Skip to content

HIPAA Website Checker

Scan your healthcare website for common HIPAA compliance gaps before they become costly violations.

Is Your Healthcare Website HIPAA Compliant?

Enter your website URL below and we will scan it across 9 critical compliance categories. Get instant results showing exactly where your site falls short - and what to fix first.

SSL & Security

2 checks

Privacy & Data

4 checks

Compliance & Accessibility

3 checks

Important Disclaimer

This tool provides an automated preliminary assessment and does not constitute legal advice. A passing result does not guarantee full HIPAA compliance. We recommend working with a qualified healthcare compliance professional for a complete assessment.

What this checker looks at

It scans a public page on your site and reports what it finds across nine areas. It watches for 25 known tracking scripts, including the Meta Pixel, Google Analytics, Google Tag Manager, TikTok, LinkedIn, Hotjar, FullStory, Microsoft Clarity, and Mouseflow.

Third-party trackers
Analytics, advertising, and session-recording scripts loading on your pages.
Contact form exposure
Whether forms that collect patient details sit on a page with trackers running.
Form security
How your forms submit, and whether that submission is protected.
SSL and TLS
Certificate validity and whether anything still loads over plain HTTP.
Cookie consent
Whether a consent mechanism exists and when it fires.
Privacy policy
Whether one is published and reachable.
BAA indicators
Signals about vendors that would need a business associate agreement.
Data handling
How the page treats the information visitors give you.
Accessibility
Basic accessibility signals, which often correlate with how a site was built.

Is Google Analytics HIPAA compliant?

Google will not sign a business associate agreement for Google Analytics. That is the part that matters. Without a BAA, sending anything that identifies a patient to Google is a problem, and the same reasoning applies to the Meta Pixel, TikTok, and the rest of the advertising tags.

The complication is that identifying information leaks more easily than people expect. A URL like /appointments/dermatology/confirm paired with an IP address can say quite a lot about who someone is and what they are being seen for. That gets sent automatically, without anyone deciding to send it.

Why booking and contact pages matter most

A tracker on your homepage is worth reviewing. A tracker on the page where someone books an appointment or describes a symptom is the one we would look at first. The homepage tells an advertiser that a person visited a medical website. The booking page can tell them what for.

This is usually not anyone’s fault. Tags get added once for a campaign, or arrive inside a template, or load through Tag Manager without appearing in the page source at all. That last case is why there are two scan modes.

Instant scan and deep scan

The instant scan reads the HTML your server returns. It is fast and it catches anything written directly into the page.

The deep scan opens your page in a real browser and watches what actually loads, for up to 90 seconds. Scripts injected by Tag Manager or added after the page renders do not appear in raw HTML, so the instant scan cannot see them. If you use Tag Manager, run the deep scan.

What this is not

It is not a compliance review, and it is not legal advice. It reads one public page and reports what loads there. It cannot see your server logs, your EHR, your vendor agreements, or the parts of your site behind a login, and a clean result does not mean you are compliant. Findings are worth taking to whoever handles compliance for you.

What it does give you is a straight answer about what is running on your pages right now, which is usually the part nobody has actually checked. If something turns up and you would rather not deal with it yourself, book a call and we can take care of it.

Questions

Is my website HIPAA compliant?

This checker cannot tell you that, and neither can any scanner. It tells you what is loading on one public page of your site, which is one input into that question. Compliance also covers your vendor agreements, your internal processes, and systems this tool never sees. Treat a clean scan as one box ticked rather than an answer.

Is Google Analytics HIPAA compliant?

Google will not sign a business associate agreement covering Google Analytics, so there is no arrangement under which it can lawfully receive information that identifies a patient. The practical risk is that identifying information reaches it without anyone intending to send it, through page URLs and IP addresses.

Is the Meta Pixel a HIPAA violation on its own?

Not by itself. The pixel existing on a page is not automatically a violation. The problem is what it sends. On a booking or symptom page it can transmit the URL and the visitor's IP address to Meta, and that combination can identify both the person and what they are seeking care for. That is the part worth looking at.

What is the difference between the instant scan and the deep scan?

The instant scan reads the HTML your server returns, which is fast and catches anything written directly into the page. The deep scan opens the page in a real browser for up to 90 seconds and records what actually loads, so it catches scripts injected by Google Tag Manager or added after render. If you use Tag Manager, use the deep scan.

Do you store my scan results?

No. Results are generated when you run the scan and returned to your browser, and we do not keep the content of scanned sites. That changes only if you choose to email yourself a report. Ephemeral logs such as a timestamp, domain, and anonymized score are kept for rate limiting and abuse prevention.

Do I need to enter an email address?

No. The scan runs and shows you the result without one. There is an option to email yourself a copy if you want it, and that is the only reason to give us an address.

The scan found trackers on my site. What now?

Do not panic and do not start deleting tags at random, because some of them are load-bearing for things you rely on. Work out which pages handle patient information, find out what is running there, and decide per tag whether it needs to be removed, replaced with something that will sign a BAA, or restricted so it does not fire on those pages. Take the findings to whoever handles compliance for you. If you would rather hand it off, we can do that work.

Can I scan a site I do not own?

Please do not. The terms of service ask you to scan sites you own or have permission to analyze. It is a public-page scan rather than anything intrusive, but permission still matters.

Need help implementing this?

Our healthcare marketing team can put these recommendations into practice for you.

Book a Free Consultation