HIPAA-safe tracking for practice websites: pixels, analytics and BAAs explained
Most practice websites carry analytics tags, ad pixels, chat widgets and call-tracking scripts. Some of those tools can send information about patients to companies that have no business receiving it. This guide explains what federal regulators have said, where the real risks sit on a typical practice website and how to measure your marketing without putting protected health information at risk.
- HHS's Office for Civil Rights has said HIPAA rules apply when tracking technologies on a covered entity's website or app collect protected health information.
- The clearest risk areas are patient portals, appointment booking, symptom or intake forms and anything after login. Keep third-party pixels off them.
- A 2024 federal court ruling narrowed part of the guidance for unauthenticated public pages, but it did not make tracking on sensitive pages safe.
- Only share PHI with vendors that will sign a Business Associate Agreement. Many mainstream ad and analytics platforms won't, so design tracking to keep PHI away from them.
- You can still measure: count conversions without their contents, use server-side tagging with filtering, and track calls with HIPAA-aware vendors.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Why tracking became a HIPAA issue
Marketing tools work by collecting information about visitors and sending it to the tool's provider. An analytics tag records which pages someone visits. An ad pixel reports that a visitor took an action, so the ad platform can measure and target. A chat widget or form tool stores what the visitor types. On most business websites, this is routine.
On a healthcare website, the same routine can expose protected health information (PHI). If a pixel fires on an appointment page for a particular condition, or on a patient portal after login, or sends the contents of an intake form, the tool's provider may receive information linking a person to their health care. Regulators, plaintiffs' lawyers and patients have all paid attention to this in recent years.
What HHS said
In December 2022, the HHS Office for Civil Rights (OCR) published a bulletin on the use of online tracking technologies by HIPAA-covered entities and business associates, and updated it in March 2024. In broad terms, it said:
- HIPAA rules apply when tracking technologies collect and disclose PHI.
- Tracking on authenticated pages, such as patient portals and telehealth platforms, generally has access to PHI and is a clear risk.
- Regulated entities may not disclose PHI to tracking vendors for marketing without patient authorization, and vendors that receive PHI must be treated as business associates, with a Business Associate Agreement in place.
- Mobile apps offered by covered entities are subject to the same concerns.
What the 2024 court ruling changed
In June 2024, a federal district court in Texas vacated part of the guidance: the portion treating certain information gathered on unauthenticated public pages (for example, an IP address combined with a visit to a page about a condition) as PHI. That gave practices more room on ordinary public pages. It did not change the concerns about portals, booking flows, forms or any page where a patient identifies themselves, and it did not affect state privacy laws or the FTC's authority over deceptive or unfair data practices.
The practical takeaway hasn't changed much: keep third-party tracking away from anything that identifies a patient or reveals their health information, and have BAAs with vendors that do handle PHI.
Where the risk sits on a typical practice website
| Area | Risk | Approach |
|---|---|---|
| Patient portal and anything after login | High | No third-party marketing pixels or analytics that aren't covered by a BAA. Treat it as clinical software. |
| Appointment booking flow | High | Keep ad pixels off the booking steps. If booking is embedded from a scheduling vendor, confirm what that vendor collects and that a BAA is in place. |
| Intake, contact and symptom forms | High | Use a form tool that signs a BAA. Never send form fields to analytics or ad platforms. Keep the "thank you" step neutral. |
| Condition and treatment pages | Medium | More room after the 2024 ruling, but be cautious with ad pixels and audience building on sensitive topics. Check state laws. |
| Chat widgets and AI assistants | Medium–high | Visitors often type health details. Use vendors that sign a BAA or configure the tool to discourage and not retain health details. |
| Call tracking | Medium | Calls can include PHI in recordings and transcripts. Use HIPAA-aware vendors with a BAA, or disable recording. |
| General pages (home, about, locations, blog) | Lower | Standard analytics with IP anonymisation, consent where state law requires it, and no sensitive parameters in URLs. |
An eight-step tracking audit
- Inventory every tag. List every script on the site: analytics, ad pixels, tag managers, chat, heatmaps, video embeds, fonts, forms and scheduling widgets. Many sites carry forgotten tags from old campaigns or vendors.
- Map pages by risk. Use the table above. Mark every page and flow where a patient can identify themselves or reveal health information.
- Remove or restrict pixels on high-risk pages. Configure your tag manager so marketing tags never fire on portal, booking and form pages.
