Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Consulting US · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic →
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
US compliance pillar · HIPAA · Meta Ads · 2026

HIPAA-safe Meta Ads for aesthetic practices — Personal Attributes, hashed audiences, Conversion API and the revoked-BAA workaround

A working reference for aesthetic practice owners, cosmetic surgeons, medspa growth heads and agency practice leads running Meta advertising campaigns under HIPAA. Written against the March 2024 Office for Civil Rights tracking-technology bulletin update, Meta's Personal Attributes and health-and-wellness policies, and the operational reality that Meta withdrew its HIPAA Business Associate Agreement years ago and has not restored it.

Direct answer
  • Meta will not sign a HIPAA Business Associate Agreement for Meta Ads. This constraint applies across Meta Ads, Meta Business Manager, Instagram advertising and WhatsApp Business advertising. Every HIPAA-scoped programme must operate a scrubbing perimeter between the practice's PHI environment and Meta.
  • Meta's Personal Attributes policy prohibits ad copy that asserts or implies personal characteristics about the viewer — including medical conditions, appearance concerns, and specific procedure interests. Aesthetic copy calibrated to that policy is aspirational and category-level, not personal-condition addressed.
  • Custom Audiences from customer lists use hashed SHA-256 matching. Hashing is not HIPAA de-identification, so the source list must either be built entirely from records with valid marketing authorisations, or be routed through the practice's BAA-covered environment for de-identification before the hash is generated.
  • Conversion API (CAPI) is the primary HIPAA-scoped signal path. Server-to-server events with fully controllable payloads let the practice drop IP, referrer, procedure URLs and every other PHI-relevant field before Meta receives a hashed-identifier conversion with a generic event name.
  • Meta ad review for aesthetic and cosmetic-medicine ads typically involves an escalated manual pass on top of the standard 24-hour automated screen. Building creative and landing pages that clear this review on the first pass is a technical craft, not a matter of trial and error.
The ICG engagement model
Every practice welcome — retainers starting from $499/mo.
Goals-Driven engagements · Performance-Linked Payout Models available. Read the full engagement model →
🎯 Ichelon Agency OS See your goals live · client-facing dashboard, updated in real time. Click any screenshot to zoom. Open the full engagement model →
Trusted by US practices · case studies → 8 live practices · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Foundation

Meta’s revoked BAA — what changed and what did not

Meta, then Facebook, briefly offered a HIPAA Business Associate Agreement for a subset of its business products. The offering was withdrawn well before Cambridge Analytica and never restored. The operational consequence for the US aesthetic vertical is that Meta Ads must be treated as an out-of-BAA channel — a channel where every event that reaches Meta must have been sanitised of PHI before it crosses the boundary.

Under 45 CFR 164.502(e) and 164.504(e), a covered entity discloses PHI to a business associate only when a BAA is in place. Without a BAA, the disclosure is unauthorised. The March 2024 OCR tracking-technology bulletin update reinforced that IP address plus a condition-relevant URL is PHI when disclosed to a third-party tracker, and specifically named ad platform tracking as high-risk. Meta Pixel deployed on a HIPAA-scoped page that captures IP and procedure URL is therefore inside OCR's stated enforcement priorities.

Why the constraint does not remove Meta from the plan

Aesthetic practices generate a very high share of their qualified enquiry volume from Instagram and Facebook. The operational answer is not to abandon the channel — it is to redesign the data plane so Meta receives only the signals that are lawful to send. Custom Audiences from lawfully-collected consented lists, Conversion API from a server-side scrubbing perimeter, ad copy calibrated to Personal Attributes, and landing pages that keep the tracking event inside a first-party BAA-covered environment before it forks to Meta — that is the architecture.

