Healthcare Web Development

UK Healthcare Website Compliance: The Complete 2026 Requirements Guide

Every compliance requirement a UK clinic, pharmacy, or practice website must meet in 2026: UK GDPR and PECR, CQC and GPhC display rules, advertising restrictions, accessibility standards, security, and a practical audit checklist.

Published16 September 2026
Last updated16 September 2026
Reading time18 min read
Pankaj Karad

Pankaj Karad

Founder & CEO

Pankaj Karad is the founder and CEO of Karad Infotech, a London-based digital agency specialising in web design, software development, and SEO for healthcare businesses. With extensive experience in pharmacy and dental clinic digital solutions, Pankaj leads the strategy and delivery of projects that help UK healthcare providers grow their online presence and patient bookings.

UK Healthcare Website Compliance: The Complete 2026 Requirements Guide

Healthcare website compliance in the UK rarely fails because a practice ignored the rules. It fails because nobody owns them. The privacy notice was written by a template generator in 2019, the cookie banner was added by a plugin that nobody configured, the CQC rating widget broke during a theme update, and the treatment page promoting a prescription-only medicine was written by a well-meaning marketing contractor who had never heard of the Human Medicines Regulations.

None of those problems are visible to the team day to day. All of them are visible to regulators, complainants, and increasingly to patients, who now expect a healthcare website to feel as trustworthy as the clinic itself.

This guide sets out what UK healthcare website compliance actually requires in 2026: the legal framework that applies, what the regulators expect to see on your site, the advertising rules that catch most clinics out, the accessibility and security standards to build to, and a practical audit checklist you can work through this week.

Quick Answer

A UK healthcare website must comply with five overlapping areas: data protection (UK GDPR, the Data Protection Act 2018, and PECR for cookies and marketing), regulator display rules (such as showing your current CQC rating under Regulation 20A, or GPhC registration details for pharmacies), advertising law (the CAP Code and the ban on advertising prescription-only medicines to the public), accessibility (the Equality Act 2010, WCAG 2.2 AA as the working standard, and the Accessible Information Standard for NHS-funded care), and security (encrypted handling of patient data, plus the NHS Data Security and Protection Toolkit where you access NHS data). Consumer and company disclosure law applies on top. Audit all five at least once a year and after every significant site change.

Why healthcare websites carry a heavier compliance load

Most business websites answer to data protection law, consumer law, and advertising standards. Healthcare websites answer to all of those plus a professional regulator, and they routinely process special category data, the most protected class of personal information under UK GDPR.

That combination changes the risk profile in three ways:

  • More regulators can act. The ICO, the ASA, the MHRA, and your professional or system regulator (CQC, GPhC, GDC, GMC, or NMC) each have a view on what your website says and does.
  • Ordinary features become regulated processing. A contact form asking "what is your enquiry about?" collects health data the moment a patient types a symptom into it.
  • Marketing copy becomes clinical communication. A treatment page is not just sales content; regulators treat claims about outcomes, safety, and medicines as matters of patient safety.

The practical consequence is that compliance cannot be a page in the footer. It has to be designed into the forms, the content, the tracking, and the hosting from the start, which is exactly how we approach it in our medical website development work.

AreaMain law or standardWhat it governs on your website
Data protectionUK GDPR, Data Protection Act 2018Forms, bookings, patient portals, privacy notices, retention
Cookies and marketingPECR, as amended by the Data (Use and Access) Act 2025Cookie consent, analytics, tracking pixels, email and SMS marketing
Regulator displayCQC Regulations 2014 (Reg 20A), GPhC standards and distance-selling guidanceRatings, registration details, responsible clinicians
AdvertisingCAP Code, Human Medicines Regulations 2012Treatment pages, offers, claims, medicine promotion
AccessibilityEquality Act 2010, WCAG 2.2 AA, Accessible Information StandardDesign, content, forms, documents
SecurityUK GDPR Article 32, NHS DSPT, Cyber EssentialsHosting, encryption, access control, incident response
Consumer and companyConsumer Contracts Regulations 2013, DMCC Act 2024, trading disclosure rulesPricing, cancellations, reviews, company details

The sections below take each area in turn.

Data protection: UK GDPR and the Data Protection Act 2018

Health data is special category data, so processing it needs both a lawful basis under Article 6 and a condition under Article 9. For most clinics and pharmacies that means relying on the provision of health care condition in the Data Protection Act 2018, supported by professional confidentiality, rather than on consent.

