My Marketing Site Had a HIPAA Badge. I’m an Australian Solo Founder.

Compliant by Design — Essay 02


Most founders never audit their own marketing site the way they’d audit their code. I only audited mine because I was heading into a redesign, and what I found was a site making claims about a product that didn’t exist yet, on behalf of a team that has never existed, under a law that doesn’t apply in this country. Nobody sat down and wrote those lies on purpose. That’s the part worth reading about.

The product, for context

Miinfo is an emergency medical-information product: a QR code that gives a first responder your critical health information when you can’t speak for yourself. The current build will be shipped for Australians, which means the Privacy Act 1988 and the APPs. And because it handles health information, it sits in the most sensitive category the Act recognises. A product like this sells exactly one thing: trust.

What the audit found

A content audit of the marketing site turned up, in one pass:

How a site lies without a liar

None of this was deliberate deception. It’s what happens when marketing copy is assembled fast from templates and AI assistance: the generator pattern-matches what credible health-tech sites say, and credible health-tech sites say HIPAA, say compliant, say trusted-by-professionals. Every claim is plausible boilerplate; none of it was checked against the actual product, the actual team, or the actual jurisdiction. Optimism autocompletes. The output is a site optimised to look trustworthy, which is precisely the property that makes it dangerous, because nobody reviews copy that looks right.

If any part of your site was generated or templated, assume it contains claims you never decided to make. Mine did.

Three separate framings, in ascending order of discomfort. First, APP 1: the foundation of the Australian regime is open and transparent management of personal information, and a privacy posture built on claims you can’t substantiate fails at step zero. Second, the Australian Consumer Law prohibits misleading or deceptive conduct in trade or commerce. A fake team, a fictional user base, and an undefined encryption standard aren’t puffery; they’re disprovable statements of fact on a commercial site. Third, jurisdiction hygiene: US frameworks pasted into an Australian product signal that the founder doesn’t know which law governs them. For a product asking people for their health information, that’s disqualifying.

I’m not a lawyer, and that’s exactly the point. It’s why “Privacy Act 1988 Compliant” had to go regardless of how compliant the architecture might eventually be. Compliance is a conclusion someone qualified reaches, not a badge you award yourself.

The fix was a list, not an edit

The obvious response is to fix the copy. That’s not enough on its own, because one-off copy fixes decay: pages get regenerated, a future AI-assisted session helpfully restores the impressive-sounding claims, and the same failure ships twice. So the audit findings became a permanent banned-claims list, embedded in the redesign brief itself: claims that must never render, each paired with a safe replacement.

The list travels with the brief, so any future executor, human or AI, regenerating a page is constrained by rule, not by whether anyone remembers the audit.

The uncomfortable takeaway

Here’s what surprised me: the honest story is strategically stronger than the inflated one. A solo founder, building under Australian law, naming the real hosting region and the migration plan: that’s the exact differentiator the template copy was burying under borrowed American credibility. False claims are disprovable; every claim is a landmine waiting for a diligent customer, journalist, or regulator. Australian-ness was the moat, and the boilerplate was filling it in.

The transferable lesson: audit your marketing claims the way you audit your code. Every sentence on the site is an assertion; each one should trace to something true. And when you find the false ones, don’t fix the instances. Ban the class.


Compliant by Design is a fortnightly series on building AI products under Australian regulation — Privacy Act, APPs, NDB, health data — written from inside the work, not above it.