Citation: 45 CFR 164.502(e); 45 CFR 164.504(e); OCR Bulletin on Tracking Technologies (Dec 2022, updated March 2024); Meta Advertising Standards; Meta Personal Attributes policy.
Personal Attributes

Meta’s Personal Attributes rule — what it actually says and how aesthetic ads pass it

Meta's advertising standards prohibit content that asserts or implies personal attributes about the viewer. The list of restricted attributes is deliberately broad and specifically enumerates race, ethnicity, religion, beliefs, age, sexual orientation or practices, gender identity, disability, medical or genetic condition, financial status, membership in a union, criminal record, name, and other characteristics.

For aesthetic advertising, the interpretive weight lands on "medical or genetic condition," "physical or mental health," and personal appearance implications. Copy that reads "Are you tired of stubborn belly fat?" implies both a physical attribute of the viewer (they have stubborn belly fat) and a health concern (they are unhappy about it). Meta's classifier will reject that ad, and a manual review escalation will typically confirm the rejection.

Ad copy patterns that pass

  • Category-level statement. "Explore body contouring at our Dallas medspa" — describes the service, not the viewer.
  • Aspirational framing. "Refreshed, natural-looking skin, delivered by a physician-led team" — asserts the outcome offered, not the viewer's current state.
  • Provider-led narrative. "Meet our Nurse Practitioner Rachel — twelve years of Botox and filler experience" — the copy is about the practice, not the viewer.
  • Educational framing. "How Ultherapy compares to Morpheus8 for skin tightening — a physician explains" — the ad is education, and the viewer's interest is inferred, not asserted.

Ad copy patterns that fail

  • "Are you unhappy with your acne scars?"
  • "Struggling with weight loss? We can help."
  • "Fix your under-eye bags today."
  • "Do you have sagging skin?"
  • "Concerned about your double chin? Book Kybella now."
Common failure pattern. A growth team ports high-performing paid-search copy directly into Meta ads. The paid-search copy is condition-addressed because Google's policy allows it. Meta rejects on first review. The team appeals, loses, and burns two weeks of launch time. Craft copy for Meta from the Personal Attributes standard on day one; do not port from other channels.
Custom Audiences

Custom Audiences — hashed matching, HIPAA de-identification and the source-list problem

Custom Audiences from a customer list use SHA-256 hashing of the customer's email address, phone number and address. Meta compares the hash against its own hashed user graph and delivers matched impressions on the union set. The hashing is done in the browser or the upload tool before the data reaches Meta.

HIPAA de-identification is defined at 45 CFR 164.514(b) — the Safe Harbor list of 18 identifiers, or Expert Determination. A SHA-256 hash of an email address is not a Safe Harbor de-identification; the email is one of the 18 identifiers and the hash is a lossless one-way function that Meta can join. The regulatory value of hashing is transport confidentiality, not de-identification.

Two lawful paths for aesthetic Custom Audiences

  • Path A — Consent-based. Build the source list entirely from patients and prospects who have signed a HIPAA marketing authorisation under 45 CFR 164.508 that specifically authorises disclosure of the identifier to Meta for advertising. Retain the authorisation for six years. Suppress any record whose authorisation has been revoked.
  • Path B — De-identified inside the BAA perimeter. Route the source list through a de-identification pipeline inside the practice's BAA-covered infrastructure. The pipeline strips the 18 Safe Harbor identifiers and produces a de-identified match key (or none at all — a pure exclusion list). Only the de-identified output is used to build the Custom Audience.

Path A is the more common architecture in aesthetic vertical because the medspa or plastic surgery practice already collects marketing consents at intake. Path B is more common where the audience is built from a broader dataset — including insurance and hospital records — that predates modern marketing consent capture.

Conversion API

Conversion API — the primary HIPAA-scoped signal path

Meta Conversion API (CAPI) is a server-to-server events pipeline. The practice's servers, not the visitor's browser, send events to Meta. That architectural shift is what makes HIPAA-safe Meta measurement feasible — the payload is completely under the practice's control, so PHI-relevant fields can be dropped at the server before the event ever exists on Meta's side.

