HIPAA and your information
What this service stores, what it never touches, and the agreement that goes with it. Written so you can read it in five minutes and hand it to a colleague.
| Kept on your site | Not kept here, ever |
|---|---|
| Your practice profile: license, specialties, fees, hours, bio, photo | Session notes, treatment plans, diagnoses |
| Consult requests: name, email, phone, the time they picked, and a short message if they left one | Session scheduling for existing clients |
| Your pages and images | Billing, insurance, claims |
| Search Console data about your site (queries, clicks; nothing about a person) | Anything from your EHR |
A consult request is someone asking to talk. They are not your client yet, and the form does not invite them to describe symptoms: the message field says "anything you'd like me to know before we talk" and nothing more. Even so, it is treated as protected information from the moment it is stored. That is the cautious reading, and it costs nothing to take it.
In December 2022 the Office for Civil Rights said that a tracking pixel on a page that collects health information can be an unauthorized disclosure. A federal court narrowed that guidance in 2024 for ordinary public pages, but left it standing for forms, booking, and anything behind a login. So the rule here is simple: no Meta pixel, no Google Analytics, no chat widget from a third party on any page of your site that has a form on it. Traffic is measured from the server log and from Search Console, which sees searches, not people.
The one third-party script on any form is Cloudflare's spam check, which runs on the same network that already delivers the page and sends no form contents anywhere. If you would rather not have it, say so and I will use the server-side check alone.
Consult bookings are written to your own calendar, not to one I hold. Google covers Calendar under its Workspace business associate agreement; a free Gmail calendar is not covered. Microsoft covers Outlook under its enterprise terms. So the onboarding asks you to connect a Workspace or Microsoft 365 account, which most practices already have for their email, and the booking page will not go live on a personal account.
Because your site is hosted here and consult requests are stored on it, I sign a business associate agreement with every practice at signup. It is short, and it is below in full so there is nothing to request. A signed copy is emailed with your draft link.
Business Associate Agreement
Between the clinician or practice named at signup ("you") and Franz Eric Richers, doing business as Ulric ("Ulric"). Effective on the date accepted at signup. Draft pending attorney review; the reviewed version replaces this text and is sent to every existing client.
- What this covers. Ulric hosts and maintains your website, consult request form, consult booking page, and the dashboard where those requests appear (the Service). In doing so Ulric may store names, contact details, and messages people send you through the Service. Some of that may be protected health information under HIPAA. This agreement covers all of it.
- What Ulric does with it. Only what is needed to run the Service for you. Ulric will not sell it, use it for advertising, or combine it with data from any other practice.
- Safeguards. Encrypted connections everywhere; encrypted backups; access limited to people who need it to support you; no third-party tracking scripts on pages that collect information; server access by key only; a log of administrative access.
- Subcontractors. Ulric uses hosting and email infrastructure providers to run the Service, and only providers that agree in writing to protect the data at least as well as this agreement requires. The list is available on request.
- If something goes wrong. Ulric will tell you within five business days of discovering any unauthorized use or disclosure of protected information, or any security incident affecting it, and will help you meet your own notification duties.
- Your clients' rights. If a client asks you for a copy of, a correction to, or an accounting of disclosures of information Ulric holds, Ulric provides what it has within ten business days of your request.
- Your rules. You will not ask Ulric to use or disclose protected information in a way that would be unlawful if you did it yourself. You are responsible for what you collect through the forms you configure.
- Ending it. Either of us can end this agreement with thirty days' written notice, and it ends when your subscription ends. Within thirty days after that, Ulric returns your data in a standard export and deletes it, including from backups as they cycle out, unless the law requires keeping something, in which case these protections continue for as long as it is kept.
- The law wins. If HIPAA or its regulations change, this agreement is read to comply with them. Nothing here gives anyone other than you and Ulric any rights.
If your compliance consultant or your board wants something stated differently, email [email protected] and I will answer in writing. I would rather change a sentence here than have you guess.