Healthcare Pharma & Life Sciences Other Industries
All Services Performance Marketing ChatGPT Ads India · NEW Social Media Marketing SEO & AEO / LLM YouTube Marketing LLM Optimization Brand & Growth Consulting AI Solutions Industries We Serve
Enterprise Hub · All Solutions + Services Growth Transformation AI Transformation Revenue Operations Fractional CGO Growth Operating System Executive Growth Advisory
Clinic Launch Programme (Hub) NABH Consulting India Healthcare Brand Launch Clinic SOP Creation Logo Design (Healthcare) Brand Book Creation Clinic Launch Marketing D2C Brand Launch Clinic Interior Design
Workforce Hub For Employers — post a requirement For Professionals — register Public Openings Training Academy AI Training Flagship
Hawk · CRM Intelligence (NEW) YODA · YouTube Intelligence Angryturtle · GBP Intelligence (NEW) Prism Pulse · Instagram Analytics (NEW) Beacon · Attribution Agency OS · Dashboards Phoenix · Clinic Revenue HealthPro 360 · PMS/HMS AI Patient Lifecycle Bots AI Lead Management System Smart Appointment System Healthcare CRM Patient Feedback System AI, Analytics & Automation Digital Transformation Calculators Free Digital Health Audit →
All 13 calculators → 🎯 Business Exploration Matrix (New) Dental Clinic Setup IVF Clinic + Lab Setup Multi-Specialty Hospital Setup Aesthetic / Cosmetology Clinic Dermatology Clinic Setup Generic Clinic Setup Physiotherapy Clinic Setup Diagnostic Centre Setup CAC Calculator CPQL Calculator Franchise ROI Calculator Revenue Leakage Calculator CRM ROI Calculator
All Events Workshop 1 · Jun 13 · AI in Clinical Practice Workshop 2 · Jun 27–28 · AI in Growth & Governance Hospital Ops Workshop · Jul 12 Pre-Summit Seminar · Aug 16 Grand Summit 2.0 · Oct 10–11 Bihar AI Summit · Recap AI Innovation Awards · Aug 22 Grand Summit 2.0 · Oct 2026 Aarambh 2026 Recap
Case Studies Insights & Blog Research Reports Calculators AI in Healthcare Digest
Our Story Leaders @ Ichelon · IN · US · AU Ichelon India · Gurgaon Ichelon Consulting US · Dallas, TX Ichelon Australia · Sydney Speakers & Panelists Client Elevation Programme 🤝 Partner Connect 🇦🇪 ICG UAE Careers
Book a Growth Diagnostic →
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · Compliance guide

HIPAA-safe tracking for practice websites: pixels, analytics and BAAs explained

Most practice websites carry analytics tags, ad pixels, chat widgets and call-tracking scripts. Some of those tools can send information about patients to companies that have no business receiving it. This guide explains what federal regulators have said, where the real risks sit on a typical practice website and how to measure your marketing without putting protected health information at risk.

Guide for US practice owners · Published September 26, 2026

TL;DR
  • HHS's Office for Civil Rights has said HIPAA rules apply when tracking technologies on a covered entity's website or app collect protected health information.
  • The clearest risk areas are patient portals, appointment booking, symptom or intake forms and anything after login. Keep third-party pixels off them.
  • A 2024 federal court ruling narrowed part of the guidance for unauthenticated public pages, but it did not make tracking on sensitive pages safe.
  • Only share PHI with vendors that will sign a Business Associate Agreement. Many mainstream ad and analytics platforms won't, so design tracking to keep PHI away from them.
  • You can still measure: count conversions without their contents, use server-side tagging with filtering, and track calls with HIPAA-aware vendors.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Trusted by US practices · case studies → 8 live practices · TX · CA · VA · nationwide telehealth
Case study for practices like yours Lakewood Primary Care & Wellness: at the top of Google for "primary care Dallas" Read the case study →
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Background

Why tracking became a HIPAA issue

Marketing tools work by collecting information about visitors and sending it to the tool's provider. An analytics tag records which pages someone visits. An ad pixel reports that a visitor took an action, so the ad platform can measure and target. A chat widget or form tool stores what the visitor types. On most business websites, this is routine.

