAA violations, familiarize yourself with HIPAA requirements, which state that healthcare websites must:

  • Implement rules and safeguards to protect patient health information.
  • Limit sharing of confidential data to authorized stakeholders who directly help patients in some way.
  • Ensure any business associates or corporate partners also safeguard PHI and share information only when done so in each patient's best interests.
  • Limit who can access PHI and train employees about security and confidentiality best practices.

5. Research and Follow HIPAA Rules

HIPAA rules don't stop with information protection; it's also adamant about tracking information access. They also require covered entities to keep track of who has viewed PHI, why they are accessing it, what they are accessing, and if the information has been transferred in any way. Working with a HIPAA eCommerce integration company that has experience protecting both is a must.

6. Encrypt HIPAA Patient Intake Forms

Another important part of a HIPAA compliance audit checklist is protecting web forms. A web form is any information-collecting form that is filled out by a patient or client. Common examples include desktop or mobile forms that collect medical and health insurance information. This information is then collected to create long-term and centralized medical records.

HIPAA-compliant web forms ensure that the connection between the browser and the website is encrypted, so information entered on the site or web forms is protected against unauthorized access. You must make sure your HIPAA-compliant website is hosted by a company that knows what it's doing when transferring contact forms to the HIPAA web server. Clarity is ready to make your forms HIPAA secure.

A HIPAA compliance checklist can help avoid a HIPAA audit.

7. Use HIPAA-Approved Contact Forms

Any page that allows patients to submit information can be considered a contact form. This includes HIPAA-compliant web forms such as pre-visit health surveys, patient portals, and live chat facilities. Even the simplest contact form has to be secure; a person contacting a doctor will not want anyone to have easy access to their inquiries regarding particular health problems. When going over your HIPAA-compliant website list, make sure that contact forms follow HIPAA rules.

8. Protect HIPAA Web Servers

PHI must be protected at every step. HIPAA-compliant servers must include the most secure protection available while PHI is in the cloud, but it also must be secure during any sort of internet transfer. That includes end-to-end encryption for any information that is sent back to or between healthcare providers.

  • Collecting PHI: If your website collects any individually identifiable medical information, such as symptoms, conditions, or requested healthcare services, you are collecting PHI. That information must be ferried securely to the web server.
  • Storing PHI: Whether you store individually identifiable health information on your own server or on a third-party server, you must ensure that the security of the information is compliant with HIPAA and that regular maintenance is done to keep it so.
  • Transmitting PHI: PHI must also be secure and encrypted when it is transferred in any way. This includes direct transfer between servers, via email, or any other digital transference. 

9. Install a Robust SSL Certificate

Secure Sockets Layer (SSL) is the industry standard for transferring data over internet channels, usually between a web server and a browser. SSL certificates make sure that data is encrypted from end to end and is not readable by third parties. The “s” in https:// that is found on most websites indicates that any information transferred on that site will be secure thanks to the SSL certificate. Some of the best low-cost—or even free—SSL certificate providers are:

Be careful; free SSL certificates often don't offer the most stringent security and could lead to a HIPAA violation. Properly installing an SSL certificate can be a tricky business as well. Since it's one of the most important parts of this HIPAA risk assessment checklist, you'll probably want to trust this step with a company familiar with HIPAA-compliant database design. We'll take care of it for you.

An SSL certificate (secure sockets layer) satisfies Health and Human Services for HIPAA-compliant websites.

HIPAA-Compliant eCommerce in Days, Not Months

We can set up a HIPAA eCommerce solution for you that's tailored to your business in a matter of days. Stop waiting to be HIPAA compliant!

10. Choosing Your HIPAA-Compliant Solution

Who you work with can determine whether or not you truly have a HIPAA-compliant website. As you saw from the previous points, the website must be secure from many angles. Clarity provides HIPAA-compliant solutions to seamlessly secure PHI that's transmitted to and from your website, all the while adhering to HIPAA-compliant server requirements.

11. Finding a Hosting Provider

Don't trust just anyone with your web hosting. HIPAA-compliant web hosting requires some of the most robust security available. Since security is so important to your business, make sure you find one that specializes in HIPAA-compliant web hosting.

