Shared Hosting
The plan type a solo physician site belongs on, and what the higher tiers actually change.
Read about shared hosting
A doctor's website is a small, quiet thing. A few pages, a bio, directions, insurance accepted. Web hosting for doctors is just as ordinary until somebody adds a contact form with a box that says "how can we help?", and a patient types their symptoms into it. That one box is where hosting stops being a routine purchase and starts being a decision you have to think about.
Nothing else on a physician website is unusual. Your hours are hours. Your bio is text. Your directions are a map. All of that sits on a server exactly the same way a plumber's website does, and it needs exactly the same things from hosting.
The exception is the contact form, and the reason is worth stating plainly. The moment a patient types a symptom, a medication, a diagnosis or the reason they want an appointment into a box on your website, that submission is carrying protected health information. It was health information before it left their phone. Nothing about being on a website makes it ordinary.
The failure that follows is almost always the same shape, and it is not dramatic. The form emails its contents to whoever set the site up. That email lands, in plain readable text, in a personal free mailbox. The patient has just described their symptoms into a chain of systems nobody has any agreement with, and everyone involved thinks of it as "the contact form".
This is a general description of a common problem, not legal advice. Where the line falls for your practice is a question for your own compliance adviser or attorney, and it is worth an hour of their time.
If your form still invites patients to describe symptoms, we can narrow it to a name, a number and a good time to call, and put the warning line above the submit button.
There are two ways to respond to this. One is to buy something. The other is to stop collecting the information in the first place. The second is cheaper, faster and holds up better, and it is the one we recommend to nearly every individual clinician.
Ask for a name and a callback number. Nothing clinical. No free-text box inviting a story. The form's only job is to say "a person would like you to ring them back", and a name and a number does that completely.
A patient who wants to describe a problem will describe it to you on the call, in a channel you already handle correctly. You have not lost anything. You have moved a sensitive conversation out of your inbox and back into the practice.
The alternative is a secure intake product: an encrypted form service that will sign an agreement with you and hold the submissions inside their system rather than emailing them out. Those exist and they are legitimate. They are also a subscription, a login and one more vendor, and for a solo clinician who mostly needs people to ring the office, that is a lot of machinery to avoid asking for a phone number.
This one saves people money, so it is worth being blunt about. If your practice has a patient portal, it belongs to your EHR vendor. It runs on their systems, under their agreements, behind their login. Your website's only relationship to it is a link.
That link is doing more work than it looks like. It means your website never holds a patient record, never authenticates a patient, and never becomes the place where clinical data lives. Your site stays what it should be: a public brochure with a phone number and a door to somebody else's secure system.
What that means for hosting is straightforward. You are hosting a handful of static pages. That is one of the lightest things you can put on a server, and shared hosting is the right product for it. If somebody is quoting you a large plan because the site is "medical", ask them which specific thing on the site requires it.
If a vendor offers to build a portal into your website itself, ask what happens to the records in it if you leave. A portal that lives inside your marketing site is a liability you now maintain personally.
The short version: a business associate agreement is what you sign with a vendor who will handle patient information on your behalf. It is the paperwork that makes them responsible too. The question is not whether they are a big company. It is whether patient information touches their system.
So the useful exercise is not shopping for vendors who advertise compliance. It is drawing the map of where a patient's words actually travel after they hit submit, and then shortening that map until the question mostly stops applying.
The contact form is the obvious one. Also count appointment request forms, prescription refill boxes, new patient paperwork you accept as an email attachment, and any chat widget. Each one is a place a patient can type something clinical.
Does it email somebody? Which mailbox, on whose system? Does it also save a copy into the website's own database or a plugin's log table? A lot of form plugins quietly keep every submission forever, which is a second copy nobody remembers exists.
Turn off submission logging you are not using. Remove the free-text box. Delete the old form that has been sitting on a page you forgot about since 2019. Most of this is deletion, and deletion is free.
Whatever is still standing after step three is your actual vendor list, and it is usually much shorter than you feared. Take that list to your compliance adviser and ask which of them you need an agreement with. Do not guess, and do not let a sales page decide for you.
Where email is concerned, the same logic applies. If staff will genuinely discuss patients by email, that mailbox needs to be on a service that will enter into an agreement with you, and free consumer webmail is not it. If the mailbox is only for referrals, vendors and the drug rep, ordinary business email at your own domain is fine and far better than a Gmail address on your business cards either way.
Send us the site and we will follow one form submission from the button to whichever mailbox and plugin log it ends up in, then delete the copies nobody needs. If it is already clean, we will tell you that.
Set the privacy question aside for a moment, because two ordinary things go wrong on physician sites more often than anything exotic.
