If you run a home health or home care agency, your website markets to families, recruits caregivers, and quietly collects health information through a contact form, a chat bubble or a “request an assessment” button. That last part is where the HIPAA worry starts.

The short answer: a HIPAA compliant website for a home health agency is less about a badge or a special theme and more about what data your forms, trackers and chat tools touch, and whether every vendor that touches it has signed a Business Associate Agreement (BAA). Your marketing pages can usually run ordinary analytics. Your intake forms, portals and AI chat need much more care.

First, what counts as PHI on a website

HIPAA applies to covered entities (health plans, clearinghouses, and health care providers that conduct certain transactions electronically, such as billing Medicare or Medicaid) and to their business associates. Most Medicare-certified home health agencies and Medicaid-billing personal care agencies fall inside that line. A purely private-pay, non-medical agency may not, but state privacy laws can still apply. I build every agency site as if HIPAA applies, because the cost of doing so is small.

Protected health information is, roughly, health information combined with something that identifies the person. On an agency website that combination shows up constantly. A daughter types, “My mother was discharged after a hip replacement and needs help bathing. She is on Medicaid,” then adds a name and phone number. That submission is health information plus identifiers. Where it travels next is the whole question.

Contact and intake forms: where most agencies slip

A basic form asking for name, email and a message is not automatically a problem. But people describe health conditions in any open text box, and many agency forms explicitly ask for diagnosis, services needed, payer or discharge date. Once a form is designed to collect that, treat every submission as PHI.

That has concrete consequences:

  • The form tool needs a BAA. Most default website form plugins and free form builders do not offer one. Some form vendors do, usually only on specific plans. Jotform, for example, limits HIPAA features and its BAA to its higher-tier plans.
  • Notifications should not carry the details. A form that emails the full submission to a shared Gmail inbox without a BAA has just moved PHI somewhere it shouldn’t be. Better: the email says “new referral received” with a link to log in and view it.
  • Integrations inherit the problem. Any CRM, spreadsheet or automation tool the form feeds needs to be covered too.

My preferred pattern is two tiers. The public site has a short, low-risk inquiry form (name, phone, best time to call, a checkbox for “care for myself” or “care for a family member”) with a note asking people not to share medical details. The detailed intake happens on the phone or inside a BAA-covered system. My home care agency website checklist covers how to design that inquiry form so it still converts.

Analytics and ad pixels after AHA v. Becerra

In December 2022 the HHS Office for Civil Rights published a bulletin on online tracking technologies, updated in March 2024. Its broadest position was that HIPAA could apply when a tracker simply connected a visitor’s IP address with a visit to a public, unauthenticated page about a health condition or provider.

On June 20, 2024, the Northern District of Texas ruled in American Hospital Association v. Becerra that this specific position exceeded HHS’s authority and vacated it. HHS filed an appeal, then withdrew it on August 29, 2024. So that part of the guidance is gone.

What remains matters more:

  • Logged-in pages are still in scope. The ruling did not touch the bulletin’s guidance on authenticated pages, like patient portals, family portals or caregiver apps. Trackers there can see PHI, and the vendor would need a BAA.
  • Other combinations still count. The court addressed the IP address plus public page combination. A tracker that captures form field contents, an email address alongside the service requested, or a “lead” event tied to someone’s identity is a different situation.

In practice, analytics on your homepage, service pages and blog are far lower risk than they looked in 2023. Be strict about intake forms, thank-you pages that reveal what someone requested, and anything behind a login.

Is Google Analytics HIPAA compliant?

Not in the sense agency owners usually mean. Google’s own Google Analytics HIPAA statement says it makes no representation that Analytics satisfies HIPAA, does not offer BAAs for it, and that HIPAA-regulated customers must not expose PHI to it. You can still use it on public marketing pages, as long as nothing that could be PHI reaches it.

What about the Meta pixel?

Meta does not offer a BAA for its ad tools, and its Business Tools Terms say advertisers must not share data that includes or is based on health information. I keep the Meta pixel off intake forms and thank-you pages entirely, and I’m cautious about using it beyond basic pageviews on marketing pages. Many agencies are better off measuring ads through call tracking and a BAA-covered intake system.

A common assumption is that a cookie consent banner solves this. It does not. OCR’s tracking technologies bulletin states that a banner asking visitors to accept or reject cookies is not a valid HIPAA authorization, and that guidance was not part of what the court vacated. It does not make it acceptable to send PHI to a vendor without a BAA.

Which vendors sign BAAs, and which generally don’t

Vendor terms change, so check current documentation before relying on this. As of 2026, the general picture looks like this:

CategoryTypical BAA situationWhat that means for you
Google AnalyticsNo BAA offeredPublic pages only; never send PHI
Meta pixel and Conversions APINo BAA; terms prohibit health dataKeep away from forms, thank-you pages and portals
Google Workspace (Gmail, Drive, Forms)BAA available for listed servicesMust be accepted by an admin before any PHI is used
Form buildersSome offer a BAA on specific plansConfirm the plan, then enable the HIPAA settings
AI model APIsSome providers offer a BAA for specific products and settingsConsumer chat apps are not the same as a covered API
Agency software (EMR, scheduling)Reputable vendors expect to sign oneAsk before you sign the contract

Google’s Workspace HIPAA page explains its BAA and covered services. Note the difference: your Gmail can be covered, while Google Analytics is not. I go further into evaluating EMR and scheduling vendors in my guide to home healthcare agency software.

