Free resource · HIPAA checklist
A working list of 22 items: administrative, technical, physical, marketing and breach response. Tick them off as you go; progress saves in this browser. No email required.
Working with a HIPAA-aware agency is not about adding warnings to ad copy. It is about how data moves through your stack. This is what we change on every healthcare engagement, and the checklist below is how you verify it.
We sign a Business Associate Agreement with every healthcare client. Not optional. It is the document that lets us legally handle anything that touches PHI.
Conversion tracking runs through server-side events with identifier stripping, so PHI never reaches Meta, Google or any platform pixel.
Tools like Hotjar and FullStory are disabled on patient-facing pages. Even with consent, replay is too risky in a medical context.
Review request automation that respects patient privacy. No appointment data goes to a third-party review platform without written consent.
Start with the group that worries you most. The bar at the top follows you down the page, and each group keeps its own count.
Pixels, GTM, forms, session tools, BAAs. A 30-minute call, a short report, zero pitch. Bring the checklist and we’ll start from whatever is still unticked.
30-minute call • Short written report • No obligation