HIPAA's Privacy and Security Rules apply when your website handles protected health information (PHI)—individually identifiable health data. The confusion arises because most optometry websites blend compliant and non-compliant elements.
HIPAA applies to:
- Patient portals where users access exam records, prescriptions, or billing
- Online appointment scheduling that collects name + reason for visit
- Intake forms asking about medical history, medications, or symptoms
- Contact forms where patients describe health concerns
- Secure messaging systems between patients and staff
HIPAA does not apply to:
- General practice information (services, hours, location)
- Educational blog content about eye health
- Staff bios and credentials
- Contact forms collecting only name, email, and phone number
- Online bill pay through a third-party processor (their compliance, not yours)
The distinction matters for SEO because many optimization activities—like adding schema markup, improving page speed, or building local citations—touch only non-PHI content. You can pursue aggressive SEO on your marketing pages while maintaining strict controls on patient-facing portals.
Disclaimer: This is educational content for general guidance. Consult a healthcare compliance attorney for advice specific to your practice.