{"id":219,"date":"2025-11-15T00:30:49","date_gmt":"2025-11-15T00:30:49","guid":{"rendered":"https:\/\/medindex.am\/accounts\/my-orders\/"},"modified":"2025-12-21T02:42:36","modified_gmt":"2025-12-21T02:42:36","slug":"small-appointment-calendar-site","status":"publish","type":"page","link":"https:\/\/medindex.am\/accounts\/small-appointment-calendar-site\/","title":{"rendered":"Appointments Website. Calendar."},"content":{"rendered":"<p dir=\"auto\">If your appointment website is for doctors and must collect contact information, you must encrypt stored data.<\/p>\n<h5 data-start=\"843\" data-end=\"880\">What laws you must assume<\/h5>\n<p data-start=\"882\" data-end=\"893\">At minimum:<\/p>\n<ul data-start=\"895\" data-end=\"1029\">\n<li data-start=\"895\" data-end=\"940\">\n<p data-start=\"897\" data-end=\"940\">\ud83c\uddfa\ud83c\uddf8 <strong data-start=\"902\" data-end=\"911\">HIPAA<\/strong> (if US healthcare providers)<\/p>\n<\/li>\n<li data-start=\"941\" data-end=\"983\">\n<p data-start=\"943\" data-end=\"983\">\ud83c\uddea\ud83c\uddfa <strong data-start=\"948\" data-end=\"966\">GDPR \/ UK GDPR<\/strong> (if EU\/UK users)<\/p>\n<\/li>\n<li data-start=\"984\" data-end=\"1029\">\n<p data-start=\"986\" data-end=\"1029\">\ud83c\udde8\ud83c\udde6 <strong data-start=\"991\" data-end=\"1001\">PIPEDA<\/strong>, \ud83c\udde6\ud83c\uddfa <strong data-start=\"1008\" data-end=\"1023\">Privacy Act<\/strong>, etc.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1031\" data-end=\"1068\">All of them share the same principle:<\/p>\n<blockquote data-start=\"1069\" data-end=\"1117\">\n<p data-start=\"1071\" data-end=\"1117\"><strong data-start=\"1071\" data-end=\"1117\">Use reasonable and appropriate safeguards.<\/strong><\/p>\n<\/blockquote>\n<p data-start=\"1119\" data-end=\"1214\">For public-facing medical systems, <strong data-start=\"1154\" data-end=\"1199\">encryption at rest is considered baseline<\/strong>, not optional.<\/p>\n<h3 dir=\"auto\">\u00a0<\/h3>\n<h3 data-start=\"782\" data-end=\"863\">Countries \/ regions where <strong data-start=\"811\" data-end=\"863\">unencrypted storage is explicitly NOT acceptable<\/strong><\/h3>\n<p data-start=\"865\" data-end=\"938\">You <strong data-start=\"869\" data-end=\"883\">should not<\/strong> deploy such a system here without database encryption:<\/p>\n<h3 data-start=\"940\" data-end=\"970\">\ud83c\uddea\ud83c\uddfa European Union (GDPR)<\/h3>\n<ul data-start=\"971\" data-end=\"1137\">\n<li data-start=\"971\" data-end=\"1036\">\n<p data-start=\"973\" data-end=\"1036\">Encryption is not strictly mandatory, <strong data-start=\"1011\" data-end=\"1036\">but strongly expected<\/strong><\/p>\n<\/li>\n<li data-start=\"1037\" data-end=\"1103\">\n<p data-start=\"1039\" data-end=\"1103\">Regulators treat unencrypted personal data as a security failure<\/p>\n<\/li>\n<li data-start=\"1104\" data-end=\"1137\">\n<p data-start=\"1106\" data-end=\"1137\">Fines are common after breaches<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1139\" data-end=\"1180\"><strong data-start=\"1139\" data-end=\"1151\">Verdict:<\/strong> \u274c Not acceptable in practice<\/p>\n<hr data-start=\"1182\" data-end=\"1185\" \/>\n<h3 data-start=\"1187\" data-end=\"1220\">\ud83c\uddec\ud83c\udde7 United Kingdom (UK GDPR)<\/h3>\n<ul data-start=\"1221\" data-end=\"1292\">\n<li data-start=\"1221\" data-end=\"1242\">\n<p data-start=\"1223\" data-end=\"1242\">Same standard as EU<\/p>\n<\/li>\n<li data-start=\"1243\" data-end=\"1292\">\n<p data-start=\"1245\" data-end=\"1292\">ICO expects encryption for stored personal data<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1294\" data-end=\"1323\"><strong data-start=\"1294\" data-end=\"1306\">Verdict:<\/strong> \u274c Not acceptable<\/p>\n<hr data-start=\"1325\" data-end=\"1328\" \/>\n<h3 data-start=\"1330\" data-end=\"1352\">\ud83c\uddfa\ud83c\uddf8 United States<\/h3>\n<ul data-start=\"1353\" data-end=\"1523\">\n<li data-start=\"1353\" data-end=\"1523\">\n<p data-start=\"1355\" data-end=\"1382\">No single privacy law, but:<\/p>\n<ul data-start=\"1385\" data-end=\"1523\">\n<li data-start=\"1385\" data-end=\"1421\">\n<p data-start=\"1387\" data-end=\"1421\">FTC enforces \u201creasonable security\u201d<\/p>\n<\/li>\n<li data-start=\"1424\" data-end=\"1467\">\n<p data-start=\"1426\" data-end=\"1467\">State laws (CA, NY, MA) expect encryption<\/p>\n<\/li>\n<li data-start=\"1470\" data-end=\"1523\">\n<p data-start=\"1472\" data-end=\"1523\">Breach notification laws penalize plaintext storage<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p data-start=\"1525\" data-end=\"1559\"><strong data-start=\"1525\" data-end=\"1537\">Verdict:<\/strong> \u274c High liability risk<\/p>\n<hr data-start=\"1561\" data-end=\"1564\" \/>\n<h3 data-start=\"1566\" data-end=\"1590\">\ud83c\udde8\ud83c\udde6 Canada (PIPEDA)<\/h3>\n<ul data-start=\"1591\" data-end=\"1676\">\n<li data-start=\"1591\" data-end=\"1626\">\n<p