What a HIPAA-safe CAPI event looks like

  • Event name. Generic — Lead, CompleteRegistration, Schedule. Never Botox_Lead or Filler_Schedule.
  • User data. Hashed email or phone, SHA-256, no plain text. External ID optional and, if used, a random identifier not derived from the medical record number.
  • Custom data. Value and currency for optimisation. No content_ids or content_name that reveal treatment type.
  • Event source URL. Rewritten at the server to a generic category page. Never the condition-specific slug the visitor actually saw.
  • Client IP address. Dropped. Meta will still receive its own client-side IP from Pixel if Pixel is deployed; disable client-side Pixel on HIPAA-scoped pages if the risk model requires.
  • Client user agent. Dropped or generalised to browser family without version.
  • Referrer. Trimmed to domain, never full URL.
Safe pattern. Client-side Pixel deployed only on unauthenticated, non-condition pages — homepage, non-medical about pages, generic contact pages. Every HIPAA-scoped page routes events through a server-side tag manager on a first-party subdomain, which drops IP and referrer, rewrites URL, generalises event name, and forwards a hashed-identifier CAPI event to Meta. Consent Mode signals honoured throughout.
Ad review

Meta ad review for aesthetic — the typical timeline and how to clear it first-pass

Standard Meta ad review runs an automated screen in under 24 hours. Aesthetic and cosmetic-medicine ads routinely receive an escalated manual review, which extends the timeline to 48-72 hours and occasionally longer. The manual reviewer applies the Personal Attributes policy, the health-and-wellness policy, the before/after imagery rules, and any active enforcement guidance for the vertical.

Building creative and landing pages that clear the first-pass review is a repeatable craft. The elements the reviewer checks are:

  • Ad copy. No personal-attribute assertion or implication about the viewer.
  • Ad imagery. No isolated body-part zoom with a "problem area" implication. Full-body or contextual imagery is preferred.
  • Before-and-after in ads. Meta restricts before/after in the ad creative itself; the practice's own website may show it with appropriate consent and disclaimers.
  • Landing page consistency. The landing page must not carry Personal Attributes copy either — a compliant ad that leads to a "Fix your wrinkles" landing page will get flagged on landing-page review.
  • Health claims. Specific medical claims trigger additional review. Aspirational and category claims pass.
  • Prescription products. Copy that names Botox, Juvéderm, Wegovy or Ozempic is scrutinised. Manufacturer brand names (Allergan, AbbVie, Galderma, Merz, Revance, Evolus, Novo Nordisk, Eli Lilly) may appear in a physician-context ad but not as consumer-directed pharmaceutical promotion.
Fix these first

Four decisions every HIPAA-scoped Meta Ads programme must make

1. Disable client-side Pixel on HIPAA pages

Pixel on the homepage and top-of-funnel category pages is defensible. Pixel on procedure-specific slugs, symptom checkers, or authenticated patient pages is not. Route those pages through CAPI-only.

2. Personal Attributes-safe copy library

Every creative in rotation calibrated against the Personal Attributes standard. Category-level and aspirational, never condition-addressed. Landing pages consistent with the ad.

3. Consent-based Custom Audiences

Source list built from records with valid HIPAA marketing authorisation, or de-identified inside the practice's BAA-covered environment before hashing. Suppression synced with revocation events.

4. CAPI with server-side PHI scrub

Server-side tag manager on a first-party subdomain. Drops IP, referrer, and condition context. Rewrites URL. Generalises event name. Forwards only a hashed-identifier CAPI event.

Lead Ads

Meta Lead Ads and WhatsApp — where HIPAA risk concentrates

Meta Lead Ads collect the lead payload inside Meta before the practice ever sees it. In a HIPAA-scoped context, that intake creates a disclosure risk — the visitor's name, phone, email, and any custom-question responses live inside Meta's environment before flowing to the practice's CRM. Without a BAA, that intake is exposed.

The safer pattern is to send Meta click-throughs to a first-party landing page hosted inside the practice's own infrastructure. The lead form on that page writes into the practice's BAA-covered CRM directly. Meta receives only a hashed-identifier CAPI conversion event afterwards.