12. Securely Back Up Data

Backing up patients' PHI—perhaps a lifetime's worth of data—is a must. But backups usually mean that data is being duplicated from one server to another. Protection must be just as protected during the backup as when it's on the original server.

Business associates can help you back up your data to follow Health and Human Services guidelines.

BONUS: Healthcare Organization Tips

  • Ensure that third-party service providers sign a business associate agreement (BAA) stating that they accept some responsibility for the security of the PHI
  • Ensure HIPAA-compliant website hosting
  • Implement secure user authentication with a hosting provider
  • Work with HIPAA-compliant web hosting providers for security needs
  • Secure the website using an SSL certificate
  • Encrypt all web forms
  • Using HIPAA-compliant email encryption

If you don’t want to deal with all of this yourself—or hire multiple companies to complete each task individually—you’ll want to seek out someone with experience in HIPAA integration. Click here to make it easy on yourself.

The Four HIPAA Compliance Rules

There are four HIPAA security rules that further define how covered entities and business associates safeguard protected health information (PHI). The four rules are:

  • HIPAA Privacy Rule
  • HIPAA Security Rule
  • HIPAA Enforcement Rule
  • HIPAA Breach Notification Rule

In the normal course of business operations, only the first three rules apply to covered entities and their business associates. The last rule comes into play only when HIPAA violations occur or websites are breached and there's a risk that PHI has been compromised.

HIPAA solutions come in many shapes and sizes. From a simple online pharmacy to a complex doctor-patient portal to a mobile application, they all need to follow a HIPAA-compliant website checklist regarding PHI.

Clarity has built many of these projects, and we are comfortable helping you make your website HIPAA-compliant and ensuring the privacy and security of patient information.

1. Privacy Rule Considerations

In addition to all of the privacy protection mentioned above, care providers must consider other patient PHI privacy concerns. For instance, they can share information with authorized individuals such as family members in certain circumstances. An example is if the patient is mentally incapacitated or if the patient is a minor.

Generally, HIPAA rules prevent healthcare providers from sharing or exposing confidential information in electronic, written, and oral forms. This means that those in the healthcare industry have a duty even when discussing health records over the phone where they could be overheard by unauthorized people.

In some cases, outside service providers may need access to information to provide medical services, so these cases are exempted from privacy restrictions. The Privacy Rule applies to computer information about patients, conversations between doctors and medical staff, billing information, medical charts, and prescription information.

2. Security Rule Considerations

National standards of security protect the information in healthcare organization databases, eCommerce customer lists where medical records are part of the database, medical clearinghouses, pharmacies, health insurance companies, and other care providers and business associates.

The HIPAA Security Rule has three components: technical safeguards, administrative safeguards, and physical safeguards. Some of the major highlights of when working a HIPAA Security Rule checklist include—but aren't limited to—the following points:

  • Performing periodic risk analysis to determine physical and digital vulnerabilities of PHI.
  • Reducing risks to acceptable levels.
  • Regularly reviewing system activities, digital logs, and audit trails.
  • Authorizing and supervising the employees who have access to PHI.
  • Protecting PHI from unauthorized parent companies, subcontractors, and partner organizations.
  • Sending regular updates to staff members about security issues and training employees to recognize malware, malicious software, and other virtual and real-world threats.
  • Implementing a system of access controls.
  • Providing encryption and decryption tools, especially when you transmit PHI.
  • Facilitating safeguards like automatic logoffs.
  • Establishing mandatory policies for using workstations and mobile devices.
Business associates are also subject to a HIPAA audit by Health and Human Services.

3. Enforcement Rule Considerations

The HIPAA Enforcement Rule mostly concerns penalties and investigations when companies are found to be non-compliant, but eCommerce companies do have some enforcement responsibilities through the administrative section of the Security Rule. These include getting authorization forms for disclosing information to third-party sources, providing customers with a Notice of Privacy Practices, and drawing up Business Associate Agreements for partners to acknowledge their responsibilities under HIPAA.

