Most of what a practice website does never touches health information. When it must, the platform keeps it off the site and under an agreement that covers it.
The short version. Standard forms on the platform collect contact details only: a name, an email, a phone number, a practice, a message. They never ask for a condition, a treatment, or a referring physician, so nothing they collect is protected health information. When a practice needs to collect health information online, the HIPAA-compliant option adds secure forms from a vendor built for that purpose. Those forms run on the vendor's service, not on the website, and the vendor signs a Business Associate Agreement directly with the practice.
Standard forms. Every inquiry form, assessment, and Get Started form on the platform is written to stay clear of health information. Submissions are emailed to the practice and removed from the website after ninety days. The website's own database is not a system for health records and is never used as one.
The HIPAA-compliant option. For intake, referrals, records requests, and anything with a document to upload, the platform embeds a secure form from a HIPAA-focused provider. The form loads in its own protected frame; the page around it cannot read what is typed. Submissions, uploads, and stored records live entirely on the provider's service, under the Business Associate Agreement the provider signs with the practice. Technivant builds and maintains the connection and never holds the records. The option is available on either plan as a managed add-on.
Email. Form notifications go to the practice's own inbox. Whether that inbox may receive health information depends on the practice's email provider and its agreement, which is why discovery includes a check of the practice's Google Workspace or Microsoft 365 configuration. It takes a few minutes and we help.
Hosting and access. The website runs on enterprise hosting with encrypted connections, daily backups, and role-based access for the practice's team. Because health information is kept off the website by design, the site itself stays out of scope.
What stays with the practice. The Notice of Privacy Practices, staff training, and the agreements with the practice's own vendors, including its email provider and its electronic health record, remain the practice's responsibility. We advise on which forms need the secure option; the practice decides.
This page describes how the platform is built. It is not legal advice. A practice's obligations under HIPAA should be reviewed with its own counsel.
Questions about the HIPAA-compliant option: hello@technivant.com, or use the contact form.