PracticeScanner — HIPAA Compliance for Healthcare Practices
HIPAA Compliance Scanning

Your practice website may already be violating HIPAA.

PracticeScanner automatically scans your website every month for HIPAA violations — tracking pixels, missing documents, insecure booking platforms, and more — and delivers a full compliance report to your inbox.

Get Your Free Report No credit card required  ·  First scan is free
82%
of healthcare practice websites have at least one HIPAA violation
$2.1M
maximum fine per violation category per year under HIPAA Tier 4
6 yrs
lookback window — violations are retroactively litigable from the date a complainant became aware

Real cases. Real settlements. Your practice could be next.

The tracking technologies on your website are the same ones that have already cost healthcare organizations hundreds of millions of dollars in fines and settlements.

2025
$18.5M
Aspen Dental Management
Class action settlement over Meta Pixel and Google tracking on appointment booking pages. 2.2 million patients affected.
2023
$12.2M
Advocate Aurora Health
Settlement after tracking pixels transmitted health information to Google and Meta across 3 million patients.
2024
$6.66M
Novant Health
Meta Pixel on patient portal transmitted protected health information directly to Facebook. 1.3 million patients affected.
⚠️

Small practices are not exempt. Plaintiffs' attorneys have identified over 664 hospital systems and individual provider websites where Meta received patient data. Class action lawsuits and OCR complaint-driven investigations are targeting practices of all sizes. Any patient who notices a tracking pixel on your website can file an OCR complaint tomorrow — and OCR is legally required to investigate every single complaint it receives.

Automated compliance monitoring in three steps.

No technical knowledge required. No software to install. We scan your website automatically every month and deliver a detailed report.

1

We Scan

Every month, our scanner automatically checks your practice website for HIPAA violations across tracking technologies, legal documents, booking platforms, SSL security, and more.

We also use the Internet Archive's Wayback Machine to document how long violations have been present on your site — creating a timestamped record that is critical for legal defense.
2

We Report

You receive a full PDF compliance report detailing every violation found, why it matters legally, the financial exposure it creates, and exactly what needs to be fixed.

Reports include real enforcement case references, penalty tier calculations, and actionable remediation instructions formatted for your web developer.
3

You Fix

Forward the report to your web developer or marketing agency. The remediation steps are written in plain language — no compliance expertise required to act on them.

Documenting and fixing violations proactively creates a legal record of good faith that regulators and courts explicitly consider when determining penalties.

Everything we check on every scan.

Our scanner covers every major category of HIPAA website violation currently being enforced by OCR and prosecuted in class action litigation.

📡

Advertising Tracking Pixels

Meta Pixel, Google Ads, TikTok, LinkedIn, Twitter/X, Pinterest, Snapchat — none offer BAAs for healthcare organizations.

🎥

Session Replay Tools

Microsoft Clarity, HotJar, FullStory, Lucky Orange, Mouseflow — record all user interactions including typed health information.

📊

Analytics Platforms

Google Analytics and Google Tag Manager require a signed BAA and proper configuration. Most practices have neither.

📋

Missing Legal Documents

Notice of Privacy Practices (legally required under 45 CFR §164.520), Privacy Policy, and Terms of Service.

📅

Booking Platform Compliance

Non-compliant platforms (JotForm, Calendly, Google Forms) and BAA-required platforms (Zocdoc, Modento, NexHealth) where the BAA is likely unsigned.

🔒

SSL / HTTPS Security

Unencrypted HTTP connections expose all data transmitted between patients and your website. Required under the HIPAA Security Rule.

🏥

Sensitive Procedure Pages

Detection of high-sensitivity pages covering HIV, oncology, mental health, sedation, fertility, and other conditions that amplify PHI exposure risk.

🕰️

Wayback Machine Documentation

We use the Internet Archive to document how long violations have been present — providing timestamped evidence relevant to HIPAA's 6-year retroactive lookback window.

💾

Back-End Storage Risk

Guidance on non-compliant storage platforms (Google Drive, Dropbox, personal email) that may be holding patient data without a signed BAA.

💬

Chat and Marketing Tools

HubSpot, Intercom, Drift, Klaviyo, Mailchimp — chat and marketing automation tools that may capture sensitive health conversations without a BAA.

Simple, transparent pricing.

Monthly automated scanning with no setup fees and no long-term contracts. Cancel anytime.

