The Blog

Field notes on compliance-first growth.

Meta ads for health & wellness, privacy-compliant tracking, and what actually works in regulated categories — from the team running the accounts.

Resource Cluster

HIPAA-Compliant Tracking

A living guide to which marketing and analytics tools can run on a healthcare site — and how to configure the ones that can. Start with the overview, then jump to the tool you're evaluating. Not legal advice.

Start Here · Living Guide

The State of HIPAA-Compliant Marketing Tracking

Can healthcare marketers use GA4, the Meta pixel, or retargeting in 2026? A plain-English, continuously updated guide to the OCR guidance, AHA v. Becerra, state laws, FTC enforcement, and pixel litigation.

Is Google Analytics HIPAA Compliant?

No — Google won't sign a BAA for GA4, and IP anonymization doesn't fix it. Here's exactly why, what changed after AHA v. Becerra, and what healthcare marketers use instead in 2026.

Is the Meta (Facebook) Pixel HIPAA Compliant?

No — and the Meta pixel is the single most litigated tracking tool in healthcare. Why it fails, what AHA v. Becerra did and didn't change, and the compliant way to keep running Meta ads.

Is the Meta Conversions API (CAPI) HIPAA Compliant?

Not by itself — Meta still won't sign a BAA. But CAPI is the compliant path for healthcare Meta ads when it runs behind a PHI-scrubbing server-side gateway. Here's the architecture.

Is Google Tag Manager HIPAA Compliant?

GTM is a delivery truck — the compliance question is the cargo. Why client-side GTM is risky on health sites, and how server-side GTM becomes the backbone of a compliant stack.

Is Google Ads Conversion Tracking HIPAA Compliant?

Not the default setup — Google won't sign a BAA for Google Ads. But healthcare advertisers can measure conversions compliantly with server-side, scrubbed imports. Here's the pattern.

Does HIPAA Apply to My Website If We Don't Collect PHI Online?

More than you think — and HIPAA isn't the only law that does. A plain-English guide by business type: covered entities, telehealth, DTC health, and wellness brands.

Is the TikTok Pixel HIPAA Compliant?

No — no BAA, the same client-side leak as the Meta pixel, and extra scrutiny on TikTok's data handling. What health and wellness brands advertising on TikTok should do instead.

Is Hotjar HIPAA Compliant? (Session Recording & Heatmaps on Health Sites)

Generally no — session recordings capture form entries and browsing behavior that become PHI on health sites, and Hotjar doesn't offer a BAA. What CRO teams at health companies use instead.

Is CallRail HIPAA Compliant? (Call Tracking for Healthcare)

Yes — but only on CallRail's Healthcare plan with a signed BAA, and only if your integrations don't leak call data to non-BAA tools. The full picture for clinics and health brands.

Is HubSpot HIPAA Compliant for Healthcare Marketing?

Yes — but only on Enterprise with a signed BAA and sensitive-data features enabled. And the HubSpot tracking code on your website is a separate question from the CRM. Both answered here.

Is Klaviyo HIPAA Compliant for a Telehealth or Health Brand?

No — Klaviyo doesn't sign BAAs. What that means for telehealth and DTC health brands running email/SMS on it, and the compliant alternatives and split-stack patterns that work.

Are Mixpanel and Amplitude HIPAA Compliant? (Product Analytics for Health Apps)

Both can be — unlike GA4, Mixpanel and Amplitude offer BAAs on qualifying plans. But compliance lives in your implementation: event design, identifiers, and where the data flows next.

Growth in a regulated category?

We run compliance-first paid acquisition for health & wellness, healthtech, and fintech brands.

Book a Consultation