WhatsApp Business advertising

WhatsApp Business is owned by Meta and does not sit under a HIPAA BAA. Ads that direct traffic to a WhatsApp thread create a channel where treatment communications may occur outside the BAA perimeter. Practices that want a WhatsApp presence should either restrict the thread to strictly appointment-logistics messaging with no PHI, or use a HIPAA-eligible provider (JaneApp, Zenoti, Boulevard, PatientEngage, Aesthetic Record) as the actual patient-communications channel and reserve WhatsApp for general enquiries.

Instagram Shopping, Reels ads and Advantage+ campaigns

Instagram Shopping surfaces and Advantage+ Shopping campaigns present the same architectural questions as the underlying Meta Ads platform, but with two additional considerations. First, Advantage+ leans heavily on Meta's own optimisation signal, which means the practice has less direct control over which audience segments a given creative reaches — the calibration of Personal Attributes-safe copy and PHI-safe events becomes even more important because a single non-compliant asset can be surfaced at scale before manual review catches it. Second, Reels advertising is often a paid boost of an organic post; the boosted post inherits the ad-review workflow even when the underlying organic post was permissible. Practices should keep an internal register of which organic posts have been boosted and treat those posts as ads for compliance purposes throughout their boosted lifetime.

Federal envelope

Where Meta compliance sits in the aesthetic marketing stack

Meta Ads compliance is one layer of a larger stack. A defensible aesthetic Meta programme sits inside a federal-and-state envelope that also includes TCPA for any SMS follow-up, CAN-SPAM for email drips, ADA for landing-page accessibility, FTC for endorsements and material connections, FDA for any manufacturer-partnership content, and state medical boards for advertising claims. Miss any one layer and the programme is exposed on that axis.

HIPAA TCPA CAN-SPAM ADA FTC 16 CFR 255 FDA State medical boards
Our research · State of Med Spa Google Presence 2026

What we found when we studied 555 US med spas on Google

Patients praise the care almost without exception. The one area where complaints outnumber praise is booking and communication, and that is where most med spas can win.

4.87★
average Google rating. Near-perfect ratings are table stakes.
5.83
median new reviews per month. Most profiles grow slowly.
~54%
of booking and communication reviews are negative, the one weak theme.

Full study · 555 US med spas across 20 metros · roughly ±4% nationally · review velocity and themes from a 115-spa subsample · verified against raw data.

Leadership

Backed by Ichelon Consulting US leadership

Every HIPAA-scoped Meta Ads engagement is reviewed by a senior member of the Leadership Team with visibility into CAPI rollouts, Personal Attributes review escalations, and the intersection with state medical board advertising rules.

The ICG technology stack

Nine tools. One compounding system. HealthApex OS
Built in-house. Deployed in every engagement.

ICG's results are reproducible because they are built on proprietary infrastructure — not agency intuition or generic tools. These nine HealthApex OS platforms are what power every ICG engagement.

WhatsApp AI

LynxFlow

WhatsApp AI Lead Qualifier

An AI assistant that holds a short WhatsApp conversation with every enquiry, decides whether it fits your criteria, and posts qualified leads to your CRM labelled Qualified. Team inbox, campaigns and consent handling included. $40/mo for US practices.

Explore LynxFlow →
Business Layer

Hawk

CRM Intelligence & Lead-Ops MIS

Sits as the business intelligence layer above your CRM — AtomCRM or any other CRM you run, including custom builds. Shows where leads are leaking, which effort is wasted, and which good leads were quietly downgraded by automation — not by a human decision.

  • Sits above your existing LMS — no replacement
  • 83% of effort goes to dead leads — surfaced Day 1
  • ~75% qualified-lead downgrades by automation
  • Free Lead-Leak Audit in 48 hours
Explore Hawk + free audit →
Attribution Core

Beacon

Attribution Engine & CAPI Middleware

Sits at the centre of every ICG attribution architecture. CAPI middleware connecting Meta Ads, Google Ads, WhatsApp and IVR to your CRM. Lifts Event Match Quality from 2.5 to 6+, reducing CPM 30–40% from the same budget.

