My Marketing Site Had a HIPAA Badge. I’m an Australian Solo Founder.
Compliant by Design — Essay 02
Most founders never audit their own marketing site the way they’d audit their code. I only audited mine because I was heading into a redesign, and what I found was a site making claims about a product that didn’t exist yet, on behalf of a team that has never existed, under a law that doesn’t apply in this country. Nobody sat down and wrote those lies on purpose. That’s the part worth reading about.
The product, for context
Miinfo is an emergency medical-information product: a QR code that gives a first responder your critical health information when you can’t speak for yourself. The current build will be shipped for Australians, which means the Privacy Act 1988 and the APPs. And because it handles health information, it sits in the most sensitive category the Act recognises. A product like this sells exactly one thing: trust.
What the audit found
A content audit of the marketing site turned up, in one pass:
- A HIPAA trust badge. HIPAA is a United States statute. It does not apply to an Australian product serving Australians, and displaying the badge doesn’t just overclaim; it claims compliance with someone else’s legal system.
- HIPAA wasn’t only copy. The product had a HIPAA Release Form and a US attorney-referral feature. Whole features built for a jurisdiction the product isn’t in.
- “Privacy Act 1988 Compliant,” asserted before any lawyer had signed off and before a privacy impact assessment existed.
- “Medical-grade encryption.” There is no such thing. It’s an undefined term that sounds like a standard.
- “Trusted by healthcare professionals worldwide,” on a product with no users.
- A founding team that doesn’t exist. Names and roles, invented.
- App Store links for an app that hadn’t shipped.
- Pricing that told three different stories across the pricing page, the FAQ, and the business plan.
How a site lies without a liar
None of this was deliberate deception. It’s what happens when marketing copy is assembled fast from templates and AI assistance: the generator pattern-matches what credible health-tech sites say, and credible health-tech sites say HIPAA, say compliant, say trusted-by-professionals. Every claim is plausible boilerplate; none of it was checked against the actual product, the actual team, or the actual jurisdiction. Optimism autocompletes. The output is a site optimised to look trustworthy, which is precisely the property that makes it dangerous, because nobody reviews copy that looks right.
If any part of your site was generated or templated, assume it contains claims you never decided to make. Mine did.
Why this is a legal problem, not a taste problem
Three separate framings, in ascending order of discomfort. First, APP 1: the foundation of the Australian regime is open and transparent management of personal information, and a privacy posture built on claims you can’t substantiate fails at step zero. Second, the Australian Consumer Law prohibits misleading or deceptive conduct in trade or commerce. A fake team, a fictional user base, and an undefined encryption standard aren’t puffery; they’re disprovable statements of fact on a commercial site. Third, jurisdiction hygiene: US frameworks pasted into an Australian product signal that the founder doesn’t know which law governs them. For a product asking people for their health information, that’s disqualifying.
I’m not a lawyer, and that’s exactly the point. It’s why “Privacy Act 1988 Compliant” had to go regardless of how compliant the architecture might eventually be. Compliance is a conclusion someone qualified reaches, not a badge you award yourself.
The fix was a list, not an edit
The obvious response is to fix the copy. That’s not enough on its own, because one-off copy fixes decay: pages get regenerated, a future AI-assisted session helpfully restores the impressive-sounding claims, and the same failure ships twice. So the audit findings became a permanent banned-claims list, embedded in the redesign brief itself: claims that must never render, each paired with a safe replacement.
- “Privacy Act 1988 Compliant” → “Built for the Privacy Act 1988 & APPs.” A design intention, stated truthfully.
- “Medical-grade encryption” → the specific, true encryption claims, verified against the actual infrastructure before being written down.
- The HIPAA Release Form and attorney-referral features → deleted, not restyled. When the feature itself belongs to another jurisdiction, the only honest edit is removal.
The list travels with the brief, so any future executor, human or AI, regenerating a page is constrained by rule, not by whether anyone remembers the audit.
The uncomfortable takeaway
Here’s what surprised me: the honest story is strategically stronger than the inflated one. A solo founder, building under Australian law, naming the real hosting region and the migration plan: that’s the exact differentiator the template copy was burying under borrowed American credibility. False claims are disprovable; every claim is a landmine waiting for a diligent customer, journalist, or regulator. Australian-ness was the moat, and the boilerplate was filling it in.
The transferable lesson: audit your marketing claims the way you audit your code. Every sentence on the site is an assertion; each one should trace to something true. And when you find the false ones, don’t fix the instances. Ban the class.
Compliant by Design is a fortnightly series on building AI products under Australian regulation — Privacy Act, APPs, NDB, health data — written from inside the work, not above it.