Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Who this scanner is for

This tool is built for covered entities assessing their own website — medical, dental, behavioral health, chiropractic, physical therapy and optometry practices, and other providers subject to the Privacy and Security Rules.

It cannot tell from the outside whether a website belongs to a covered entity, a business associate, or an organization HIPAA does not reach at all. Some checks apply to everyone — TLS, security headers, email authentication. Others, such as posting a Notice of Privacy Practices, are requirements only for covered entities under 45 CFR 164.520. Findings scoped that way are labeled, so a vendor or software company running this scan can see which results do not apply to them.

What is a HIPAA website scanner?

A HIPAA website scanner inspects the publicly observable signals on a healthcare organization’s website — the things any visitor’s browser can see. That includes tracking technologies and third-party scripts, patient-facing forms, security headers, TLS configuration, email authentication records, and whether a Notice of Privacy Practices is posted and reachable.

Those signals matter because a healthcare website is where tracking technologies most often end up somewhere they were never considered: on an appointment page, a symptom checker, a patient portal login.

An external scanner cannot determine whether an organization is HIPAA compliant. It cannot see contracts, business associate agreements, authorizations, internal policies, server-side data handling, workforce practices or compensating controls. Any tool that returns a compliance verdict from a public crawl is inferring most of it.

What this scan inspects

Privacy & tracking

Advertising pixels, analytics tags, session recording, third-party forms and chat widgets — and which of your patient-facing pages they load on.

Public security configuration

HTTPS and certificate state, security headers, and publicly reachable administrative endpoints.

Email protection

SPF and DMARC records for your domain, and whether a published DMARC policy is actually enforcing.

Public notices

Whether a Notice of Privacy Practices is posted and reachable — required of covered entities that maintain a customer-facing website — and, separately, whether a website privacy policy exists.

Why website exposure matters

Most healthcare websites were built with the same toolkit as any other small-business site: an analytics tag, an advertising pixel, a chat widget, an embedded form. On a retail site none of that is remarkable. On a page where someone books an appointment or describes a symptom, the same tools may be transmitting more than anyone intended.

In December 2022, HHS OCR published guidance on how existing HIPAA rules apply to online tracking technologies. That guidance was an interpretation of rules already in force, not a change to them. In June 2024 the Northern District of Texas vacated the portion treating an IP address combined with a visit to an unauthenticated public webpage as sufficient on its own to trigger HIPAA obligations, and OCR withdrew its appeal in August 2024.

What survives is the part that matters most operationally. Tracking inside authenticated portals and patient workflows remains squarely in scope, and whether any particular disclosure implicates HIPAA depends on what is actually transmitted, the vendor relationship, and whether an agreement or authorization covers it. Those are questions a practice has to answer from the inside. This scan tells you where to ask them.

What this scan can — and cannot — tell you

The limits are the reason the findings are worth reading. A tool that claimed to determine compliance from outside would be wrong about it.

It can observe

  • Third-party technologies loaded by your public pages
  • The hostnames those technologies contact
  • Which patient-facing pages carry them
  • Publicly visible security configuration
  • Email-domain authentication records
  • Publicly reachable notices and certain exposed endpoints

It cannot determine

  • Whether your practice is HIPAA compliant
  • Whether a detected disclosure actually contains PHI
  • Whether a business associate agreement or authorization exists
  • What your forms do server-side
  • Your internal security controls, policies, or workforce training
  • Your risk analysis decisions or compensating controls
  • Whether OCR would find a violation

How the scan works

  1. 01 Discover

    We identify a limited number of high-signal public pages from the homepage's own links — appointment, contact, patient and intake paths first.

  2. 02 Observe

    The scanner loads those pages as an unauthenticated visitor and inspects public page source, HTTP response headers, DNS records and the TLS handshake.

  3. 03 Classify

    Findings are separated into HIPAA requirement, potential HIPAA relevance, security best practice, and informational — and labeled with who they apply to.

  4. 04 Limit

    We do not log in, submit forms, enter patient information, test for vulnerabilities, or claim to determine HIPAA compliance.

Methodology version
2.0
Last materially reviewed
August 2026
Recent methodology changes
  • Aug 2026 — removed compliance grading; findings now report observable evidence and stated uncertainty.
  • Aug 2026 — findings record how evidence was obtained, separating a script reference from an observed network request.
  • Aug 2026 — findings scoped to covered entities are labeled, so vendors and business associates can see what does not apply to them.
  • Aug 2026 — clean results describe what was observed on the pages evaluated rather than asserting site-wide absence.
  • Aug 2026 — pages that fail to load produce inconclusive checks instead of passes.

Why doesn’t Patient Protect give my website a HIPAA compliance score?

