Please read these Terms of Service ("Terms") carefully before using the HIPAA Media website, scanner tool, or any services we offer. By accessing or using our services, you agree to be bound by these Terms. If you do not agree, please do not use our services.
Effective Date: January 1, 2025 | Last Reviewed: January 1, 2025
Acceptance of Terms
By accessing or using HIPAAReport.com (the "Site") or running a scan through our automated platform, you agree to be bound by these Terms of Use ("Terms") and our Privacy Policy. If you do not agree to these Terms, you must not access or use the Site.
Scope and Nature of Scanning Services
HIPAAReport.com provides an automated, publicly accessible website inspection platform designed to evaluate publicly visible security indicators on healthcare and medical websites.
Passive, Read-Only Methodology
All assessments performed by HIPAAReport.com are strictly read-only, non-intrusive, and passive. Our tool evaluates publicly available data, HTTP responses, DNS records, and publicly rendered HTML source code. Our platform does not perform penetration testing, attempt system exploits, log into administrative portals, submit form data, or access back-end infrastructure.
Scope of the 41 Technical Checks
Our scanner evaluates websites across ten specific categories encompassing 41 distinct technical checks:
- SSL / TLS Certificate: Verifies SSL/TLS certificate validity, certificate authority, and expiration thresholds (expiring within 30 days).
- Security Headers: Inspects Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and server software version disclosure (Server, X-Powered-By).
- Transport Security: Verifies plain HTTP-to-HTTPS redirects (301/302/307/308), enforces modern TLS protocol versions (flagging deprecated TLS 1.0/1.1), and checks for unencrypted mixed content.
- Cookie Security: Evaluates Set-Cookie header attributes for Secure, HttpOnly, and SameSite flags.
- Tracking & Analytics Scripts: Identifies public third-party tracking scripts, including Meta Pixel, Google Analytics 4, Google Tag Manager, Hotjar, Microsoft Clarity, LinkedIn Insight Tag, TikTok Pixel, Mixpanel, Segment, Heap Analytics, Intercom, and Mouseflow.
- Contact Email Quality: Checks public contact email addresses for personal or free domain usage (e.g., Gmail, Yahoo, Hotmail) vs. organization domain usage.
- Health Data Safety: Confirms HTTPS enforcement on health pages, identifies protected health information (PHI) keywords within public forms, and checks for simultaneous exposure to third-party trackers on health-related pages.
- Privacy & Legal Documentation: Detects the presence of required policy links and statements, including Privacy Policies, Notices of Privacy Practices (NPP §164.520), Terms of Service, HIPAA Notices, Cookie Policies, Accessibility Statements, ACA Section 1557 Non-Discrimination notices, and State Privacy Rights notices (CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, WMHMD).
- Resource Integrity: Inspects third-party CDN scripts for Subresource Integrity (SRI) attributes.
- Email Authentication (DNS): Queries public DNS records for SPF authorization, DMARC policies (p=none, p=quarantine, p=reject), and DKIM selectors.
Disclaimers and Operational Limitations
No Legal Advice or HIPAA Compliance Guarantee
Scan results reflect a automated, point-in-time snapshot of technical indicators visible on public web pages. A passing score or scan report does NOT constitute formal legal advice, a HIPAA compliance certification, an official regulatory audit, or a guarantee of compliance with federal or state privacy laws.
No Patient Health Information (PHI) Processing
HIPAAReport.com does not collect, process, store, or transmit Patient Health Information (PHI). Users and website visitors should not attempt to submit PHI through HIPAAReport.com.
Third-Party Web Application Firewalls (WAF)
If a target website is protected by bot-mitigation tools or web application firewalls (e.g., Cloudflare in JavaScript challenge mode), certain page-level checks (Categories 2, 4, 5, 6, 7, 8, and 9) may be unable to complete. In such instances, incomplete checks reflect network-level blocking rather than a definitive security vulnerability.
Permitted Use and Restrictions
- Public Inspection: Anyone (including patients, website owners, or administrators) may request a public scan of a domain URL.
- Scan Frequency: Manual user-initiated scans are restricted to once every 24 hours per domain. Automated re-scans are scheduled monthly for stored domains.
- Prohibited Conduct: You agree not to:
- Use automated scripts, bots, or scrapers to flood our scanning engine or launch denial-of-service (DoS) attacks against third-party websites.
- Use scan results for extortion, harassment, tortious interference, or malicious cyber activity.
- Misrepresent HIPAAReport.com scan scores as an official regulatory enforcement action or legal ruling.
Proprietary Rights and Service Integration
The technical scoring algorithms, report layouts, brand assets, and platform contents are the property of HIPAAReport.com. Scanned website information is retained in our secure database to track performance over time and to deliver web enhancement and technical services offered by our parent brand, HIPAA Media.
Limitation of Liability
To the maximum extent permitted by law, HIPAAReport.com, HIPAA Media, and its officers, directors, employees, or agents shall not be liable for any direct, indirect, incidental, consequential, or punitive damages arising out of:
- Errors, omissions, or inaccuracies within automated scan reports.
- Reliance on suggestions or indicators provided by the platform.
- Reputational injury or business disruption arising from public access to scan results.
- Inability of our scanner to inspect sites protected by firewalls or bot mitigations.
Contact Information
For questions regarding these Terms of Service, please contact:
- Email: [email protected]
- Parent Organization: HIPAA Media