Doctor's Point Logo
menu

HIPAA Compliance

Welcome to Doctor’s Point.

We understand that healthcare websites require special attention to privacy, security and regulatory requirements. Doctor’s Point is committed to building professional, high performance websites for medical professionals while taking a careful approach to protecting sensitive healthcare information.

Please read this page carefully to understand how Doctor’s Point approaches HIPAA compliance and how responsibility is divided between Doctor’s Point, the healthcare practice and third party service providers.

Throughout this page, “We,” “Us,” “Our,” and “Doctor’s Point” refer to Doctor’s Point and its services. “You,” “Your,” “Doctor,” “Client,” and “Medical Practice” refer to the healthcare professional, clinic, hospital or organization using our services.

Our Services

Doctor’s Point provides professional web design and front end development services for medical professionals and healthcare organizations.

We specialize in building high performance, user friendly marketing websites that serve primarily as information and professional presence platforms for patients.

Our websites may include features such as doctor profiles, professional information, services, qualifications, contact information, appointment links, social media links and other publicly accessible content.

1. How We Handle HIPAA Compliance

To maintain a privacy conscious architecture and reduce unnecessary exposure to Protected Health Information (PHI), Doctor’s Point follows an Integration and Embedding approach.

We do not develop custom website functionality intended to independently collect, process or store Protected Health Information (PHI) on the Doctor’s Point managed marketing website.

Features involving sensitive patient information, including but not limited to:

  • Patient intake forms
  • Medical appointment scheduling
  • Patient portals
  • Patient communications
  • Electronic medical information
  • Live consultations or telehealth

should be provided through appropriate external third party platforms that are designed and configured to support applicable HIPAA requirements.

Examples may include HIPAA eligible services such as Jotform Enterprise, HIPAAtizer, Updox, or another provider selected and approved by the medical practice.

The applicable third party provider should securely collect and process the information through its own infrastructure and, where required, provide a Business Associate Agreement (BAA) directly to the medical practice.

Doctor’s Point does not represent that every third party platform is automatically HIPAA compliant in every configuration. The medical practice is responsible for confirming that the selected provider, service plan and implementation satisfy its specific HIPAA obligations.

2. Limitation of Liability and Client Responsibility

Doctor’s Point does not, through its standard marketing website service, intentionally host, capture, process, store or transmit patient medical history or Protected Health Information (PHI).

The medical practice remains responsible for its own legal and regulatory obligations relating to patient information.

This responsibility may include:

  • Selecting appropriate HIPAA eligible hosting and technology providers where PHI is involved
  • Executing required Business Associate Agreements with applicable vendors
  • Properly configuring third party forms, portals, scheduling and communication systems
  • Reviewing analytics, tracking technologies, cookies and advertising pixels that may interact with patient information
  • Ensuring patient information is not unintentionally submitted through public website areas
  • Establishing appropriate internal privacy and security policies
  • Training staff on applicable privacy and security requirements

Doctor’s Point provides the website and frontend implementation based on the agreed scope of work. The purchasing medical practice or covered entity remains responsible for determining how patient information is collected, processed and managed through its overall technology environment.

3. Integration With Third Party Platforms

Where a website requires functionality involving sensitive information, Doctor’s Point may integrate or embed an external platform rather than developing custom PHI handling functionality.

The external provider remains responsible for its own platform, infrastructure and applicable security controls.

The medical practice is responsible for reviewing the provider's terms, privacy practices, HIPAA documentation and BAA requirements before using the service with PHI.

4. Public Website Information

Doctor’s Point websites are primarily designed as public professional and informational platforms.

Doctors should only publish information that is appropriate for public access.

Patient medical records, diagnosis information, treatment information, confidential communications and other PHI should never be published on publicly accessible website sections.

Testimonials, reviews, photographs and other patient related content should only be published when the medical practice has obtained any consent or authorization required under applicable law.

5. Analytics, Cookies and Tracking

Third party analytics, advertising, tracking pixels and similar technologies may collect information about website visitors.

Medical practices are responsible for reviewing which tracking technologies are used on their website and determining whether their configuration is appropriate for their regulatory obligations.

Where necessary, healthcare practices should avoid placing tracking technologies on pages or forms where sensitive patient information may be collected.

6. Business Associate Agreements

Whether a Business Associate Agreement is required depends on the nature of the service, the information involved and the relationship between the parties.

Where Doctor’s Point itself is determined to be a Business Associate for a particular service, the applicable contractual and HIPAA requirements should be addressed separately.

Where an external technology provider handles PHI directly, the medical practice should establish the appropriate contractual relationship and BAA with that provider where required.

7. What Doctors Should Do Before Using PHI

Before allowing patients to submit or communicate PHI through a Doctor’s Point website, please confirm:

  • The relevant service has been specifically evaluated for PHI use.
  • The third party provider supports the applicable HIPAA requirements.
  • A required BAA has been executed with the appropriate provider.
  • Forms, scheduling systems, portals and other integrations are configured appropriately.
  • Analytics and tracking technologies have been reviewed.

8. Our Position

Doctor’s Point is designed primarily to provide professional marketing and informational websites for healthcare professionals.

Our standard website development approach is intentionally structured so that sensitive patient information is handled through specialized external systems rather than being collected and stored directly by the marketing website.

This architecture helps separate the doctor's public digital presence from systems responsible for handling sensitive patient information.

9. Important Notice

HIPAA compliance depends on the complete technology environment, configuration, policies and operational practices of a healthcare organization.

Using a Doctor’s Point website or a particular third party integration does not, by itself, make a medical practice HIPAA compliant.

Healthcare organizations should seek qualified legal, privacy or compliance advice regarding their specific obligations.

10. Updates

Doctor’s Point may update this HIPAA Compliance Policy as our services, technology infrastructure or applicable requirements change.

Last Updated: August 29, 2026

Contact Us

For questions about HIPAA related integrations or the handling of sensitive information through our services: