Personal Health Information (PHI) Compliance and Your Website TL;DR
Healthcare websites handle sensitive Personal Health Information (PHI) and electronic Personal Health Information (ePHI), and compliance with regulations like PHIPA (Ontario), PIPA (British Columbia), PHIA (Manitoba), Law 25 (Quebec), and HIPAA (U.S.) is essential to safeguard patient data. Websites often fall out of compliance regarding personal health information, due to reliance on non-compliant platforms, lack of encryption, improper data collection practices, and insufficient staff training. Building and maintaining compliance requires secure hosting, SSL/TLS encryption, explicit user consent, and ongoing audits.
Key Takeaways
1. Encryption is Non-Negotiable: Implement SSL/TLS encryption to secure data transmissions.
2. Limit Data Collection: Avoid open-ended form fields to prevent accidental PHI submissions.
3. Data Residency Matters: In Canada, PHI often must remain on Canadian servers (varies by province). PHIPA Compliance for Ontario.
4. Website Builders Aren’t Fully Compliant: Platforms like Wix, WordPress, Shopify, and Squarespace, lack inherent PHI and PIPEDA compliance.
5. Explicit User Consent: Include a checkbox on contact forms for data handling consent.
6. Use Secure Tools: Rely on compliant platforms such as JaneApp, Jotform, or MakeForms for PHI storage.
7. Clarify Roles: Define clear responsibilities for compliance maintenance.
8. Ongoing Commitment: Regular audits, staff training, and software updates are essential for long-term compliance.
By implementing these strategies, healthcare providers can ensure their websites meet regulatory standards, protect sensitive health information, and maintain patient trust.
Disclaimer
The information provided in this blog post is for general informational purposes only and is based on our interpretation of compliance regulations related to electronic Protected Health Information (PHI) under frameworks such as HIPAA, PHIPA, PIPA, PHIA, and Law 25. It is not intended as legal advice, nor should it be relied upon as such. For legal advice tailored to your specific situation, please consult with a qualified legal professional or compliance expert.

Introduction to electronic Personal Health Information Website Compliance
Imagine a patient reaching out through your website, trusting you with their most personal health concerns. Every click and form submission carries sensitive information, making the security and privacy of electronic Personal Health Information (ePHI) more than just a legal checkbox. It’s a promise to protect trust and integrity at every digital touchpoint.
Healthcare websites handle appointment bookings, patient inquiries, resource sharing, and secure portals. Each interaction involving PHI introduces potential risks and regulatory responsibilities.
Compliance isn’t just about avoiding penalties; it’s about building lasting trust, enhancing your reputation, and positioning your practice as a reliable and secure choice. Regulations like PHIPA (Ontario), PIPA (British Columbia), PHIA (Manitoba), Law 25 (Quebec), and HIPAA (U.S.) set clear expectations for handling sensitive health information.
Clear compliance strategies help streamline processes, reduce vulnerabilities, and create a seamless, secure experience for every patient visiting your website.
Key Compliance Requirements for Healthcare Websites
Protecting PHI on your website starts with understanding the key compliance requirements set by regulations like PHIPA, PIPA, PHIA, Law 25, and HIPAA. These regulations outline specific responsibilities for healthcare providers when handling sensitive health information online.
Encryption and Data Security
Ensure all data transmitted through your website, including forms and portals, is encrypted using SSL/TLS protocols. Encryption prevents unauthorized access during transmission and secures patient data.
Data Collection Best Practices
Limit the collection of personal health information through website forms. Avoid open-ended fields where users might accidentally submit sensitive details.
Secure Hosting and Storage
Use hosting providers that comply with healthcare data regulations. Regular backups, server security protocols, and access controls are essential.
Transparent Privacy Policies
Clearly outline how patient data is collected, stored, and used in a publicly accessible Privacy Policy. This document builds trust and ensures transparency.
Access Control and Authentication
Implement strong access controls for website administrators and staff. Use multi-factor authentication (MFA) to protect backend systems.
Data Residency Requirements
In Canada, healthcare data residency laws vary by province. For example, PHIPA Compliance (Ontario) and Law 25 Compliance (Quebec) do not require healthcare data to be stored on servers located within Canada, however it is highly recommended. For provinces like British Columbia (PIPA), storing data outside Canada could result in non-compliance unless specific criteria and safeguards are in place. Always consult with legal and compliance experts to ensure your hosting provider meets these requirements.