data-start=\"1593\" data-end=\"1626\">\u201cAppropriate safeguards\u201d required<\/p>\n<\/li>\n<li data-start=\"1627\" data-end=\"1676\">\n<p data-start=\"1629\" data-end=\"1676\">Encryption is considered baseline for databases<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1678\" data-end=\"1707\"><strong data-start=\"1678\" data-end=\"1690\">Verdict:<\/strong> \u274c Not acceptable<\/p>\n<hr data-start=\"1709\" data-end=\"1712\" \/>\n<h3 data-start=\"1714\" data-end=\"1746\">\ud83c\udde6\ud83c\uddfa Australia (Privacy Act)<\/h3>\n<ul data-start=\"1747\" data-end=\"1823\">\n<li data-start=\"1747\" data-end=\"1789\">\n<p data-start=\"1749\" data-end=\"1789\">Reasonable steps to secure personal data<\/p>\n<\/li>\n<li data-start=\"1790\" data-end=\"1823\">\n<p data-start=\"1792\" data-end=\"1823\">Plaintext databases fail audits<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1825\" data-end=\"1854\"><strong data-start=\"1825\" data-end=\"1837\">Verdict:<\/strong> \u274c Not acceptable<\/p>\n<hr data-start=\"1856\" data-end=\"1859\" \/>\n<h3 data-start=\"1861\" data-end=\"1909\">\ud83c\uddef\ud83c\uddf5 Japan, \ud83c\uddf0\ud83c\uddf7 South Korea, \ud83c\uddf8\ud83c\uddec Singapore<\/h3>\n<ul data-start=\"1910\" data-end=\"1972\">\n<li data-start=\"1910\" data-end=\"1939\">\n<p data-start=\"1912\" data-end=\"1939\">Strong data protection laws<\/p>\n<\/li>\n<li data-start=\"1940\" data-end=\"1972\">\n<p data-start=\"1942\" data-end=\"1972\">Encryption considered standard<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1974\" data-end=\"2003\"><strong data-start=\"1974\" data-end=\"1986\">Verdict:<\/strong> \u274c Not acceptable<\/p>\n<p data-start=\"0\" data-end=\"135\">Below is a case:<\/p>\n<blockquote data-start=\"137\" data-end=\"268\">\n<p data-start=\"139\" data-end=\"268\"><strong data-start=\"139\" data-end=\"170\">Medical appointment website<\/strong><br data-start=\"170\" data-end=\"173\" \/>Collects <strong data-start=\"184\" data-end=\"210\">age, sex, email, phone<\/strong><br data-start=\"210\" data-end=\"213\" \/>Uses <strong data-start=\"220\" data-end=\"229\">HTTPS<\/strong><br data-start=\"229\" data-end=\"232\" \/><strong data-start=\"234\" data-end=\"268\">No database encryption at rest<\/strong><\/p>\n<\/blockquote>\n<p data-start=\"270\" data-end=\"376\">W<strong data-start=\"295\" data-end=\"316\">hat the law says<\/strong>, <strong data-start=\"318\" data-end=\"344\">what regulators expect<\/strong>, and <strong data-start=\"350\" data-end=\"375\">real enforcement risk<\/strong>.<\/p>\n<hr data-start=\"378\" data-end=\"381\" \/>\n<h3 data-start=\"383\" data-end=\"441\">\ud83c\uddf7\ud83c\uddfa Russia (Federal Law No. 152-FZ \u201cOn Personal Data\u201d)<\/h3>\n<h5 data-start=\"443\" data-end=\"466\">Does the law apply?<\/h5>\n<p data-start=\"467\" data-end=\"562\"><strong data-start=\"467\" data-end=\"475\">Yes.<\/strong><br data-start=\"475\" data-end=\"478\" \/>Email and phone number are <strong data-start=\"505\" data-end=\"522\">personal data<\/strong> under Russian law, even without a name.<\/p>\n<p data-start=\"564\" data-end=\"718\">If the site is used by a <strong data-start=\"589\" data-end=\"613\">medical organization<\/strong>, the data is also treated as <strong data-start=\"643\" data-end=\"676\">medical-related personal data<\/strong>, which increases protection requirements.<\/p>\n<p>Is database encryption legally mandatory?<\/p>\n<p data-start=\"771\" data-end=\"805\"><strong data-start=\"771\" data-end=\"799\">Not explicitly mandatory<\/strong>, but\u2026<\/p>\n<p data-start=\"807\" data-end=\"828\">Russian law requires:<\/p>\n<ul data-start=\"829\" data-end=\"963\">\n<li data-start=\"829\" data-end=\"895\">\n<p data-start=\"831\" data-end=\"895\">\u201cNecessary and sufficient organizational and technical measures\u201d<\/p>\n<\/li>\n<li data-start=\"896\" data-end=\"963\">\n<p data-start=\"898\" data-end=\"963\">Protection against <strong data-start=\"917\" data-end=\"963\">unauthorized access, leakage, modification<\/strong><\/p>\n<\/li>\n<\/ul>\n<p data-start=\"965\" data-end=\"1087\">Roskomnadzor guidance and court practice treat <strong data-start=\"1012\" data-end=\"1058\">encryption as a standard technical measure<\/strong> for internet-facing systems.<\/p>\n<h5 data-start=\"1094\" data-end=\"1137\">Can you legally store unencrypted data?<\/h5>\n<p data-start=\"1138\" data-end=\"1197\">\u26a0\ufe0f <strong data-start=\"1141\" data-end=\"1162\">Formally possible<\/strong>, but <strong data-start=\"1168\" data-end=\"1181\">high risk<\/strong>, especially if:<\/p>\n<ul data-start=\"1198\" data-end=\"1279\">\n<li data-start=\"1198\" data-end=\"1221\">\n<p data-start=\"1200\" data-end=\"1221\">Public-facing website<\/p>\n<\/li>\n<li data-start=\"1222\" data-end=\"1239\">\n<p data-start=\"1224\" data-end=\"1239\">Medical context<\/p>\n<\/li>\n<li data-start=\"1240\" data-end=\"1279\">\n<p data-start=\"1242\" data-end=\"1279\">Cloud or internet-accessible database<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1281\" data-end=\"1367\">After a breach, <strong data-start=\"1297\" data-end=\"1366\">unencrypted storage is routinely considered inadequate protection<\/strong>.