Third-party hosting

As a healthcare organization, Penn Medicine applies strict requirements for third-party hosting, including HIPAA compliance and a Business Associate Agreement (BAA) when personal health information is involved. Third-party hosting must also meet privacy, security, accessibility, and performance standards.

Technical standards overview
Browser and device compatibility
Domain policy
Former Site URL redirects
HIPAA and privacy
Image optimization
Page load time
Performance
Technical SEO standards
Third-party hosting
Use of QR codes
Vanity URLs

Standard scope

This standard applies to:

  • pennmedicine.org
  • All Penn Medicine websites
  • Penn Medicine mobile applications
  • All Penn Medicine digital products

Overview

Standards sustain patient trust and help guard Penn Medicine from data breaches, accessibility violations and legal liabilities. For Penn Medicine, as a healthcare organization, third-party hosting web standards are essential to:

  • Safeguard patient data and privacy (HIPAA)
  • Guarantee accessible digital services (ADA/WCAG)
  • Protect against security risks and legal exposures
  • Ensure consistent, high-quality performance
  • Preserve brand reputation and trust
  • Enable seamless system integration

Penn Medicine requirements

To achieve compliance for third party hosting, refer to the following requirements:

Contact

For questions, please contact  web-standards@pennmedicine.upenn.edu

Last updated

Date
Version
Description
08/11/25
1.0.0
Initial Release