What that means for your website in practice:

  • A specific, accurate privacy notice. It must name you as controller, explain what you collect through each form and system, your lawful bases, who you share data with (booking platforms, PMR systems, payment providers), where data is stored, how long you keep it, and how patients exercise their rights. A generic template that mentions none of your actual processors is not compliant.
  • Data minimisation in every form. Ask only for what you need to respond. A general enquiry form rarely needs date of birth, NHS number, or medical history.
  • Secure transmission and storage. Form submissions containing health information should not land in a shared, unencrypted mailbox or sit indefinitely in a website plugin's database.
  • Processor agreements. Every third party that handles patient data on your behalf, from your host to your booking system, needs a contract meeting Article 28.
  • Retention rules you actually enforce. Decide how long enquiry and booking data is kept and make sure the website deletes it.
  • A Data Protection Impact Assessment for higher-risk features such as online consultations, patient portals, or symptom checkers.
  • ICO registration. Most healthcare organisations must pay the data protection fee.

Our detailed GDPR guide for healthcare and pharmacy websites covers form design, lawful bases, and processor contracts in depth.

Key Takeaway

Treat every free-text box as a potential health data collector. If a patient can type symptoms into it, it must be encrypted in transit, stored securely, covered by your privacy notice, and deleted in line with your retention policy.

Cookies, tracking, and PECR

The Privacy and Electronic Communications Regulations govern cookies and similar technologies, as well as electronic marketing. The Data (Use and Access) Act 2025 amended PECR, introducing limited consent exemptions for certain low-risk analytics and raising the maximum PECR penalty to UK GDPR levels. The exemptions are narrow, and they do not cover advertising or cross-site tracking.

For healthcare sites, tracking deserves particular care, because a tracking pixel on a page about sexual health, fertility, or weight-loss treatment can reveal health information to an advertising platform. The ICO has made clear it expects organisations to scrutinise exactly this.

Compliance requirements:

  • No non-essential cookies before consent, except where a specific statutory exemption genuinely applies.
  • "Reject" as easy as "accept" on the first layer of the banner, with no pre-ticked boxes.
  • Advertising pixels blocked until consent, and ideally kept off sensitive treatment pages altogether.
  • A cookie policy that matches reality, listing what actually loads.
  • Marketing consent captured separately for email and SMS, never bundled into a booking form's terms.

The practical detail, including how to configure consent tools so they block scripts rather than merely display a banner, is in our cookie consent guide for UK healthcare websites.

Regulator requirements: CQC, GPhC, GDC, and GMC

CQC-registered providers

If you are registered with the Care Quality Commission, Regulation 20A of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires you to display your most recent performance rating conspicuously on your website, as well as at your premises. In practice:

  • Show the rating on your homepage and on relevant location or service pages.
  • Link to your CQC profile page.
  • Keep it current. The CQC's own rating widget updates automatically, which is why most providers use it; if a redesign or theme update has broken it, you may be in breach without knowing.

Beyond the rating, the CQC's fundamental standards shape what your website should support: an accessible complaints process (Regulation 16), clear information about who provides care, and transparency when things go wrong under the duty of candour.

Pharmacies and the GPhC

Registered pharmacies should show their GPhC premises registration number and the name and registration details of the pharmacist responsible for the service. Pharmacies providing services at a distance, including online, must also follow the GPhC guidance for registered pharmacies providing pharmacy services at a distance, which sets expectations around prescribing safeguards, identity checks, and making clear who is providing care.

Selling medicines online has further requirements depending on where you operate, including MHRA distance-selling rules that differ between Great Britain and Northern Ireland. Our pharmacy ecommerce website guide walks through the prescription and online sales workflow in detail.

Dental, medical, and other practitioners

Dentists (GDC), doctors (GMC), nurses (NMC), and other registered professionals are bound by their regulator's standards on honest and accurate communication. Websites should:

  • Show practitioners' names and registration numbers, and where relevant their specialist list status.
  • Avoid titles or implied qualifications that are misleading, such as implying specialist status that is not held.
  • Present fees and treatment options clearly and fairly.

Our dental website legal requirements guide covers the GDC-specific detail.

Advertising rules: the area that catches most clinics out

Treatment pages, offers, and social content are advertising, and the CAP Code administered by the Advertising Standards Authority applies to your own website as well as to paid ads. Section 12 covers medicines, medical devices, and health-related claims.

The rules that most often cause problems:

  • Prescription-only medicines cannot be advertised to the public. Under the Human Medicines Regulations 2012 this covers botulinum toxin, prescription weight-loss injections, and many other treatments. You can describe the consultation service; you cannot promote the medicine itself. Naming a brand in a promotional context, offering discounts on a POM, or using imagery that promotes the product are all common breaches, and the ASA has taken repeated action against clinics on exactly these points.
  • Health claims need robust evidence. Claims that a treatment works, or works better, must be substantiated. Testimonials do not count as evidence for efficacy claims.
  • No claims to treat conditions for which medical supervision should be sought, unless the treatment is provided under suitable supervision.
  • Before-and-after images must be genuine and representative, not retouched and not cherry-picked.
  • No time-limited pressure on medical decisions. Promotions that rush patients towards a clinical procedure attract complaints and regulator attention.
  • Reviews must be real. The Digital Markets, Competition and Consumers Act 2024 explicitly bans fake reviews and concealing negative ones, with the CMA able to fine directly.

