Design for Counselors

Trust · HIPAA & your therapy website

HIPAA-compliant websites for therapists: the honest version

It’s the question every therapist asks before launching a site — and most “HIPAA-compliant website builder” claims quietly overpromise on it. Here’s the plain-English version of how the line actually works, so you can stop worrying and build the right thing.

The short answer

A marketing website usually isn’t what HIPAA is about.

HIPAA governs protected health information — the records, diagnoses and treatment details a practice holds. A public marketing website isn’t a records system, so as long as it never collects health information, it generally sits outside HIPAA’s reach.

What genuinely needs to be compliant is anything that touches that information: your EHR, your intake forms, your scheduling, sometimes your email. The website’s job is to inform and invite — then hand the sensitive work to a tool that’s built and covered for it.

So the risk was never the template. It’s a form that asks a worried visitor to type their symptoms. Remove that, and most of the anxiety around a “HIPAA website” goes with it.

This is general, plain-English information to help you ask better questions — not legal advice. Your exact obligations depend on your setup; confirm them with a qualified HIPAA compliance professional.

Staying on the safe side

Four simple rules that keep a therapy site clear of HIPAA

Never ask for health details on the page

No “describe your symptoms,” no diagnosis dropdown, no free-text box that invites a worried visitor to over-share. Keep public enquiries to name, email and a short, general note.

Send sensitive intake to a vetted, compliant tool

Real intake, assessments and scheduling belong in a service built for it — one that will sign a Business Associate Agreement. Your website links out to that; it doesn’t try to be it.

Get a BAA wherever PHI could land

Any vendor that might touch protected health information — your EHR, intake, scheduling, sometimes email — should sign a Business Associate Agreement. A brochure site that collects none needs none.

Keep the marketing site a marketing site

The moment a website starts collecting or storing health information, it stops being “just marketing.” The clean line is: the site informs and invites; a compliant tool does the sensitive work.

On “HIPAA-compliant website builder” claims

What that badge really tells you — and what it doesn’t

A platform advertising a “HIPAA-compliant website builder” usually means it’s HIPAA-capable: it will sign a Business Associate Agreement and secure the data you collect through it. That’s genuinely useful — if you’re collecting protected health information on your site.

For a straightforward practice website that doesn’t collect health details, the badge is mostly reassurance you don’t strictly need — and paying a premium for it can distract from the questions that matter: does my site collect PHI at all, and if it does, is that specific tool covered by a BAA? Answer those honestly and the compliance picture gets a lot simpler.

How this template is built

Designed to stay on the safe side by default

Design for Counselors is built to keep you clear of that line without you having to think about it. It never asks visitors for health details, it keeps enquiries to the minimum (name, email, a short general note), and it leaves you free to plug in your own vetted, BAA-backed tools for intake, scheduling and records.

We’d rather explain how the line works than sell you a compliance badge we can’t stand behind. If you want to see exactly what it collects and how it feels, the full template is live to click through.

Be first to know

Want a site that keeps this simple?

We’re finishing the template and setting pricing now. Leave your details and we’ll let you know the moment it’s ready — with first access.

Have a HIPAA question about your specific setup? Add it to the note and we’ll give you a straight, plain-English answer — or point you to someone who can.

If you have one, paste the link — we can use it to show you a preview of your new site, already filled in.

No spam, ever. We'll only email you about the template. Please don't include any client or health details.

Questions

Common questions about HIPAA and therapist websites

Does a therapist need a HIPAA-compliant website?

Usually the website itself doesn’t fall under HIPAA — a marketing site isn’t a records system, so as long as it never collects health information (symptoms, diagnoses, treatment details), it generally sits outside HIPAA. What does need to be compliant is anything that touches protected health information: your EHR, intake forms, scheduling, and sometimes email. This is general information, not legal advice — confirm your own setup with a qualified compliance professional.

What does a “HIPAA-compliant website builder” actually give me?

Often less than the phrase implies. A platform can be “HIPAA-capable” — it will sign a Business Associate Agreement and secure data you collect — but that only matters if you’re collecting protected health information through it. For a straightforward marketing site that doesn’t collect health details, the badge is largely reassurance you don’t need. The honest questions are: does your site collect PHI, and if so, is that specific tool covered by a BAA?

Is a simple contact form on my website a HIPAA problem?

A basic “name, email, short message” form is generally fine, because a prospective client reaching out isn’t the same as you storing their health record — and you can gently signal “please don’t include health details.” The risk appears when a form invites symptoms, diagnoses or treatment history. Keep the public form general; route anything clinical to a compliant intake tool.

What about scheduling and telehealth links?

Those often do involve protected health information, so they should run on services built for it that will sign a BAA (many scheduling and telehealth tools are HIPAA-capable). Your website’s job is simply to link to them — it doesn’t need to host them.

Is the Design for Counselors template HIPAA-compliant?

We’d rather be precise than sell you a badge: the template is built to stay outside HIPAA by never collecting health information. It keeps enquiries to the minimum and leaves you free to choose your own vetted, BAA-backed tools for intake, scheduling and records. We won’t claim coverage we can’t stand behind — and again, this is general guidance, not legal advice.

Related: therapist website templates · therapist website builder · website design for therapists · the principles behind good therapist websites.