AI chat widgets and AI receptionists

This is the fastest-growing risk on agency websites. A chat widget invites people to describe symptoms, medications and family situations, then sends that text to a third-party model. For a covered entity, those conversations are very likely PHI.

Before adding any chat or voice assistant, I look at four things:

  1. A BAA with every vendor in the chain. The chat widget company, the AI model provider behind it, and any tool that stores transcripts. A BAA with the widget vendor alone is not enough if it passes data to a model provider that hasn’t signed one. OpenAI, for example, reviews BAA requests for its API case by case and ties eligibility to specific data retention settings.
  2. Data retention. How long are transcripts and recordings kept, where, and can you delete them? Shorter is better.
  3. Model training. Get it in writing that conversations are never used to train models.
  4. What it is allowed to ask. The assistant should collect only what it needs to route a call: name, callback number, whether care is for themselves or a family member, and preferred time. It should never ask for Social Security numbers, Medicaid or Medicare ID numbers, full diagnoses, medication lists or insurance card details.

When I designed an AI receptionist for a home healthcare agency, the rule was simple: it answers general questions, captures a callback request and hands anything clinical or sensitive to a person. I wrote about that design in how I built an AI receptionist for a home healthcare agency.

Hosting, email and SSL basics

  • SSL everywhere. Every page should load over HTTPS, with no mixed content. It is also part of the technical SEO checklist for small businesses anyway.
  • Hosting depends on what the site stores. A marketing site that stores no PHI doesn’t need special hosting. If form submissions, documents or portal data live on your server or in your database, that host needs to sign a BAA and meet the Security Rule’s safeguards.
  • Email is a PHI channel. Staff will email about clients. Use an email provider under a BAA, turn on two-factor authentication, and stop forwarding referrals to personal accounts.
  • Access. Limit who can log in to the website admin, form tool and CRM, and remove former staff promptly.

None of this has to be expensive. I break down where the money goes in what a home health agency website costs.

A 10-point audit you can run this week

You don’t need a consultant to start. Sit down with your office manager and walk through this list:

  1. List every form on the site and note which ones ask about health, services, payer or diagnosis.
  2. Check each form tool for a signed BAA and confirm you are on the plan that includes it.
  3. Follow each submission: where is the notification emailed, and where is the data stored or synced?
  4. List every tracking script (analytics, ad pixels, heatmaps, session recorders) using your tag manager or a browser extension.
  5. Remove trackers from forms, thank-you pages and any logged-in area unless the vendor has signed a BAA.
  6. Check URLs and events for personal data, such as names, emails or services requested appearing in query strings or conversion events.
  7. Review chat and AI tools for a BAA chain, retention settings, training use and what they are allowed to ask.
  8. Confirm email is covered by a BAA, with two-factor authentication on every account.
  9. Review admin access to the website, form tool, CRM and hosting, and remove anyone who no longer needs it.
  10. Update your privacy notice so it accurately describes the tools you use, and set a reminder to repeat this audit every six months or whenever you add a new tool.

Frequently asked questions

Does a home health agency website need to be HIPAA compliant?

The public marketing pages don’t hold PHI by themselves, so the usual concern is what the site collects and where it sends it. If your agency is a covered entity, any form, chat, portal or tracker that handles health information plus an identifier must follow HIPAA, including BAAs with every vendor involved. Treat the site as part of your compliance program.

Is Google Analytics HIPAA compliant?

Google says it does not offer a BAA for Google Analytics and that HIPAA-regulated customers must not send it PHI. You can generally use it on public, unauthenticated marketing pages if nothing identifying or health-related reaches it. Keep it off intake forms, thank-you pages that reveal requests, and any logged-in portal. Confirm your setup with your compliance lead.

Can I use the Meta pixel on a healthcare website?

Meta doesn’t sign BAAs, and its Business Tools Terms prohibit sharing data that includes or is based on health information. Meta also limits tracking for health advertisers. If you use the pixel at all, restrict it to basic pageviews on general marketing pages, and keep it away from forms, conversion events tied to services, and anything behind a login.

What does AHA v. Becerra mean for tracking on my site?

The court vacated OCR’s view that an IP address plus a visit to a public health-related page is PHI, and HHS withdrew its appeal in August 2024. The rest of the bulletin still stands: trackers on logged-in pages, and trackers capturing other identifiable health information, can still create HIPAA problems. It narrowed the risk, it did not remove it.

Is a HIPAA compliant contact form enough?

A BAA-covered form tool is necessary but not sufficient. You also need to check where notifications go, which systems the data syncs into, who can access submissions, and whether tracking scripts on the page can read the form. A covered form that emails full submissions to an uncovered inbox still exposes PHI to a vendor without a BAA.

Want a second pair of eyes?

Most agency sites don’t need a rebuild. They need a few forms moved, a few scripts removed and a clear rule for what the chat bubble can ask. If you’d like me to walk through your site with you and flag what to fix first, get in touch and I’ll give you an honest read.