<\/p>\n<h5 data-start=\"1374\" data-end=\"1405\">Practical reality in Russia<\/h5>\n<ul data-start=\"1406\" data-end=\"1576\">\n<li data-start=\"1406\" data-end=\"1454\">\n<p data-start=\"1408\" data-end=\"1454\">Medical IT systems are <strong data-start=\"1431\" data-end=\"1443\">expected<\/strong> to encrypt<\/p>\n<\/li>\n<li data-start=\"1455\" data-end=\"1519\">\n<p data-start=\"1457\" data-end=\"1519\">Hosting providers and clinics usually require it contractually<\/p>\n<\/li>\n<li data-start=\"1520\" data-end=\"1576\">\n<p data-start=\"1522\" data-end=\"1576\">Fines are modest, but <strong data-start=\"1544\" data-end=\"1564\">service blocking<\/strong> is possible<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1578\" data-end=\"1647\"><strong data-start=\"1578\" data-end=\"1599\">Verdict (Russia):<\/strong><br data-start=\"1599\" data-end=\"1602\" \/>\u26a0\ufe0f <em data-start=\"1605\" data-end=\"1647\">Technically possible, practically unsafe<\/em><\/p>\n<h3 data-start=\"1654\" data-end=\"1712\">\ud83c\udde6\ud83c\uddf2 Armenia (Law on Protection of Personal Data, 2015)<\/h3>\n<h5 data-start=\"1714\" data-end=\"1737\">Does the law apply?<\/h5>\n<p data-start=\"1738\" data-end=\"1746\"><strong data-start=\"1738\" data-end=\"1746\">Yes.<\/strong><\/p>\n<p data-start=\"1748\" data-end=\"1856\">Email and phone number = <strong data-start=\"1773\" data-end=\"1790\">personal data<\/strong><br data-start=\"1790\" data-end=\"1793\" \/>Medical appointment context = <strong data-start=\"1823\" data-end=\"1856\">higher protection expectation<\/strong><\/p>\n<p>Is encryption explicitly required?<\/p>\n<p data-start=\"1902\" data-end=\"1948\"><strong data-start=\"1902\" data-end=\"1936\">No explicit encryption mandate<\/strong> in the law.<\/p>\n<p data-start=\"1950\" data-end=\"1976\">However, the law requires:<\/p>\n<ul data-start=\"1977\" data-end=\"2075\">\n<li data-start=\"1977\" data-end=\"2021\">\n<p data-start=\"1979\" data-end=\"2021\">\u201cNecessary technical means for protection\u201d<\/p>\n<\/li>\n<li data-start=\"2022\" data-end=\"2075\">\n<p data-start=\"2024\" data-end=\"2075\">Prevention of unauthorized access and dissemination<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2077\" data-end=\"2187\">Armenian regulators <strong data-start=\"2097\" data-end=\"2136\">do not prescribe exact technologies<\/strong>, but rely on a <strong data-start=\"2152\" data-end=\"2186\">\u201creasonable security\u201d standard<\/strong>.<\/p>\n<p>Can you legally store unencrypted data?<\/p>\n<p data-start=\"2238\" data-end=\"2270\">\u2705 <strong data-start=\"2240\" data-end=\"2265\">Yes, legally possible<\/strong>, if:<\/p>\n<ul data-start=\"2271\" data-end=\"2378\">\n<li data-start=\"2271\" data-end=\"2299\">\n<p data-start=\"2273\" data-end=\"2299\">Access controls are strong<\/p>\n<\/li>\n<li data-start=\"2300\" data-end=\"2315\">\n<p data-start=\"2302\" data-end=\"2315\">HTTPS is used<\/p>\n<\/li>\n<li data-start=\"2316\" data-end=\"2338\">\n<p data-start=\"2318\" data-end=\"2338\">Minimal staff access<\/p>\n<\/li>\n<li data-start=\"2339\" data-end=\"2378\">\n<p data-start=\"2341\" data-end=\"2378\">Clear internal security policy exists<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2380\" data-end=\"2391\">\u26a0\ufe0f However:<\/p>\n<ul data-start=\"2392\" data-end=\"2492\">\n<li data-start=\"2392\" data-end=\"2458\">\n<p data-start=\"2394\" data-end=\"2458\">In case of breach, lack of encryption weakens your legal defense<\/p>\n<\/li>\n<li data-start=\"2459\" data-end=\"2492\">\n<p data-start=\"2461\" data-end=\"2492\">Medical data increases scrutiny<\/p>\n<\/li>\n<\/ul>\n<h5 data-start=\"2499\" data-end=\"2522\">Enforcement reality<\/h5>\n<ul data-start=\"2523\" data-end=\"2643\">\n<li data-start=\"2523\" data-end=\"2549\">\n<p data-start=\"2525\" data-end=\"2549\">Enforcement is <strong data-start=\"2540\" data-end=\"2549\">light<\/strong><\/p>\n<\/li>\n<li data-start=\"2550\" data-end=\"2565\">\n<p data-start=\"2552\" data-end=\"2565\">Fines are low<\/p>\n<\/li>\n<li data-start=\"2566\" data-end=\"2643\">\n<p data-start=\"2568\" data-end=\"2643\">Focus is usually on <strong data-start=\"2588\" data-end=\"2617\">absence of any safeguards<\/strong>, not encryption specifics<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2645\" data-end=\"2724\"><strong data-start=\"2645\" data-end=\"2667\">Verdict (Armenia):<\/strong><br data-start=\"2667\" data-end=\"2670\" \/>\u2705 <em data-start=\"2672\" data-end=\"2696\">Legally possible today<\/em><br data-start=\"2696\" data-end=\"2699\" \/>\u26a0\ufe0f <em data-start=\"2702\" data-end=\"2724\">Weak future-proofing<\/em><\/p>\n<h3 data-start=\"2731\" data-end=\"2794\">\ud83c\uddec\ud83c\uddea Georgia (Law on Personal Data Protection, updated 2023)<\/h3>\n<h5 data-start=\"2796\" data-end=\"2819\">Does the law apply?