DRAFT — attorney review required before publishing. This page has not been reviewed by a lawyer. Statements marked [ATTORNEY] need confirmation before the page goes live.
HIPAA statement from ClinicRankPro, Georgetown, TX
ClinicRankPro is a marketing vendor, not a HIPAA covered entity. In normal service we do not create, receive, maintain or transmit protected health information, so no Business Associate Agreement is needed. If a client wants work that touches patient data, such as call recording review, we sign a BAA first. Never send us patient information.
Reviewed by [OWNER NAME], last reviewed 16 September 2026. This page describes our working practices. It is not legal advice.
Are you a covered entity or a business associate?
Neither, in normal service. Under HIPAA, your practice is the covered entity. A vendor becomes a business associate when it handles protected health information (PHI) on the practice’s behalf. Local SEO, Google Business Profile management, content, citations and reporting need none of it. We need your practice name, address, hours, services, providers and insurance list, and nothing about any patient. [ATTORNEY] Confirm that a marketing vendor with no PHI access is outside the business associate definition, and whether the Texas medical records privacy law, which is generally described as broader than HIPAA, reaches a vendor in our position.
What is PHI, and why do we not need it?
PHI is any information that identifies a person and relates to their health, care or payment for care. A name on an appointment list is PHI. A phone number tied to a visit is PHI. A caller describing symptoms is PHI. Marketing a clinic means describing the clinic, so patients never come into it. Keeping it that way protects you, protects us, and keeps the work simple.
What must clients never send us?
- Forms. Our website forms take business details only. Never enter a patient’s name, condition or appointment.
- Emails and messages. Never email, text or attach anything about a specific patient, including screenshots of your schedule or practice software.
- Call recordings and transcripts. Not without the BAAs described below. Recording stays off by default.
- Review replies. Never ask us to confirm in a reply that someone is a patient or what treatment they had.
- Patient lists. Review-request platforms run under your account; your staff upload contacts. We configure, we never hold the list.
- Photos. No patient photos or before-and-after images without specific written consent held by the practice.
If PHI reaches us by mistake, we delete it and every copy, tell you the same day, and use nothing from it. Nothing that arrives by mistake is entered into our tools or sent to any AI model.
When would a Business Associate Agreement be needed?
Whenever we would create, receive, maintain or transmit PHI for you. We sign an attorney-supplied BAA in that case, before any access is granted, and the vendor involved signs one with your practice too.
| Situation | PHI involved? | BAA with us? |
|---|---|---|
| SEO, profile management, content, citations, reporting | No | No |
| Call tracking, recording and transcription off | Call metadata only | Generally no [ATTORNEY] |
| Call tracking with recording or transcription on | Yes | Yes, plus vendor BAA with the practice |
| Reviewing recordings for lead quality or front-desk coaching | Yes | Yes |
| Online booking or patient portal | Yes | We take no access; vendor BAA with the practice |
| Review replies that stay generic | No | No |
[ATTORNEY] Confirm whether caller phone numbers without recordings count as PHI in this context, and whether a BAA is prudent even with recording off. Our BAA covers permitted uses, minimum necessary access, safeguards, subcontractors, breach reporting, and return or destruction of PHI on termination. More on the compliance page.
How do review replies and marketing copy avoid PHI?
By never confirming a patient relationship. A public review is the patient’s own disclosure. A reply that says “thanks for coming in for your crown, Maria” is the practice’s disclosure, and that is the problem. Our replies thank the reviewer, stay generic, and offer to continue offline. Marketing copy describes services, providers and the practice; it never uses a real patient story unless the practice holds written consent for that exact use. Every reply and every page is approved by you before it goes live.
What is the rule on tracking pixels?
No pixels on any patient-facing page, and consent for analytics. Federal regulators have taken action over tracking pixels on healthcare websites that passed appointment or condition details to advertising platforms. On every site we touch:
- Google Analytics 4 runs on public marketing pages only, behind a consent banner, and is configured to receive no form contents, identifiers or health details.
- No pixel or tag of any kind on patient portal, booking, booking-confirmation or post-login pages.
- Advertising pixels only on marketing pages, only with a privacy notice, and never set to capture form fields or URLs that carry identifiers.
- The setup is documented in your client file so it can be audited.
How are staff trained?
ClinicRankPro is run by one person, [OWNER NAME], who completes HIPAA awareness training every year and keeps the certificate on file. Any contractor who could see a client account completes the same training before access is granted and signs a confidentiality agreement. Training records are available to clients on request. [ATTORNEY] Confirm whether documented training is required before we sign a BAA.
What happens if there is a breach?
We tell you fast. If we ever learn of unauthorized access to PHI in our possession under a BAA, or to any client account we manage, we notify the practice within [N] days of discovery, with what happened, what was affected, and what we have done. We contain the problem first, cooperate with your own notification duties, and write a post-mortem. [ATTORNEY] Set the notification window to match HIPAA breach rules and the BAA text. Security measures are on the Security page.
How do you contact us?
Email [EMAIL], write to [LEGAL ENTITY NAME], [BUSINESS ADDRESS], Georgetown, Texas, or use the contact page. Related pages: Privacy Policy, California Privacy Notice, AI Use Policy, Terms and Conditions.
Frequently asked questions
Do we need a BAA to work with you?
Usually not, because standard marketing work never touches patient information. You need one if you want us to review call recordings or transcripts, or to access any system that holds patient data. In that case we sign an attorney-supplied BAA before any access is granted.
I accidentally emailed you a patient’s name. What happens?
We delete the email and any copy, tell you the same day, and do not use the information for anything. Nothing about it reaches our tools or any AI model. If it happens repeatedly we will ask for a short call to fix the process.
Can you reply to a review that mentions a patient’s treatment?
Yes, without confirming anything. The patient can say what they like about their own care; our reply thanks them, stays generic, and offers to help offline. We never confirm that the reviewer is a patient or mention a procedure, date or provider.
Is Google Analytics on my website a HIPAA problem?
Not on public marketing pages, when it is configured to receive no form contents, identifiers or health details, and only after consent. It must not run on booking, portal or post-login pages. Google does not sign a BAA for Analytics, which is why we keep it away from anything patient-facing.
Do you handle call recordings?
Only with two signed BAAs: one between your practice and the call-tracking vendor, and one between your practice and us. Until both are in place, recording and transcription stay off at the account level. Reports carry call counts, never recordings.
What HIPAA training do you have?
[OWNER NAME] completes HIPAA awareness training every year and keeps the certificate on file. Any contractor who could see client accounts completes the same training before access is granted. Training records are available to clients on request.