Look at your HIPAA Notice of Privacy Practices. If it is dated prior to 2013, it’s not compliant with current standards.
Office after office, website after website, I see template Notice of Privacy Practices dated 2003. Much has changed in those 10 years.
For a recap on what HIPAA requires for your website, read our previous post