Skip to content

Healthcare marketing

Patient privacy in online marketing: tracking pixels, HIPAA and the FTC

What HHS, the FTC, courts and state laws say about tracking pixels and health data in marketing, and how to audit your practice's website.

In this article9 sections
  1. Key takeaways
  2. How marketing tags expose patient information
  3. What HHS says: the online tracking guidance
  4. What the FTC says: health data outside HIPAA
  5. Pixel lawsuits against hospitals
  6. State laws: Washington's My Health My Data Act
  7. Audit your website's tracking
  8. Marketing that does not depend on tracking patients
  9. FAQ

Patient privacy in online marketing is now mostly a question about tracking technology. The Meta pixel, Google Analytics, session recorders and ad tags on a healthcare website can send what a visitor clicks, searches and books to third parties. Since 2022 that flow of data has drawn HHS guidance, FTC enforcement, multimillion-dollar class action settlements and a federal court ruling, and states such as Washington have passed their own health data laws.

The safe position for a provider: keep advertising and analytics tags off patient portals, appointment flows and anything a patient logs into; sign a business associate agreement with any vendor that receives protected health information; and treat condition and provider pages with care even after the 2024 court ruling. This guide covers what each regulator has said and gives you an audit you can run. It is not legal advice.

How marketing tags expose patient information

A tracking pixel is a snippet of code that reports page views and actions to an ad or analytics platform. On most sites that is routine. On a healthcare site the page itself can be sensitive: a visit to "/conditions/hiv-treatment" or a click on "Book with Dr. Patel, oncology" combined with an IP address or a logged-in Facebook cookie can tie a person to a health concern.

The Markup's 2022 Pixel Hunt investigation tested Newsweek's top 100 hospitals and found the Meta pixel on 33 of them sending Facebook data when someone clicked to schedule an appointment, including the doctor's name and search terms. It also found the pixel inside the password-protected patient portals of seven health systems.

What HHS says: the online tracking guidance

The HHS Office for Civil Rights issued its bulletin, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, in December 2022 and updated it in March 2024. Its main points:

Where the tracking runsHHS's position
User-authenticated pages (patient portals, telehealth, logged-in apps)Tracking generally has access to PHI (names, appointment dates, diagnoses, prescriptions). Disclosures to the vendor must be permitted by the Privacy Rule, and the vendor needs a business associate agreement
Booking flowsIf an individual makes an appointment and the tag sends appointment details and IP address to a vendor, the vendor is a business associate and a BAA is required
Unauthenticated public pagesTracking is not regulated by HIPAA when it has no access to PHI (for example, a general page on hours or job openings)
Mobile appsApps offered by covered entities that collect health information are covered the same way

The 2024 court ruling

In American Hospital Association v. Becerra, the US District Court for the Northern District of Texas on June 20, 2024 vacated the guidance to the extent it said HIPAA obligations are triggered when an online technology connects an individual's IP address with a visit to an unauthenticated public page addressing specific health conditions or providers. HHS added a note to the top of its bulletin describing the ruling.

What the ruling did not change: the guidance on authenticated pages, booking flows and apps, the requirement for BAAs when vendors receive PHI, and HIPAA itself. The FTC and state laws also apply regardless of HIPAA. Because the class action risk described below did not go away with the ruling, the cautious approach keeps ad pixels off condition and provider pages too.

What the FTC says: health data outside HIPAA

Many health apps, telehealth startups and wellness companies are not HIPAA covered entities. The FTC regulates them under the FTC Act and the Health Breach Notification Rule.

DateActionWhat happened
February 1, 2023GoodRxFirst enforcement under the Health Breach Notification Rule. $1.5 million civil penalty for sharing health information with Facebook, Google, Criteo and others without notifying users
March 2, 2023BetterHelp$7.8 million for consumer refunds. The FTC said BetterHelp shared email addresses, IP addresses and health questionnaire answers with Facebook, Snapchat, Criteo and Pinterest for advertising. Order bans sharing health data for advertising
July 20, 2023Joint FTC and HHS lettersAbout 130 hospital systems and telehealth providers warned about tracking technologies such as the Meta pixel and Google Analytics
April 26, 2024Health Breach Notification Rule updateConfirms the rule covers health apps and similar technologies. A "breach" now includes unauthorized disclosure, such as sharing with an ad platform without authorization, and notices must name the third parties involved

The final rule was published in the Federal Register on May 30, 2024. The FTC's rule page has the text and business guidance.

Pixel lawsuits against hospitals

After the 2022 reporting, patients filed class actions against health systems over tracking on their websites and portals. One example: Advocate Aurora Health agreed to a $12.225 million settlement over Meta pixel and Google tracking on its websites, app and MyChart portal, which the court gave final approval in July 2024, without any admission of wrongdoing (Data Privacy + Security Insider).

These suits do not depend on HHS's guidance. They turn on whether data was shared without consent, which is why the 2024 court ruling did not end the risk.

