Most HIPAA conversations about a medical practice's website focus on marketing content: what you can say, what claims you can make. The intake form and patient portal are a different category of risk entirely, because they're where the website actually touches protected health information, and a lot of practices are running that piece on tools that were never built for it.
The line that matters: does the form collect PHI?
A simple "request an appointment" form asking only for name, phone, and preferred time is generally low-risk. The moment a form asks about symptoms, medications, insurance details tied to a specific person, or any other health information, it's collecting protected health information, and the tool handling that submission needs to be treated as part of your HIPAA-covered infrastructure, not as a generic marketing plugin.
Why a standard WordPress contact form usually isn't enough
Popular WordPress form plugins are frequently configured, by default, to email form submissions in plain text to a staff inbox. That's a problem for two reasons: email is not an encrypted channel unless specifically configured to be, and the form plugin vendor itself won't sign a Business Associate Agreement for a default installation, meaning there's no BAA covering the tool actually processing the PHI. Running unencrypted PHI over email is one of the more common, avoidable HIPAA exposures we find in practice website audits.
The fix isn't necessarily to abandon WordPress. It's to route any form that touches PHI through a properly configured, BAA-covered intake or patient portal tool, and keep the website's own contact forms limited to non-PHI scheduling requests.
What a compliant setup actually looks like
- A signed Business Associate Agreement with whatever vendor hosts the intake form, patient portal, or practice management system that touches PHI, not just with your hosting provider.
- Encryption in transit (TLS/HTTPS, which should be table stakes site-wide already) and encryption at rest for any stored PHI.
- Access controls limiting who on staff can view submitted intake data, with logging of who accessed what and when.
- A documented breach notification process, since HIPAA requires specific timelines and steps if PHI collected through the site is ever exposed.
- Regular review of who has admin access to the website and form backend, since a compromised WordPress admin account is a realistic path to a PHI exposure, not just a defaced homepage.
"HIPAA-compliant hosting" is a starting point, not the whole answer
A hosting provider willing to sign a BAA and offering appropriate technical safeguards is a necessary piece, but hosting alone doesn't make a website HIPAA compliant. The forms, plugins, analytics tools, and any chat widgets on the site all need their own review, since a HIPAA-compliant host sitting underneath a form plugin that emails PHI in plain text doesn't close the actual gap.
This connects directly to the broader question of which marketing and analytics tools are even appropriate to run on pages that touch PHI; see our guide on HIPAA-compliant Google Ads tracking for how that plays out on the analytics side specifically.
Tridigiam builds and audits WordPress infrastructure for HIPAA-aware configuration, but we're a marketing and development agency, not a HIPAA compliance auditor or legal counsel. A full security risk assessment, BAA review, and breach response plan should involve your own compliance officer or healthcare attorney. For the fuller picture on marketing a medical practice, see our Medical Practice Marketing Guide.
Frequently asked questions
Does a simple appointment-request form need a BAA?
If the form only collects contact details and a preferred time, without symptoms, insurance, or other health information, it generally doesn't rise to the level of PHI. The moment it asks anything health-specific, treat it as PHI and get the vendor relationship covered.
Can we use a popular form plugin if we upgrade to its paid tier?
Check specifically whether that vendor will sign a BAA at any tier; not all form plugin companies offer one regardless of price point. If they won't, a paid upgrade doesn't solve the underlying compliance gap.
Is emailing appointment confirmations to patients a HIPAA problem?
Generally lower risk if the email only confirms a time and doesn't include clinical details, but many practices ask patients to opt in to email communication precisely to document that the patient accepted the (small) risk of an unencrypted channel for non-sensitive confirmations.
Who's actually responsible if a WordPress plugin leaks patient intake data?
Liability can extend to the covered entity (the practice) regardless of which vendor's tool caused the exposure, which is exactly why vetting vendors and securing BAAs before deploying any PHI-touching tool matters so much.
Resources
Need marketing that actually moves the needle?
Tridigiam is a Las Vegas marketing and advertising agency built for regulated and growth-focused businesses. Call (702) 748-7005 or request a consultation.