A browser warning on a doctor's website reads worse than it does anywhere else. People are already nervous about entering their name. An expired SSL certificate turns that into a full screen warning, and it happens for the dullest reason in the world: nobody was watching the renewal. Know whether yours renews automatically, and know whose email address the reminder goes to.
Physicians move practices, change hospital affiliations and get married. The website tends to lag by years. The bio still lists a hospital you left, the address is the old suite number, and the domain renewal notice goes to a university address you lost access to when you finished residency. That last one is how sites disappear, so put your domain on a mailbox you will still hold in five years and check the expiry date now rather than the week it lapses.
Neither of these is a hosting feature. They are both somebody remembering, and on a solo practice that somebody has patients booked all day. Deciding in advance who it is beats hoping.
This page is written for the individual clinician. One name on the sign, a small site, and a website that is essentially an introduction and a phone number. If that is you, the advice above is close to complete and the entry plan is genuinely enough.
It stops fitting once other people are involved. If you are buying for a practice with several providers, staff mailboxes, shared calendars and somebody at a front desk handling intake all day, your problem is not really the website. It is who has access to what, and how a mailbox is set up when the person using it leaves. That is covered on the medical practices page, which is about running the systems a staffed office depends on rather than about a single doctor's public page.
There is a third case in between. If you are a therapist, a chiropractor, a nurse practitioner or any clinician whose site takes bookings and intake paperwork directly rather than through an EHR portal, the healthcare providers page is the closer fit. The difference is that this page's main advice is to stop collecting information on the website, and that page assumes you have to collect it and deals with how.
Where spending more is fair: you accept intake documents through the site, you run several locations or providers on one site, or the site carries anything a patient logs into. Those are real reasons. Being a doctor, on its own, is not one.
AldoMedia has built and looked after websites for Western New York businesses since 1999, and physician sites with a wide open "tell us your symptoms" box are familiar work. We are an independent authorised reseller rather than the operator of the underlying platform, and we will tell you when the plan you are already on is the right one.
We are not your compliance adviser and will not pretend to be. What we can do is show you exactly where your form's submissions go, shorten that path, and set the site up so the sensitive conversation happens on the phone. If you inherited the site from somebody you have lost touch with, start with taking over a website. Call 716-771-2536 or tell us what your site runs on.
Yes, and most physicians should. The question is what it asks for. A form that collects a name, a phone number and a good time to call is not collecting clinical information, and it does the job you actually need it to do. The risk comes from the open text box that invites a patient to describe their problem, because that submission then travels through email to wherever it lands. Ask for the callback, have the conversation on the phone.
It happens even with a well worded form, so plan for it rather than being surprised. Handle that email the way you would handle a fax containing the same words: keep it in the systems you already treat as clinical, do not forward it around, and do not leave copies sitting in a website plugin's submission log. Then change the form so the next one asks for less. If it has been happening for a while, that is a conversation to have with your compliance adviser rather than with your web host.
Hosting is not really something that is compliant or not on its own. What matters is whether patient information passes through a given system and whether the vendor behind it has an agreement with you. A brochure site with hours, a bio and a callback form is not holding patient information, so the question mostly does not arise. Once the site collects clinical details or lets patients log in, it does. Where your specific site falls is a question for your own adviser, and it is worth asking before you buy anything.
Almost never. If your practice uses an EHR, the portal is the vendor's product, running on their systems under their agreements, and your website should simply link to it. That keeps patient records off your site entirely. If a web vendor offers to build a portal into your site, ask who is responsible for the records inside it and what happens to them if you stop working together.
Only if patient information actually lands on their systems. For a static site with no clinical intake and no portal, it generally does not, and the honest answer is to shorten the path first and then ask. Map where every form submission travels, delete the intake points and stored copies you are not using, and take whatever is still on the list to your compliance adviser. The list is usually much shorter than expected.
For a five page site that links out to a portal, no. It is a small amount of static text and an entry shared plan carries it comfortably. Spending more is fair once you accept intake documents through the site, run several providers or locations on one site, or host anything a patient logs into. Being a physician is not by itself a reason to be on a bigger plan.
The plan type a solo physician site belongs on, and what the higher tiers actually change.
Read about shared hostingWhy a mailbox at your own domain beats a free address on a doctor's business card.
Read about business emailWhat to do when the person who built your site and set up that form is no longer reachable.
How to take back controlEvery trade we cover is listed on hosting by industry.
Hero image: Infrogmation, CC BY-SA 4.0, via Wikimedia Commons. Cropped.
Tell us what your site runs on and we will trace what happens to a form submission after a patient hits send. If the answer is fine already, we will say so.
Get Your Web Hosting Plan Get help choosing
Or call 716-771-2536 and tell us what the site has to do. If the plan you are already on is the right one, we will say so.