<\/h5>\n<p data-start=\"2820\" data-end=\"2828\"><strong data-start=\"2820\" data-end=\"2828\">Yes.<\/strong><\/p>\n<p data-start=\"2830\" data-end=\"2868\">Georgia\u2019s law is now <strong data-start=\"2851\" data-end=\"2867\">GDPR-aligned<\/strong>.<\/p>\n<p data-start=\"2870\" data-end=\"2954\">Email + phone = personal data<br data-start=\"2899\" data-end=\"2902\" \/>Medical services = <strong data-start=\"2921\" data-end=\"2954\">special category data context<\/strong><\/p>\n<h5 data-start=\"2961\" data-end=\"2988\">Is encryption required?<\/h5>\n<p data-start=\"2989\" data-end=\"3006\">The law requires:<\/p>\n<ul data-start=\"3007\" data-end=\"3095\">\n<li data-start=\"3007\" data-end=\"3060\">\n<p data-start=\"3009\" data-end=\"3060\">\u201cAppropriate technical and organizational measures\u201d<\/p>\n<\/li>\n<li data-start=\"3061\" data-end=\"3095\">\n<p data-start=\"3063\" data-end=\"3095\">Protection proportionate to risk<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3097\" data-end=\"3165\">The Georgian Personal Data Protection Service explicitly references:<\/p>\n<ul data-start=\"3166\" data-end=\"3197\">\n<li data-start=\"3166\" data-end=\"3178\">\n<p data-start=\"3168\" data-end=\"3178\">Encryption<\/p>\n<\/li>\n<li data-start=\"3179\" data-end=\"3197\">\n<p data-start=\"3181\" data-end=\"3197\">Pseudonymization<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3199\" data-end=\"3264\">as <strong data-start=\"3202\" data-end=\"3225\">expected safeguards<\/strong> for sensitive or high-risk processing.<\/p>\n<h5 data-start=\"3271\" data-end=\"3306\">Can you store data unencrypted?<\/h5>\n<p data-start=\"3307\" data-end=\"3373\">\u274c <strong data-start=\"3309\" data-end=\"3333\">Strongly discouraged<\/strong> and <strong data-start=\"3338\" data-end=\"3356\">hard to defend<\/strong>, especially for:<\/p>\n<ul data-start=\"3374\" data-end=\"3422\">\n<li data-start=\"3374\" data-end=\"3396\">\n<p data-start=\"3376\" data-end=\"3396\">Medical appointments<\/p>\n<\/li>\n<li data-start=\"3397\" data-end=\"3422\">\n<p data-start=\"3399\" data-end=\"3422\">Internet-facing systems<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3424\" data-end=\"3505\">In a breach, plaintext storage would almost certainly be ruled <strong data-start=\"3487\" data-end=\"3504\">non-compliant<\/strong>.<\/p>\n<h5 data-start=\"3512\" data-end=\"3535\">Enforcement reality<\/h5>\n<ul data-start=\"3536\" data-end=\"3608\">\n<li data-start=\"3536\" data-end=\"3554\">\n<p data-start=\"3538\" data-end=\"3554\">Active regulator<\/p>\n<\/li>\n<li data-start=\"3555\" data-end=\"3577\">\n<p data-start=\"3557\" data-end=\"3577\">Administrative fines<\/p>\n<\/li>\n<li data-start=\"3578\" data-end=\"3608\">\n<p data-start=\"3580\" data-end=\"3608\">Orders to suspend processing<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"3610\" data-end=\"3667\"><strong data-start=\"3610\" data-end=\"3632\">Verdict (Georgia):<\/strong><br data-start=\"3632\" data-end=\"3635\" \/>\u274c <em data-start=\"3637\" data-end=\"3667\">Not realistically acceptable<\/em><\/p>\n<h5 data-start=\"3674\" data-end=\"3709\">Summary Table\u00a0<\/h5>\n<div class=\"TyagGW_tableContainer\">\n<div class=\"group TyagGW_tableWrapper flex w-fit flex-col-reverse\" tabindex=\"-1\">\n<table class=\"w-fit min-w-(--thread-content-width)\" data-start=\"3711\" data-end=\"4012\">\n<thead data-start=\"3711\" data-end=\"3808\">\n<tr data-start=\"3711\" data-end=\"3808\">\n<th data-start=\"3711\" data-end=\"3721\" data-col-size=\"sm\">Country<\/th>\n<th data-start=\"3721\" data-end=\"3736\" data-col-size=\"sm\">Law applies?<\/th>\n<th data-start=\"3736\" data-end=\"3770\" data-col-size=\"sm\">Encryption explicitly required?<\/th>\n<th data-start=\"3770\" data-end=\"3808\" data-col-size=\"sm\">Unencrypted DB legally defensible?<\/th>\n<\/tr>\n<\/thead>\n<tbody data-start=\"3898\" data-end=\"4012\">\n<tr data-start=\"3898\" data-end=\"3940\">\n<td data-start=\"3898\" data-end=\"3907\" data-col-size=\"sm\">Russia<\/td>\n<td data-col-size=\"sm\" data-start=\"3907\" data-end=\"3913\">Yes<\/td>\n<td data-col-size=\"sm\" data-start=\"3913\" data-end=\"3928\">Not explicit<\/td>\n<td data-col-size=\"sm\" data-start=\"3928\" data-end=\"3940\">\u26a0\ufe0f Risky<\/td>\n<\/tr>\n<tr data-start=\"3941\" data-end=\"3976\">\n<td data-start=\"3941\" data-end=\"3951\" data-col-size=\"sm\">Armenia<\/td>\n<td data-col-size=\"sm\" data-start=\"3951\" data-end=\"3957\">Yes<\/td>\n<td data-col-size=\"sm\" data-start=\"3957\" data-end=\"3962\">No<\/td>\n<td data-col-size=\"sm\" data-start=\"3962\" data-end=\"3976\">\u2705 Possible<\/td>\n<\/tr>\n<tr data-start=\"3977\" data-end=\"4012\">\n<td