What a Website Audit Really Finds: The Accessibility, Privacy and Security Gaps Hiding on Practice Websites
A practice website can look polished and still contain serious accessibility, privacy, security and trust gaps.
That is why a real website audit goes far beyond checking whether the homepage loads. It examines how people use your website, what third-party tools collect, whether forms handle sensitive information appropriately, and whether important technical details have been neglected.
For doctors, dentists, chiropractors, medical specialists, attorneys, law firms and other service businesses, these gaps can affect more than compliance. They can reduce inquiries, create privacy concerns, frustrate visitors, weaken trust and make your business appear less current than it really is.
Keep reading to see what a thorough audit uncovers and how to turn those findings into a practical improvement plan.
1. Accessibility barriers hidden behind a professional design
A website may use attractive colors, modern photography and polished branding while remaining difficult or impossible for some visitors to use.
A meaningful accessibility review evaluates the site against recognized standards such as WCAG 2.1 Level AA and WCAG 2.2. Automated tools can help identify certain issues, but manual testing is essential because many barriers only appear when a person navigates with a keyboard or screen reader.
A website audit commonly finds:
- Images with missing, vague or inaccurate alt text
- Text and buttons with insufficient color contrast
- Forms that do not provide properly associated labels
- Error messages that screen readers cannot understand
- Menus, pop-ups, calendars and booking tools that cannot be operated by keyboard
- Focus indicators that are missing or difficult to see
- Content that becomes unusable when visitors zoom in or use a mobile device
- Decorative elements incorrectly announced by assistive technology
These are not merely design imperfections. If a prospective patient cannot complete an appointment form or a prospective client cannot reach an attorney’s intake page, your website is creating a direct business barrier.
Put some thought into your highest-value journeys. Test the homepage, contact page, appointment flow, intake form, navigation menu and any payment or scheduling feature. These are the places where accessibility problems can directly prevent new business.
2. Cookie consent and state privacy opt-out gaps
Privacy reviews now require more than checking whether a website has a privacy policy.
As of 2026, approximately 20 states are commonly counted as having comprehensive consumer privacy laws in effect, although the exact number can vary depending on how particular statutes are classified. These laws generally address consumer rights involving personal information, targeted advertising, data sharing and opt-out requests.
A website audit maps what happens when someone visits your site. It checks whether analytics, advertising pixels, chat tools, social media scripts and other technologies load before a visitor has made an appropriate consent choice.
Common findings include:
- Analytics or marketing cookies loading immediately
- Advertising pixels firing before consent
- Cookie banners that offer “Accept” prominently but hide rejection options
- No simple method to change or withdraw consent
- Privacy notices that do not match the tools actually installed
- Missing or unclear “Do Not Sell or Share My Personal Information” controls
- Failure to recognize applicable universal opt-out signals, where required
- Third-party scripts collecting information that the business does not realize it is sharing
Your website’s privacy policy should describe actual data practices, not an idealized version of them. If your site uses a chat widget, booking platform, advertising pixel, call-tracking tool or embedded form, the audit should identify that vendor and consider what information may be transmitted.
Use our own WebSwan Digital Solutions privacy policy as a starting point for reviewing the types of disclosures your website may need. Then take the next step: compare the policy against the website’s real scripts and data flows.
For a self-serve starting point, use the State Compliance Penalty Checker and WebSwan Insights Hub to review state-specific resources. The tool is educational and does not replace advice from qualified privacy counsel.
3. HIPAA intake form and tracking risks for medical practices
Medical practices need to examine every website feature that can collect health-related information.
A contact form may ask for a name, phone number, insurance information, reason for visit, symptoms or appointment details. A scheduling platform may collect the same information through an embedded tool. A chat widget may invite visitors to describe a medical concern.
The important question is not only whether the form is encrypted. You also need to know:
- Where the submission goes
- Which vendors can access it
- How the information is stored
- Whether the vendor may use it for another purpose
- Whether a Business Associate Agreement, or BAA, is appropriate and actually in place
The U.S. Department of Health and Human Services guidance on online tracking technologies explains why tracking technologies deserve special attention on healthcare websites. Note that in June 2024 a federal court in American Hospital Association v. Becerra vacated part of that guidance as it applied to certain tracking on public, unauthenticated web pages, and HHS later withdrew its appeal. Tracking on patient portals, booking flows and other pages where people submit their own information still deserves careful review.
