Free Tool · Instant Results · No Follow-Up Emails
Is your practice's website quietly leaking privacy risk?
Enter your website and get an instant check of the three things we find broken most often: your privacy policy, tracking scripts firing before consent, and whether anyone can send email pretending to be you. Results on screen in about a minute, plus a copy to your inbox.
What this check cannot see: the written HIPAA Risk Analysis, your vendor BAAs, training records, and internal policies, which is where most enforcement actually lands. If anything above came back red, that is usually the tip of it.
Get the $750 full review or book a free consultation →What does this tool check?
- Privacy policy: whether one is linked from your homepage and how recently it appears to have been updated. Rules changed in 2025 and 2026; a stale policy is a visible signal.
- Tracking technologies: whether analytics, advertising pixels, or session-recording scripts load in your page source, and whether a consent tool is present. For healthcare sites, trackers on patient-facing pages have drawn federal scrutiny and class actions.
- Email spoofability: whether your domain publishes SPF and enforced DMARC records. Without them, anyone can send email as your practice, and cyber insurers increasingly check.
The check reads only your public website and DNS records. It never logs into anything, stores patient data, or scans beyond the address you submit. Built by Sam Cherkaoui, CIPP/US, North Privacy Advisors.