Use this section to decide whether core technical and data-handling controls have evidence behind them. A tool result is supporting evidence, not a legal conclusion, and each item should be closed only after the named validation step succeeds.
Form data handling - Evidence required: inventory of every form field, destination, processor or vendor configuration, transport behavior, access controls, retention settings, and the clinic's applicable privacy review.
Pass/fail condition: pass only when the documented configuration matches actual collection and transmission behavior and the responsible reviewer has approved the handling; fail when a form's data path is unknown, mismatched, or unsupported.
Severity: High. Owner: privacy lead with web operations. Corrective action: remove unnecessary collection, correct configuration or routing, and update public disclosures where the responsible reviewer determines they are needed.
Validation step: submit controlled test data, trace the destination and access path, and retain the reviewer signoff. Tools that may support inspection: JotForm Health, WPForms HIPAA, Google Search Console.
Core Web Vitals - Evidence required: current field or lab measurements for representative mobile and desktop templates plus the affected URLs. Pass/fail condition: pass when the measured templates meet the current documented 'Good' thresholds for LCP and CLS or have a documented exception and remediation plan; fail when the site team cannot reproduce the measurements or known poor templates remain untriaged.
Severity: Medium. Owner: web performance lead. Corrective action: address the specific rendering, layout, media, script, or server causes shown by diagnostics instead of assuming one optimization fits every template.
Validation step: rerun the same measurement workflow after deployment and record before-and-after evidence. Tools: PageSpeed Insights, GTmetrix.
MedicalClinic and Physician JSON-LD - Evidence required: rendered structured data, the visible page facts it describes, and the clinic's source records for names, locations, services, and clinician credentials.
Pass/fail condition: pass when the markup is syntactically valid, uses applicable properties, and matches visible supportable facts; fail when markup invents services, credentials, locations, or relationships, or differs from the page.
Severity: Medium. Owner: technical SEO lead with content owner. Corrective action: remove unsupported properties and align markup with the published page and source records. Validation step: test the deployed markup and manually compare every material property with visible content.
Tools: Schema.org, Merkle Schema Generator. This check helps with machine-readable entity description but does not guarantee rankings, rich results, featured snippets, or Google AI Overviews.
TLS and HSTS configuration - Evidence required: certificate status, redirect behavior, protocol scan, security headers, and renewal ownership. Pass/fail condition: pass when intended pages load over HTTPS without certificate errors, insecure redirects, or mixed-content defects and the documented HSTS policy matches the clinic's deployment decision; fail when a public path exposes a certificate, redirect, or mixed-content problem.
Severity: High. Owner: infrastructure or web operations. Corrective action: repair certificates, redirects, mixed resources, or header configuration according to the approved hosting plan. Validation step: retest representative public pages and record the scan result. Tools: Let's Encrypt, Qualys SSL Labs.