  • Server-side CAPI — bypasses iOS privacy changes
  • EMQ 2.5 → 6+ across portfolio
  • 30–40% CPM reduction from EMQ lift alone
  • Multi-touch: ad → consultation → revenue
Explore Beacon →
Practice Management

HealthPro 360

PMS with built-in revenue intelligence layer

A PMS built to track cross-sell and up-sell opportunities within your existing patient base. 12 modules covering OPD, IPD, Pharmacy, Labs, Billing, Inventory, Patient Portal, Smart Scheduling, RBAC, AES-256 encrypted storage.

  • Only PMS with built-in Revenue Intelligence
  • Cross-sell signal tracking within existing patients
  • 12 modules: OPD, IPD, Pharmacy, Labs, Billing+
  • Audit trails + RBAC + AES-256 encryption
Explore HealthPro 360 →
Revenue Layer

Phoenix

Revenue intelligence built over your existing PMS

If you already have a PMS, whichever one it is, Phoenix builds the business intelligence layer on top of it without replacement. Built for single clinics and multi-centre chains alike.

  • Works over your existing PMS — no migration
  • Daily action queue: Prevent Loss / Maintain / Grow
  • Catches unbilled services, collection gaps, lapsing patients
  • CPQL variance ₹620–₹3,800 → ₹680–₹1,420
Explore Phoenix →
YouTube Intelligence

YODA

YouTube analytics that measures patients, not views

A YouTube intelligence platform built for healthcare business outcomes. Connects video performance to actual consultation bookings — not views, not subscribers. Patient testimonial videos generate 6.9× more consultations per view than condition explainers.

  • Consultation attribution per video — not views
  • Demand-gap: what patients search that your channel misses
  • 50+ doctor channels tracked across India
  • AIO readiness scoring: which videos AI tools cite
Explore YODA →
Governance & Transparency

Agency OS

Full transparency. Instant diagnosis. Zero surprises.

ICG's centralised governance platform — every client sees everything in real time, and ICG's team sees every problem the moment it surfaces. 30+ real-time alert systems fire the moment a metric drifts outside its performance envelope.

  • GSC, GA4, Google Ads, Meta Ads, IVR — one live view
  • 30+ real-time alert systems per account
  • CPQL drift alert at >15% week-on-week change
  • Client login: full transparency on your account
Explore Agency OS →
AEO & LLM Intelligence

AIO Intel

AI Overview + LLM citation tracking, healthcare-tuned

Knows the moment ChatGPT, Perplexity, Google AI Overviews and Gemini cite your brand in patient answers — and which content drove the citation. Bot-aware dashboard with GA4-registered custom dims (AIO source, AIO referrer) and IndexNow + GSC API integration.

  • Live tracking across ChatGPT / Perplexity / Google AIO / Gemini
  • Bot-aware: knows human vs scraper traffic
  • Custom GA4 dims register AIO source + referrer
  • IndexNow + GSC API: content surfaced to LLMs within hours
View AIO Intel dashboard →
Competitor Intelligence

Prism Spy

Every Meta + Google ad your competitors run, watched daily

Tracks 75+ Indian healthcare brands, 2,150+ active ads, ₹50Cr+ aggregate ad spend visibility per month. Surfaces what's working, what's been killed, what offers are emerging. Powers every ICG Meta Ads brief, Performance Marketing diagnostic, and IVF / derm / dental specialty campaign with real competitive intelligence.