State laws: Washington's My Health My Data Act

Washington's My Health My Data Act protects consumer health data that falls outside HIPAA, including inferences about health drawn from other data. According to the Washington Attorney General:

  • Its main obligations applied to regulated entities from March 31, 2024, and to small businesses from June 30, 2024.
  • Collecting and sharing consumer health data requires consent; selling it requires a signed authorization kept for six years.
  • Consumers can request deletion of their data.
  • Violations are violations of the state Consumer Protection Act, enforced by the Attorney General and through private lawsuits.

The law also makes it unlawful to geofence an in-person health care facility (a virtual boundary of 2,000 feet or less, per RCW 19.373.010) to track consumers, collect their health data or send them ads about health care services. That rule took effect in July 2023 and applies to any person, including businesses outside Washington. Location-based ad campaigns that target competitors' clinics are exactly what it prohibits.

Other states have passed or are considering their own health data and privacy laws. Check the laws of every state where your patients live as well as where you operate.

Audit your website's tracking

Run this audit with your web developer and privacy officer at least once a year and after any site change.

StepWhat to doTools
1. Inventory tagsList every script on the site: analytics, ad pixels, chat widgets, heatmaps, session recorders, embedded videoBrowser developer tools (Network tab), Google Tag Assistant, your tag manager's container
2. Map sensitive pagesMark the portal, login, booking flow, forms, bill pay, and condition and provider pagesYour sitemap
3. Remove ad pixels from sensitive pagesNo Meta, TikTok or other ad pixels on portals, booking and forms; decide deliberately about condition pagesTag manager triggers
4. Check what each tag sendsLook at the request payloads: URLs with conditions, form fields, search terms, email hashesDeveloper tools
5. Confirm BAAsAny vendor receiving PHI signs a business associate agreement, or stops receiving PHIContracts
6. Review consentMake sure your consent banner and privacy policy describe what you actually doPrivacy policy
7. Check URLs and page titlesBooking confirmation URLs and titles should not contain names, conditions or appointment detailsSite templates
8. Retest after changesNew plugins and redesigns re-add tagsQuarterly spot check

Session recording tools deserve special attention: they can capture everything typed into a form. Turn them off on any page with forms, or remove them.

Marketing that does not depend on tracking patients

Strong healthcare marketing does not require following individual patients around the web. The channels that bring patients to practices rely on being findable:

  • Search and Maps. A complete Google Business Profile and a page for every service and location. See Google Maps for healthcare.
  • Content. Pages that answer the questions patients search, written without patient information (HIPAA-compliant content).
  • Reviews. A steady flow of honest reviews and compliant replies (healthcare reputation management).
  • AI answers. Patients increasingly ask ChatGPT or Gemini for a provider. Rank.ai's AI visibility tracking checks whether your practice is named for those questions every day, and the free AI grade gives a snapshot. Neither involves any tag on your website.
  • Aggregate measurement. Count calls, form submissions and bookings in aggregate, inside systems covered by a BAA.

FAQ

Is the Meta pixel a HIPAA violation?

It depends on where it runs and what it sends. HHS's guidance says tracking on authenticated pages such as patient portals and booking flows generally discloses PHI, which requires a permitted purpose and a business associate agreement with the vendor. A 2024 court ruling narrowed the guidance for public pages, but pixel class actions continue.

What did the AHA v. Becerra ruling change?

On June 20, 2024, a federal court in Texas vacated the part of HHS's tracking guidance that said HIPAA is triggered when a technology connects an IP address with a visit to an unauthenticated public page about specific health conditions or providers. The guidance on portals, logged-in pages, booking flows and apps, and the BAA requirement for vendors receiving PHI, were not vacated.

Can a healthcare provider use Google Analytics?

Yes, with care. Keep it off authenticated pages and booking flows unless the setup is covered by a business associate agreement, make sure no PHI (names, conditions in URLs, form fields) is sent, and document your configuration. If you need analytics on sensitive pages, ask vendors whether they will sign a BAA before you install anything.

Does the FTC Health Breach Notification Rule apply to my practice?

The rule covers vendors of personal health records and related entities that are not covered by HIPAA, such as many health apps. A HIPAA covered provider is governed by HIPAA's breach rules instead. If your practice runs a separate consumer app or wellness product outside HIPAA, check whether the FTC rule applies.

What is the Washington My Health My Data Act?

It is a Washington State law that protects consumer health data outside HIPAA. It requires consent to collect and share that data, a signed authorization to sell it, honors deletion requests, allows private lawsuits, and bans geofencing within 2,000 feet of in-person health care facilities for tracking or advertising.

Can we retarget website visitors who viewed a treatment page?

This is the highest-risk use of tracking in healthcare. Retargeting depends on sending a visitor's activity on a health page to an ad platform, which raises HIPAA questions for covered entities, FTC questions for non-covered companies, consent requirements under laws like Washington's, and class action exposure. Get a written opinion from counsel before running it.

See if AI names you when customers ask who’s best.

Enter your website. In about two minutes, Rank.ai asks ChatGPT, Claude and Gemini 12 questions your customers ask and grades how often they name you.

  • Your grade out of 100How often AI names you, cites your site, and how high it ranks you.
  • Who gets namedEvery competitor in the answers, most named first.
  • The pages AI readsThe sources behind each answer.
  • Three fixesWhat to fix first, with a brief for the first page.