Key Takeaway

Write treatment pages about the consultation, the clinician, and the patient's options, not about a named prescription-only product. That single shift resolves most healthcare advertising problems while still giving search engines the depth they need to rank the page.

Accessibility standards

Healthcare websites serve older patients, patients with disabilities, and people who are unwell, so accessibility is both a legal duty and a basic quality measure.

  • Equality Act 2010. Private providers must make reasonable adjustments so disabled people are not placed at a substantial disadvantage, and that duty extends to services delivered through a website.
  • Public Sector Bodies Accessibility Regulations 2018. NHS bodies must meet the accessibility standard and publish an accessibility statement. Providers delivering NHS services should check whether they fall within scope.
  • Accessible Information Standard (DCB1605). Organisations providing NHS or publicly funded adult social care must identify, record, and meet patients' information and communication needs.
  • WCAG 2.2 Level AA is the benchmark regulators, courts, and procurement teams use. Build to it from the wireframe onwards.

Common failures on healthcare sites include low-contrast text, booking widgets that cannot be used by keyboard, PDFs of forms that screen readers cannot read, missing form labels, and time-out warnings that give no chance to extend. The full checklist is in our healthcare website accessibility guide.

Security requirements

UK GDPR Article 32 requires security appropriate to the risk, and for health data the risk is high. There is no single prescribed technical standard, but the baseline regulators expect is well established:

  • HTTPS everywhere, with modern TLS and HSTS.
  • Security headers including a content security policy.
  • Patched and supported software, with no abandoned plugins or end-of-life CMS versions.
  • Multi-factor authentication on every admin, hosting, and domain account.
  • UK or adequately protected hosting, with the transfer mechanism documented where data leaves the UK.
  • Backups, monitoring, and an incident response plan, including the 72-hour ICO breach reporting deadline.

If your organisation accesses NHS patient data or systems, as most GP practices, NHS dental practices, and community pharmacies do, you must complete the NHS Data Security and Protection Toolkit annually, and your website and its suppliers form part of that picture. Cyber Essentials certification is increasingly expected by NHS commissioners and is a sensible baseline for any healthcare provider.

For the complete technical baseline, see our healthcare website security guide.

Consumer and company disclosure law

Private healthcare is a consumer service, so general consumer law applies alongside the clinical rules:

  • Company and trading details. Registered name, company number, registered office, and contact details, required under the trading disclosure rules and the Electronic Commerce Regulations 2002.
  • Clear pricing. Show the total price including unavoidable fees. The DMCC Act 2024 strengthened enforcement against drip pricing and misleading pricing.
  • Cancellation rights. Online bookings and purchases generally carry a 14-day cancellation right under the Consumer Contracts Regulations 2013, with specific exceptions. State your cancellation and refund terms plainly.
  • Terms and conditions that match how bookings, deposits, and no-show fees actually work.

UK healthcare website compliance audit checklist

Use this as a working audit. Anything you cannot tick is a task.

Data protection

  • Privacy notice names your real processors, lawful bases, and retention periods
  • Every form collects only what it needs and transmits over HTTPS
  • Form submissions are stored securely and deleted on schedule
  • Processor agreements are in place for host, booking, CRM, and payments
  • DPIA completed for online consultations, portals, or symptom tools
  • ICO data protection fee paid

Cookies and tracking

  • No non-essential scripts load before consent
  • Reject is as prominent as accept
  • Advertising pixels absent from sensitive treatment pages
  • Cookie policy matches the scripts that actually load

Regulator display

  • Current CQC rating displayed and linked (if CQC-registered)
  • GPhC premises and responsible pharmacist details shown (if a pharmacy)
  • Practitioner names and registration numbers shown
  • Complaints procedure easy to find

Advertising

  • No prescription-only medicines promoted by name or offer
  • Every efficacy claim has evidence behind it
  • Before-and-after images genuine and representative
  • Reviews genuine and unfiltered

Accessibility

  • Tested against WCAG 2.2 AA with automated and manual checks
  • Booking and forms fully usable by keyboard and screen reader
  • Accessibility statement published
  • Documents available in accessible formats

Security

  • TLS, HSTS, and security headers configured
  • CMS, plugins, and dependencies supported and patched
  • MFA on all admin, hosting, and domain accounts
  • Backups tested and incident response plan documented
  • DSPT submitted on time (if accessing NHS data)

Consumer and company

  • Company details in the footer or legal page
  • Prices shown in full, with cancellation terms clear
  • Terms and conditions reflect actual booking practice

Key Takeaway

Run this audit at least once a year, and again after any redesign, new booking system, new tracking tool, or new treatment launch. Most compliance breaches are introduced by change, not by neglect.