  • 75+ brands tracked across 30+ healthcare specialties
  • 2,150+ active ads · daily refresh
  • Activity Feed: every spend / hook / pause logged
  • Offers Intelligence: 250+ offers in market tracked
Explore Prism Spy →
GBP Intelligence Platform

Angryturtle

Every Google Business Profile scored, tracked, protected, and grown from one command centre

ICG's proprietary Google Business Profile intelligence platform. Scores every listing across 7 dimensions, tracks rank on a live geo-grid across your actual service area, audits NAP + citations, monitors 531 suspension-risk factors continuously, and drafts Google Posts on cadence. Currently managing 143 healthcare listings with 0 suspensions and 4.76★ portfolio average across 28,137 reviews.

  • 143 listings under management · 0 suspensions · 4.76★
  • 7-dimension Health Score + 5-factor Rank OS per listing
  • Geo-grid rank tracking + NAP + Citation audit + Profile Shield
  • NMC + NABH + ART Act + DPDP compliance built into every content + review workflow
Explore Angryturtle →

Every ICG engagement runs on some combination of these ten HealthApex OS tools. The diagnostic determines which combination is right for your practice.

Explore HealthApex OS → See the full stack live on your account — free 30-min audit →
FAQ

HIPAA-safe Meta Ads for aesthetic — common questions

Does Meta sign a HIPAA BAA for Meta Ads?

No. Meta withdrew its HIPAA BAA offering years ago and has not restored it. Every HIPAA-scoped Meta Ads programme must build an external scrubbing perimeter before events reach Meta.

What is the Meta Personal Attributes policy?

Meta prohibits ads that assert or imply personal attributes about the viewer — including physical or mental health, medical conditions, and appearance concerns. Aesthetic copy calibrated to the policy is category-level and aspirational, not condition-addressed.

What ad copy passes Meta review for aesthetic services?

Category-level, aspirational, provider-led and educational framing pass. Personal-condition addressed copy fails. Draft creative from the Personal Attributes standard on day one rather than porting from paid search.

Can aesthetic practices use Custom Audiences?

Yes, with either consent-based lists (records with valid HIPAA marketing authorisations) or lists de-identified inside the practice's BAA-covered environment before hashing. Hashing alone is not HIPAA de-identification.

How does Conversion API work for HIPAA-safe aesthetic ads?

Server-to-server events with fully controllable payloads. The practice or a BAA-covered vendor drops IP, referrer, condition URLs and specific-procedure parameters before Meta receives a hashed-identifier CAPI event with a generic event name.

How long does aesthetic ad review typically take on Meta?

Standard automated screen under 24 hours; escalated manual review 48-72 hours. First-pass approval requires copy, imagery and landing-page consistency against the Personal Attributes policy.

Are Lead Ads HIPAA-safe for aesthetic practices?

Meta Lead Ads collect the lead payload inside Meta. Without a BAA, that intake creates a disclosure risk. The safer pattern is click-through to a first-party landing page inside the BAA-covered environment.

What about WhatsApp for patient outreach?

WhatsApp Business is not under a HIPAA BAA. Restrict WhatsApp threads to appointment-logistics messaging without PHI, or use a HIPAA-eligible provider (JaneApp, Zenoti, Boulevard, PatientEngage, Aesthetic Record) for sensitive traffic.

Can we still use client-side Meta Pixel anywhere?

Yes — on unauthenticated, non-condition pages such as the homepage, non-medical about pages and generic contact pages. Procedure slugs, symptom checkers and authenticated pages should route via CAPI-only.

How do we handle before/after content in Meta ads?

Meta restricts before/after in the ad creative itself; keep those assets on the practice's own website with appropriate consent and disclaimers under the FTC and state medical board guides. Ads may reference the transformation category without showing the imagery.

Scope your HIPAA-safe Meta Ads programme

Book a 30-minute call with a senior member of the Leadership Team, email the US practice lead, or call the Dallas office. Retainers are custom-scoped per engagement · from USD 250 per month equivalent, with Meta Ads compliance audits priced on scope.

Selected ICG clients

Healthcare brands ICG
has worked with.

A representative slice of the 150+ healthcare brands ICG has delivered for across India. Full client list available under NDA during a Brand and Growth Diagnostic.

Read full client case studies →

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership