It depends on one question: Your website needs HIPAA hosting if it collects, transmits, processes, or stores protected health information (PHI). This includes contact forms where patients submit health information, appointment scheduling tools, patient portals, file upload systems, and telehealth platforms. If your website is purely informational and never handles PHI, standard hosting may be acceptable — but many healthcare organizations are collecting PHI without realizing it.


  • A website needs HIPAA hosting the moment it collects, transmits, or stores PHI — even through a simple contact form
  • There is no official government “HIPAA hosting certification” — what matters is a signed BAA and documented security controls
  • Standard web hosting providers like GoDaddy, Bluehost, and WP Engine do not offer BAAs and are not HIPAA compliant
  • Contact forms, appointment schedulers, chat widgets, and file uploads can all create unexpected PHI exposure
  • Your hosting provider is a business associate — they must sign a BAA before PHI touches their servers

Not sure if your website needs HIPAA hosting? HIPAA Vault’s compliance specialists can assess your environment and identify gaps before they become incidents.

Schedule a free consultation →


The One Question That Determines Everything

Does your website collect, transmit, process, or store protected health information?

If the answer is yes — even partially, even occasionally — your hosting environment may need to comply with the HIPAA Security Rule (45 CFR Part 164) and its required technical, administrative, and physical safeguards.

Many healthcare organizations assume HIPAA only applies to electronic medical records stored in their EHR. In reality, something as simple as a contact form asking about symptoms, or an appointment scheduler that captures a patient’s name and date of birth alongside a chief complaint, can create HIPAA compliance obligations for the hosting environment those tools run on.

As Gil Vidals, CTO and co-founder of HIPAA Vault, explains:

“If you have a website that’s just brochureware and you’re just having a person fill out some basic information without touching patient healthcare, then you probably don’t need that. But for those practitioners that do collect information that’s considered PHI, they need to be careful to make sure they’re properly protecting it.”


Don’t Trust Patient Data to Standard Web Hosting

Protect your practice from breaches and fines. Our hosting includes intrusion detection, firewalls, and audit logs.

Learn More

When Your Website Does NOT Need HIPAA Hosting

Many healthcare websites never touch protected health information and do not require HIPAA-compliant hosting. Examples include:

  • Healthcare blogs and medical news sites
  • Physician profile and bio pages
  • Marketing websites with only general contact information (name, email, phone)
  • Educational resources with no patient-facing functionality
  • Websites with only a general “contact us” form that doesn’t ask about health conditions

For example, a dermatology clinic website that lists office hours, staff bios, and a phone number — with no online scheduling and no patient portal — generally does not require HIPAA hosting.

This changes immediately the moment patients begin submitting health-related information through the site.


Don't wait until it's too late. Download our free HIPAA Compliance Checklist and make sure your organization is protected.

When Your Website DOES Need HIPAA Hosting

The following website features almost always create PHI exposure and require a HIPAA-compliant hosting environment:

Appointment Request Forms

When patients provide their name, date of birth, symptoms, insurance information, or preferred provider alongside an appointment request, the combination constitutes PHI. Gil Vidals on when compliance kicks in:

“When someone fills out the form on their laptop, you can’t protect what they’re typing — someone could walk behind them and see it. But once they hit the submit button, it becomes your responsibility. It’s traveling through the Internet to the web server, and that connection needs to be encrypted — that’s HTTPS. And then it hits the web server and it’s your job to make sure that the data that was just entered is safe and secure.”

Patient Portals

Patient portals that store medical records, lab results, messages, prescriptions, or billing information require HIPAA-compliant infrastructure. These represent the highest-risk scenario because they intentionally store large volumes of PHI.

Secure File Uploads

If patients upload referral documents, insurance cards, lab reports, medical history, or imaging files, your website is handling ePHI. Every file upload feature needs to be evaluated for HIPAA compliance. For secure file transfer between organizations, see HIPAA Vault’s SFTP hosting

Telehealth Websites

Telehealth platforms that process video sessions, medical questionnaires, patient messages, or treatment plans require HIPAA hosting as part of a broader compliant environment.

Secure Messaging

Live chat widgets, support ticket systems, and patient messaging tools frequently store transcripts that contain PHI — even when the conversation starts about scheduling or billing.

Prescription Refill Requests

Prescription-related forms collect medication names, dosage information, and patient identifiers — all of which constitute PHI when linked to a specific individual.


Common Website Features That Collect PHI Without Organizations Realizing It

Beyond the obvious examples above, PHI exposure frequently occurs through features that organizations never flagged as compliance risks:

🔄 Rotate your phone for a better view of the comparison table.
Feature PHI Risk Why It's Often Missed
Contact form asking "What brings you in?" High Seems like a general inquiry
Online scheduling with "reason for visit" field High Treated as convenience, not compliance
Chat widget with health-related conversations High Third-party tool, not considered "the website"
Patient satisfaction surveys Medium Collected post-visit, overlooked as non-clinical
Membership or login portals High PHI stored in user profiles
Website backup files High PHI in production = PHI in backups
Third-party analytics with health data Medium Analytics tools often receive form field data
Blog comments from patients about conditions Low-Medium User-generated content, often unmoderated

Even if information is only stored temporarily before being forwarded to your EHR or deleted, it still requires appropriate safeguards during transmission and storage.


What Makes Hosting HIPAA Compliant?

