Skip to main content

Fixed scope. A two-week plan.

Find out what your website is sending to advertising and analytics tools.

Pages and forms can send information to third-party tools. We observe the agreed workflows using synthetic data, document what leaves the site and prepare a prioritized fix plan for your team and counsel.

What the audit covers

We watch what goes out.

The audit observes technical behavior within a written test scope. Your counsel determines which legal requirements apply to the information and its use.

HHS issued tracking guidance in 2022 and revised it in 2024. A federal court partially vacated that guidance in June 2024 as to an IP address combined with visits to certain unauthenticated public health pages. The information and context matter; a public-page visit alone does not establish a HIPAA violation. See the current HHS guidance and court-order notice.

Observe authorized test workflows

Inspect network requests from the representative pages and workflows agreed in writing, using authorized synthetic test sessions. Record observed destinations and data fields. Patient records, real visitor sessions and unsolicited access are outside the base scope.

Technical evidence for your team and counsel

Document data flows, configuration issues and questions for counsel to assess under applicable privacy requirements. The work provides technical findings and an implementation plan; it does not determine compliance or issue legal opinions.

What you get

Findings, priorities and an evidence report.

Deliverable 01

A findings document

One row per observed finding: the test workflow, request destination, relevant fields and configuration issue, with questions for your team and counsel.

Deliverable 02

A fix list, ranked by exposure

Priced with a fixed quote to execute it in the same envelope. Hand it to your own team or have us do the work. Your call, and you know the price either way.

Deliverable 03

An evidence report written for counsel

Your lawyer can read it without a translator, and it answers the question that started this.

What this is not: a certification, an attestation, or a warranty that your site is clean. We report observed behavior within the agreed tests. Implementation requires your approval and a separate scope.

Price

Fixed fee. Never hourly.

Planned delivery is two weeks after written authorization, access and scope are agreed. Week one covers interviews, inventory and authorized synthetic test sessions. Week two documents findings, prioritizes fixes and prepares a remediation quote, followed by a walkthrough. Access delays or scope changes can change the schedule.

The $24,500 cap covers only the properties, representative pages, workflows, access levels and test rounds named in the signed scope. It does not buy unlimited properties or testing. Additional scope needs a separate written quote. Rush delivery adds $3,000 if available; remediation is separate.

First property $9,500
Each additional agreed property $2,800
Cap for the agreed property and test scope $24,500
One-week rush, subject to availability +$3,000
Remediation Quoted separately

Fit

Who this is for, and who it isn't.

For

  • Healthcare practices and groups running ads or analytics on pages that touch appointments, portals or intake
  • Lenders, mortgage, insurance and wealth firms taking applications online
  • Any company with California visitors running session recording, chat or call tracking
  • Operators with several properties: multi-location groups, franchise systems, brands with microsites

Not for

  • You need a signed certification, a SOC 2 letter or a HITRUST assessment. Those are outside this technical audit scope.
  • You want the whole site rebuilt. Scope is capped in writing at inventory, findings and the fix quote.
  • You run a brochure site with no forms, no chat, no call tracking and no ad pixels. There's probably nothing to find, and we'd rather say that on the call than bill you for it.

Questions about the scope

What does a website data leak audit actually check?

We inspect network requests from representative pages and workflows agreed in writing, using authorized synthetic test sessions. The report records observed destinations, fields and configuration issues. Patient records, real visitor sessions and unsolicited access are outside the base scope. Your team and counsel assess the findings in context.

How much does the audit cost?

The first property is $9,500 and each additional agreed property is $2,800. The $24,500 cap covers only the properties, representative pages, workflows, access levels and test rounds named in the signed scope. It does not buy unlimited properties or testing. Additional scope needs a separate written quote. Rush delivery is subject to availability and adds $3,000; remediation is separate.

How long does it take?

Planned delivery is two weeks after written authorization, access and scope are agreed. Week one covers interviews, inventory and authorized synthetic test sessions. Week two documents findings, prioritizes fixes and prepares a remediation quote, followed by a walkthrough. Access delays or scope changes can change the schedule.

Is this a compliance certification?

No. The deliverables are technical findings, a prioritized fix list and an evidence report for your team and counsel. This is not a legal opinion, certification, attestation or warranty that the site has no issues.

Why do tracking pixels create legal risk?

Tracking can disclose page, form or account data to third parties. Whether HIPAA or another law applies depends on the information, organization and use. HHS published tracking guidance in 2022 and revised it in 2024. A federal court partially vacated that guidance in June 2024 as to an IP address combined with visits to certain unauthenticated public health pages. Your counsel assesses the legal implications of the observed data flows.

One next step

Discuss the scope of a website audit.

Leave your contact details, company name and timeline. We will follow up about your domains and workflows before defining the audit scope.

Business inquiries only. Please do not include patient names, dates of birth, medical details, or other patient information in this form.

2000 characters remaining.

Please do not include passwords, patient information or confidential information.

Business inquiries only. Please do not include patient information, credentials or confidential information. Privacy policy

Website Data Leak Audit

Define the audit scope.

Start with your properties.

ModLab logo

Tell us your domains and workflows. The proposal will name the properties, access and synthetic tests included.