The HIPAA Privacy, Security, and Breach Notification Rules apply to covered entities and business associates. For a psychology practice subject to HIPAA, a website feature enters the HIPAA compliance program when it creates, receives, maintains, or transmits PHI. Public educational pages do not become PHI merely because they discuss health, but identifiable information submitted in a care-seeking context can be PHI.
Website features that can handle PHI include:
- Contact forms asking about symptoms, diagnoses, treatment history, or reasons for seeking care
- Online scheduling systems that connect identifiable people with appointment reasons or care
- Patient portals with records or secure messaging
- Intake forms collecting identifiable health or insurance information
Features that usually do not create PHI by themselves include:
- Public blog posts and educational resources
- Public descriptions of services and credentials
- A Business Profile listing that does not disclose patient information
Name, email, phone number, IP address, page context, appointment details, and health information must be assessed together. Do not assume a “general” form is outside HIPAA merely because it omits a diagnosis field.
Controls when a website handles ePHI can include:
- Appropriate transport protection and secure downstream storage
- A BAA with each vendor that creates, receives, maintains, or transmits PHI on the practice's behalf
- Access controls, workforce procedures, risk analysis, and activity review appropriate to the system
- Documented incident and breach-response procedures
This is educational content, not legal advice. Consult qualified privacy counsel for your specific practice and data flows.