Is Squarespace HIPAA Compliant?
No. Squarespace does not sign Business Associate Agreements. That does not mean you cannot use it for a practice website, but it does decide where your patient forms can live.
Short answer: no. Squarespace does not sign Business Associate Agreements, which means it cannot be the place your patients enter health information.
That is a narrower statement than it first sounds, and the distinction is worth a few minutes because it decides whether you need to rebuild your site or just move one form.
Why the answer is no
Under HIPAA, any company that receives, stores or transmits protected health information on your behalf is a business associate and needs a signed agreement with you. It is not optional and there is no version of it that happens by default.
Squarespace does not offer one. Their platform is built for general business websites, and the company has not positioned it for regulated health data. There is no enterprise tier that changes this, which is different from some vendors where the answer is really "not on your current plan."
So a Squarespace form that asks a patient why they are booking is collecting health information into a system nobody has signed for.
What still works perfectly well
A Squarespace site is fine for everything that is not patient data, and that is most of a practice website.
Your services, your team, your hours, your location, your pricing, your blog, photographs, directions, a phone number. None of that is protected health information and none of it needs a BAA. There is no rule against a dental practice using Squarespace, and we are not going to invent one.
The line is the moment somebody types something about their own health.
Where practices cross the line without noticing
Four patterns account for nearly all of it.
The contact form with an open message box. The form asks for name, email and "how can we help." A patient writes "I think I cracked a molar and it has been throbbing since Tuesday." That is health information, volunteered, sitting in a system with no agreement behind it. The form was never designed to collect it, which does not help.
Appointment request forms. Anything asking what the appointment is for.
New patient intake. Obvious once you look, and surprisingly often still on the site.
A scheduler embedded on the page. Even where the scheduling vendor will sign, the page around it is still Squarespace, and what else loads on that page is still your responsibility.
The fix itself is small
You almost never need to leave Squarespace.
Move the patient-facing forms to a service that will sign a BAA, and link or embed them instead of using native Squarespace forms. Your marketing site stays exactly as it is. The work is typically an afternoon.
Two things to get right while you do it. Make sure the form vendor's agreement covers the specific feature you are using rather than just their core product. And check what else is loading on the page where the form sits, because an embedded compliant form on a page running a tracking script is still a problem, and that part is your page rather than their product.
What the fix leaves you holding
That last sentence is the whole reason this article does not end here.
Once you embed a covered form into a Squarespace page, the vendor is responsible for the form and you are responsible for the page. That is the correct division and it is not a bad deal. It does mean the exposure moves rather than disappears, and it moves to the one place nobody is watching.
Your page is a surface anyone with access can add to. A marketing agency adds a conversion tag to the appointment page, which is exactly where a competent agency puts a conversion tag. Somebody turns on a Squarespace analytics integration because it looked useful. A new location page gets built and the native form is copied onto it, because the native form is what was there to copy. Every one of those is somebody doing their job, and every one of them lands on your side of the line.
When we scanned 4,601 independent practice sites in July 2026, 44.9% had a third-party tracker running on a page that carries a patient form, the most common by far being ordinary Google Analytics. Across all four things we measured, 88.0% produced at least one finding and 10.7% came back with nothing to report. Almost none of those sites launched broken. They launched fine and then a year happened to them.
So the afternoon of work is real and it is worth doing. What it buys is a correct configuration on a Tuesday. Keeping it correct is a different job, and it is ongoing, and on a builder you control it belongs to you.
What about the rest of them
The answer is similar for most mainstream builders. Wix, GoDaddy's builder and Weebly do not sign either. WordPress is software rather than a company, so what matters there is the host underneath it.
We go through the whole set in what actually qualifies as a HIPAA compliant website builder.
Where to go from here
If you are on Squarespace and unsure whether any of your forms are collecting health information, start with the scan. It reports which pages carry forms, what is loading on them, and whether the companies behind them will sign for what they receive.
If you would rather not own the page-watching job, our Managed Plan takes the whole path instead: the site, the hosting, the form chain and the agreements as one relationship, rechecked on a schedule. Practices move to it not because Squarespace failed them, but because nobody wants a compliance task that has to be redone quietly every time somebody edits a page.