Patient privacy in online marketing is now mostly a question about tracking technology. The Meta pixel, Google Analytics, session recorders and ad tags on a healthcare website can send what a visitor clicks, searches and books to third parties. Since 2022 that flow of data has drawn HHS guidance, FTC enforcement, multimillion-dollar class action settlements and a federal court ruling, and states such as Washington have passed their own health data laws.
The safe position for a provider: keep advertising and analytics tags off patient portals, appointment flows and anything a patient logs into; sign a business associate agreement with any vendor that receives protected health information; and treat condition and provider pages with care even after the 2024 court ruling. This guide covers what each regulator has said and gives you an audit you can run. It is not legal advice.
How marketing tags expose patient information
A tracking pixel is a snippet of code that reports page views and actions to an ad or analytics platform. On most sites that is routine. On a healthcare site the page itself can be sensitive: a visit to "/conditions/hiv-treatment" or a click on "Book with Dr. Patel, oncology" combined with an IP address or a logged-in Facebook cookie can tie a person to a health concern.
The Markup's 2022 Pixel Hunt investigation tested Newsweek's top 100 hospitals and found the Meta pixel on 33 of them sending Facebook data when someone clicked to schedule an appointment, including the doctor's name and search terms. It also found the pixel inside the password-protected patient portals of seven health systems.
What HHS says: the online tracking guidance
The HHS Office for Civil Rights issued its bulletin, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, in December 2022 and updated it in March 2024. Its main points:
| Where the tracking runs | HHS's position |
|---|---|
| User-authenticated pages (patient portals, telehealth, logged-in apps) | Tracking generally has access to PHI (names, appointment dates, diagnoses, prescriptions). Disclosures to the vendor must be permitted by the Privacy Rule, and the vendor needs a business associate agreement |
| Booking flows | If an individual makes an appointment and the tag sends appointment details and IP address to a vendor, the vendor is a business associate and a BAA is required |
| Unauthenticated public pages | Tracking is not regulated by HIPAA when it has no access to PHI (for example, a general page on hours or job openings) |
| Mobile apps | Apps offered by covered entities that collect health information are covered the same way |
The 2024 court ruling
In American Hospital Association v. Becerra, the US District Court for the Northern District of Texas on June 20, 2024 vacated the guidance to the extent it said HIPAA obligations are triggered when an online technology connects an individual's IP address with a visit to an unauthenticated public page addressing specific health conditions or providers. HHS added a note to the top of its bulletin describing the ruling.
What the ruling did not change: the guidance on authenticated pages, booking flows and apps, the requirement for BAAs when vendors receive PHI, and HIPAA itself. The FTC and state laws also apply regardless of HIPAA. Because the class action risk described below did not go away with the ruling, the cautious approach keeps ad pixels off condition and provider pages too.
What the FTC says: health data outside HIPAA
Many health apps, telehealth startups and wellness companies are not HIPAA covered entities. The FTC regulates them under the FTC Act and the Health Breach Notification Rule.
| Date | Action | What happened |
|---|---|---|
| February 1, 2023 | GoodRx | First enforcement under the Health Breach Notification Rule. $1.5 million civil penalty for sharing health information with Facebook, Google, Criteo and others without notifying users |
| March 2, 2023 | BetterHelp | $7.8 million for consumer refunds. The FTC said BetterHelp shared email addresses, IP addresses and health questionnaire answers with Facebook, Snapchat, Criteo and Pinterest for advertising. Order bans sharing health data for advertising |
| July 20, 2023 | Joint FTC and HHS letters | About 130 hospital systems and telehealth providers warned about tracking technologies such as the Meta pixel and Google Analytics |
| April 26, 2024 | Health Breach Notification Rule update | Confirms the rule covers health apps and similar technologies. A "breach" now includes unauthorized disclosure, such as sharing with an ad platform without authorization, and notices must name the third parties involved |
The final rule was published in the Federal Register on May 30, 2024. The FTC's rule page has the text and business guidance.
Pixel lawsuits against hospitals
After the 2022 reporting, patients filed class actions against health systems over tracking on their websites and portals. One example: Advocate Aurora Health agreed to a $12.225 million settlement over Meta pixel and Google tracking on its websites, app and MyChart portal, which the court gave final approval in July 2024, without any admission of wrongdoing (Data Privacy + Security Insider).
These suits do not depend on HHS's guidance. They turn on whether data was shared without consent, which is why the 2024 court ruling did not end the risk.
State laws: Washington's My Health My Data Act
Washington's My Health My Data Act protects consumer health data that falls outside HIPAA, including inferences about health drawn from other data. According to the Washington Attorney General:
- Its main obligations applied to regulated entities from March 31, 2024, and to small businesses from June 30, 2024.