4. Breach Notification Rule Considerations

Breaches occur when unauthorized people gain access to protected health information in some manner that's not permitted under the HIPAA Privacy Rule. These breaches include unauthorized access to physical areas, inadvertent disclosures, stolen or misplaced documents, and digital hacks. If the HIPAA Breach Notification Rule is violated, covered entities must:

  • Determine if PHI is compromised.
  • Assess the type and amount of data involved.
  • Find out who used the PHI illegally or to whom information was disclosed.
  • Chronicle steps taken to mitigate the breach.
  • Ascertain if the breach was closed or information returned before being used.
  • If the breach occurred inadvertently under a covered associate’s or entity’s authority.
  • Send notices of breach incidents to each patient's last known address by First Class mail or email if electronic notifications are authorized.
  • If the Breach Notification Rule is broken, write notices in easy-to-understand language and include a summary of how the situation occurred, the date of exposure, and other relevant details.

Specific Concerns for Covered Entities & Business Associates

Covered entities and business associates must consider not only whether their websites are compliant with HIPAA requirements but also whether all forms of their digital presence online are compliant. Technology advances often result in web pages and social media that act as customer service extensions.

Any transmission of data or storage of protected information offsite or in the Cloud must be compliant. Fortunately, eCommerce companies don't need to be overwhelmed by restrictions and compliance issues because they can hire third-party consultants like Clarity.

We specialize in HIPAA compliance and secure portals to transfer PHI. We can also point you to the right place to follow another part of a HIPAA-compliant website list: administrative safeguards.

Are All Webforms Required to Reach HIPAA Compliance?

Even simple opt-in forms on websites must comply with the HIPAA security rule if the forms collect any kind of personal health information. For example, if website forms only ask for names, email addresses, phone numbers, and physical addresses (i.e., information readily available on the internet), then the forms don't need to be HIPAA compliant.

However, if any medical, insurance, social security, or other information is required, the form must comply with HIPAA requirements, and the storage and transmission of the data collected must adhere as well.

HIPAA-compliant webforms needed for Health and Human Services

HIPAA-Compliant Website Design

Major eCommerce companies usually employ a team of designers for their websites, stores, and online catalogs, and if the website is required to adhere to HIPAA rules, these professionals should know this information and act accordingly.

However, that's not the way things always work. Designers can overlook key elements even if they're following a HIPAA compliant website checklist, and unless your designer is familiar with what HIPAA requires, it's in the company's best interest to confirm HIPAA rules to make a HIPAA-compliant website viable.

Design issues that should be added to a HIPAA-compliant website list include:

  • Ensuring that health data being transmitted is always encrypted according to HIPAA guidelines
  • Implementing safeguards to prevent tampering with health logs
  • HIPAA hosting should adhere to HIPAA-complaint rules or a HIPAA Business Associate Agreement
  • Limiting access to PHI to authorized staff
  • Backing up all PHI information in ways that ensure the data is recoverable

Integrate HIPAA with eCommerce

It's important to remember that a website isn't just about protecting HIPAA-protected information. The medical field is a business, after all, and the HIPAA eCommerce side has to be considered as well. It's especially critical to choose the right eCommerce and HIPAA development partner to create the most secure portals and websites possible.

Clarity has been designing and building HIPAA-compliant portals that incorporate eCommerce platforms for more than 16 years. We understand the challenges that come with our clients' projects and the need to secure and transmit PHI, whether health-related or financial. Tell us what you need protecting and we'll protect it.

HIPAA rules to follow Health and Human Services.

Discover Your HIPAA Solution

We hope this HIPAA compliance checklist has helped. It's vital to know what you and your business associates need to do to comply.

If you'd like to learn more, we offer a free discovery process where our experts go over your business's needs and help you find the best solution. Feel free to take the information with you anywhere after the session—this is a freebie to get you started. Click the button below to get your free session.



A HIPAA-compliant website is one that adheres to the act of Congress called the Health Insurance Portability and Accountability Act. A HIPAA-compliant website has robust security to protect any patient and customer PHI that passes through it on its way to servers that meet HIPAA compliance standards.

HIPAA guidelines and HIPAA rules are enforced by Health and Human Services. This department of the U.S. government can levy fines if a company does not have secure servers and a compliant website.