An audit looks closely at Meta Pixel, Google tags, session-recording tools, heat maps, chat tools and analytics scripts placed on:
- Patient portals
- Appointment-booking pages
- Intake forms
- Symptom checkers
- Payment and refill workflows
- Treatment-specific pages, especially where visitors can submit information
A tracker can create a problem when it receives identifiable information connected to someone seeking or receiving care. The appropriate response may involve removing the tracker, changing its configuration, using a suitable vendor, documenting the data flow or obtaining qualified compliance guidance.
Do not assume a tool is safe because it is popular. Review what the tool receives, what the vendor does with that information, and whether the vendor’s terms support your practice’s obligations.
4. HIPAA-safer patient intake paths vs. general web forms
For medical practices, there is a major difference between a standard website contact form and a dedicated, HIPAA-safer intake path.
A general website form often sends submissions through a website plugin, form builder, CRM, email service, chat tool or marketing platform that was built for ordinary business inquiries. That may be acceptable for simple non-medical contact requests in some situations, but it is not the same thing as collecting patient information through a dedicated healthcare workflow.
A HIPAA-safer intake path is typically routed into the practice’s own secure patient system or portal instead of a general website form. In many cases, that means using a clear button such as Patient Portal, Complete Intake Forms or Request an Appointment Securely that sends the visitor into the practice’s authorized platform, such as Epic MyChart, athenahealth, Dentrix, Jane App, SimplePractice or a similar practice-managed system.
That pattern matters because a privacy notice or a consent checkbox by itself does not make a form HIPAA compliant. Do not assume disclosure equals protection. A checkbox that says “I agree” does not change where data travels, which vendor receives it, whether the vendor signs a BAA, or how that information is later used or stored.
An audit should ask practical questions such as:
- Is the website collecting PHI through a normal contact form?
- Does the form invite symptoms, treatment details, insurance data or other sensitive information?
- Are submissions being emailed in plain business workflows?
- Is the data entering a CRM, marketing automation tool or help desk platform with no healthcare-specific safeguards?
- Is there an actual BAA with each vendor that touches the information?
- Would the safer design be to remove the medical-detail field and route the visitor to a secure portal instead?
This is also where tracking risk increases. If a patient enters sensitive information on a page that also runs analytics tags, advertising pixels, session recorders or embedded scripts, that page may transmit data to third parties the practice never intended to involve.
HHS specifically discusses HIPAA obligations around online tracking technologies, which is why booking flows, intake pages, refill requests, portal access points and similar healthcare journeys deserve close review. The concern is not just the visible form itself. The concern is the full path the visitor takes and every technology loaded along the way.
A safer website pattern for many practices is straightforward:
- Use a simple public contact form for ordinary business questions only
- Avoid inviting visitors to submit diagnoses, symptoms or detailed treatment information through that general form
- Clearly direct patients to a secure portal button for intake, records, booking, billing or clinical communication
- Review every vendor involved in those flows, including whether a BAA is appropriate and in place
- Reduce or remove third-party tracking on sensitive healthcare pages where risk is higher
This is a risk-based review, not a fear pitch. We inform practices about where data may be exposed, where third-party tools may create avoidable privacy issues, and where a more secure routing pattern may better support patient trust. That does not mean every website is doing something unlawful, and this is not legal advice. It means your intake path deserves a closer look.
5. GPC signals and privacy opt-out controls visitors should not have to hunt for
Cookie banners are only part of the privacy picture.
Global Privacy Control, or GPC, is a browser-level signal that lets a visitor tell every website they visit: “do not sell or share my personal information.” Browsers and tools such as Brave, DuckDuckGo and Firefox can send that signal automatically on the visitor’s behalf, either by default or once the visitor turns it on.
That matters because GPC helps protect privacy without forcing people to hunt for an opt-out link on every single site they visit. Instead of making someone scroll to the footer, find the correct link and repeat the same request over and over, the browser can communicate that preference up front.
Where state privacy opt-out rights apply, GPC may be recognized as a valid opt-out mechanism under laws such as the CCPA/CPRA and other state privacy laws. It works alongside a cookie consent banner rather than replacing it. In other words, keep your banner, but do not stop there. Your website still needs a practical way to recognize and honor applicable universal opt-out signals.
