HIPAA rules for regulated entities and business associates matter when a website workflow creates, receives, maintains, or transmits protected health information (PHI). The first decision is therefore not whether a page looks medical, but what information moves through the page, where it goes, which vendors receive it, and which entity is responsible for the disclosure.
Website workflows to inventory:
- Contact and admissions forms that collect identity, contact, insurance, or treatment-request information
- Live chat and chatbot tools where a visitor may discuss care needs
- Insurance verification, screening, intake, or scheduling workflows
- Authenticated patient or family portals
- Email, messaging, call-tracking, analytics, session-replay, and other tools that can receive data from a healthcare interaction
For a covered entity or business associate, do not assume that HTTPS alone resolves the privacy analysis. Encryption in transit is one safeguard, while permitted use or disclosure, access controls, retention, vendor roles, and business associate agreements must be assessed according to the actual data flow. A vendor that creates, receives, maintains, or transmits PHI on behalf of a regulated entity may require a BAA when it is acting as a business associate.
Review questions for the marketing and compliance teams:
- Does any form or chat tool send sensitive submissions into ordinary marketing or email systems?
- Can analytics, pixels, tag managers, or replay tools receive form values or other identifying healthcare information?
- Are intake and insurance tools configured so only authorized systems and people receive the submitted data?
- Does the privacy notice match the website's real collection, sharing, and communication practices?
Substance-use-disorder records can also fall under 42 CFR Part 2. The current rule should be evaluated on its own terms because its coverage, consent, redisclosure, notice, and proceeding-related restrictions are not identical to HIPAA. Whether a specific workflow is governed by HIPAA, 42 CFR Part 2, both, or neither depends on the entity, program, record, purpose, and disclosure path.
Document the data flow and route ambiguous implementations to qualified privacy and healthcare counsel before deployment.