Security & HIPAA

What we actually do, and what we will not claim

A marketing website should not hold protected health information, and yours will not. That single design decision does more for your compliance posture than any badge a vendor can put in a footer.

Last updated: August 10, 2026

The short version

Your practice website is a public marketing site. By design it collects no patient health information, so there is nothing sensitive on it to leak. If you later add a feature that would collect health information, we will not turn it on without a signed Business Associate Agreement first.

There is no such thing as HIPAA certification

The Department of Health and Human Services does not certify, accredit, or approve any software vendor for HIPAA compliance. No agency does. Any vendor showing you a “HIPAA certified” badge is showing you either a self-assessment or a certificate they bought.

So we do not claim it, and you should be skeptical of anyone in this category who does. What a vendor can honestly tell you is what safeguards are in place, where your data lives, who can reach it, and whether they will sign a BAA. Those are below.

Why your site holds no PHI

Protected health information is information that identifies a patient and relates to their care. A website that lists your services, your providers, your hours and your phone number contains none of it.

The two places PHI usually sneaks onto a practice website are:

  • Contact and appointment-request forms. Ours are built to collect a name and a way to reach someone, and they say on the form not to include medical details. Form submissions are relayed to your practice and are not retained as a patient record.
  • Patient stories and photos. We will not write a testimonial that describes a patient’s condition, and we do not invent reviews or ratings. If you supply a real patient testimonial, you are responsible for having written authorization on file.

Intake and support channels are the same: do not send us patient information. Nothing we build for you requires it.

When a BAA applies

A Business Associate Agreement is required when a vendor creates, receives, maintains or transmits PHI on your behalf. The standard website does none of those things, so the standard website does not require one.

Two optional add-ons change that, and both are gated accordingly: the HIPAA Forms suite is only enabled with a signed BAA in place, and the patient-story add-on requires written patient consent on file before we will publish anything. If you want a BAA for your own recordkeeping regardless, ask — we will sign one.

CaringCodex is the website arm of ClaimCarePro, a medical billing company that works under BAAs every day. This is familiar ground, not a checkbox we discovered on the way to launch.

What is actually in place

  • Encryption in transit and at rest

    Every page is served over HTTPS with certificates managed by AWS. Stored data is encrypted at rest by the AWS services holding it.

  • United States regions only

    Hosting, database and backups run in US AWS regions. Nothing is replicated outside the United States.

  • No card numbers touch us

    Card details go from your browser to Square. We receive a customer identifier, a subscription identifier, and whether a payment succeeded — never a card number.

  • Least-privilege access

    Operator access to your tenant is scoped to your tenant. Administrative actions against your account are written to an append-only audit log that cannot be edited or deleted from the application.

  • Your data leaves with you

    Cancel and your site stays up 30 days, and you can export the entire site as static files. There is no lock-in mechanism and no exit fee.

No third-party tracking pixels. Ever.

There is no Meta pixel, no Google Ads remarketing tag, and no third-party analytics script on your site or on ours. This is not a setting — the product does not ship the capability.

This matters more for medical practices than for most businesses: an advertising pixel on a page about a condition can disclose a health inference about a visitor to an ad network. Health systems have paid substantial settlements over exactly that. The full list of who processes what is on our privacy policy.

Reporting a problem

If you believe you have found a security issue, email jacob@claimcarepro.com and say “security” in the subject. Tell us what you found and how to reproduce it. We will confirm receipt, and we will not pursue anyone who reports a genuine issue in good faith and does not access or alter other people’s data while finding it.

If you have a compliance question we have not answered here, ask before you buy — contact us. A question we cannot answer honestly is a question worth knowing about.