HIPAA compliance is not achieved through hosting alone — and there is no official government certification for “HIPAA compliant hosting.” What matters is whether the hosting environment provides the infrastructure and contractual protections needed to meet the HIPAA Security Rule’s requirements.

A HIPAA compliant hosting provider must offer:

1. Business Associate Agreement (BAA) If a hosting provider creates, receives, maintains, or transmits ePHI on your behalf, they are a business associate under HIPAA and must sign a BAA. Without one, using them for any PHI-related purpose is a HIPAA violation — regardless of how secure their infrastructure may be.

Gil Vidals on the BAA as the non-negotiable starting point:

“A lot of people make the mistake of getting a hosting provider and they don’t even know if they have a BAA. You need to get a BAA signed. That’s the first thing. And when you do get a hosting provider, make sure they’re truly HIPAA compliant — not just saying they are.”

2. Encryption at Rest and in Transit PHI must be encrypted when stored (AES-256) and when transmitted (TLS 1.2 or higher). As Gil Vidals explains, encryption isn’t one thing — it’s three:

“Encryption at rest, encryption in flight or in transport, and then encryption in use. Those are three. It’s the same encryption, but you’re using it really in three different ways.”

3. Access Controls Role-based access management, multi-factor authentication (MFA), and least-privilege principles must be enforced. Only authorized personnel should be able to access PHI — and that access must be enforced at the hosting level, not just assumed.

4. Audit Logging Complete records of who accessed PHI, when, from where, and what they did. This is both a HIPAA Security Rule requirement and a critical tool for detecting and investigating breaches. NIST SP 800-66 Rev. 2 provides detailed implementation guidance for audit controls in HIPAA environments.

5. Secure Backups Backups must be encrypted and protected with the same controls as production data. This is one of the most commonly overlooked compliance gaps.

6. Ongoing Security Monitoring Intrusion detection, vulnerability management, and security patching. Continuous monitoring is required to identify threats before they become major incidents.

7. Physical Security The data center housing PHI must have physical access controls — biometric scanners, security cameras, access cards, and controlled facility entry.

8. U.S.-Based Infrastructure and Staff While not explicitly required by HIPAA, maintaining PHI on U.S.-based servers managed by U.S.-based staff is considered best practice and may be required by payer contracts or state regulations.


Why Standard Web Hosting Is Not Enough

Traditional shared hosting providers — including GoDaddy, Bluehost, WP Engine, SiteGround, and similar services — prioritize affordability and ease of use over compliance. Their standard plans typically offer:

  • No Business Associate Agreement — the most critical gap
  • Weak or no access controls beyond basic login credentials
  • Limited or no audit logging
  • Shared server environments with no PHI isolation
  • Basic or no security monitoring
  • Backup capabilities that don’t meet HIPAA requirements

Using these providers for a website that handles PHI creates direct compliance exposure. If a breach occurs, the absence of a BAA means your organization bears full regulatory liability — with no contractual recourse against the hosting provider.


How to Determine Whether Your Website Needs HIPAA Hosting

Work through this assessment:

Step 1 — Inventory your website’s data collection points List every form, scheduler, chat widget, upload field, login portal, and third-party integration on your website. For each one, ask: does this collect, transmit, or store information that could identify a patient and relate to their health?

Step 2 — Apply the PHI test Under HIPAA’s definition, PHI is any individually identifiable health information — including names, addresses, dates, account numbers, and any other information that could link a person to their health condition, treatment, or payment for healthcare.

Step 3 — Evaluate your hosting provider Does your current hosting provider sign BAAs? If not, and your website handles PHI, you have a compliance gap. Ask directly: “Will you sign a Business Associate Agreement for HIPAA compliance?”

Step 4 — Conduct a Security Risk Assessment The HHS Security Risk Assessment Tool is free and helps identify compliance gaps across your technology environment — including your website. For a more comprehensive evaluation, consider a HIPAA penetration test to identify vulnerabilities before attackers do.

Step 5 — Consult a compliance specialist If you’re unsure after completing steps 1–4, a professional assessment can identify risks before they become incidents.


Does your website need HIPAA hosting? HIPAA Vault provides fully managed HIPAA-compliant hosting with a signed BAA, U.S.-based private servers, AES-256 encryption, and 24/7 security monitoring.

View hosting plans →  |  Request a free risk assessment →


Risks of Using Non-Compliant Hosting

The consequences of using standard hosting for a PHI-handling website extend beyond regulatory fines:

Regulatory penalties — OCR civil penalties vary based on culpability and are adjusted periodically for inflation, with annual caps reaching into the millions for willful neglect. Criminal penalties apply for intentional violations.

Breach notification obligations — any unauthorized access to PHI triggers the HIPAA Breach Notification Rule, requiring notification to affected individuals within 60 days and reporting to HHS.

Reputational damage — healthcare data breaches are among the most publicly reported. Patient trust, once lost, is extremely difficult to rebuild.

No contractual recourse — without a BAA, your hosting provider has no legal obligation to protect your patients’ data. If a breach occurs due to their infrastructure, you have no contractual remedy.

Business disruption — a breach or OCR investigation can disrupt clinical operations, trigger legal proceedings, and divert significant organizational resources away from patient care.


Frequently Asked Questions


This article is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney for guidance specific to your organization. HIPAA Vault has provided managed HIPAA-compliant hosting for healthcare organizations since 1997.