This ties directly back to the cookie consent and state privacy review in Section 2. An audit should confirm:
- Whether the website can detect a GPC signal
- Whether ad-tech or sharing-related tags are adjusted when that signal is present
- Whether the privacy notice explains opt-out choices accurately
- Whether the “Do Not Sell or Share” workflow matches what the site actually does
- Whether the site’s consent platform and tag configuration work together instead of contradicting each other
For healthcare practices, law firms and other service businesses, respecting GPC is not just a technical detail. It shows that your website is prepared to honor privacy preferences in a modern, user-friendly way. Ignoring that signal where opt-out rights apply can create unnecessary compliance and trust risk.
If you want a quick educational starting point for state-specific privacy issues, the State Compliance Penalty Checker and WebSwan Insights Hub can fit naturally into your review process alongside a full audit.
6. Attorney intake, confidentiality and communication concerns
Law firm websites have their own risk areas.
An intake form can encourage a visitor to submit highly detailed information before the firm has checked conflicts or agreed to representation. The form may also lack a clear statement that submitting information does not automatically create an attorney-client relationship.
A website audit checks for:
- Prompts that invite sensitive case details through ordinary forms
- Missing no-attorney-client-relationship disclaimers
- Missing instructions not to submit urgent or confidential information
- Form submissions routed to advertising or marketing platforms
- Unclear email-forwarding and CRM storage practices
- Phone and text consent language that is incomplete or bundled into general terms
- No practical method for recording or honoring communication opt-outs
If a firm uses automated or marketing calls and texts, its web forms should include clear, optional and properly documented consent language. The Telephone Consumer Protection Act’s prior express written consent requirements still apply. The FCC’s separate “one-to-one” consent rule was vacated by the U.S. Court of Appeals for the Eleventh Circuit in January 2025, so have qualified counsel confirm the current requirements for your practice and jurisdiction before finalizing your language.
This is not about making your website sound intimidating. It is about setting accurate expectations before a visitor submits information.
7. Technical problems that quietly reduce trust
Some audit findings look small but have a large effect on credibility.
A website audit checks for:
- Broken internal and external links
- Missing redirects
- Expired or incorrectly configured SSL certificates
- Mixed-content warnings
- Outdated copyright dates and stale footers
- Forms that fail silently
- Slow or unstable pages
- Missing updates to plugins, themes or integrations
- Inconsistent contact information
- Duplicate or poorly structured page titles
Visitors notice when a link leads nowhere, a security warning appears, or a footer says the business has not updated its website in years. Search engines and accessibility tools also rely on a technically sound, clearly structured site.
These issues can weaken trust, reduce conversions, interfere with crawling and make your practice look less reliable than it is. Fix the basics before investing more money in advertising. Sending more traffic to a website that fails visitors is not a growth strategy.
8. The four-step path from hidden gaps to a healthier website
A website audit should produce more than a long list of problems. It should give you a practical path forward.
1. Request the audit.
Start with a complimentary website analysis and ADA website compliance audit. Share your website address and identify the pages that matter most, such as booking, intake, contact and payment pages.
2. We find the leaks.
Our review examines accessibility barriers, privacy controls, cookies, forms, third-party scripts, tracking tools, security basics, broken links and visible trust issues.
3. You receive a prioritized fix plan.
Not every issue has the same urgency. Your report should separate high-priority data and access concerns from routine improvements, then explain the business reason behind each recommendation.
4. We fix and monitor.
WebSwan Digital Solutions can help implement appropriate website improvements, improve form usability, update privacy controls, resolve technical issues and monitor the site over time. Ongoing monitoring matters because websites change whenever a plugin, advertising tool, booking system or third-party script is added.
Request your complimentary website audit
Your website should make it easier for people to contact your practice or firm, not create hidden obstacles.
Request your complimentary website audit
WebSwan Digital Solutions serves businesses nationwide, including doctors, dentists, chiropractors, medical specialists, attorneys, law firms and small service businesses. We inform you about what your website reveals, prioritize the practical risks and help you create a clearer path to improvement, without fear-based claims or one-size-fits-all recommendations.
This article is educational information, not legal, medical, privacy or regulatory advice. Requirements vary by business model, state, industry, technology stack and specific data practices. Consult qualified counsel for legal or compliance decisions.