HIPAA and Your Website Contact Form: What Is and Is Not Protected Health Information
For physicians and the people who build their websites: what counts as protected health information, when a contact form creates it, and how to design one that does not.
Added a direct answer, a weekly action list and primary sources from HHS and the CFR; split the densest paragraphs and linked the secure platforms guide.
In short
A contact form falls under HIPAA when a covered entity receives health information tied to an identifiable person through it. Name, phone, email and a preferred call time alone are not protected health information; a symptom, a medication or a visit is. Keep the public form to what a scheduler needs; real intake belongs on the practice’s own platform.
In this article
A website contact form is a HIPAA issue only when it collects health information tied to a person: a symptom, a diagnosis, a medication, a visit. Name, phone, email and a good time to call are identifiers, not protected health information. The rule is narrower than most physicians fear, and a safe form is easy to build.
This is not legal advice, and your compliance officer or attorney has the final word for your practice. It is the working understanding we build websites with, in plain language.
What is protected health information?
HIPAA protects individually identifiable health information held or transmitted by a covered entity (a practice that bills insurance electronically is one) or its business associates. Two things have to be true at once: the information has to identify a person, and it has to relate to their health, their care or payment for it.
Identifiers alone
- Name, phone, email on a “contact us” form
- A request for office hours or directions
- A question about whether you accept a plan
- A newsletter signup
Identifiers plus health information
- “I have been having chest pain for a week”
- A medication list or a diagnosis
- A request to reschedule a specific procedure
- Anything typed into a symptom or pre-visit form
The left column is a marketing inquiry. The right column, received by a covered entity, is PHI, even though it arrived through a public web page. The form did not change the rule. The content did.
When does a contact form cross the line?
A contact form crosses into PHI in three common ways, and all three are design choices you control.
- A free-text box with no guidance. “How can we help?” invites a paragraph about symptoms. The moment a patient writes one, you are holding PHI in whatever system received it.
- Delivery to the wrong place. Submissions forwarded to a personal email address, a shared inbox with no access control, or a form vendor that will not sign a business associate agreement.
- Fields that only make sense for existing patients. Date of birth, insurance member number, reason for visit. Those belong in an intake system built for PHI, not in the marketing form.
The safest data is the data you never collected. A marketing form that asks only for what a scheduler needs to call back cannot leak what it does not hold.
How do you build a contact form that stays on the right side?
Ask for what a scheduler needs, and nothing else
A prospective patient wants a call back. Name, phone, email and a good time to call are enough to make that happen. Everything clinical can wait for the phone call or the pre-visit form on a platform the practice controls, where it belongs.
Tell people not to type medical details
One line next to the message box, in both languages: “Please do not include medical information here; we will ask what we need when we call.” It changes what people write, and it documents that you tried.
Deliver to a controlled inbox
Submissions should land somewhere with access limited to the staff who need it, not in a personal email. If your form vendor or your email provider can see the content, they should be able to sign a business associate agreement, or the content should never contain PHI. Both approaches work; “we never thought about it” does not.
Encrypt in transit, retain little
HTTPS on the whole site, always. Then decide how long form submissions live and where. A marketing inquiry from three years ago has no reason to still exist in an inbox.
Keep real intake where it belongs
Symptom questionnaires, medical histories, portals and appointment systems that capture medical details are PHI systems. They belong on infrastructure with the right agreements in place, designed for that from the start, never in the same generic form builder as your newsletter. Our guide to secure platforms for medical practices lists them by need, and online scheduling for medical practices covers the appointment form specifically.
What about analytics and advertising pixels?
This is the part most practices have never considered. Advertising pixels and some analytics tools send what a visitor does on your site to a third party, sometimes with enough detail to identify them.
Federal guidance has warned that on pages behind a patient login, and on pages where visitors share health information, that can involve PHI. A federal court narrowed part of that guidance in 2024, and the area is still moving.
