US Privacy Law United States (Federal)

HIPAA Compliance for Websites and Digital Tools

How HIPAA applies to websites, portals, and tracking technologies: covered entities, the Privacy and Security Rules, the OCR tracking guidance fight, and penalty tiers.

Regulation

Health Insurance Portability and Accountability Act (1996), Privacy/Security/Breach Rules (45 CFR Parts 160, 164), HITECH Act

Max Penalty

Tiered civil penalties up to roughly $2.1M per violation category per year (inflation-adjusted); criminal penalties up to $250,000 and 10 years

Enforcing Authority

HHS Office for Civil Rights (OCR); state AGs under HITECH

Official Source

www.hhs.gov

Executive Summary

  • HIPAA applies to covered entities (providers who transmit standard electronic transactions, health plans, clearinghouses) and their business associates, not to health data generally: most health apps and wellness sites fall outside it.
  • For digital properties, the pressure point is protected health information (PHI) leaking through web technologies: analytics and advertising pixels on patient portals, appointment schedulers, and condition pages.
  • OCR's tracking-technology guidance (2022, revised 2024) treated IP-plus-health-page-visit combinations as PHI; a federal court vacated its broadest application in 2024 (AHA v. Becerra), but authenticated-page tracking and the underlying disclosure rules remain live.
  • The Security Rule requires risk analysis, access controls, encryption practices, audit logging, and business associate agreements; OCR's enforcement record shows risk-analysis failures in most resolution agreements.
  • Penalties tier by culpability from ~$141 to ~$71,000 per violation, capped around $2.1M per provision per year, with parallel FTC enforcement (GoodRx, BetterHelp, Cerebral) covering non-HIPAA health data.

HIPAA is narrower than most people assume and stricter than most websites are built for. It regulates specific actors, not health data at large, but for those actors it converts ordinary web plumbing, analytics tags, ad pixels, chat widgets, session replay, into potential federal violations the moment patient context flows through them. The last three years of enforcement, OCR guidance, FTC actions against non-covered apps, and hundreds of pixel class actions, have made the tracking layer the defining digital HIPAA issue.

LawHIPAA + HITECH; 45 CFR Parts 160, 164
CoversCovered entities + business associates handling PHI
Penalty tiers~$141 to ~$71,000 per violation; ~$2.1M annual caps
Breach clock60 days to individuals and HHS
Digital flashpointTracking technologies on patient-facing properties

The digital compliance checklist

Map PHI’s web surface. Portals, schedulers, symptom checkers, refill flows, and any page whose visit implies health status. Then inventory every third-party request those pages fire, the same discipline as an ad-tech audit, with a lower tolerance: default is zero third-party trackers in PHI contexts.

BAA or block. Any vendor receiving PHI (hosting, chat, analytics with server-side redaction, email) signs a business associate agreement or gets removed. Google Analytics will not sign one; Meta will not either. Design accordingly.

Run the risk analysis OCR asks for. Enterprise-wide, asset-based, documented, updated on change, it is the first document requested in every investigation and the most-cited gap in resolution agreements. Encrypt ePHI everywhere to claim the breach safe harbor.

Prepare the 60-day machine. Discovery-to-notification workflows, business associate notice obligations in contracts, and drafted templates; ransomware events are presumptively breaches unless a documented low-probability-of-compromise analysis says otherwise.

Cover the non-HIPAA remainder. Marketing sites, wellness products, and de-identified analytics fall to FTC and state regimes, Washington’s My Health My Data (private right of action) chief among them; the state sensitive-data rules treat health data as consent-gated in every comprehensive state law.

The tracking layer is externally observable, which is why plaintiffs find it first. See what your health-adjacent pages actually transmit with a free scan.

Frequently Asked Questions

Does HIPAA apply to our health-related website or app?

Only if you are a covered entity or a business associate handling PHI for one. A hospital's portal: yes. A consumer wellness app with no provider or plan relationship: no HIPAA, but the FTC's Health Breach Notification Rule and Section 5 authority apply (GoodRx paid $1.5M and BetterHelp $7.8M in 2023 for sharing health data with advertisers), and state laws like Washington's My Health My Data add private rights of action. 'Not covered by HIPAA' no longer means unregulated.

Are analytics and ad pixels on our health pages a HIPAA problem?

On authenticated pages (portals, scheduling, billing): yes, transmitting identifiers plus health context to Google, Meta, or ad tech without a BAA and authorization is an impermissible disclosure, the theory behind OCR investigations and a wave of class actions and breach filings by health systems. On unauthenticated pages, AHA v. Becerra (N.D. Tex. 2024) vacated OCR's position that IP-plus-page-visit is automatically PHI, but the litigation risk and state-law exposure remain. The defensible architecture is no third-party trackers where health context exists.

What does the Security Rule actually require?

A documented, organization-wide risk analysis (the control OCR cites most in enforcement), administrative safeguards (workforce training, access management, sanctions), technical safeguards (unique user IDs, automatic logoff, encryption of ePHI at rest and in transit as addressable-but-expected, audit controls), physical safeguards, and business associate agreements with every vendor touching ePHI. A 2025 proposed rule would make MFA, encryption, and asset inventories explicitly mandatory; build to it now.

What are the breach notification duties?

Notify affected individuals without unreasonable delay and within 60 days of discovering a breach of unsecured PHI; notify HHS within 60 days (breaches of 500+ get contemporaneous reporting and public listing on the OCR 'wall of shame,' plus media notice in affected regions); business associates notify the covered entity within 60 days. Encryption to NIST standards is the safe harbor that makes an incident non-reportable, the strongest single argument for encrypting everything.

What do OCR penalties look like in practice?

Four culpability tiers, from no-knowledge (~$141 minimum per violation) to willful neglect uncorrected (~$71,000 minimum), with annual caps per violated provision around $2.1M. Historic resolutions: Anthem $16M (2018, 79M-record breach), Premera $6.85M (2020), Excellus $5.1M (2021); recent years add right-of-access fines against small practices and 2024-2025 ransomware-driven settlements. State AGs sue under HITECH, and class actions follow every large incident.

Regulatory Crosswalk

State health privacy laws (WA My Health My Data)FTC Health Breach Notification Rule42 CFR Part 2

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.