How often should you review compliance?

Set a rhythm rather than waiting for a complaint:

  • Annually: full audit against the checklist above, aligned with your DSPT submission if you have one.
  • Quarterly: check the CQC rating display, cookie behaviour, and any new pages or offers for advertising issues.
  • On every change: a new form, integration, tracking tag, or treatment page should get a compliance check before it goes live.
  • After a redesign: re-audit everything, because rebuilds are when rating widgets break, consent tools get reconfigured, and legal pages go missing. Our healthcare website redesign guide builds compliance checks into each phase for exactly this reason.

Bringing it together

UK healthcare website compliance comes down to five disciplines working together: lawful, minimal, secure handling of patient data; consent-led tracking; accurate regulator disclosures; advertising that informs rather than promotes regulated medicines; and a site that every patient can use. None of it is exotic, but all of it has to be owned. The practices that stay compliant are the ones that design it into the build and review it on a schedule, rather than discovering the gaps when a complaint arrives.

Useful next reads:

If you are not sure where your site stands, get in touch and we will audit it against every area in this guide and give you a prioritised list of fixes.

Medical Website Development UK

Compliant healthcare websites for UK clinics, pharmacies, and practices, with UK GDPR-ready forms, consent-led tracking, WCAG 2.2 AA accessibility, and regulator disclosures built in from day one.

About the Author

Pankaj Karad

Pankaj Karad

Founder & CEO

Pankaj Karad is the founder of Karad Infotech, a London-based agency specialising in web design, SEO, and software development for healthcare businesses across the UK.

Connect on LinkedIn

FAQ: UK healthcare website compliance

A UK healthcare website must comply with UK GDPR and the Data Protection Act 2018 for patient data, PECR for cookies and electronic marketing, the CAP Code and Human Medicines Regulations 2012 for advertising, the Equality Act 2010 for accessibility, and consumer and trading disclosure law for pricing, cancellations, and company details. On top of that, your professional or system regulator, such as the CQC, GPhC, GDC, or GMC, sets its own expectations about what your website must display and how you communicate with patients.

Do I have to display my CQC rating on my website?

Yes. Regulation 20A of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires CQC-registered providers to display their most recent rating conspicuously on their website, as well as at their premises. Most providers use the CQC's own widget because it updates automatically. Check it after any site update, because a broken or removed widget can put you in breach without anyone noticing.

Can my clinic website mention Botox or weight-loss injections?

You can describe the consultation and treatment service you offer, but you cannot advertise prescription-only medicines to the public. That means no promoting products by brand name, no discounts or offers on the medicine itself, and no imagery that promotes the product. The ASA has repeatedly ruled against clinics for this, including on social media posts. Focus your pages on the consultation, the clinician's expertise, suitability, and the patient's options.

Is a contact form on a healthcare website processing health data?

Very often, yes. If patients can describe symptoms, conditions, or treatments in a form, you are collecting special category data under UK GDPR, even if you did not ask for it. That form needs HTTPS, secure storage, a clear privacy notice, a retention period, and a processor agreement with any third party that handles the submissions. Reduce the risk by asking only for what you need and guiding patients not to share clinical detail in a general enquiry.

What accessibility standard should a healthcare website meet?

Build to WCAG 2.2 Level AA. It is the benchmark used to judge reasonable adjustments under the Equality Act 2010 and the standard required of NHS bodies under the Public Sector Bodies Accessibility Regulations 2018. Providers of NHS-funded care must also meet the Accessible Information Standard, which covers identifying and meeting patients' communication needs. Test with automated tools and with real keyboard and screen reader use.

How often should a healthcare website be audited for compliance?

Run a full audit at least once a year, ideally alongside your NHS Data Security and Protection Toolkit submission if you complete one. Carry out quick quarterly checks on your rating display, cookie behaviour, and new content, and review every new form, integration, tracking tag, or treatment page before it goes live. Always re-audit after a redesign, because rebuilds are when compliance features most often break.

Need a partner to implement this? We build compliant websites, custom software, and ongoing SEO programmes for UK pharmacies, dental clinics, and wider healthcare SMEs.
Pankaj Karad

Pankaj Karad

Founder & CEO

Pankaj Karad is the founder and CEO of Karad Infotech, a London-based digital agency specialising in web design, software development, and SEO for healthcare businesses. With extensive experience in pharmacy and dental clinic digital solutions, Pankaj leads the strategy and delivery of projects that help UK healthcare providers grow their online presence and patient bookings.

Visit website