data-start=\"3977\" data-end=\"3987\" data-col-size=\"sm\">Georgia<\/td>\n<td data-col-size=\"sm\" data-start=\"3987\" data-end=\"3993\">Yes<\/td>\n<td data-col-size=\"sm\" data-start=\"3993\" data-end=\"4004\">Expected<\/td>\n<td data-col-size=\"sm\" data-start=\"4004\" data-end=\"4012\">\u274c No<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h5 data-start=\"4019\" data-end=\"4064\">Important strategic point<\/h5>\n<p data-start=\"4066\" data-end=\"4116\">Even where <strong data-start=\"4077\" data-end=\"4097\">legally possible<\/strong> (Russia, Armenia):<\/p>\n<ul data-start=\"4118\" data-end=\"4287\">\n<li data-start=\"4118\" data-end=\"4182\">\n<p data-start=\"4120\" data-end=\"4182\">Doctors and clinics often <strong data-start=\"4146\" data-end=\"4182\">require encryption contractually<\/strong><\/p>\n<\/li>\n<li data-start=\"4183\" data-end=\"4217\">\n<p data-start=\"4185\" data-end=\"4217\">Hosting providers may require it<\/p>\n<\/li>\n<li data-start=\"4218\" data-end=\"4287\">\n<p data-start=\"4220\" data-end=\"4287\">One breach can retroactively turn \u201cacceptable\u201d into \u201cnon-compliant\u201d<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"4289\" data-end=\"4304\">And encryption:<\/p>\n<ul data-start=\"4305\" data-end=\"4392\">\n<li data-start=\"4305\" data-end=\"4315\">\n<p data-start=\"4307\" data-end=\"4315\">Is cheap<\/p>\n<\/li>\n<li data-start=\"4316\" data-end=\"4348\">\n<p data-start=\"4318\" data-end=\"4348\">Has near-zero performance cost<\/p>\n<\/li>\n<li data-start=\"4349\" data-end=\"4392\">\n<p data-start=\"4351\" data-end=\"4392\">Removes cross-border compliance headaches<\/p>\n<\/li>\n<\/ul>\n<h5 data-start=\"4399\" data-end=\"4429\">Encryption<\/h5>\n<ul data-start=\"4431\" data-end=\"4619\">\n<li data-start=\"4431\" data-end=\"4515\">\n<p data-start=\"4433\" data-end=\"4515\"><strong data-start=\"4433\" data-end=\"4444\">Armenia<\/strong> \u2192 You can legally deploy today without DB encryption (not recommended)<\/p>\n<\/li>\n<li data-start=\"4516\" data-end=\"4563\">\n<p data-start=\"4518\" data-end=\"4563\"><strong data-start=\"4518\" data-end=\"4528\">Russia<\/strong> \u2192 Legally gray, practically unsafe<\/p>\n<\/li>\n<li data-start=\"4564\" data-end=\"4619\">\n<p data-start=\"4566\" data-end=\"4619\"><strong data-start=\"4566\" data-end=\"4577\">Georgia<\/strong> \u2192 Not acceptable for medical appointments<\/p>\n<\/li>\n<\/ul>\n<hr data-start=\"2005\" data-end=\"2008\" \/>\n<h3 data-start=\"2010\" data-end=\"2128\">Countries where <strong data-start=\"2029\" data-end=\"2079\">unencrypted storage may be <em data-start=\"2058\" data-end=\"2077\">legally tolerated<\/em><\/strong> (lower enforcement \/ less explicit requirements)<\/h3>\n<p data-start=\"2130\" data-end=\"2209\">\u26a0\ufe0f <strong data-start=\"2133\" data-end=\"2209\">This does NOT mean \u201csafe\u201d or \u201cbest practice\u201d \u2014 only lower legal exposure<\/strong><\/p>\n<h5 data-start=\"2211\" data-end=\"2224\">Parts of:<\/h5>\n<ul data-start=\"2225\" data-end=\"2509\">\n<li data-start=\"2225\" data-end=\"2268\">\n<p data-start=\"2227\" data-end=\"2268\">\ud83c\uddee\ud83c\uddf3 India (outside sensitive data scope)<\/p>\n<\/li>\n<li data-start=\"2269\" data-end=\"2306\">\n<p data-start=\"2271\" data-end=\"2306\">\ud83c\uddf5\ud83c\udded Philippines (weak enforcement)<\/p>\n<\/li>\n<li data-start=\"2307\" data-end=\"2346\">\n<p data-start=\"2309\" data-end=\"2346\">\ud83c\uddee\ud83c\udde9 Indonesia (emerging enforcement)<\/p>\n<\/li>\n<li data-start=\"2347\" data-end=\"2394\">\n<p data-start=\"2349\" data-end=\"2394\">\ud83c\uddfb\ud83c\uddf3 Vietnam (law exists, enforcement uneven)<\/p>\n<\/li>\n<li data-start=\"2395\" data-end=\"2449\">\n<p data-start=\"2397\" data-end=\"2449\">\ud83c\uddf9\ud83c\udded Thailand (PDPA exists, but limited enforcement)<\/p>\n<\/li>\n<li data-start=\"2450\" data-end=\"2509\">\n<p data-start=\"2452\" data-end=\"2509\">\ud83c\udde7\ud83c\uddf7 Brazil (LGPD exists, but enforcement still maturing)<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2511\" data-end=\"2574\"><strong data-start=\"2511\" data-end=\"2523\">Verdict:<\/strong> \u26a0\ufe0f Possible, but risky and future-proofing is poor<\/p>\n<hr data-start=\"2576\" data-end=\"2579\" \/>\n<h3 data-start=\"2581\" data-end=\"2646\">Countries with <strong data-start=\"2599\" data-end=\"2646\">minimal or no enforced data protection laws<\/strong><\/h3>\n<p data-start=\"724\" data-end=\"1651\">\ud83c\udde6\ud83c\uddeb <strong data-start=\"729\" data-end=\"744\">Afghanistan<\/strong> \u2014 no comprehensive law<br data-start=\"767\" data-end=\"770\" \/>\ud83c\udde7\ud83c\udde9 <strong data-start=\"775\" data-end=\"789\">Bangladesh<\/strong> \u2014 no comprehensive law<br data-start=\"812\" data-end=\"815\" \/>\ud83c\udde7\ud83c\uddee <strong data-start=\"820\" data-end=\"831\">Burundi<\/strong><br data-start=\"831\" data-end=\"834\" \/>\ud83c\udde8\ud83c\uddeb <strong data-start=\"839\" data-end=\"867\">Central African Republic<\/strong><br data-start=\"867\" data-end=\"870\" \/>\ud83c\udde8\ud83c\uddfa <strong data-start=\"875\" data-end=\"883\">Cuba<\/strong><br data-start=\"883\" data-end=\"886\" \/>\ud83c\udde9\ud83c\uddef <strong data-start=\"891\" data-end=\"903\">Djibouti<\/strong><br data-start=\"903\" data-end=\"906\" \/>\ud83c\udde9\ud83c\uddf2 <strong data-start=\"911\" data-end=\"923\">Dominica<\/strong> (limited \/ no privacy law)<br data-start=\"950\" data-end=\"953\" \/>\ud83c\uddea\ud83c\uddf7 <strong data-start=\"958\" data-end=\"969\">Eritrea<\/strong><br data-start=\"969\" data-end=\"972\" \/>\ud83c\uddf8\ud83c\uddfe <strong data-start=\"977\" data-end=\"986\">Syria<\/strong><br data-start=\"986\" data-end=\"989\" \/>\ud83c\uddf1\ud83c\uddf7 <strong data-start=\"994\" data-end=\"1005\">Liberia<\/strong><br data-start=\"1005\" data-end=\"1008\" \/>\ud83c\uddf8\ud83c\uddf1 <strong data-start=\"1013\" data-end=\"1029\">Sierra Leone<\/strong><br data-start=\"1029\" data-end=\"1032\" \/>\ud83c\uddec\ud83c\uddfc <strong data-start=\"1037\" data-end=\"1054\">Guinea-Bissau<\/strong><br data-start=\"1054\" data-end=\"1057\" \/>\ud83c\uddf8\ud83c\udde9 <strong data-start=\"1062\" data-end=\"1071\">Sudan<\/strong><br data-start=\"1071\" data-end=\"1074\" \/>\ud83c\uddfb\ud83c\uddea <strong data-start=\"1079\" data-end=\"1092\">Venezuela<\/strong><br data-start=\"1092\" data-end=\"1095\" \/>\ud83c\uddf5\ud83c\uddec <strong data-start=\"1100\" data-end=\"1120\">Papua New Guinea<\/strong><br data-start=\"1120\" data-end=\"1123\" \/>\ud83c\uddf9\ud83c\uddf1 <strong data-start=\"1128\" data-end=\"1156\">Timor-Leste (East Timor)<\/strong><br data-start=\"1156\" data-end=\"1159\" \/>\ud83c\udde7\ud83c\uddf3 <strong data-start=\"1164\" data-end=\"1174\">Brunei<\/strong><br data-start=\"1174\" data-end=\"1177\" \/>\ud83c\uddf2\ud83c\uddfb <strong data-start=\"1182\" data-end=\"1194\">Maldives<\/strong> (listed in some mappings as lacking a law\/pending)<br data-start=\"1245\" data-end=\"1248\" \/>\ud83c\uddf8\ud83c\uddf4 <strong data-start=\"1253\" data-end=\"1264\">Somalia<\/strong> \u2014 <em data-start=\"1267\" data-end=\"1357\">has a law passed, but enforcement and regulatory capacity are extremely weak in practice<\/em> <span class=\"\" data-state=\"closed\"><span class=\"ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]\" data-testid=\"webpage-citation-pill\"><a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/en.wikipedia.org\/wiki\/Data_Protection_Act%2C_2023\" target=\"_blank\" rel=\"noopener\"><span class=\"relative start-0 bottom-0 flex h-full w-full items-center\"><span class=\"flex h-4 w-full items-center justify-between overflow-hidden\"><span class=\"max-w-[15ch] grow truncate overflow-hidden text-center\">Wikipedia<\/span><\/span><\/span><\/a><\/span><\/span><br data-start=\"1395\" data-end=\"1398\" \/>\ud83c\uddf2\ud83c\uddff <strong data-start=\"1403\" data-end=\"1417\">Mozambique<\/strong> \u2014 no clear data\/implementation gaps in enforcement in some assessments<br data-start=\"1488\" data-end=\"1491\" \/>\ud83c\uddf8\ud83c\uddff <strong data-start=\"1496\" data-end=\"1511\">South Sudan<\/strong> \u2014 lacking data and established enforcement bodies<br data-start=\"1561\" data-end=\"1564\" \/>\ud83c\uddff\ud83c\uddf2 <strong data-start=\"1569\" data-end=\"1579\">Zambia<\/strong> \u2014 pending regulator establishment (legislation passed but incomplete)<\/p>\n<p data-start=\"1653\" data-end=\"1747\">Additionally, <strong data-start=\"1667\" data-end=\"1736\">some territories\/places with no clear information or missing data<\/strong> include:<\/p>\n<ul data-start=\"1748\" data-end=\"1782\">\n<li data-start=\"1748\" data-end=\"1766\">\n<p data-start=\"1750\" data-end=\"1766\">Western Sahara<\/p>\n<\/li>\n<li data-start=\"1767\" data-end=\"1782\">\n<p data-start=\"1769\" data-end=\"1782\">North Korea<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1784\" data-end=\"2058\">\ud83d\udc49 <em data-start=\"1787\" data-end=\"1794\">Note:<\/em> In some of the above, draft privacy bills exist but are not implemented or lack enforcement capacity. For example, many African and Asian countries have draft laws or pending regulatory action, but no active enforcement body. <span class=\"\" data-state=\"closed\"><span class=\"ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]\" data-testid=\"webpage-citation-pill\"><a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/iapp.org\/news\/a\/data-protection-and-privacy-laws-now-in-effect-in-144-countries\" target=\"_blank\" rel=\"noopener\"><span class=\"relative start-0 bottom-0 flex h-full w-full items-center\"><span class=\"flex h-4 w-full items-center justify-between\"><span class=\"max-w-[15ch] grow truncate overflow-hidden text-center\">IAPP<\/span><span class=\"-me-1 flex h-full items-center rounded-full px-1 