THE FORM THAT EMAILS PHI
The most common thing we find on a healthcare site built by a general agency is a contact form that asks about symptoms, insurance, or medications, and then delivers the answers to a staff inbox as plain email through a third-party form service nobody signed an agreement with. It works. It looks fine. It is also a disclosure, and it has usually been running for two years before anybody notices.
The pattern repeats: an appointment request stored in a marketing platform's database, a chat widget that logs conversations to a vendor with no business associate agreement, an analytics tag firing on a page whose URL contains a condition name. None of it is malice. It is what happens when the people building the site have never had to think about where data comes to rest.
We treat that question as the first design input, not the last review gate. What is collected, where it lands, who can reach it, how long it is kept, and what is recorded about who looked at it — decided before the first component is written.
SYSTEMS THAT SURVIVE SCRUTINY
STRAIGHT ANSWERS
CAN YOU BUILD A HIPAA-COMPLIANT WEBSITE?
A website is not certified compliant on its own — compliance is a property of your whole organisation, its agreements, and its policies. What we can do is build the technical side so it holds up: PHI routed only through infrastructure covered by a business associate agreement, encryption in transit and at rest, access control and audit logging, and tracking configured so it cannot leak clinical detail. We document all of it so your compliance officer has something concrete to review.
WILL YOU SIGN A BUSINESS ASSOCIATE AGREEMENT?
Where our work involves systems that handle protected health information, yes. We also tell you plainly when a project does not require one — a purely informational marketing site that collects nothing should be scoped so no PHI is ever in play, which is cheaper and safer than building something that needs the paperwork.
CAN YOU INTEGRATE WITH OUR EHR OR PRACTICE MANAGEMENT SYSTEM?
Usually. It depends on what the vendor exposes — a documented API, an HL7 or FHIR interface, or in the worst case a file drop. We establish what is actually available during scoping rather than promising an integration and discovering the limitation in week six. If the vendor offers nothing workable, we say so before you commit.
OUR CURRENT SITE WAS BUILT BY A MARKETING AGENCY. IS THAT A PROBLEM?
Not automatically, but it is worth checking. The recurring issues we find are forms that deliver patient information as plain email, chat or scheduling widgets from vendors with no agreement in place, and analytics tags capturing URLs that name a condition. We can audit the existing site and hand you the findings whether or not you engage us to fix them.
DO YOU WORK WITH HEALTH TECHNOLOGY COMPANIES AS WELL AS PROVIDERS?
Yes. Digital health products, medical device companies, and health SaaS all sit in the same constraint set with a different shape — the marketing site is usually straightforward, and the interesting work is in the product surfaces, the security posture your enterprise customers will diligence, and the documentation their procurement team will ask for.
HOW LONG DOES A HEALTHCARE BUILD TAKE?
A practice or clinic site is typically measured in weeks; anything with authenticated patient access or a system integration runs longer, because the integration and the review cycle set the pace rather than the design. You get a fixed scope and timeline in writing after the scoping call, not a range that drifts.
SEND US THE INTAKE FORM.
Point us at whatever on your current site collects information from patients. We will tell you where that data actually goes — within 24 hours, and without a proposal attached.

