PracticeScanner automatically scans your website every month for HIPAA violations — tracking pixels, missing documents, insecure booking platforms, and more — and delivers a full compliance report to your inbox.
Why This Matters
The tracking technologies on your website are the same ones that have already cost healthcare organizations hundreds of millions of dollars in fines and settlements.
Small practices are not exempt. Plaintiffs' attorneys have identified over 664 hospital systems and individual provider websites where Meta received patient data. Class action lawsuits and OCR complaint-driven investigations are targeting practices of all sizes. Any patient who notices a tracking pixel on your website can file an OCR complaint tomorrow — and OCR is legally required to investigate every single complaint it receives.
The Process
No technical knowledge required. No software to install. We scan your website automatically every month and deliver a detailed report.
Every month, our scanner automatically checks your practice website for HIPAA violations across tracking technologies, legal documents, booking platforms, SSL security, and more.
You receive a full PDF compliance report detailing every violation found, why it matters legally, the financial exposure it creates, and exactly what needs to be fixed.
Forward the report to your web developer or marketing agency. The remediation steps are written in plain language — no compliance expertise required to act on them.
Scan Coverage
Our scanner covers every major category of HIPAA website violation currently being enforced by OCR and prosecuted in class action litigation.
Meta Pixel, Google Ads, TikTok, LinkedIn, Twitter/X, Pinterest, Snapchat — none offer BAAs for healthcare organizations.
Microsoft Clarity, HotJar, FullStory, Lucky Orange, Mouseflow — record all user interactions including typed health information.
Google Analytics and Google Tag Manager require a signed BAA and proper configuration. Most practices have neither.
Notice of Privacy Practices (legally required under 45 CFR §164.520), Privacy Policy, and Terms of Service.
Non-compliant platforms (JotForm, Calendly, Google Forms) and BAA-required platforms (Zocdoc, Modento, NexHealth) where the BAA is likely unsigned.
Unencrypted HTTP connections expose all data transmitted between patients and your website. Required under the HIPAA Security Rule.
Detection of high-sensitivity pages covering HIV, oncology, mental health, sedation, fertility, and other conditions that amplify PHI exposure risk.
We use the Internet Archive to document how long violations have been present — providing timestamped evidence relevant to HIPAA's 6-year retroactive lookback window.
Guidance on non-compliant storage platforms (Google Drive, Dropbox, personal email) that may be holding patient data without a signed BAA.
HubSpot, Intercom, Drift, Klaviyo, Mailchimp — chat and marketing automation tools that may capture sensitive health conversations without a BAA.
Pricing
Monthly automated scanning with no setup fees and no long-term contracts. Cancel anytime.
Common Questions
Answers to the questions we hear most from dental practice owners and administrators.
Almost certainly. In scanning thousands of dental practice websites, we find violations on over 82% of them. The most common are Meta Pixel, Google Analytics without a BAA, and missing Notice of Privacy Practices. These are not edge cases — they are standard tools used by virtually every dental marketing agency, and almost none configure them to be HIPAA-compliant. The first scan is free, so you can find out in minutes.
No. Under HIPAA, the covered entity — your practice — is ultimately responsible for its own compliance. Your marketing agency may have installed the tracking pixels, but you are the one who faces OCR investigation and class action lawsuits. You can and should require your agency to remediate violations, but legal liability rests with you. This is one of the most dangerous misconceptions in dental compliance.
Yes. OCR enforcement does not have a size threshold. Any patient, competitor, or disgruntled employee can file an OCR complaint against any practice at any time — and OCR is legally required to investigate every complaint it receives. Class action plaintiff attorneys have already identified hundreds of individual provider websites and are actively monitoring for violations. Aspen Dental was a large organization, but the legal exposure mechanism is identical for a single-location practice.
A Business Associate Agreement (BAA) is a contract required by HIPAA whenever a covered entity shares protected health information with a third-party vendor. If you use Google Analytics, a booking platform, or a chat widget on your healthcare website, each vendor that could receive patient data must have a signed BAA with your practice. Meta and most advertising platforms explicitly refuse to sign BAAs with healthcare organizations — meaning those tools are non-compliant by design, regardless of configuration.
One-time audits go stale immediately. Your website changes constantly — your marketing agency adds a new tracking pixel, a plugin update introduces a new script, or your booking platform changes its integration. Any of these can introduce new violations the day after your audit. HIPAA compliance on a website is not a one-time checkbox — it requires continuous monitoring. A monthly scan costs far less than discovering a new violation a year after it was introduced.
Under HIPAA's statute of limitations, violations are retroactively litigable for up to 6 years from the date a complainant became aware of the issue. The December 2022 OCR bulletin formally put all healthcare providers on notice about pixel tracking violations — meaning that clock has been running since then. The Internet Archive's Wayback Machine preserves timestamped snapshots of your website, and plaintiffs' attorneys use this tool to prove continuous violation across multi-year periods.
Each report includes: every tracking technology detected and why it violates HIPAA, missing legal documents with legal citation, your financial exposure estimate based on published HIPAA penalty tiers, Wayback Machine documentation of how long violations have been present, real enforcement case references, and step-by-step remediation instructions written for your web developer. Reports are formatted to be forwarded directly to your marketing agency or developer.
Removing Meta Pixel is a critical step, but likely not sufficient on its own. Google Analytics without a signed BAA, Google Tag Manager loading non-compliant scripts, a missing Notice of Privacy Practices, and non-compliant booking forms are each independent HIPAA violations. Most practices that discover and remove one violation find several others they were unaware of. A full scan will tell you exactly where you stand across all violation categories.
A HIPAA compliance consultant typically performs a one-time assessment across your entire practice — policies, staff training, physical security, and more. PracticeScanner focuses specifically on continuous website compliance monitoring, which is the fastest-growing area of HIPAA enforcement and the category most likely to generate class action exposure. We are not a replacement for a consultant covering your internal operations — we are a specialized tool for the specific risk vector that has generated over $100 million in settlements since 2023.
Email us at support@practicescanner.com with your practice website URL. We will run your first scan at no charge and send you a full compliance report within 24 hours. No contract, no credit card required. If you decide to subscribe after reviewing your report, we will set up automated monthly scanning from there.
Reach out and we'll get back to you within 24 hours.