Compliance for clinics and care providers online

The requirements that shape a healthcare website: health data protection, professional advertising rules, accessibility, and secure patient communication.

4 minread 864words last updated

The short answer

A healthcare website carries four layers of requirement beyond an ordinary business site. Health data protection: anything about a person’s health is special category data, needing a specific condition for processing, stronger security, strict minimisation and short retention, with a data protection impact assessment where Article 35 requires one: a likely high risk, or one of the cases it lists, including special category data processed on a large scale, or an operation on your supervisory authority’s own list. Recital 91 explains that processing by an individual health professional is not large-scale on that basis alone. Professional rules: health professions have their own restrictions on advertising, claims, comparisons and testimonials, set by professional bodies and national law, and they vary by profession and country. Secure communication: a website may become a channel for patients to send clinical information, and either it is designed for that with appropriate security and handling, or it warns against it and defines what happens when patients do it anyway. And accessibility, which matters more than average because the audience includes a higher proportion of people with impairments. On top of those sit the general obligations: company and professional details, privacy statement, cookie consent, and the ordinary security discipline. The practical result is that a clinic site needs more care in intake, communication and claims than in anything else.

The four layers

LayerWhat it requiresWhere it bites
Health dataSpecific condition for processing; impact assessment where required; minimisation; strong security; short retention; restricted accessIntake forms, appointment reasons, messages, reviews
Professional rulesRestrictions on advertising, claims, comparisons, testimonials; professional details publishedTreatment pages, before-and-after images, reviews
Secure communicationEncrypted, access-controlled channels; patient portal rather than email for clinical contentContact forms, email, chat
AccessibilityLevel AA in practice; larger share of users with impairmentsForms, contrast, keyboard, screen reader
GeneralCompany and professional identification, privacy, cookies, securityFooter, policies, banner

Building a clinic website responsibly

  1. Decide what the site collects and keep health data out of general channels entirely.
  2. Build intake properly if you need it: secure, writing into the practice system, minimal fields, clear information, defined retention.
  3. Warn on the general contact form not to send health information, and define how such messages are handled when they arrive.
  4. Check the professional rules for your profession before publishing treatment claims, comparisons or testimonials.
  5. Publish professional details: registrations, supervisory body, complaints procedure.
  6. Use a patient portal for anything clinical rather than email.
  7. Check whether an impact assessment is required for intake and any new data flow, and do it where it is.
  8. Meet level AA and test with a screen reader and a keyboard.
  9. Apply the security discipline: second factors, access control, logging, retention, processor agreements.
  10. Review annually with your data protection adviser and against professional guidance.

What patients notice

Booking that works, information that is clear, and the sense that their information is handled carefully. A site that asks for the minimum, explains what happens to it, offers a secure route for anything sensitive and states the practice’s registrations and complaints procedure communicates competence before any treatment page does. Compliance and trust point the same way here more strongly than in most sectors.

What this means for you

A healthcare website must handle health data with a specific condition, minimisation, strong security and short retention, follow the professional rules on claims and testimonials, provide secure channels for clinical communication rather than email, and meet accessibility at level AA. Keep health data out of general forms and inboxes, publish professional details, do the impact assessments the rules require and review annually. This is general information rather than legal advice; your professional body and data protection adviser govern your specific position.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Can we take symptom information through a web form?

Only in a form designed for it: a secure intake that writes into the practice system, with a specific condition for processing health data, clear information to the patient, restricted access, defined retention and no copies in general email. A general contact form is the wrong channel, and the risk is that patients volunteer health details into it anyway, which is why the form should warn against it and the handling of such messages should be defined.

What rules apply to what we say on the site?

Beyond general advertising and unfair commercial practices rules, health professions carry their own restrictions on advertising, claims, comparisons, testimonials and the use of patient material, set by professional bodies and national law and varying by profession. Claims about treatment outcomes are the usual pressure point. Check your professional body's guidance before publishing marketing material about treatments.

Can we publish patient reviews and photographs?

Only with valid, specific, freely given consent, documented, and with an easy way to withdraw it, and even then professional rules may restrict testimonials for your profession. Before-and-after images and patient stories are health data about identifiable people and carry both the data protection weight and the professional restrictions. Many practices conclude the risk is not worth the marketing benefit.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679, Articles 9 and 35, and recital 91 (accessed 2026-09-14)
  2. Autoriteit Persoonsgegevens: Health data (accessed 2026-09-12)