Is Squarespace HIPAA-compliant? What therapists should know about website forms and PHI
Estimated reading time: 7 minutes.
TL;DR:
- Prospective clients share sensitive health information through website contact forms, even when you don't ask for it. That means HIPAA considerations apply to your website forms from the very first message someone sends you.
- Is Squarespace HIPAA-compliant? Not for its website platform. Acuity Scheduling is the only Squarespace product covered by a business associate agreement (BAA).
- The important question is whether information submitted through your website could contain PHI and whether it's being handled securely.
- Limiting your form to name and email, or adding a disclaimer, doesn't remove your obligations.
- You don't have to leave Squarespace. You need a HIPAA-compliant form that works alongside it.
Your Squarespace website looks great. Your contact form is simple: name, email, and a message field. You've read that as long as you're not asking health questions on the form, you should be fine.
Then someone fills it out: "I recently lost my mother, and I'm looking for a therapist who works with grief."
You didn't ask a health question. But you're now holding a name, an email address, and information tied to a future healthcare need, all submitted through a contact form that wasn't designed to handle sensitive health information.
"Providers often ask whether their website is HIPAA-compliant. But the compliance question really starts with the contact form. If someone can submit identifiable health information through your site, the safeguards around that form matter."
Steven O. Youngman, VP of Legal and Compliance, Hushmail
Table of contents
Is Squarespace HIPAA-compliant?
No, not for its core services.
Squarespace does not sign a BAA for its website hosting, built-in contact forms, email campaigns, or other standard website tools. If you're collecting information through a Squarespace form block, that form isn't covered by a BAA, as Squarespace wasn't designed to meet HIPAA requirements.
Squarespace's own help center is straightforward about this. They state that providers should not maintain or transmit protected health information (PHI) through Squarespace outside of Acuity Scheduling.
Here's the good news: this doesn't mean you need to leave Squarespace. It's a solid choice for a professional practice website. The issue isn't the website itself. It's what happens when someone submits information through a built-in Squarespace form.
Why your contact form matters more than you think
When most providers hear that Squarespace isn't HIPAA-compliant, they focus on the website. But the consideration that matters most is the form, and specifically what gets submitted through it.
Two things make website contact forms a HIPAA concern.
1. Prospective clients share health information whether or not you ask for it.
A contact form on a therapist's website can collect PHI even before someone explains why they're reaching out. When someone contacts a healthcare provider through a practice website, the information they submit may become protected health information because it identifies them in connection with seeking healthcare services. If they also include details about their health or the care they're seeking, the HIPAA implications become even clearer.
And if your form includes a message field, most people will share more: what they're going through, what kind of help they need, why now. That's exactly what you want them to feel comfortable doing. In the end, what matters is whether the form itself has the right safeguards in place to be HIPAA compliant.
HIPAA defines protected health information (PHI) as individually identifiable health information that relates to an individual's past, present, or future physical or mental health or condition, the provision of healthcare, or payment for healthcare. The word "future" is doing a lot of heavy lifting here. It means HIPAA can apply before someone ever becomes your client.
👉 For a deeper look, see our posts on what counts as PHI and whether email from a prospective client is considered PHI under HIPAA.
2. A standard contact form doesn't have the safeguards HIPAA requires.
A built-in Squarespace form typically sends submissions to your email inbox or stores them in your Squarespace dashboard. If a prospective client submits PHI through that form, it's handled by a service that doesn't provide the HIPAA safeguards required of healthcare providers, such as a BAA, appropriate security controls, and clear access management.
What does HIPAA require for website forms?
HIPAA doesn't tell you which tools to use. It requires reasonable safeguards. For a contact form on your practice website, that means a few things need to be in place.
- A BAA. If a company receives and stores form submissions that could contain PHI, it's acting as a business associate. You need a Business Associate Agreement in place before PHI comes through that form.
- Encryption. PHI must be protected during transmission and in how it's stored and accessed.
- Access controls. You must be able to control who can view form submissions, and the system must support authentication.
