Skip to content
Have a question? Click the swan 🦢
🦢

SwanBot 🦢

Ask me anything about The WebSwan

What Is Website Compliance? (And Why It Could Be Costing You Customers)

If you've never heard the term "website compliance" before, you're not alone — most business owners haven't, until it becomes a problem. In plain terms, website compliance means your site meets accessibility standards (commonly referenced as ADA/WCAG) so that people using screen readers, keyboard navigation, or other assistive technology can actually use it.

The common gaps

  • Images without alt text, so screen readers can't describe what's on the page
  • Low color contrast that makes text hard to read for visually impaired visitors
  • Menus and forms that only work with a mouse, locking out keyboard users
  • Form fields with no labels, so screen readers can't tell users what to enter

Why it matters

Two things are on the line: your customers and your legal exposure. Businesses have received demand letters and lawsuits under ADA Title III over inaccessible websites — and separately, an inaccessible site is simply turning away real customers who can't use it. On top of that, some of the same fixes (clean structure, real alt text, fast load times) are exactly what search engines reward with better rankings.

How to check your own site

A few quick things you can look at yourself: try navigating your site using only your keyboard (Tab key), check whether your images have descriptive alt text in the page code, and run your homepage through a free accessibility checker. If more than a couple of things fail, it's worth a professional audit before it becomes a bigger issue.

Next step

Get a free compliance and performance audit and find out exactly where your site stands — no obligation, just a clear list of what's working and what needs attention.
Learn More

Cookie Compliance: What a Banner Actually Covers (And What It Doesn't)

You've probably seen the pitch: install a $10/month cookie banner plugin and your website is suddenly "fully privacy compliant." That's not how it works — a cookie banner is one tool inside a bigger privacy framework, not a shield that protects you from every law that could apply to your site.
The common misconceptions
  • Believing a banner alone satisfies every privacy law that could apply to your business
  • Not realizing CCPA/CPRA (California's privacy law) only legally applies to businesses that cross specific thresholds — over $25 million in annual revenue, buying or selling personal data on 100,000+ California residents a year, or earning 50%+ of revenue from selling personal data
  • Treating "Do Not Sell or Share My Info" as decoration instead of a working opt-out link
Letting a banner default to "accepted" the moment someone closes it or scrolls past — current rules require the "reject" option to be just as easy to find as "accept"
Why it matters
If your business does cross those thresholds, non-compliance carries real financial risk, and vague or fake consent options don't hold up. If you don't cross them, you're not legally required to run a banner under CCPA — but plenty of vendors will sell you one anyway, and plenty of agencies will tell you you're required to when you're not, on either side of that line.
How to check if this applies to you
Look at your actual numbers: annual revenue, and whether you're tracking or sharing visitor data at any real scale. If you're a small local business under those thresholds, a lightweight, honest privacy policy may be all you need — you don't have to buy the biggest plugin on the market to be "safe."
Next step

Get a free compliance and performance audit and find out exactly where your site actually stands — no upsell, just a clear answer.
Learn More

HIPAA and Your Website's Intake Form: What Actually Triggers Compliance

Most healthcare websites don't need a HIPAA-compliant contact form. A basic "name, email, phone, send us a message" form isn't a HIPAA issue by itself. The line gets crossed the moment your form asks about symptoms, medical history, medications, or "reason for visit" — because at that point, you're collecting Protected Health Information (PHI), and that changes what's required.
The common misconceptions
  • Assuming a popular off-the-shelf form plugin is automatically HIPAA compliant — most aren't, unless your practice has a signed Business Associate Agreement (BAA) with that vendor
  • Believing PHI only means what's in a medical chart — a name paired with any health detail (a symptom, a medication, a reason for visit) typed into a "message" box counts as PHI too
  • Auto-forwarding form submissions to a regular, unencrypted inbox — one of the most common real-world HIPAA violations, not a hypothetical one
  • Trusting a "HIPAA compliant" badge on a form vendor's marketing page as proof — a badge is not a BAA, and a badge is not a legal shield
Why it matters
Penalties for operating without a proper BAA have ranged from roughly $31,000 to $2.7 million, and a covered entity (your practice) can be held liable even when the vendor is technically at fault, if reasonable due diligence wasn't done before handing that vendor patient data.
How to check if this applies to you
Ask your form vendor directly: will they sign a BAA, is submitted data encrypted end-to-end, and where does that data go after it's submitted? If email notifications land in a regular inbox with patient details spelled out, that's worth fixing today, not eventually.
This information is educational, not legal advice. For guidance specific to your practice or your state, talk to a healthcare attorney or compliance specialist.
Next step
​​​​​​​Want a straight answer on whether your intake forms are exposing you? Get a free compliance audit — we'll walk through exactly where the risk is, and where it isn't.
Learn More

Do Not Sell My Personal Information

Third-Party Disclaimer

We want to assure you that our company does not sell, rent, trade, or share your personal information with any third parties for marketing or profit-making purposes. Any information you choose to provide—such as your name, contact details, business information, or service preferences—is collected solely for the purpose of delivering the services you request, communicating with you regarding your project, and ensuring the best possible experience for you and your company. We do not participate in any data-broker programs, lead-selling networks, or third-party marketing exchanges. Our firm is a professional service provider, not a marketing company that gathers and distributes consumer information. Your data stays with us, securely stored, and used only in direct relation to the services you have chosen to receive. We maintain strict internal controls, safeguard all sensitive data, and uphold clear boundaries regarding access and use. If you would like to learn more about how we handle, store, and protect your information, please review our full Privacy Policy here:Privacy Policy. Your trust matters to us, and we are fully committed to protecting your privacy at every step.

Opt-out of Sale/Sharing

Note: This preference is stored via a cookie. If you clear your browser cookies, you will need to reset this preference.

🦢
★★★★★

Write a Review

Check Your Email

Your Review