This page describes controls in place for the Divaker Pediatrics marketing website. It is not a certification and does not claim HIPAA, SOC 2, or ADA compliance. It is maintained by the practice and describes what is currently implemented.
In-place controls
- HTTPS-only delivery (HSTS via host).
- Security response headers:
X-Content-Type-Options,Referrer-Policy,Permissions-Policy,X-Frame-Options,Content-Security-Policy. - Server-side input validation on all form submissions.
- Database access protected by row-level security policies. Admin operations require authenticated staff accounts.
- No advertising pixels, session-replay, or third-party analytics are loaded on this website.
- No Protected Health Information is collected through the website. Booking and messaging happen inside HIPAA-capable third-party systems (healow, eClinicalWorks).
Shared responsibility
Website controls are one layer of a broader program. The practice is responsible for workforce access, workstation security, incident response, and vendor management — including Business Associate Agreements where PHI is involved.
Report a security concern
If you believe you have found a security or privacy issue with this website, please call the office and ask to speak with the privacy officer, or submit a data / privacy request with a description of the concern (please do not include exploit details or personal health information).
