Skip to content

HIPAA and Your Website Contact Form: What Is and Is Not Protected Health Information

Does a physician website contact form create HIPAA obligations? What counts as protected health information, where the line is, and how to build a form that stays on the right side of it.

Roger de OcaRoger de OcaFounder, DEOCAs8 min read
In this article
  1. 1.What protected health information actually is
  2. 2.Where contact forms cross the line
  3. 3.How to build a contact form that stays on the right side
  4. 4.Analytics and advertising pixels
  5. 5.The mistakes we find on physician sites
  6. 6.The bottom line

Ask ten physicians whether their website contact form is a HIPAA issue and you will get two answers: “of course not, it is just a website” and “we cannot have a form at all”. Neither is right. The rule is narrower and more practical than either camp assumes, and once you see where the line is, building a form that stays on the right side of it is straightforward.

This is not legal advice, and your compliance officer or attorney has the final word for your practice. It is the working understanding we build websites with, in plain language.

What protected health information actually is

HIPAA protects individually identifiable health information held or transmitted by a covered entity (a practice that bills insurance electronically is one) or its business associates. Two things have to be true at once: the information has to identify a person, and it has to relate to their health, their care or payment for it.

Identifiers alone

  • Name, phone, email on a “contact us” form
  • A request for office hours or directions
  • A question about whether you accept a plan
  • A newsletter signup

Identifiers plus health information

  • “I have been having chest pain for a week”
  • A medication list or a diagnosis
  • A request to reschedule a specific procedure
  • Anything typed into a symptom or intake form

The left column is a marketing inquiry. The right column, received by a covered entity, is PHI, even though it arrived through a public web page. The form did not change the rule. The content did.

Where contact forms cross the line

A contact form crosses into PHI in three common ways, and all three are design choices you control.

  • A free-text box with no guidance. “How can we help?” invites a paragraph about symptoms. The moment a patient writes one, you are holding PHI in whatever system received it.
  • Delivery to the wrong place. Submissions forwarded to a personal email address, a shared inbox with no access control, or a form vendor that will not sign a business associate agreement.
  • Fields that only make sense for existing patients. Date of birth, insurance member number, reason for visit. Those belong in an intake system built for PHI, not in the marketing form.

The safest data is the data you never collected. A marketing form that asks only for what a scheduler needs to call back cannot leak what it does not hold.

How to build a contact form that stays on the right side

1Ask for name, phone, email and a preferred time to call
2Say clearly: do not include medical details here
3Keep the free-text box short and labeled
4Deliver submissions to a controlled inbox
5Encrypt in transit, keep nothing you do not need
6Keep intake and portals on compliant infrastructure

Ask for what a scheduler needs, and nothing else

A prospective patient wants a call back. Name, phone, email and a good time to call are enough to make that happen. Everything clinical can wait for the phone call or the intake form, where it belongs.

Tell people not to type medical details

One line next to the message box, in both languages: “Please do not include medical information here; we will ask what we need when we call.” It changes what people write, and it documents that you tried.

Deliver to a controlled inbox

Submissions should land somewhere with access limited to the staff who need it, not in a personal email. If your form vendor or your email provider can see the content, they should be able to sign a business associate agreement, or the content should never contain PHI. Both approaches work; “we never thought about it” does not.

Encrypt in transit, retain little

HTTPS on the whole site, always. Then decide how long form submissions live and where. A marketing inquiry from three years ago has no reason to still exist in an inbox.

Keep real intake where it belongs

Symptom questionnaires, medical histories, portals and appointment systems that capture medical details are PHI systems. They belong on compliant infrastructure with the right agreements in place, designed for that from the start. They do not belong in the same generic form builder as your newsletter.

Analytics and advertising pixels

This is the part most practices have never considered. Advertising pixels and some analytics tools send what a visitor does on your site to a third party, sometimes with enough detail to identify them. Federal guidance has warned that on pages behind a patient login, and on pages where visitors share health information, that can involve PHI; a federal court narrowed part of that guidance in 2024, and the area is still moving.

You do not need to follow the litigation to make a safe decision. Keep advertising pixels off pages where patients describe conditions or request care, use analytics that does not identify individual visitors, and review what every script on your site sends and to whom. If a marketing vendor cannot answer that question, that is the answer.

The mistakes we find on physician sites

  • A “tell us about your condition” box on the public contact page, delivered to a personal Gmail.
  • A full intake form built in a generic form tool with no agreement and no access control.
  • Advertising pixels on the “symptoms” and “book now” pages.
  • The word “HIPAA compliant” on the website with nothing behind it. There is no such certification, and claiming it invites scrutiny.
  • A web developer who has never asked what the form collects or where it goes.

Do

  • Keep the public form to contact details and a call-back time
  • Label the message box so patients do not type medical details
  • Route submissions to a controlled inbox, and know who can read it
  • Put real intake on compliant infrastructure with the right agreements

Don’t

  • Forward form submissions to personal email
  • Run advertising pixels on pages where patients describe care
  • Claim to be “HIPAA certified”
  • Assume your website builder handles any of this by default

The bottom line

HIPAA does not forbid a contact form. It asks you to know what the form collects, where it goes and who can see it, and to keep health information out of places that were never built for it. Every platform we build for physicians starts with that decision: the marketing site collects no PHI, and anything that does is designed for it from day one. See how we approach medical website design and custom clinical tools, or read the wider physician website design guide, which covers HIPAA alongside everything else a physician site needs.

Frequently asked questions

Is a name, phone number and email address on a contact form PHI?

On their own, on a marketing page, generally no: they are identifiers without health information attached. The moment the same form asks or allows the person to describe a condition, a symptom, a medication or a visit, and your practice is a covered entity, the submission can contain PHI and should be handled as such.

Is regular email HIPAA compliant?

Standard email is not encrypted end to end and is not designed for PHI. Sending form submissions that contain health details to an ordinary inbox, or to a personal Gmail, is one of the most common ways practices mishandle PHI without noticing. Use a form service and an inbox that can be covered by a business associate agreement, or keep health details out of the form.

Do I need a business associate agreement with my web developer?

If the developer, the hosting company or the form vendor can access PHI in the course of their work, HIPAA expects a business associate agreement with them. If your website collects no PHI at all, there is nothing for the agreement to cover. Deciding which situation you are in is the first design decision, not an afterthought.

What about analytics and advertising pixels on my site?

Federal guidance has said that tracking technologies on pages where visitors share health information, or on pages behind a patient login, can involve PHI, and part of that guidance was narrowed by a federal court in 2024. The cautious path is simple: no advertising pixels on pages where patients describe conditions or book care, and analytics that does not identify individuals.

Roger de Oca

Article written by

Roger de Oca

Web designer, developer, and founder of DEOCAs. Roger builds and maintains web platforms for physicians and medical organizations, including the 2025-2026 president of a national medical society, and writes about what actually works for practices online.

This article is general information for physicians and practice managers, not legal, medical or financial advice. Rules and prices change; confirm anything that affects your practice with your own advisors.

Keep reading

Ready for a website that works as hard as you do?

We design, build, and maintain web platforms exclusively for physicians and healthcare institutions.

ContactCall now