Adhering to these requirements isn’t just about meeting legal standards. It’s about delivering a safe, reliable experience for your patients.

Common Compliance Mistakes and How to Avoid Them
Even with the best intentions, healthcare websites often fall short in critical compliance areas. Recognizing these common mistakes can help you address them before they become liabilities.
Overlooking Encryption Protocols
Failing to use SSL/TLS encryption leaves patient data vulnerable to interception. Ensure every page and form submission uses HTTPS.
Collecting Unnecessary Data
Forms should only ask for essential information. Open-ended text boxes often invite users to overshare sensitive details unintentionally.
Outdated Software and Plugins
Websites relying on outdated software are prime targets for cyberattacks. Regularly update all plugins, themes, and systems.
Poorly Written Privacy Policies
Vague or incomplete privacy policies fail to set clear expectations. Ensure your privacy policy explicitly states how data is handled.
Inadequate Staff Training
Even the most secure systems can fail if staff aren’t trained on handling sensitive data responsibly. Regular training sessions are essential.
Unintended PHI Submission via Contact Forms
A common issue arises when patients unintentionally share sensitive health details in open-text contact forms. While the form may not explicitly ask for health data, once this information is submitted, it falls under compliance regulations. Implement disclaimers and train staff to handle such submissions appropriately.
Website Builders Are Not Fully Compliant
Popular website platforms like Wix, WordPress, Shopify, and Squarespace are not inherently PHI or HIPAA compliant. These platforms lack the necessary infrastructure to meet stringent healthcare compliance standards.
Backend Storage of Form Submissions
Contact form submissions are often stored in the backend of websites. If the website platform itself isn’t compliant (as mentioned above), storing sensitive health data on these platforms automatically places your website out of compliance.
Three Ways To Solve This Problem:
1. Use PHI compliant hosting providers to host website and store data.
2. Store your website on a private/local server setup and owned by your company
3. Use external embed forms by service providers such as MakeForms, JotForm or JaneApp.
Clarify Roles and Responsibilities
Compliance is not solely the responsibility of website developers or IT teams. Clearly define who is responsible for compliance measures, including updates, audits, and oversight.
Avoiding these pitfalls helps minimize risk, improve patient confidence, and maintain compliance with healthcare privacy regulations.

Steps to Build a Compliant Healthcare Website
Creating a website that meets PHI compliance standards requires intentional planning and execution. Below are actionable steps to guide you:
Conduct a Compliance Audit
Start with a thorough audit of your existing website to identify vulnerabilities, outdated tools, and areas requiring improvement.
Choose a Compliant Hosting Provider
Select a hosting provider that explicitly supports healthcare compliance standards such as PHIPA, HIPAA, and PIPA.
Implement SSL/TLS Encryption
Ensure your website uses SSL/TLS encryption on every page, especially those collecting or displaying patient information.
Limit Data Collection
Minimize the amount of personal health information collected on web forms. Use dropdowns or pre-set fields to avoid open-ended text entries.
Publish a Clear Privacy Policy
Write and publish a detailed privacy policy explaining how data is collected, stored, and used.
Enable Multi-Factor Authentication
Protect backend systems with multi-factor authentication (MFA) to prevent unauthorized access.
Train Staff Regularly
Provide ongoing training for staff members to ensure they understand compliance protocols and best practices.
Include Explicit Consent on Contact Forms
Add a checkbox for users to explicitly consent to the collection and handling of their data. Clearly state how the information will be used and stored.
Use External CRMs and Secure Forms
Instead of relying on website platforms to store PHI, use compliant solutions such as JaneApp, Jotform, or MakeForms for data storage and management.
Secure File Upload Protocols
If your website allows users to upload documents, ensure uploads are encrypted, restricted by file type, scanned for malware, and securely stored.
Why Are Most Healthcare Websites Out of Compliance?
Many healthcare websites fall short of compliance standards for PHI due to a combination of factors. Some of the most common reasons include:
1. Websites Built by Practice Owners or Friends/Family Members:
Many healthcare providers turn to family members, friends, or acquaintances with basic website knowledge to build their sites. While these individuals may create functional websites, they often lack an understanding of healthcare compliance regulations and the security measures required for handling sensitive health information.
