HTTPS and transport security
Evidence required: inspect the live protocol, certificate status, canonical destinations, redirects, mixed-content warnings, and security configuration owned by the practice or hosting team.
Pass: patient-facing pages load over the intended secure protocol without browser warnings or conflicting canonical states. Fail: broken certificates, mixed resources, insecure form actions, or redirects create an obvious security or usability problem.
Severity: critical when patient data or intake paths are involved. Owner: web or infrastructure lead with privacy and security review. Corrective action: repair the certificate, redirects, insecure assets, or form destination according to the approved architecture. Validation: retest representative pages and submission paths on desktop and mobile.
Forms, calls, analytics, and other data flows
Evidence required: inventory every intake form, chat tool, call tracker, analytics tag, advertising pixel, URL parameter, CRM handoff, and vendor that can receive data.
Pass: the configuration matches the center's approved privacy and data-handling requirements, and the event model avoids collecting unnecessary sensitive information. Fail: an unreviewed tool transmits patient or intake data, or measurement is so incomplete that the team cannot distinguish meaningful inquiries from page views.
Severity: critical. Owner: privacy or compliance lead with analytics, legal, and technical owners. Corrective action: remove, reconfigure, or replace the affected implementation based on the center's reviewed requirements. Validation: repeat tag, network, and form-payload testing with non-sensitive test data and retain the review record.
Core Web Vitals and mobile intake usability
Evidence required: field data where available, laboratory tests, mobile rendering checks, and direct testing of contact, call, insurance, and program pages.
Pass: no measured performance or layout issue materially obstructs reading, navigation, or the intake path. Fail: delayed primary content, unstable layouts, oversized assets, inaccessible controls, or broken interactions interfere with use.
The source previously used an LCP threshold of 2.5 Seconds; preserve it as a source-recorded diagnostic reference rather than a guarantee of rankings, conversions, or patient retention. Severity: high.
Owner: developer or performance owner. Corrective action: fix the measured bottleneck rather than applying generic speed changes. Validation: rerun the same tests and compare before-and-after evidence.
Healthcare organization and service structured data
Evidence required: compare rendered markup with visible facility, organization, service, address, hours, and page information. Pass: structured data describes facts that users can verify on the page and does not invent services, credentials, locations, or insurance claims.
Fail: markup conflicts with visible content or includes unsupported information. Severity: high. Owner: technical SEO or developer with editorial review. Corrective action: remove unsupported properties and align remaining markup with published content.
Validation: retest rendered markup and manually compare it with the page. Structured data can improve machine-readable clarity but should not be described as a guaranteed ranking or rich-result mechanism.
URL hierarchy and indexable program pages
Evidence required: crawl the indexable site and map URLs to genuine outpatient programs, conditions, insurance information, physicians or clinicians, and real locations.
Pass: URLs are stable, descriptive, internally linked, canonicalized correctly, and each important page has a distinct purpose. Fail: parameter-heavy duplicates, orphan pages, conflicting canonicals, or multiple near-identical pages compete for the same intent.
Severity: medium to high. Owner: technical SEO with content and development. Corrective action: consolidate overlap, repair internal links, and use stable destinations. Validation: recrawl and compare the final indexable set with the approved content map.