You may want to take a look at this article, which shows how to embed a report in a secure portal or website like Power Pages.
As for whether it is "legally and securely able to do this", you'll have to make sure your entire configuration is secure, and consider using row-level and object-level security, use a secure embedded code, secure your site, and make sure that your data source is secure, that you have established proper access controls and that it does not contain unnecessary PII or PHI for which you have no valid business reason for storing (a.k.a. the "we keep everything forever" retention policy 😉). You also have to consider your organization's internal processes are in compliance.
Ultimately, you have to evaluate the system according to your organization's security standards; don't let anybody else tell you whether it is secure enough for your needs or not. But I'm sure you already know that!
For more information, take a look at the Health Insurance Portability and Accountability Act & Health Information Technology for Economic and Clinical Health Act in the Microsoft compliance offerings documentation.
I hope this helps?!