Does Your Therapy Website Need to Be HIPAA-Compliant? What to Know

Website Compliance · Private Practice

Does your therapy website need to be HIPAA-compliant? what the 2026 rules actually say

Your entire website does not need to be locked down like a bank vault. But specific parts absolutely do. Here is exactly what is regulated, what the 2026 updates require, and where to focus.

Key takeaways

  • Not everything on your site is regulated. Static pages (bio, services, blog) are public. Interactive tools that collect client data are where HIPAA applies.
  • The 2026 NPP update is mandatory. Post an updated Notice of Privacy Practices that includes new substance use disorder language. It must be posted prominently on your site.
  • Your contact form is the most common failure point. Standard forms send unencrypted data. Replace them with HIPAA-compliant alternatives.
  • A BAA is non-negotiable. If a vendor handles PHI and won’t sign a Business Associate Agreement, you cannot use them.
  • SSL is not enough. It only encrypts data while it is in transit. It does not cover how data is stored or who can access it.

The word HIPAA carries a specific kind of weight for any private practice owner managing a therapy website. It often feels like a heavy cloud. This guide will show you exactly which parts of a HIPAA-compliant therapy website are actually regulated and which are not.

The short answer is that while your entire website might not need to be locked down like a bank vault, specific parts absolutely do. In 2026, the rules around digital privacy have tightened. It is no longer enough to just have a “Contact Me” button and hope for the best.

This guide will walk you through the specifics of what actually needs protection and what can stay public. We will look at the new 2026 requirements for your Notice of Privacy Practices. By the end, you will know exactly where to focus your energy and where you can breathe a little easier.

01

Are you actually a covered entity?

Not every page on your site needs the same level of security. Your website is generally split into two types of content.

Static content includes your homepage, your bio, your blog posts, and your services list. This is public information. It does not contain Protected Health Information (PHI). HIPAA does not regulate how you describe your approach to trauma or how you explain your fees. You can host these pages on standard, high-quality platforms without a specialized HIPAA hosting plan.

Interactive content is where things change. This includes anything that collects, stores, or transmits data from a potential or current client. If a visitor types their name and their reason for seeking therapy into a form on your site, that data becomes PHI the moment they hit submit.

A two-panel comic-style illustration showing what a HIPAA-compliant therapy website must protect versus what is public-facing content. One side shows a therapist bio and blog. The other shows an encrypted contact form and secure client portal.
02

The 2026 Notice of Privacy Practices requirement

There is one rule that applies to your entire website if you are a covered entity. As of February 16, 2026, you must prominently post your updated Notice of Privacy Practices on your website.

This is not just a link buried in your privacy policy page. It needs to be easy to find. Most clinicians place it in their website footer so it appears on every single page.

2026 deadline

The 2026 NPP update is specific. Your notice must now include information about how you handle substance use disorder records under the new 42 CFR Part 2 rules. Failing to post this is a common way practices get flagged during audits.

If your website provides information about your services, that updated notice must be there. It is a simple fix that shows you are paying attention to the current standards.

03

Securing your HIPAA-compliant therapy website forms

The contact form is the most common point of failure for a HIPAA-compliant website. A standard contact form that comes with a basic website builder usually sends an unencrypted email to your inbox. This is a direct violation if that email contains health information.

You have three main ways to handle this.

First, you can use a HIPAA-compliant form builder. These tools encrypt the data the moment it is submitted. They store it on secure servers and only send you a notification that a new message is waiting. You then log into the secure portal to read it.

Second, you can link directly to your EHR portal. Many systems like SimplePractice or Jane allow you to embed or link to their secure contact forms. This keeps the data entirely within your clinical system.

Third, you can use a secure email service that offers a HIPAA-compliant contact form widget. The key across all these options is the Business Associate Agreement (BAA).

A private practice owner signs a business agreement at a secure desk while a glowing privacy shield and locked file folder sit nearby. Navy and orange comic-book editorial style.
04

The Business Associate Agreement is non-negotiable

A BAA is a legal contract between you and a service provider. It states that the provider understands they are handling PHI and that they agree to follow HIPAA security standards.

If a company will not sign a BAA with you, you cannot use them to handle client data. This is why you cannot use the free version of Gmail or a standard “plug and play” contact form. Many large tech companies offer BAAs, but usually only on their paid professional tiers.

