Patient-data collection control. Evidence required: a current form inventory, every field collected, vendor list, transmission path, storage destination, access permissions, tracking tags, consent language, and applicable agreements.
Pass/fail condition: pass only when the responsible privacy, security, and legal owners have reviewed the actual implementation for the practice's obligations; fail when sensitive information reaches an unreviewed destination or is exposed to an unapproved tool.
Severity: critical. Owner: privacy or compliance leadership with engineering. Corrective action: minimize collection, replace unapproved systems, correct transmission or storage controls, and update notices or consent where required.
Validation step: submit controlled test data, trace each destination, verify access, and retain the review record. Tools: JotForm HIPAA, HIPAA Vault
Structured-data accuracy control. Evidence required: the rendered clinic or practitioner page, the generated MedicalBusiness and Physician Schema markup, and validator output. Pass/fail condition: pass when every marked-up fact is visible or otherwise properly supported and the syntax is valid; fail when markup invents specialties, locations, accepted insurances, credentials, or relationships.
Severity: medium. Owner: technical SEO or development, with practice operations approving facts. Corrective action: remove unsupported properties and correct entity relationships so the machine-readable version matches the public page.
Validation step: compare final markup with rendered content and run a technical validator without interpreting validation as a ranking promise. Tools: Merkle Schema Generator, Google Rich Results Test
Mobile performance control. Evidence required: representative page templates, field measurements when available, lab traces, and observed Interaction to Next Paint (INP) issues. Pass/fail condition: pass when priority journeys remain usable and no reproducible performance defect materially blocks navigation, reading, or form interaction; fail when page behavior creates measurable friction on the tested templates.
Severity: high. Owner: engineering or web performance. Corrective action: address the measured bottleneck, such as excessive script work, oversized media, or template behavior, instead of applying generic speed changes.
Validation step: retest the same templates using the same measurement approach and compare the post-deployment evidence. Tools: PageSpeed Insights, Chrome UX Report