- Collecting and sharing consumer health data requires consent; selling it requires a signed authorization kept for six years.
- Consumers can request deletion of their data.
- Violations are violations of the state Consumer Protection Act, enforced by the Attorney General and through private lawsuits.
The law also makes it unlawful to geofence an in-person health care facility (a virtual boundary of 2,000 feet or less, per RCW 19.373.010) to track consumers, collect their health data or send them ads about health care services. That rule took effect in July 2023 and applies to any person, including businesses outside Washington. Location-based ad campaigns that target competitors' clinics are exactly what it prohibits.
Other states have passed or are considering their own health data and privacy laws. Check the laws of every state where your patients live as well as where you operate.
Audit your website's tracking
Run this audit with your web developer and privacy officer at least once a year and after any site change.
| Step | What to do | Tools |
|---|---|---|
| 1. Inventory tags | List every script on the site: analytics, ad pixels, chat widgets, heatmaps, session recorders, embedded video | Browser developer tools (Network tab), Google Tag Assistant, your tag manager's container |
| 2. Map sensitive pages | Mark the portal, login, booking flow, forms, bill pay, and condition and provider pages | Your sitemap |
| 3. Remove ad pixels from sensitive pages | No Meta, TikTok or other ad pixels on portals, booking and forms; decide deliberately about condition pages | Tag manager triggers |
| 4. Check what each tag sends | Look at the request payloads: URLs with conditions, form fields, search terms, email hashes | Developer tools |
| 5. Confirm BAAs | Any vendor receiving PHI signs a business associate agreement, or stops receiving PHI | Contracts |
| 6. Review consent | Make sure your consent banner and privacy policy describe what you actually do | Privacy policy |
| 7. Check URLs and page titles | Booking confirmation URLs and titles should not contain names, conditions or appointment details | Site templates |
| 8. Retest after changes | New plugins and redesigns re-add tags | Quarterly spot check |
Session recording tools deserve special attention: they can capture everything typed into a form. Turn them off on any page with forms, or remove them.
Marketing that does not depend on tracking patients
Strong healthcare marketing does not require following individual patients around the web. The channels that bring patients to practices rely on being findable:
- Search and Maps. A complete Google Business Profile and a page for every service and location. See Google Maps for healthcare.
- Content. Pages that answer the questions patients search, written without patient information (HIPAA-compliant content).
- Reviews. A steady flow of honest reviews and compliant replies (healthcare reputation management).
- AI answers. Patients increasingly ask ChatGPT or Gemini for a provider. Rank.ai's AI visibility tracking checks whether your practice is named for those questions every day, and the free AI grade gives a snapshot. Neither involves any tag on your website.
- Aggregate measurement. Count calls, form submissions and bookings in aggregate, inside systems covered by a BAA.
FAQ
Is the Meta pixel a HIPAA violation?
It depends on where it runs and what it sends. HHS's guidance says tracking on authenticated pages such as patient portals and booking flows generally discloses PHI, which requires a permitted purpose and a business associate agreement with the vendor. A 2024 court ruling narrowed the guidance for public pages, but pixel class actions continue.
What did the AHA v. Becerra ruling change?
On June 20, 2024, a federal court in Texas vacated the part of HHS's tracking guidance that said HIPAA is triggered when a technology connects an IP address with a visit to an unauthenticated public page about specific health conditions or providers. The guidance on portals, logged-in pages, booking flows and apps, and the BAA requirement for vendors receiving PHI, were not vacated.
Can a healthcare provider use Google Analytics?
Yes, with care. Keep it off authenticated pages and booking flows unless the setup is covered by a business associate agreement, make sure no PHI (names, conditions in URLs, form fields) is sent, and document your configuration. If you need analytics on sensitive pages, ask vendors whether they will sign a BAA before you install anything.
Does the FTC Health Breach Notification Rule apply to my practice?
The rule covers vendors of personal health records and related entities that are not covered by HIPAA, such as many health apps. A HIPAA covered provider is governed by HIPAA's breach rules instead. If your practice runs a separate consumer app or wellness product outside HIPAA, check whether the FTC rule applies.
What is the Washington My Health My Data Act?
It is a Washington State law that protects consumer health data outside HIPAA. It requires consent to collect and share that data, a signed authorization to sell it, honors deletion requests, allows private lawsuits, and bans geofencing within 2,000 feet of in-person health care facilities for tracking or advertising.
Can we retarget website visitors who viewed a treatment page?
This is the highest-risk use of tracking in healthcare. Retargeting depends on sending a visitor's activity on a health page to an ad platform, which raises HIPAA questions for covered entities, FTC questions for non-covered companies, consent requirements under laws like Washington's, and class action exposure. Get a written opinion from counsel before running it.



