HIPAA Compliant Website Builder: What Actually Qualifies
Squarespace, Wix, GoDaddy and WordPress all host practice websites. Almost none of them will sign a BAA. What that means, and what the alternatives actually are.
Search for a HIPAA compliant website builder and you will find a lot of pages that do not answer the question. Here is the short version, then the reasoning.
Almost no mainstream website builder will sign a Business Associate Agreement. Not Squarespace, not Wix, not GoDaddy's builder, not Weebly. WordPress is not a company and cannot sign anything, so the answer there depends entirely on who hosts it.
That does not make them illegal to use. It makes them unsuitable for one specific job.
The distinction that decides everything
A website builder becomes a HIPAA problem at exactly one moment: when a patient types something into it.
A brochure site with your hours, your services and a phone number handles no patient information. Build that anywhere you like. There is no rule against a dentist using Squarespace.
The moment you add a contact form that asks what the appointment is regarding, an intake form, a "describe your symptoms" box, or a scheduling widget that captures a reason for visiting, the platform is now receiving protected health information on your behalf. That is the definition of a business associate, and it needs an agreement.
So the real question is not "is this builder compliant." It is "does patient information ever touch it."
Where each one stands
We scanned 4,601 independent practice websites in July 2026. WordPress was the most common platform at 32.5%, followed by Wix at 6.3%, GoDaddy's builder at 6.1%, Squarespace at 5.2% and Weebly at 2.0%. The rest either could not be identified or were custom builds.
Squarespace does not sign BAAs. Their forms are not built for patient data, and the company has not positioned the product for it.
Wix does not sign BAAs for the general product.
GoDaddy will not sign for hosting, their WordPress product, or their forms. We have written about what that means for practices on GoDaddy in more detail, because it is the most common single answer we see.
Weebly does not sign.
WordPress is software rather than a service, so nobody signs for WordPress itself. What matters is the host underneath it and every plugin in the form path. A WordPress site on HIPAA-eligible hosting with a covered form tool is entirely workable. The same site on ordinary shared hosting is not, and the site looks identical either way. In our scan, 39.0% of practices were on a host whose published position is that it will not sign.
What the real options are
Keep the builder, move the forms. The cheapest fix and a genuinely correct one. Your marketing site stays where it is. Every field that collects patient information moves to a service that will sign, and the form is linked or embedded rather than native. The work is typically an afternoon.
What that afternoon does not buy you is a permanent state, and this is the part nobody mentions when they recommend it. You now own a chain: a builder, a form vendor, a host, and whoever touches the page. Each of those can change without telling you. The form vendor ships a feature that is not in the BAA. Your marketing agency adds a conversion tag to the appointment page, which is exactly where a competent agency puts one. Somebody builds a new location page and copies the old native form onto it, because the old form is what was there to copy. None of those is a mistake. All of them undo the afternoon.
Move to hosting that will sign. More work, more control, and it collapses two links of the chain into one. The right answer if your site does more than brochure duty. It has the same maintenance property as the first option: correct on the day it is done, and only as durable as whoever is watching it.
Have one company hold the whole chain, and keep holding it. The site, the hosting, the form path, the agreements and the pages around them as a single relationship, rechecked rather than remembered. This is what we built the Managed Plan to be, and it is not a more expensive version of option one. It is the version where the answer is still true next year, because somebody is being paid to look.
Of the 4,601 practice sites we scanned, 88.0% produced at least one finding and 10.7% came back with nothing to report. Almost none of them launched broken. That figure is not evidence that practice owners are careless. It is evidence of what happens to a correct configuration that nobody is maintaining.
What is not an option is a builder with an ordinary form on it and a hope that nobody asks. That configuration is the single most common thing we find.
Two things to ignore while shopping
"HIPAA certified" badges. No such certification exists, from any agency. HHS declined to create one on the record in 2003 and has never reversed that. The badge is a self-assessment.
Encryption claims on their own. Every serious platform encrypts traffic. That is table stakes and says nothing about whether they will sign for what they receive, which is the actual question.
The one question to lead with
Before comparing features, ask each vendor: will you sign a BAA for my account, on my current plan, covering the specific feature I intend to use for patient forms?
That question ends most of these conversations in one email, which is the point.
And once you have the answer, ask yourself the follow-up: who is going to ask it again next year, of every vendor in the chain, and how would you find out if one of them changed their answer.
If nobody, then the honest recommendation is not a different builder. It is our Managed Plan, where the whole path is one accountable relationship and gets rechecked on a schedule rather than when something goes wrong.
If you want to know where your current site stands before deciding either way, the scan reports which of your existing vendors will sign, and what is loading on the pages where your patients type.