2. General Web Design Agencies:
Even professional web design agencies may lack specialized knowledge about healthcare regulations like HIPAA, PHIPA, PIPA, and PHIA. These agencies might prioritize aesthetics and user experience but overlook critical compliance requirements.
3. Use of Non-Compliant Website Builders:
Platforms like Wix, WordPress, Shopify, and Squarespace are commonly used due to their ease of setup and affordability. However, these platforms are not inherently compliant with PHI regulations and lack the infrastructure needed to ensure secure data handling.
4. Lack of Encryption Protocols:
Many healthcare websites fail to properly implement SSL/TLS encryption, leaving data transmissions vulnerable to interception.
5. Improper Data Collection Practices:
Open-ended contact forms often allow patients to unintentionally submit sensitive health information without proper safeguards in place.
6. Inadequate Training and Awareness:
Staff members may not be adequately trained on PHI compliance protocols, leading to mishandling of sensitive data or improper system access.
7. Backend Storage of Contact Form Submissions:
Many websites store form submissions in their backend databases, which may not meet compliance standards if hosted on non-compliant platforms.
8. Missing Explicit Consent Mechanisms:
Contact forms often lack an explicit consent checkbox, failing to inform users about how their data will be collected, stored, and used.
9. Absence of Compliance Audits:
Many healthcare providers fail to perform regular security audits to identify vulnerabilities and maintain ongoing compliance.

Key Similarities and Differences Between HIPAA, PHIPA, PIPA, PHIA, and Law 25
Understanding the differences and similarities between healthcare privacy regulations like HIPAA (U.S.), PHIPA (Ontario), PIPA (British Columbia), PHIA (Manitoba), and Law 25 (Quebec) is essential for compliance. Below is an overview:
Key Similarities Across Regulations
1. Protection of Personal Health Information (PHI):
All regulations aim to protect personal health information (PHI) and electronic personal health information (ePHI) from unauthorized access, use, or disclosure.
2. Data Collection and Use Limitations:
Personal health data should only be collected for specific purposes and not used beyond the intended scope.
3. Patient Rights:
Patients have the right to access their health records, request corrections, and know how their data is being used.
4. Consent Requirements:
Explicit consent is required before collecting, using, or sharing personal health data in most scenarios.
5. Data Security Standards:
Websites and systems handling health information must implement encryption protocols (SSL/TLS) and access controls (e.g., MFA).
6. Incident Response:
In case of a data breach, organizations must notify affected individuals and, in most cases, regulatory authorities.
7. Accountability and Compliance Audits:
Organizations must have clear policies, staff training, and regular audits to ensure ongoing compliance.
Key Differences Between Regulations
Scope
HIPAA in the U.S. is a federal law governing protected health information (PHI) for healthcare providers, insurers, and clearinghouses. In contrast, PHIPA compliance in Ontario applies specifically to health information custodians, while PIPA in British Columbia applies more broadly to private-sector organizations. PHIA in Manitoba focuses on health information custodians, and Quebec’s Law 25 governs all private-sector organizations handling personal information.
Data Residency
Regarding data residency, HIPAA allows data storage outside the U.S. if safeguards are met. In Ontario and Manitoba under PHIPA and PHIA, data must generally remain in Canada. PIPA in British Columbia permits data storage outside Canada if adequate safeguards are in place, whereas Law 25 in Quebec requires data to generally remain within the province.
Consent Model
The consent models also differ. HIPAA permits implied consent for treatment but requires explicit consent for sharing data outside providers. PHIPA, PHIA, and Law 25 mandate explicit consent for sharing PHI, with Quebec emphasizing detailed transparency. PIPA also requires explicit consent unless otherwise specified by law.
Breach Notification
Breach notification requirements are consistent across jurisdictions. Under HIPAA, breach reporting to affected parties and regulatory bodies is mandatory. PHIPA requires mandatory reporting if harm is likely, PIPA mandates it if significant harm is likely, while PHIA and Law 25 both enforce mandatory breach reporting to affected parties and authorities.
Right to Access
Rights to access and correction are granted universally. Under HIPAA, PHIPA, PHIA, PIPA, and Law 25, patients and individuals have the right to access their records and request corrections.
Third-Party Compliance
For third-party compliance, HIPAA mandates Business Associate Agreements (BAAs) for vendors. PHIPA requires oversight of third-party compliance by custodians, while PIPA, PHIA, and Law 25 necessitate strict third-party compliance, with Quebec emphasizing strong contractual safeguards.