- A process for what comes through. When a prospective client submits sensitive information, how do you follow up? Moving the conversation to a secure channel is a practical first step.
⚠️ One thing worth noting: your Squarespace website already includes SSL (HTTPS), which protects data traveling between a visitor's browser and the server. But SSL doesn't cover what happens after the form is submitted. It doesn't determine where the data is stored, who can access it, or whether the vendor handling it has signed a BAA. Those are the gaps that matter.
These gaps aren't unique to Squarespace. The same considerations apply to any form tool that isn't designed for HIPAA, including Google Forms.
What about limiting your form fields or adding a disclaimer?
If you've looked into this before, you've probably come across advice suggesting that the fix is simple: keep your contact form minimal, don't include health-related fields, and maybe add a line that says "Please do not submit personal health information through this form."
It sounds reasonable. But it doesn't hold up.
Limiting your form fields doesn't change what the form is collecting. Even a form with only two fields, name and email, is collecting PHI when it sits on a healthcare provider's website. The person submitting it is identifying themselves in connection with a future healthcare need. If the form also has a message field, they'll almost certainly share more. But the form is already handling PHI before they type a single word in that box.
A disclaimer doesn't change your obligations. A name and email submitted through a therapist's website is already PHI. Adding a line asking people not to share health information doesn't change that, and it doesn't change what happens if they do.
The issue isn't what you're asking for. It's whether the form has appropriate safeguards. A BAA with the form vendor. Encryption for submissions. Access controls. Those are what matter, not the number of fields on the form or the fine print underneath it.
You don't have to leave Squarespace
If you've made it this far, you might be wondering whether you need to start over with a new website. You don't.
Squarespace is a good website builder. The design tools are intuitive, the templates look polished, and your site works well on desktop and mobile. None of that changes due to HIPAA considerations regarding contact forms. You've already done the hard part of building a professional online presence. This is about one piece of it.
The fix is more targeted than most providers expect. You keep your Squarespace website exactly as it is. You replace the built-in contact form with a secure form from a provider that signs a BAA and encrypts submissions. Most solutions provide an embed code that you can drop into a Squarespace code block. The form looks and feels like part of your site. Visitors won't notice a difference. But the information they submit goes through a HIPAA-compliant service rather than Squarespace's built-in form handler.
You don't need a web developer, and you don't need to redesign anything. For most providers, this is a single-page update that takes a few minutes. If you'd like to see what that looks like, we have a step-by-step walkthrough on adding a HIPAA-compliant contact form to Squarespace.
And it's not just for your contact form. The same approach works for intake forms, questionnaires, insurance information requests, or anything else where a client or prospective client might share PHI. Once a secure form is in place, you have a channel that works across your website.
For a broader look at how this works across other platforms, see our posts on securing your Google Business Profile, HIPAA-compliant forms, and our form builders comparison.
💡 Hushmail tip: Hush™ Secure Forms can be embedded directly on your Squarespace site. Every Hushmail for Healthcare plan includes a signed BAA, and form submissions are encrypted. When someone fills out your form, you can continue the conversation securely through Hushmail, and they don't need a Hushmail account to respond. For more on how secure forms work, see our forms FAQ.
Your next step
Look at the contact form on your practice website. Could a prospective client submit information that connects them to a healthcare need? For most therapy and healthcare practice websites, the answer is yes.
If it is, check whether that form is covered by appropriate safeguards. A good starting point: confirm whether your form vendor has signed a BAA with you. If not, that's the gap to close first.
For a broader look at where your practice stands, our HIPAA compliance checklist can help you see the full picture.
Ready to close that gap? See how to add a secure, HIPAA-compliant contact form to your Squarespace website.
"Your HIPAA obligations don't start when someone signs an intake form. They start when identifiable health information reaches you. For most practices, that includes what comes through your website."
Steven O. Youngman, VP of Legal and Compliance, Hushmail
Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.
Overwhelmed by the business side of private practice? In this guide, therapists share 20 ways they've offloaded what drains them, to create more space for the work they love.