On a healthcare website, the same routine can expose protected health information (PHI). If a pixel fires on an appointment page for a particular condition, or on a patient portal after login, or sends the contents of an intake form, the tool's provider may receive information linking a person to their health care. Regulators, plaintiffs' lawyers and patients have all paid attention to this in recent years.

What HHS said

In December 2022, the HHS Office for Civil Rights (OCR) published a bulletin on the use of online tracking technologies by HIPAA-covered entities and business associates, and updated it in March 2024. In broad terms, it said:

  • HIPAA rules apply when tracking technologies collect and disclose PHI.
  • Tracking on authenticated pages, such as patient portals and telehealth platforms, generally has access to PHI and is a clear risk.
  • Regulated entities may not disclose PHI to tracking vendors for marketing without patient authorization, and vendors that receive PHI must be treated as business associates, with a Business Associate Agreement in place.
  • Mobile apps offered by covered entities are subject to the same concerns.

What the 2024 court ruling changed

In June 2024, a federal district court in Texas vacated part of the guidance: the portion treating certain information gathered on unauthenticated public pages (for example, an IP address combined with a visit to a page about a condition) as PHI. That gave practices more room on ordinary public pages. It did not change the concerns about portals, booking flows, forms or any page where a patient identifies themselves, and it did not affect state privacy laws or the FTC's authority over deceptive or unfair data practices.

The practical takeaway hasn't changed much: keep third-party tracking away from anything that identifies a patient or reveals their health information, and have BAAs with vendors that do handle PHI.

Risk map

Where the risk sits on a typical practice website

AreaRiskApproach
Patient portal and anything after loginHighNo third-party marketing pixels or analytics that aren't covered by a BAA. Treat it as clinical software.
Appointment booking flowHighKeep ad pixels off the booking steps. If booking is embedded from a scheduling vendor, confirm what that vendor collects and that a BAA is in place.
Intake, contact and symptom formsHighUse a form tool that signs a BAA. Never send form fields to analytics or ad platforms. Keep the "thank you" step neutral.
Condition and treatment pagesMediumMore room after the 2024 ruling, but be cautious with ad pixels and audience building on sensitive topics. Check state laws.
Chat widgets and AI assistantsMedium–highVisitors often type health details. Use vendors that sign a BAA or configure the tool to discourage and not retain health details.
Call trackingMediumCalls can include PHI in recordings and transcripts. Use HIPAA-aware vendors with a BAA, or disable recording.
General pages (home, about, locations, blog)LowerStandard analytics with IP anonymisation, consent where state law requires it, and no sensitive parameters in URLs.
Step by step

An eight-step tracking audit

  1. Inventory every tag. List every script on the site: analytics, ad pixels, tag managers, chat, heatmaps, video embeds, fonts, forms and scheduling widgets. Many sites carry forgotten tags from old campaigns or vendors.
  2. Map pages by risk. Use the table above. Mark every page and flow where a patient can identify themselves or reveal health information.
  3. Remove or restrict pixels on high-risk pages. Configure your tag manager so marketing tags never fire on portal, booking and form pages.
  4. Clean URLs and events. Check that URLs, page titles and event names don't carry names, emails, conditions, appointment types or form answers. A URL like "/book?reason=diabetes" sends that reason to every tag on the page.
  5. Collect BAAs. For every vendor that handles PHI (hosting, forms, scheduling, chat, call tracking, email), have a signed BAA on file. If a vendor won't sign one, keep PHI away from it.
  6. Consider server-side tagging. Routing events through a server you control lets you strip IP addresses, identifiers and sensitive parameters before anything reaches an ad platform. The server itself should be covered by a BAA with its host.
  7. Measure conversions without contents. Record that a booking or form was completed, not what it said. Reconcile marketing reports with booked visits in your practice management system, where PHI belongs.
  8. Document and review. Keep a short record of what's on the site, why, and who approved it. Review it whenever you add a vendor, launch a campaign or redesign the site, and at least twice a year.
Measurement

