Skip to content
Analytics

Is Your Marketing Analytics HIPAA Compliant? Most Practices Are Wrong About This

A practice manager called me a few months ago, certain her marketing was HIPAA compliant. Her agency had told her so. Her web vendor had told her so. She had a signed business associate agreement with her EHR company and a HIPAA policy binder on the shelf.

Then I pulled up her website in a browser, opened the network tab, and watched it fire a Meta Pixel and a Google Analytics tag the moment a patient landed on her “schedule a colonoscopy” page. Both tags were sending the page URL, the visitor’s IP address, and a persistent identifier to two of the largest advertising companies on earth. Nobody had signed anything with either one.

That is a HIPAA problem. A serious one. And almost every practice I audit has some version of it running right now, usually without knowing it exists.

I want to walk through what HIPAA actually requires of your marketing analytics, where the violations hide, and how to keep measuring your marketing without exposing your practice. This is the part of healthcare marketing that nobody sells you, because it is unglamorous and it does not generate leads. It just keeps you out of a settlement.

The Thing Almost Everyone Gets Wrong

Most people in healthcare think of protected health information as the obvious stuff. Names, diagnoses, dates of birth, the contents of a chart. They picture a spreadsheet of patient records getting emailed to the wrong address.

HIPAA is broader than that, and the gap is exactly where marketing lives.

Protected health information is any information that relates to a person’s health condition, care, or payment for care, and that can be tied back to an individual. The second half of that sentence is the trap. You do not need a name to identify someone. An IP address is an identifier. A device ID is an identifier. A cookie that follows someone across the web is an identifier.

So when a visitor lands on a page about a specific condition, treatment, or provider, and your website ships their IP address plus that page URL off to a third party, you have potentially just disclosed protected health information. The URL says something about their health. The IP says who they are. Together they are exactly what HIPAA was written to protect.

In December 2022, the HHS Office for Civil Rights made this explicit in a bulletin on tracking technologies, and revised it again in March 2024. The agency stated plainly that the combination of an individual’s IP address with a visit to a page about a specific health condition can constitute protected health information, even if the person never logs in, never books an appointment, and never enters their name. The visit itself is the disclosure.

That single clarification turned the standard marketing stack into a compliance liability for a lot of practices overnight.

Where The Violations Actually Hide

When I audit a practice’s analytics setup, the problems are almost never in the EHR or the patient portal. Those systems are usually locked down because everyone knows to lock them down. The exposure is in the marketing layer, where nobody was thinking about HIPAA at all.

Here is where I find it.

The Meta Pixel is the most common offender. Practices install it to run Facebook and Instagram ads, and by default it tracks every page view and sends that data back to Meta to optimize ad targeting. In 2022, an investigation by The Markup found the Meta Pixel installed on the websites of 33 of the top 100 hospitals in America. A third of the largest hospital systems in the country were running it. If they were exposed, your three-provider specialty practice almost certainly is too.

Standard Google Analytics is the next one. The default GA4 configuration collects IP-derived location and a client identifier on every page, including your condition pages and your provider bios. Google does not sign business associate agreements for the standard analytics product, which means there is no legal cover for the data it collects.

Then there are the quiet ones. Call tracking widgets that record and transcribe patient calls. Chat tools that log conversations. Heatmap and session-recording software that literally films a visitor moving through your appointment request form. Scheduling embeds from a third party that see every field a patient types. Each of these can carry protected health information to a vendor who never agreed to protect it.

In July 2023, OCR and the Federal Trade Commission sent a joint warning letter to roughly 130 hospital systems and telehealth providers about exactly this category of tracking technology. When two federal agencies coordinate a mailing to that many organizations, the enforcement posture is not theoretical anymore.

Why “We Anonymize It” Does Not Save You

The most common defense I hear is that the practice turned on IP anonymization, or that the data is aggregated, so it cannot identify anyone.

I wish that held up. It usually does not.

IP anonymization in Google Analytics truncates the last part of the address, which reduces precision but does not reliably prevent re-identification, especially when combined with the other signals these tools collect. Aggregation only protects you if the data was never individually identifiable in transit, and the disclosure to the third party already happened before any aggregation occurred. HIPAA cares about the moment of disclosure, not what the recipient does with the data afterward.

There is also a contract problem underneath all of this. A disclosure of protected health information to a vendor is only permissible if that vendor has signed a business associate agreement taking on HIPAA obligations. Meta will not sign one for the Pixel. Google will not sign one for standard Analytics. So even if you believed the data were perfectly de-identified, the legal structure that HIPAA requires simply does not exist with these vendors. There is no version of “we anonymized it” that creates a business associate agreement after the fact.

How To Fix It Without Going Blind

Here is the part practice owners worry about. They hear all this and assume the only compliant option is to turn everything off and fly blind on their marketing. That is not true, and it is the wrong response. You can measure your marketing rigorously and stay compliant. You just have to change where the measurement happens.

Start with an audit. Open your website, look at every tag and tracker firing on it, and map what each one collects and where it sends that data. Most practices have no current inventory of this, and you cannot fix what you have not found. If you do nothing else after reading this, do that.

Move to server-side tracking for the data you need to keep. Instead of a visitor’s browser shipping raw data straight to Google or Meta, the data routes through a server you control, where you can strip identifiers and sensitive parameters before anything leaves. This is the technical fix that lets you keep measuring conversions without disclosing protected health information. It takes engineering work, but it is the difference between compliant analytics and a liability.

Get business associate agreements in place for every vendor that touches data which could be protected health information. Some analytics and call tracking vendors will sign one and configure a compliant version of their product. Use those. Drop the ones that will not.

Treat your condition pages and provider pages as the sensitive zone they are. The page about a specific procedure is where the health inference lives. That is where tracking needs to be the most careful, not the least.

And keep your conversion measurement focused on what actually matters to the practice, which is whether marketing is producing patients, not whether you can retarget a specific person who read about a diagnosis. You can answer the business question cleanly without ever collecting the data that creates the risk.

The Real Cost Of Getting This Wrong

I am not writing this to scare anyone into a panic. I am writing it because the gap between what practices believe about their compliance and what is actually running on their websites is the widest I see anywhere in healthcare marketing.

The settlements in this area are not small, the enforcement is active, and the reputational damage of a breach notice going out to your patient base is the kind of thing a small practice does not recover from quickly. All of it traces back to a few lines of tracking code that someone installed years ago to make the ads work, and that nobody has looked at since.

The fix is not complicated, but it does require someone who understands both the marketing technology and the compliance obligation, because the people who usually own each half rarely talk to each other. Your agency knows ads. Your compliance officer knows HIPAA. The exposure lives in the seam between them.

If you want a clear answer on what is firing on your practice website and whether it puts you at risk, that is exactly the kind of audit I do. Book a consultation at huntgrowth.net/contact and I will walk through your actual setup with you, in plain language, and tell you where you stand. No binder of policies. Just a look at what your website is really doing.

Ryan

William Hunt

William Hunt

Founder of HuntGrowth. Computer scientist, Johns Hopkins MBA, 21+ years building growth engines for organizations from the Pentagon to healthcare AI.

Learn more →

Want the whole system, not just this post?

This is one slice of how I market in health tech. The full playbook is 25 chapters and 210 pages of the exact frameworks I run. Long sales cycles, the buying committee, HIPAA-aware campaigns, the 90-day plan you can start Monday.

See the Healthcare SaaS Marketing Playbook

Marketing & Growth Insights

Monthly strategies for data-driven growth. No fluff, no spam, just what works.

Ready to build a growth engine?

Let's talk about how an engineer's approach to marketing can transform your business.

Schedule a Call