Compliance posture
The cleanest HIPAA stance is: don't touch PHI on the public site.
HHS guidance is clear — the safest marketing posture is to never collect Protected Health Information through the public website at all. Real bookings, refill requests, secure messaging all live inside your existing HIPAA-compliant patient portal under its existing BAA. The public site does what it should: tell patients who you are, where you are, what you treat, and link them straight into the portal.
- 0PHI collected on public site
- 50–70%Monthly savings
- 3–5wMigration time