Enforcement Authority
Enforcement authority differs across these laws. In the U.S., HIPAA is enforced by the Department of Health and Human Services (HHS). In Ontario, the Information and Privacy Commissioner (IPC) oversees PHIPA compliance, while British Columbia relies on its Information and Privacy Commissioner. Manitoba designates the Ombudsman for enforcement, and Quebec assigns this responsibility to the Commission d’accès à l’information (CAI).
Unique Aspects of Each Regulation
HIPAA Compliance (USA)
Known for strict vendor agreements (BAAs) and specific technical security controls (e.g., encryption, MFA).
PHIPA Compliance (Ontario)
Places a strong emphasis on data residency and patient consent models.
PIPA Compliance (British Columbia)
Applies beyond healthcare to include all private-sector organizations, making it broader in scope.
PHIA Compliance (Manitoba)
Emphasizes provincial data residency and individual privacy rights.
Law 25 Compliance (Quebec)
Introduces modernized privacy provisions, including strong penalties for non-compliance and stricter requirements for data localization.

Checklist for Healthcare Website Compliance
- Encryption: Ensure all data, including forms and transmissions, is encrypted (SSL/TLS).
- Consent Forms: Include explicit consent checkboxes on contact and data collection forms.
- Data Residency: Use compliant Canadian hosting providers for PHIPA, PHIA, and Law 25 compliance.
- Third-Party Tools: Verify tools (e.g., CRMs, form builders) are compliant with the relevant regulations.
- Breach Protocols: Have a data breach response plan in place, including notification workflows.
- Regular Audits: Conduct ongoing compliance audits and train staff regularly.
PHI Compliance Final Thoughts
Regional differences (e.g., data residency requirements, consent models) mean healthcare providers must ensure their websites comply with both federal and provincial regulations. Most healthcare websites are built with good intentions but lack the specialized expertise required for healthcare compliance. Whether created by well-meaning family members, general web designers, or using non-compliant platforms, these websites often miss critical security measures and compliance protocols. Addressing these shortcomings requires intentional planning, expert consultation, and ongoing commitment to meet regulatory requirements and protect sensitive health information effectively. To get a closer a look at the different variables your practice may need to consider from a marketing standpoint, read our post on marketing security.
When it comes to protecting health information, it’s important to note that any health information, regardless of how generalized, seems to be considered PHI and therefore needs to be appropriately protected.
Reach out to our team today to become PHI compliant if:
- Your website is collecting health information submitted via contact forms.
- Your website is storing those contact forms on the backend of your website.
- You are unsure of your website compliance and would like our team to review it.
Explore our services if you need help with your healthcare marketing.
Personal Health Information Compliance Frequently Asked Questions
What is the primary purpose of each law (HIPAA, PHIPA, PIPA, PHIA, Law 25)?
These laws aim to protect personal health information (PHI) by establishing rules for its collection, use, and disclosure within their respective jurisdictions.
Who must comply with Personal Health Information regulations?
Compliance is required from entities handling PHI, such as healthcare providers, insurers, and associated organizations, varying by jurisdiction.
How is 'personal health information' defined under each law?
While definitions vary, PHI generally includes any identifiable information related to an individual’s health status, care, or payment details.
What are the consent requirements for collecting and sharing PHI?
Consent models differ; some laws allow implied consent for treatment but require explicit consent for other uses, while others mandate explicit consent for all disclosures.
Are there specific data residency requirements for storing PHI?
Yes, certain laws mandate that PHI remains within specific geographic boundaries, such as within the province or country, to ensure data protection.
What should organizations do in the event of a data breach involving PHI?
Organizations are generally required to notify affected individuals and regulatory bodies promptly, with specific timelines and procedures varying by law.
What rights do individuals have regarding access to their PHI?
Individuals typically have the right to access their PHI and request corrections to ensure accuracy across all jurisdictions.
How do these laws impact third-party service providers handling PHI?
Third-party providers must comply with the same standards as primary entities, often formalized through agreements like Business Associate Agreements (BAAs) or similar contracts.
What are the penalties for non-compliance with these regulations?
Penalties vary but can include substantial fines, legal action, and reputational damage, emphasizing the importance of adherence.
How do these laws interact with other federal or provincial privacy regulations?
There can be overlaps; organizations must ensure compliance with all applicable laws, considering both specific health information acts and broader privacy legislation.