- Clean URLs and events. Check that URLs, page titles and event names don't carry names, emails, conditions, appointment types or form answers. A URL like "/book?reason=diabetes" sends that reason to every tag on the page.
- Collect BAAs. For every vendor that handles PHI (hosting, forms, scheduling, chat, call tracking, email), have a signed BAA on file. If a vendor won't sign one, keep PHI away from it.
- Consider server-side tagging. Routing events through a server you control lets you strip IP addresses, identifiers and sensitive parameters before anything reaches an ad platform. The server itself should be covered by a BAA with its host.
- Measure conversions without contents. Record that a booking or form was completed, not what it said. Reconcile marketing reports with booked visits in your practice management system, where PHI belongs.
- Document and review. Keep a short record of what's on the site, why, and who approved it. Review it whenever you add a vendor, launch a campaign or redesign the site, and at least twice a year.
You can still measure marketing properly
Practices sometimes respond to this issue by removing all tracking, then find they can't tell which campaigns bring patients. That isn't necessary. A HIPAA-aware setup can still tell you:
- How many people visited from each channel and campaign.
- How many started and completed a booking or form, counted without their contents.
- How many calls came from each source, through a call-tracking vendor under a BAA.
- How many booked visits and new patients each month, from your own systems.
Ad platforms get less detail, so their automated bidding may have less to learn from. That is a trade-off worth making. Many practices compensate with better-structured campaigns, tighter geographic targeting and offline reconciliation of booked visits.
How we handle it
Ichelon Consulting US sets up tracking this way by default on the websites and campaigns we run. Forms, booking flows and tracking are configured so protected health information is not sent to ad platforms or analytics tools, and we are prepared to sign a BAA where our work involves PHI. Results are reported on Ichelon Agency OS against goals agreed with each practice.
For the wider compliance picture, see our HIPAA-compliant healthcare marketing guide, our guides to HIPAA-safe Google Ads and HIPAA-safe Meta ads, and our TCPA outreach guide.
Related pages from the US team
Primary care marketing USA
Our full approach for primary care practices, with HIPAA-aware tracking by default.
HIPAA-compliant healthcare marketing
The wider HIPAA marketing picture: authorizations, testimonials, email and ads.
Case study: Lakewood Primary Care
A primary care website with a patient portal, built with the practice owner.
Healthcare marketing agency USA
How Ichelon Consulting US works with practices across the country.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Can a medical practice use Google Analytics or a Meta pixel on its website?
On general marketing pages, many practices do, with care. The risk comes when these tools collect protected health information, for example on appointment booking, patient portal, intake form or symptom-checker pages, or when form contents are passed to them. Keep third-party tracking off those pages, don't send form contents or health details, and remember that many mainstream platforms will not sign a Business Associate Agreement.
What did HHS say about online tracking technologies?
The HHS Office for Civil Rights issued a bulletin in December 2022, updated in March 2024, explaining that HIPAA applies when regulated entities use tracking technologies that collect and disclose protected health information. It highlighted authenticated pages such as patient portals as a clear risk and said regulated entities need a Business Associate Agreement with tracking vendors that receive PHI, or patient authorization.
Did a court strike down the HHS tracking guidance?
In part. In June 2024, a federal district court in Texas vacated the portion of the guidance that treated certain information collected on unauthenticated public web pages, such as an IP address combined with a visit to a page about a health condition, as protected health information. The rest of the guidance, including concerns about authenticated pages and PHI shared with vendors, was not affected. State privacy laws and FTC rules may also apply.
What is a Business Associate Agreement and when do we need one?
A Business Associate Agreement (BAA) is a contract required by HIPAA when a vendor creates, receives, maintains or transmits protected health information on your behalf. Hosting, form, scheduling, chat and call-tracking vendors that handle PHI need one. Ichelon Consulting US is prepared to sign a BAA where our work involves PHI.
How can we measure marketing results without sharing PHI?
Count conversions such as "booking started" or "form submitted" without sending their contents, fire conversion events from a neutral thank-you step rather than from pages that reveal a condition, use server-side tagging that strips identifiers and sensitive parameters before data reaches ad platforms, and use call-tracking and form vendors that will sign a BAA. Reconcile marketing reports against booked visits in your own systems.
Is this legal advice?
No. This guide explains common marketing practice and the published federal guidance at a general level. Rules change and state privacy laws vary, so confirm your setup with a healthcare privacy attorney.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Not sure what your website is sending, or to whom?
A 30-minute benchmarking call with the US team. We'll look at the tags on your key pages and tell you what we'd change first.