Making a HIPAA compliant checklist is vital because it identifies the areas of your business that are most susceptible to attack. It also creates a plan going forward with the subsequent security measures that can be added over time.

If HIPAA rules are not followed, you may be in violation and contact by the U.S. Department of Health and Human Services.

In order to follow a HIPAA-compliant website checklist, it's best to find developer that has experience making a compliant website. They can follow HIPAA rules to ensure compliance with HIPAA-compliant web forms, an SSL certificate, HIPAA-compliant hosting, and protecting data at rest.


The three primary ways to make a website HIPAA compliant are to a) ensure transmitted health data is encrypted, b) host websites on web servers that adhere to HIPAA compliant rules, and c) limiting PHI access only to authorized staff.

HIPAA rules that govern a HIPAA-compliant website are enforced by the U.S Department of Health and Human Services.


Any organization or business that collects and stores PHI (protected health information) is subject to HIPAA-compliant rules. Holders of this information are called covered entities, or CEs. Each CE should seek legal counsel to determine the level of security necessary to protect PHI in transit and at rest.

HIPAA-compliant websites, servers, and transmitted files must be protected in order to adhere to the Health Insurance Portability and Accountability Act, enforced by the U.S. Department of Health and Human Services.

Making a website fully HIPAA compliant is an extensive process in order to meet HIPAA rules as dictated by the Health Insurance Portability and Accountability Act of 1996 (and enforced by the U.S. department of Health and Human Services.)

For a preexisting website and related servers, it’s important to address the most vulnerable and high-value areas first. Additional protection can be added as necessary to secure PHI that may be compromised in edge cases. Working with an experienced HIPAA developer is an excellent first step for following HIPAA rules and getting a HIPAA-compliant website.


The healthcare provider or organization that owns and operates the website is responsible for ensuring compliance with HIPAA rules and regulations. This includes ensuring that all patient information handled by the website is properly secured and protected and that all employees who handle patient information are properly trained on HIPAA regulations and policies.

The responsibility also extends to any third-party vendors or partners that handle patient information on behalf of the healthcare provider.

Ultimately, it's the responsibility of the healthcare provider or organization to follow a HIPAA compliant website checklist to protect patient information and comply with HIPAA regulations, and to quickly and effectively respond to any security incidents that may occur.


To meet the requirements to be HIPAA compliant, care providers must take several important steps. It's necessary to follow HIPAA rules and be in line with the U.S. Department of Health and Human Sevices.

First, they need to conduct a thorough risk analysis to identify potential vulnerabilities and risks to the security and privacy of patient information.

Based on this analysis, policies and procedures should be developed and implemented to protect patient information. This includes physical and technical safeguards, such as access controls to ensure that only authorized personnel can access patient information. It also means that the server and the HIPAA compliant website is secure.

It's also crucial to train all employees on HIPAA regulations and policies and to provide ongoing training to ensure continued compliance. Implement a security awareness training program to help avoid HIPAA violations. Also, healthcare providers should establish business associate agreements with any third-party vendors or partners who handle patient information in case a HIPAA violation occurs.

Regular review and updating of policies and procedures are also essential, along with quickly and effectively responding to security incidents and promptly reporting any incidents to affected patients and relevant authorities. Using a HIPAA compliant website checklist is an excellent way to ensure you are following HIPAA rules.


The most important parts of a HIPAA-compliant checklist typically include privacy and security policies. This includes outlining how patient information is accessed, shared, and protected, and procedures for reporting and responding to security incidents. HIPAA rules are enforced by the U.S. Department of Health and Human Services.

Training and awareness ensure all staff members who handle patient information are properly trained on HIPAA regulations and privacy and security policies. Regular risk assessments to identify and mitigate potential security risks, and implement security controls to manage those risks.

Incident response and reporting means having procedures in place to quickly and effectively respond to security incidents, and promptly reporting any incidents to affected patients and relevant authorities.

Still have questions? Chat with us on the bottom right corner of your screen #NotARobot

Stephen Beer is a Content Writer at Clarity Ventures and has written about various tech industries for nearly a decade. He is determined to demystify HIPAA, integration, and eCommerce with easy-to-read, easy-to-understand articles to help businesses make the best decisions.