Begin with the parts of the site that determine whether patients and search engines can reach intended public information and whether website tools handle data as the clinic expects. A technical pass confirms observed behavior; it does not substitute for medical, legal, privacy, or security approval.
Crawl, index, canonical, and redirect control
Evidence required: a current crawl export, Google Search Console indexing evidence, canonical tags on representative templates, redirect tests, robots directives, and an approved inventory of condition, service, physician, and genuine location pages.
Pass: intended public pages are internally discoverable, return the expected response, use a coherent canonical target, and are not unintentionally excluded from crawling or indexing. Fail: a priority page is orphaned, blocked against intent, duplicated without a documented canonical decision, trapped in a redirect pattern, or returns an unintended 404 response.
Severity: High when access to a priority patient page is affected; otherwise Medium. Owner: SEO lead with developer support. Corrective action: repair the specific internal link, redirect, robots, canonical, template, or status-code defect based on the approved page purpose. Validation step: recrawl the affected templates and inspect representative URLs in Search Console after release.
Form, chat, call, and vendor data flows
Evidence required: an inventory of appointment requests, contact forms, chat tools, call-tracking systems, analytics tags, vendor endpoints, fields collected, access controls, retention settings, and the clinic's documented review decisions.
Pass: responsible privacy, security, legal, and operational owners can explain what each system receives, why it is needed, where it is transmitted, and which safeguards or agreements apply to that use.
Fail: sensitive health information can enter a tool or vendor workflow that has not been approved for the clinic's intended data flow. Severity: Critical. Owner: privacy or security lead, legal reviewer, and technical owner.
Corrective action: remove unnecessary fields, reconfigure the workflow, change the destination, or complete the required review before sensitive information is collected. Validation step: submit test information that contains no real patient data and confirm the expected payload, destination, access, logging, and retention behavior.
HTTPS and transport behavior
Evidence required: browser inspection, certificate status, requests to insecure variants, mixed-content checks, and any security-header review required by the clinic's engineering standard.
Pass: intended public and form pages load over HTTPS, insecure variants resolve as designed, and active content does not depend on an insecure resource. Fail: a patient can reach an unintended insecure version, the certificate is invalid, or active content is loaded through an insecure connection.
Severity: Critical for active exposure and High for a configuration defect that can create exposure. Owner: infrastructure or application developer. Corrective action: renew or reconfigure certificates, correct redirect behavior, and replace insecure resource references.
Validation step: repeat browser and automated checks on representative public pages and submission flows after deployment.
Mobile rendering, interaction, and stability
Evidence required: field data when available, lab results for representative page types, device or emulator checks, and evidence for Core Web Vitals such as LCP, INP, and CLS.
The source previously stated that over 65% of pain-related searches occurred on mobile devices while people were experiencing discomfort. No supporting source URL exists in this JSON, so that figure should remain a historical claim pending source reconciliation rather than a verified benchmark.
Pass: essential content, navigation, phone actions, and form controls work on supported mobile viewports, and material regressions have a documented owner and remediation decision. Fail: layout movement blocks an action, essential content does not render, controls are difficult to use, or a release materially degrades the clinic's agreed performance standard.
Severity: High when access or interaction is impaired; otherwise Medium. Owner: frontend developer and SEO lead. Corrective action: address the measured source of delay, layout instability, oversized media, blocking assets, or template failure. Validation step: rerun the same tests and manually complete key patient tasks on representative mobile environments.
Sitemaps, architecture, and existing structured data
Evidence required: XML sitemap output, current indexable URL inventory, navigation structure, internal-link depth, page-purpose mapping, and an inventory of structured data already deployed.
Pass: sitemaps contain canonical indexable URLs the clinic intends search engines to discover, important pages are also reachable through meaningful internal navigation, and deployed structured data matches visible, supportable facts.
Fail: sitemaps contain redirected, duplicate, blocked, or noncanonical URLs, a priority page depends on sitemap discovery alone, or markup contradicts the rendered page. Severity: Medium, elevated when a large group of important pages becomes difficult to discover or understand.
Owner: SEO lead and developer. Corrective action: align sitemap generation, navigation, internal links, and existing markup with the approved page inventory. Validation step: regenerate the sitemap, recrawl the site, and compare submitted and rendered facts with the intended indexable inventory.