Because the public website is only part of the evidence. A scanner can observe technologies and configuration, but it cannot know whether transmitted data is PHI, whether a valid agreement or authorization applies, how your internal systems handle data, or whether compensating controls exist.

Scanners that return a number have to fill those gaps with assumptions, and the number inherits every one of them. We would rather tell you precisely what we observed than manufacture certainty we do not have.

So the report gives you four counts — what needs review, what would improve security, what came back clean, and what the scan could not conclude — and every finding says what it could not determine.

Common questions

What is a HIPAA website scanner?
A tool that inspects the publicly observable signals on a healthcare website — tracking technologies and third-party scripts, patient-facing forms, security headers, TLS configuration, email authentication records, and whether a Notice of Privacy Practices is posted. It reports what it observed from outside; it does not audit an organization.
Can a website scanner determine whether my practice is HIPAA compliant?
No. Compliance turns on evidence an external scan cannot reach: business associate agreements, patient authorizations, what your forms do server-side, your risk analysis, your policies, training and compensating controls. A scanner that returns a compliance verdict from a public crawl is inferring most of it.
Who should use this scanner?
Covered entities assessing their own website — practices subject to the Privacy and Security Rules. The scanner cannot tell from outside whether a site belongs to a covered entity, a business associate, or an organization HIPAA does not reach, so findings that apply only to covered entities are labeled. A software vendor operating under BAAs will see those marked as not applicable to them.
Does HIPAA prohibit Google Analytics or Meta Pixel?
Not as such. What matters is whether the information transmitted constitutes PHI, and whether the disclosure is permitted — by a business associate agreement, an authorization, or otherwise. A tag on a general information page and the same tag inside an authenticated patient portal are different situations. The scanner reports where a tag was referenced and leaves the determination to someone who can see the data flow.
What does HHS say about tracking technologies on healthcare websites?
OCR issued guidance in December 2022 explaining how existing HIPAA rules apply to online tracking technologies — an interpretation of rules already in force, not a rule change. In June 2024 the Northern District of Texas vacated the portion treating an IP address combined with a visit to an unauthenticated public webpage as sufficient on its own to trigger HIPAA obligations, and OCR withdrew its appeal in August 2024. The remainder of the guidance stands, and tracking inside authenticated portals and patient workflows remains squarely in scope.
Does a missing DMARC record violate HIPAA?
No. DMARC is a widely adopted email authentication control that makes it harder to spoof your domain. HIPAA does not name it. The scanner classes it as a security best practice, not a requirement.
Is a public WordPress login page a HIPAA violation?
No. Most content management systems expose an administrative login by default. It is a sensible thing to protect with multi-factor authentication and rate limiting, but its existence is not a violation, and the scanner does not present it as one.
Does HIPAA require my Notice of Privacy Practices on my website?
For covered entities, yes, with a specific trigger: a covered entity that maintains a website providing information about its customer services or benefits must prominently post the notice on that site and make it available electronically through it, under 45 CFR 164.520(c)(3)(i). This does not apply to organizations that are not covered entities.
Why doesn't Patient Protect assign a compliance score?
Because a number implies the scan weighed everything that matters, and it cannot. We report four counts — needs review, security improvements, observed clean, and inconclusive — and every finding states what it could not determine.
Is the scan safe? Will it affect my website?
It reads your site the way a visitor's browser would. Public GET and HEAD requests for pages and headers, DNS lookups for your SPF and DMARC records, and one TLS connection to read your certificate. No credentials, no sign-in, no form submission, no active vulnerability testing, and nothing about your site's content or configuration is changed. Like any visit, the requests can appear in your server logs and analytics.
Does the scanner submit information into my forms?
No. It never submits a form, never enters test data of any kind, never authenticates, and never triggers a production workflow. It reads what is publicly served and stops there.
How often should I scan my healthcare website?
HIPAA does not set a cadence for this. As security practice, it is worth re-checking after any website release, when a new marketing or analytics tool is added, and periodically otherwise — website configuration tends to drift as vendors and tags are added over time.

This is the part we can see from outside.

Your website is one surface. The Patient Protect risk assessment covers the controls an external scan cannot see — risk analysis, workforce, vendors, policies, access, and how ePHI moves through your practice.

Part of the HIPAA Foundation · Free tools & resources

See the full collection
AssessFree · proprietary

Assess risk

The Scan reads what your website exposes publicly. It does not watch it afterwards — re-run it after a release or a new marketing tag. What the platform keeps current is the compliance record underneath: BAAs and their expiry, workforce training and its evidence, access and audit review, vendor inventory, and the risk analysis those feed.

Next in the sequence

Risk Assessment

Assessments, classification tools, and an AI assistant that reveal your actual compliance standing and starting point.