When you build your HIPAA-compliant website, keep a list of every vendor that touches your site data. This includes your form builder, your secure email provider, and potentially your website host if they store form data on their servers.

05

Why your website host matters

Most modern therapy websites use a “hybrid” approach. The website itself is hosted on a standard platform, but the clinical data is handled by third-party tools.

If your website does not store any client data, your website host does not necessarily need to be HIPAA-compliant. For example, if your contact form is an embedded widget from a secure provider, the data never actually touches your website’s server. It goes straight from the visitor’s browser to the secure provider.

However, if you use a plugin that saves form entries to your website’s database, your hosting provider is now storing PHI. In that case, you must have a BAA with the hosting company. This can be very expensive. Most solo practitioners find it much easier and cheaper to use secure third-party tools that link out from their simple website design.

06

The nuance of state laws

While HIPAA provides a federal baseline, some states have much stricter requirements. California, Texas, and New York have specific privacy acts that can apply even if you do not bill insurance.

Some states require a specific type of consent before a client can even use a contact form. Others have shorter timelines for reporting data breaches. You should always check with your local professional association or a legal consultant in your state. A HIPAA-compliant website is a great start. It must also meet the specific rules of the state where you practice.

07

It is about building trust

At the end of the day, these rules exist to protect the people who come to you for help. When someone visits your site, they are often in a vulnerable state. They want to know that their story is safe with you.

Seeing a clear Notice of Privacy Practices and a secure way to reach out sends a powerful message. It tells the visitor that you are a professional who takes their safety seriously. It turns a technical requirement into a trust-building asset for your practice.

If you are feeling overwhelmed by the technical side of this, remember that you do not have to build it all from scratch. You can find help with website design services that specialize in these specific clinical needs.

Focus on the parts that move data. Keep your public pages clean and helpful. Post your 2026 notice. Those steps alone will put you ahead of most practices.

A close-up of a private practice website footer on a laptop shows a clearly highlighted privacy notice area with secure design cues and a lock icon. Deep navy and burnt orange comic-book illustration style.
08

Your HIPAA website checklist

Use this checklist to audit your current setup against the 2026 requirements. Each item is a specific action, not a vague aspiration.

Confirm whether you are a covered entityIf you submit electronic claims to insurance, you are almost certainly covered under HIPAA.
Update your Notice of Privacy Practices for 2026Add required substance use disorder language under the new 42 CFR Part 2 rules.
Post the updated NPP prominently in your website footerIt must appear on every page of your site, not just a buried privacy policy link.
Audit every form on your site to see where the data goesTrace the path from submission to inbox. Unencrypted = non-compliant.
Replace non-secure contact forms with a HIPAA-compliant alternativeOptions include Hushmail, Spruce, or embedding your EHR portal intake link.
Collect and sign BAAs for every tool that handles client dataForm builder, EHR, email provider, and scheduling tool. Every single one needs a signed BAA on file.
Check your specific state laws for any additional requirementsCA, TX, and NY all have stricter rules than federal HIPAA minimums.
09

Frequently asked questions

Can I just use a standard WordPress contact form?
No. Standard WordPress forms usually store data in your website database and send unencrypted emails. Neither of these is secure enough for PHI without a specific HIPAA hosting plan and a BAA. Use a dedicated secure form provider instead.
Does my website need to be HIPAA-compliant if I only take self-pay?
You might not be a federal covered entity. But you are likely still bound by state privacy laws and ethical codes that require the same level of protection. Using secure tools is the best way to avoid liability and protect your clients regardless of your billing model.
What is the deadline for the new Notice of Privacy Practices?
The deadline to have the updated notice posted on your website was February 16, 2026. This update must include specific language about substance use disorder records and patient rights. If you have not yet updated, do it now.
Do I need a BAA with my website designer?
Only if the designer has access to Protected Health Information. If they are just building the public-facing pages and do not have access to your secure forms or EHR, a BAA is usually not required. However, many specialized designers will sign a confidentiality agreement regardless.
Is an SSL certificate enough to make my site HIPAA-compliant?
No. An SSL certificate (the padlock in the browser) only encrypts data while it is moving from the browser to the server. It does not cover how the data is stored or who has access to it. It is one small piece of a much larger security puzzle.

Need a therapy website that’s both effective and compliant?

We build secure, beautiful practice websites with the right tools in place. You focus on clients. We handle the compliance side.

Start the conversation
Posted in