You do not need to follow the litigation to make a safe decision. Keep advertising pixels off pages where patients describe conditions or request care, use analytics that does not identify individual visitors, and review what every script on your site sends and to whom. If a marketing vendor cannot answer that question, that is the answer.
The mistakes we find on physician sites
- A “tell us about your condition” box on the public contact page, delivered to a personal Gmail.
- A full pre-visit form built in a generic form tool with no agreement and no access control.
- Advertising pixels on the “symptoms” and “book now” pages.
- A privacy badge or a compliance claim on the website with nothing behind it. There is no such certification for a website, and claiming one invites scrutiny.
- A web developer who has never asked what the form collects or where it goes.
Do
- Keep the public form to contact details and a call-back time
- Label the message box so patients do not type medical details
- Route submissions to a controlled inbox, and know who can read it
- Put real intake on compliant infrastructure with the right agreements
Don’t
- Forward form submissions to personal email
- Run advertising pixels on pages where patients describe care
- Claim to be “HIPAA certified”
- Assume your website builder handles any of this by default
The bottom line
HIPAA does not forbid a contact form. It asks you to know what the form collects, where it goes and who can see it, and to keep health information out of places that were never built for it.
Every platform we build for physicians starts with that decision: the marketing site collects no PHI, and anything that does is designed for it from day one. See how we approach medical website design, or read the wider physician website design guide, which covers HIPAA alongside everything else a physician site needs.
What to do this week
- Read your contact form as a patient would and remove any field that invites symptoms or a reason for visit.
- Find out where submissions land and who can open that inbox.
- List every script on the site that sends visitor data to a third party, and remove advertising pixels from pages about care.
Frequently asked questions
Is a name, phone number and email address on a contact form PHI?
On their own, on a marketing page, generally no: they are identifiers without health information attached. The moment the same form asks or allows the person to describe a condition, a symptom, a medication or a visit, and your practice is a covered entity, the submission can contain PHI and should be handled as such.
Is regular email safe for health information?
Standard email is not encrypted end to end and is not designed for PHI. Sending form submissions that contain health details to an ordinary inbox, or to a personal Gmail, is one of the most common ways practices mishandle PHI without noticing. Use a form service and an inbox that can be covered by a business associate agreement, or keep health details out of the form.
Do I need a business associate agreement with my web developer?
If the developer, the hosting company or the form vendor can access PHI in the course of their work, HIPAA expects a business associate agreement with them. If your website collects no PHI at all, there is nothing for the agreement to cover. Deciding which situation you are in is the first design decision, not an afterthought.
What about analytics and advertising pixels on my site?
Federal guidance has said that tracking technologies on pages where visitors share health information, or on pages behind a patient login, can involve PHI, and part of that guidance was narrowed by a federal court in 2024. The cautious path is simple: no advertising pixels on pages where patients describe conditions or book care, and analytics that does not identify individuals.
Sources
- 1.45 CFR 160.103, Definitions , Electronic Code of Federal Regulations (2026)
- 2.Summary of the HIPAA Privacy Rule , U.S. Department of Health and Human Services, Office for Civil Rights (2026)
- 3.Covered entities and business associates , U.S. Department of Health and Human Services (2026)
- 4.Business associate contracts: sample provisions , U.S. Department of Health and Human Services (2026)
- 5.Use of online tracking technologies by HIPAA covered entities and business associates , U.S. Department of Health and Human Services, Office for Civil Rights (2024)
- 6.Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues with patients? , U.S. Department of Health and Human Services (2026)

Article written by
Roger de Oca
Web designer, developer, and founder of DEOCAs. Roger builds and maintains web platforms for physicians and medical organizations, including the 2025-2026 president of a national medical society, and writes about what actually works for practices online.
This article is general information for physicians and practice managers, not legal, medical or financial advice. Rules and prices change; confirm anything that affects your practice with your own advisors.
Keep reading
Ready for a website that works as hard as you do?
We design, build, and maintain web platforms exclusively for physicians and healthcare institutions.