You can still measure marketing properly

Practices sometimes respond to this issue by removing all tracking, then find they can't tell which campaigns bring patients. That isn't necessary. A HIPAA-aware setup can still tell you:

  • How many people visited from each channel and campaign.
  • How many started and completed a booking or form, counted without their contents.
  • How many calls came from each source, through a call-tracking vendor under a BAA.
  • How many booked visits and new patients each month, from your own systems.

Ad platforms get less detail, so their automated bidding may have less to learn from. That is a trade-off worth making. Many practices compensate with better-structured campaigns, tighter geographic targeting and offline reconciliation of booked visits.

How we handle it

Ichelon Consulting US sets up tracking this way by default on the websites and campaigns we run. Forms, booking flows and tracking are configured so protected health information is not sent to ad platforms or analytics tools, and we are prepared to sign a BAA where our work involves PHI. Results are reported on Ichelon Agency OS against goals agreed with each practice.

For the wider compliance picture, see our HIPAA-compliant healthcare marketing guide, our guides to HIPAA-safe Google Ads and HIPAA-safe Meta ads, and our TCPA outreach guide.

Keep reading

Related pages from the US team

Primary care marketing USA

Our full approach for primary care practices, with HIPAA-aware tracking by default.

HIPAA-compliant healthcare marketing

The wider HIPAA marketing picture: authorizations, testimonials, email and ads.

Case study: Lakewood Primary Care

A primary care website with a patient portal, built with the practice owner.

Healthcare marketing agency USA

How Ichelon Consulting US works with practices across the country.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Can a medical practice use Google Analytics or a Meta pixel on its website?

On general marketing pages, many practices do, with care. The risk comes when these tools collect protected health information, for example on appointment booking, patient portal, intake form or symptom-checker pages, or when form contents are passed to them. Keep third-party tracking off those pages, don't send form contents or health details, and remember that many mainstream platforms will not sign a Business Associate Agreement.

What did HHS say about online tracking technologies?

The HHS Office for Civil Rights issued a bulletin in December 2022, updated in March 2024, explaining that HIPAA applies when regulated entities use tracking technologies that collect and disclose protected health information. It highlighted authenticated pages such as patient portals as a clear risk and said regulated entities need a Business Associate Agreement with tracking vendors that receive PHI, or patient authorization.

Did a court strike down the HHS tracking guidance?

In part. In June 2024, a federal district court in Texas vacated the portion of the guidance that treated certain information collected on unauthenticated public web pages, such as an IP address combined with a visit to a page about a health condition, as protected health information. The rest of the guidance, including concerns about authenticated pages and PHI shared with vendors, was not affected. State privacy laws and FTC rules may also apply.

What is a Business Associate Agreement and when do we need one?

A Business Associate Agreement (BAA) is a contract required by HIPAA when a vendor creates, receives, maintains or transmits protected health information on your behalf. Hosting, form, scheduling, chat and call-tracking vendors that handle PHI need one. Ichelon Consulting US is prepared to sign a BAA where our work involves PHI.

How can we measure marketing results without sharing PHI?

Count conversions such as "booking started" or "form submitted" without sending their contents, fire conversion events from a neutral thank-you step rather than from pages that reveal a condition, use server-side tagging that strips identifiers and sensitive parameters before data reaches ad platforms, and use call-tracking and form vendors that will sign a BAA. Reconcile marketing reports against booked visits in your own systems.

Is this legal advice?

No. This guide explains common marketing practice and the published federal guidance at a general level. Rules change and state privacy laws vary, so confirm your setup with a healthcare privacy attorney.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Not sure what your website is sending, or to whom?

A 30-minute benchmarking call with the US team. We'll look at the tags on your key pages and tell you what we'd change first.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership