Most web developers building sites for therapists and medical professionals aren't thinking about any of this.
Here's what they miss:
Contact forms that aren't HIPAA-compliant encrypted channels. Standard form builders (Gravity Forms, WPForms, basic Squarespace forms) are not compliant for collecting PHI — and "what brings you in today?" on your intake form IS PHI.
Scheduling tools that aren't BAA-covered. Tools like Calendly, in their standard form, don't sign Business Associate Agreements. You need one. Acuity, SimplePractice, and Jane App do. Your developer needs to know the difference.
Website hosting without a BAA. If your site collects any patient data and your host doesn't offer a BAA, you have a problem. Generic WordPress hosting doesn't cover this.
Google Analytics tracking patient behavior. If someone visits your depression therapy page and fills out a form, that behavioral data touching a form submission can become a compliance issue depending on configuration.
Blog content that inadvertently identifies clients. A case study that's "anonymized" but recognizable to the person it describes is still a violation.
Third-party chat widgets. That Tidio or Intercom widget on your site? If a prospective patient types their symptoms into it, where does that data go? Whose servers? What's the retention policy?