DSO / Enterprise
Enterprise
For group practices, DSOs, and organizations with multiple locations or complex compliance requirements.
Custom
  • Everything in Standard
  • Multiple location coverage
  • Consolidated exposure summary across locations
  • BAA gap analysis and checklist
  • Custom remediation roadmap
  • Dedicated account review
  • Priority support
Contact Us

Everything you need to know.

Answers to the questions we hear most from dental practice owners and administrators.

Do I actually have HIPAA violations on my website right now?

Almost certainly. In scanning thousands of dental practice websites, we find violations on over 82% of them. The most common are Meta Pixel, Google Analytics without a BAA, and missing Notice of Privacy Practices. These are not edge cases — they are standard tools used by virtually every dental marketing agency, and almost none configure them to be HIPAA-compliant. The first scan is free, so you can find out in minutes.

My website was built by a marketing agency. Aren't they responsible?

No. Under HIPAA, the covered entity — your practice — is ultimately responsible for its own compliance. Your marketing agency may have installed the tracking pixels, but you are the one who faces OCR investigation and class action lawsuits. You can and should require your agency to remediate violations, but legal liability rests with you. This is one of the most dangerous misconceptions in dental compliance.

We're a small practice. Do we really need to worry about this?

Yes. OCR enforcement does not have a size threshold. Any patient, competitor, or disgruntled employee can file an OCR complaint against any practice at any time — and OCR is legally required to investigate every complaint it receives. Class action plaintiff attorneys have already identified hundreds of individual provider websites and are actively monitoring for violations. Aspen Dental was a large organization, but the legal exposure mechanism is identical for a single-location practice.

What is a BAA and why does it matter?

A Business Associate Agreement (BAA) is a contract required by HIPAA whenever a covered entity shares protected health information with a third-party vendor. If you use Google Analytics, a booking platform, or a chat widget on your healthcare website, each vendor that could receive patient data must have a signed BAA with your practice. Meta and most advertising platforms explicitly refuse to sign BAAs with healthcare organizations — meaning those tools are non-compliant by design, regardless of configuration.

I already had a HIPAA audit done. Why do I need ongoing scanning?

One-time audits go stale immediately. Your website changes constantly — your marketing agency adds a new tracking pixel, a plugin update introduces a new script, or your booking platform changes its integration. Any of these can introduce new violations the day after your audit. HIPAA compliance on a website is not a one-time checkbox — it requires continuous monitoring. A monthly scan costs far less than discovering a new violation a year after it was introduced.

How far back can violations be used against us?

Under HIPAA's statute of limitations, violations are retroactively litigable for up to 6 years from the date a complainant became aware of the issue. The December 2022 OCR bulletin formally put all healthcare providers on notice about pixel tracking violations — meaning that clock has been running since then. The Internet Archive's Wayback Machine preserves timestamped snapshots of your website, and plaintiffs' attorneys use this tool to prove continuous violation across multi-year periods.

What exactly does the PDF report include?

Each report includes: every tracking technology detected and why it violates HIPAA, missing legal documents with legal citation, your financial exposure estimate based on published HIPAA penalty tiers, Wayback Machine documentation of how long violations have been present, real enforcement case references, and step-by-step remediation instructions written for your web developer. Reports are formatted to be forwarded directly to your marketing agency or developer.

We already removed our Meta Pixel. Are we covered?

Removing Meta Pixel is a critical step, but likely not sufficient on its own. Google Analytics without a signed BAA, Google Tag Manager loading non-compliant scripts, a missing Notice of Privacy Practices, and non-compliant booking forms are each independent HIPAA violations. Most practices that discover and remove one violation find several others they were unaware of. A full scan will tell you exactly where you stand across all violation categories.

How is this different from hiring a HIPAA compliance consultant?

A HIPAA compliance consultant typically performs a one-time assessment across your entire practice — policies, staff training, physical security, and more. PracticeScanner focuses specifically on continuous website compliance monitoring, which is the fastest-growing area of HIPAA enforcement and the category most likely to generate class action exposure. We are not a replacement for a consultant covering your internal operations — we are a specialized tool for the specific risk vector that has generated over $100 million in settlements since 2023.

How do I get started?

Email us at support@practicescanner.com with your practice website URL. We will run your first scan at no charge and send you a full compliance report within 24 hours. No contract, no credit card required. If you decide to subscribe after reviewing your report, we will set up automated monthly scanning from there.

Questions? We're here.

Reach out and we'll get back to you within 24 hours.

support@practicescanner.com