text-[#8F8F8F]\">+1<\/span><\/span><\/span><\/a><\/span><\/span><\/p>\n<hr data-start=\"2060\" data-end=\"2063\" \/>\n<h5 data-start=\"2065\" data-end=\"2088\">\u26a0\ufe0f Important context<\/h5>\n<h5 data-start=\"2090\" data-end=\"2140\">\ud83d\udccc Most countries <em data-start=\"2112\" data-end=\"2116\">do<\/em> now have privacy laws<\/h5>\n<p data-start=\"2141\" data-end=\"2335\">According to global data, <strong data-start=\"2167\" data-end=\"2248\">around 144+ countries have enacted comprehensive privacy\/data protection laws<\/strong> \u2014 a clear majority of the world\u2019s jurisdictions. <span class=\"\" data-state=\"closed\"><span class=\"ms-1 inline-flex max-w-full items-center relative top-[-0.094rem] animate-[show_150ms_ease-in]\" data-testid=\"webpage-citation-pill\"><a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/iapp.org\/news\/a\/data-protection-and-privacy-laws-now-in-effect-in-144-countries\" target=\"_blank\" rel=\"noopener\"><span class=\"relative start-0 bottom-0 flex h-full w-full items-center\"><span class=\"flex h-4 w-full items-center justify-between overflow-hidden\"><span class=\"max-w-[15ch] grow truncate overflow-hidden text-center\">IAPP<\/span><\/span><\/span><\/a><\/span><\/span><\/p>\n<h5 data-start=\"2337\" data-end=\"2369\">\ud83d\udccc \u201cNo law\u201d \u2260 \u201csafe forever\u201d<\/h5>\n<p data-start=\"2370\" data-end=\"2623\">Even where a comprehensive data protection law <strong data-start=\"2417\" data-end=\"2439\">does not yet exist<\/strong>, other legal frameworks (like <em data-start=\"2470\" data-end=\"2491\">telecommunications.<\/em> <em data-start=\"2492\" data-end=\"2514\">consumer protection.<\/em>, <em data-start=\"2516\" data-end=\"2528\">cybercrime<\/em>, or <em data-start=\"2533\" data-end=\"2552\">health data rules<\/em>) may still regulate how data like email and phone numbers are handled.<\/p>\n\n<hr data-start=\"2060\" data-end=\"2063\" \/>\n\n<h3 class=\"wp-block-heading\">\ud83c\uddfa\ud83c\uddf8 USA<\/h3>\n\n\n\n<h6 class=\"wp-block-heading\">HIPAA applies to any website (even a small one) if it collects, stores, or transmits Protected Health Information (PHI) \u2014 including appointment calendars that include patient names, dates, reasons for visit, or contact info.<\/h6>\n\n\n\n<p>When HIPAA <strong>DOES Apply<\/strong> to a Appointments Website. Calendar Site<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Scenario<\/th><th>HIPAA Applies?<\/th><th>Why<\/th><\/tr><\/thead><tbody><tr><td>Patient books appointment <strong>with name, email, phone, reason for visit<\/strong><\/td><td>YES<\/td><td>This is <strong>PHI<\/strong> (identifiable health data)<\/td><\/tr><tr><td>Calendar shows <strong>&#8220;John Doe \u2013 Knee Pain \u2013 3 PM&#8221;<\/strong><\/td><td>YES<\/td><td>Combines identity + health condition<\/td><\/tr><tr><td>You <strong>store data in a database or Google Sheet<\/strong><\/td><td>YES<\/td><td>You\u2019re a <strong>Covered Entity<\/strong> or <strong>Business Associate<\/strong><\/td><\/tr><tr><td>You use <strong>WordPress + Appointments plugin<\/strong> (e.g., Bookly, Amelia)<\/td><td>YES<\/td><td>If PHI is collected\/stored<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">When HIPAA <strong>Does NOT Apply<\/strong><\/h6>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Scenario<\/th><th>HIPAA-Free?<\/th><th>Why<\/th><\/tr><\/thead><tbody><tr><td>Anonymous booking (no names, no health info)<\/td><td>NO<\/td><td>Not PHI<\/td><\/tr><tr><td>Business services only (e.g., \u201cBook a marketing consult\u201d)<\/td><td>NO<\/td><td>Not healthcare<\/td><\/tr><tr><td>You delete data immediately after booking<\/td><td>NO (still applies during transmission)<\/td><td>Temporary PHI still protected<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">HIPAA Requirements for Small Appointment Sites (Even 1 Doctor)<\/h6>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Requirement<\/th><th>What You Must Do<\/th><th>Low-Cost Tools<\/th><\/tr><\/thead><tbody><tr><td><strong>Business Associate Agreement (BAA)<\/strong><\/td><td>Sign with hosting, plugins, email, calendar tools<\/td><td>AWS, Google Workspace, HIPAA Vault<\/td><\/tr><tr><td><strong>Encryption<\/strong><\/td><td>Data in transit (SSL\/TLS) + at rest<\/td><td>Let\u2019s Encrypt (free SSL), encrypted DB<\/td><\/tr><tr><td><strong>Access Controls<\/strong><\/td><td>Login passwords, role-based access<\/td><td>WordPress user roles, 2FA<\/td><\/tr><tr><td><strong>Audit Logs<\/strong><\/td><td>Track who views\/edits PHI<\/td><td>WP Activity Log, server logs<\/td><\/tr><tr><td><strong>Risk Analysis<\/strong><\/td><td>Annual security review<\/td><td>Free HHS template<\/td><\/tr><tr><td><strong>Patient Rights<\/strong><\/td><td>Allow access\/deletion of their data<\/td><td>GDPR\/CCPA plugins help<\/td><\/tr><tr><td><strong>Secure Backup<\/strong><\/td><td>Encrypted offsite backups<\/td><td>UpdraftPlus + encrypted