
Are WordPress Forms HIPAA Compliant? The Hidden ePHI Risk (2026)
A WordPress form can quietly turn a healthcare website into an ePHI system. Where patient data actually travels, what breaks, and how to reduce the risk.

Collective editorial voice · Editorial Team
Reviewed by the founders · Published under editorial standards
“Every post under this byline is reviewed by a CTO, a CSO, and a CEO before it publishes. No post reflects one person's view — and none is filler.”
The Patient Protect Editorial Team publishes original guidance, breach coverage, research, and product commentary under a single collective byline. Every post carrying this attribution has passed through review by the company's Chief Technology Officer, Chief Security Officer, and Chief Executive Officer — or by researchers working on the Secure Care Research Institute program.
Posts under this byline draw on three deep sources of expertise. Joseph A. Perrin (CTO) brings federal-grade infrastructure security experience, having designed the zero-trust architecture that protects the Patient Protect platform. Angie Perrin, RDH (CSO) brings more than a decade of direct clinical practice and Certified HIPAA Consultant credentialing. Alexander Perrin (CEO) brings twenty years of enterprise SaaS and platform architecture, and directs the company's research program through the Secure Care Research Institute.
The editorial program covers HIPAA compliance operations, healthcare cybersecurity, breach analysis, OCR enforcement, business associate risk, and the operational reality of independent healthcare practices. Every published claim is either sourced from primary regulation, publicly available breach intelligence, verified vendor documentation, or Patient Protect's own research. Speculation, unattributed statistics, and industry generalities do not appear under this byline.
Coverage runs across three permanent surfaces: the Patient Protect blog for long-form operational guidance and vendor analysis, HIPAA Pulse for daily healthcare breach and enforcement intelligence, and the Secure Care Research Institute for peer-facing research. Cross-referencing between the three is intentional — the blog explains what to do, HIPAA Pulse explains what just happened, and SCRI explains the underlying economics.
Who reviews the work
No content publishes under the Editorial Team byline without review by at least two of the three. Deep technical or clinical topics route to the corresponding domain reviewer.

Chief Security Officer
Angie Perrin, RDH
RDH · Certified HIPAA Consultant
10+ years clinical practice.
Full bio

Chief Technology Officer
Joseph A. Perrin
Infrastructure Architect
Clinical & government healthcare infrastructure.
Full bio

Chief Executive Officer
Alexander Perrin
Founder · SaaS Product Architect
20 years enterprise technology.
Full bio
Where the team publishes
Patient Protect blog
Long-form operational guidance, compliance breakdowns, vendor evaluation, and platform reference for independent practices.
HIPAA Pulse
Daily healthcare breach and enforcement intelligence, with editorial context on what independent practices need to do next.
Secure Care Research Institute
Peer-facing research on breach economics, ePHI exposure modeling, and the operational reality of small-practice compliance.
Patient Protect Signal (iOS)
Mobile breach alerts, compliance tools, and risk intelligence — the editorial layer delivered to the pocket.
Recent Editorial Team posts

A WordPress form can quietly turn a healthcare website into an ePHI system. Where patient data actually travels, what breaks, and how to reduce the risk.

OCR ended COVID-era telehealth enforcement discretion in 2023. Five violations define most of the exposure for telehealth providers right now — consumer platform use, session recording storage, home office device failures, and more.

Everything telehealth clinicians need to know about HIPAA compliance — platform BAAs, home office security, session recordings, multi-state practice, and the step-by-step path to full compliance after the end of COVID-era enforcement discretion.

Four HIPAA violations that hit optometry practices hardest — retail staff accessing clinical records, optical lab BAA gaps, insurance coordination disclosure failures, and the shared-system access control problem.

Everything optometry practices need to know about HIPAA compliance — retail staff access, vision and medical record overlap, optical lab BAAs, insurance coordination, and the step-by-step compliance path.

Home visit device loss, PRN staff access gaps, exercise app BAA failures, and workers' comp disclosure violations — the HIPAA violations most common in PT practices, with enforcement context and what to do now.
Corrections and editorial contact
If a Patient Protect Editorial Team post contains a factual error, we correct it and note what changed. Rewriting the record silently is not an editorial practice we consider defensible. Send corrections, source questions, or interview requests to info@patient-protect.com.
For editorial commentary on healthcare-security research, breach economics, or independent-practice compliance operations, editors and reporters can reach any of the three named reviewers through their LinkedIn profiles linked from the individual bios above.