storage<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">Real-World Example: WordPress + Bookly\/Amelia<\/h6>\n\n\n\n<pre class=\"wp-block-code\"><code>Plugin: Bookly Pro\nCollects: Name, Email, Phone, Service (\"Physical Exam\"), Notes\n\u2192 This is PHI \u2192 HIPAA applies<\/code><\/pre>\n\n\n\n<p><strong>You must:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Host on <strong>HIPAA-compliant server<\/strong> (e.g., HIPAA Vault: ~$84\/mo)<\/li>\n\n\n\n<li>Use <strong>encrypted forms<\/strong> (SSL + field encryption add-ons)<\/li>\n\n\n\n<li>Sign <strong>BAAs<\/strong> with Bookly (if Pro), hosting, email (e.g., Google Workspace)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">Cheapest HIPAA-Compliant Setup (2025)<\/h6>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Item<\/th><th>Cost<\/th><\/tr><\/thead><tbody><tr><td>HIPAA Hosting (HIPAA Vault WP)<\/td><td>$1,008\/yr<\/td><\/tr><tr><td>SSL (Let\u2019s Encrypt)<\/td><td>FREE<\/td><\/tr><tr><td>Appointment Plugin (Bookly Pro)<\/td><td>$99\/yr<\/td><\/tr><tr><td>BAA + Compliance Tools<\/td><td>$0\u2013$360\/yr<\/td><\/tr><tr><td><strong>Total<\/strong><\/td><td><strong>~$1,100\u2013$1,500\/yr<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">Bottom Line for Small Clinics<\/h6>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>If your appointment calendar collects any patient-identifiable health info \u2192 HIPAA applies \u2014 no exceptions for size.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p><strong>Do this now:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Switch to <strong>HIPAA-compliant hosting<\/strong> (e.g., HIPAA Vault, AWS with BAA)<\/li>\n\n\n\n<li>Add <strong>SSL + form encryption<\/strong><\/li>\n\n\n\n<li>Use plugins with <strong>BAA support<\/strong> (or avoid storing PHI)<\/li>\n\n\n\n<li>Document your <strong>risk analysis<\/strong> (1-page is fine)<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>Pro Tip<\/strong>: Use <strong>anonymous booking links<\/strong> or <strong>patient portal logins<\/strong> (e.g., OpenEMR portal) to avoid PHI on the public site.<\/p>\n\n\n\n<p><br><\/p>\n\n\n\n<h6 class=\"wp-block-heading\">BAA Checklist (Print &amp; Sign)<\/h6>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Vendor<\/th><th>BAA Status<\/th><th>Link<\/th><\/tr><\/thead><tbody><tr><td>HIPAA Vault<\/td><td>Signed<\/td><td><a href=\"https:\/\/hipaavault.com\">hipaavault.com\/baa<\/a><\/td><\/tr><tr><td>OpenEMR Host (AWS\/GCP)<\/td><td>Signed<\/td><td>AWS BAA<\/td><\/tr><tr><td>Google Workspace<\/td><td>Signed<\/td><td><a href=\"https:\/\/workspace.google.com\/terms\">workspace.google.com\/terms<\/a><\/td><\/tr><tr><td>Bookly\/Amelia (if used)<\/td><td>Not needed (no PHI stored)<\/td><td>\u2014<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h6 class=\"wp-block-heading\">Action Plan (Do This Week)<\/h6>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Switch hosting<\/strong> \u2192 <a href=\"https:\/\/hipaavault.com\" target=\"_blank\" rel=\"noreferrer noopener\">HIPAA Vault<\/a> (sign BAA)<\/li>\n\n\n\n<li><strong>Enable SSL<\/strong> \u2192 Let\u2019s Encrypt (free via hosting)<\/li>\n\n\n\n<li><strong>Sign BAAs<\/strong> \u2192 With hosting, Google, plugin (if Pro)<\/li>\n\n\n\n<li><strong>Add audit log<\/strong> \u2192 Install <strong>WP Activity Log<\/strong> (free)<\/li>\n\n\n\n<li><strong>Document risk analysis<\/strong> \u2192 Use <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/guidance\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">HHS free template<\/a><\/li>\n<\/ol>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If your appointment website is for doctors and must collect contact information, you must encrypt stored data. What laws you must assume At minimum: \ud83c\uddfa\ud83c\uddf8 HIPAA (if US healthcare providers) \ud83c\uddea\ud83c\uddfa GDPR \/ UK GDPR (if EU\/UK users) \ud83c\udde8\ud83c\udde6 PIPEDA, \ud83c\udde6\ud83c\uddfa Privacy Act, etc. All of them share the same principle: Use reasonable and appropriate [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"slim_seo":{"title":"Appointments Website. Calendar. - Medindex","description":"If your appointment website is for doctors and must collect contact information, you must encrypt stored data. What laws you must assume At minimum: \ud83c\uddfa\ud83c\uddf8 HIPAA (i"},"footnotes":""},"class_list":["post-219","page","type-page","status-publish","hentry"],"_hostinger_reach_plugin_has_subscription_block":false,"_hostinger_reach_plugin_is_elementor":false,"_links":{"self":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages\/219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/comments?post=219"}],"version-history":[{"count":0,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages\/219\/revisions"}],"wp:attachment":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/media?parent=219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}