HIPAA Tracking · Q&A
Does HIPAA Apply to My Website If We Don't Collect PHI Online?
Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Probably more than you think — and even where HIPAA genuinely doesn't reach, the FTC and state health-privacy laws almost certainly do. "We don't collect PHI on our website" is the most common false belief we encounter in healthcare marketing audits. It's usually wrong for a simple reason: PHI isn't a field type you either add or don't. It's created by context — an identifiable visitor plus anything revealing about their health, care, or payment for care.
The audit question that breaks the assumption
Ask: can any page, URL, form, or flow on our site say something about a specific visitor's health? Then look honestly:
- Appointment and contact forms — name + "reason for visit" is PHI at creation.
- Condition and service pages — an identifiable visitor reading "/treatments/eating-disorders" is health-revealing context, which is why trackers on these pages drive the litigation wave.
- Patient portals, intake, telehealth flows — unambiguously PHI under any reading; third-party trackers here are the fact pattern OCR still enforces, post-AHA v. Becerra.
- Symptom checkers, quizzes, "find care" tools — every answer is health data.
If your site is truly brochure-ware — locations, hours, careers, a company blog with no condition content — your HIPAA surface is small. Almost nobody who says that has actually crawled their site.
What applies to you, by business type
Covered entity (provider, plan, or their business associates): HIPAA applies to you as an organization; the website question is only where PHI shows up. Authenticated surfaces and forms are clearly in; public health-content pages are a narrower federal question after the 2024 ruling but remain fully exposed to state law and wiretapping suits.
Telehealth and hybrid-care companies: usually covered entities (or close enough that counsel treats them as such), with the most health-revealing websites in existence. The whole visitor journey — landing page to intake — is sensitive.
DTC health brands and health apps not covered by HIPAA: the FTC has made you its lane — GoodRx ($1.5M), BetterHelp ($7.8M), Premom, and Cerebral were all reached via the FTC Act and Health Breach Notification Rule, all over ad-tracking data flows.
Wellness, supplements, fitness, health publishers: state law is your binding constraint. Washington's My Health My Data Act defines "consumer health data" so broadly that inferences from browsing count, requires separate opt-in consents, and lets consumers sue directly. California's Healthline settlement ($1.55M) established that even article titles implying a diagnosis create exposure for publishers.
The uncomfortable summary: the question "does HIPAA apply to my website?" has mostly stopped mattering, because the practical answer to "does some health-privacy regime apply?" is yes for anyone whose visitors can be linked to health interests.
FAQ
Our website is hosted by a third party. Does that shift the liability? No — data flowing to trackers is your configuration choice. Vendors handling identifiable health data on your behalf need BAAs (if you're HIPAA-regulated) or equivalent contractual controls.
Does a privacy policy disclosure solve this? Disclosure alone doesn't create HIPAA authorization, doesn't substitute for MHMDA's separate opt-in consents, and hasn't stopped wiretapping claims. Policies matter, but architecture is the defense.
What's the fastest way to know our actual exposure? A tracker inventory: crawl every page, catalog every tag and what it transmits, classify pages by health-revealingness. It's a days-long exercise that most organizations have never done — and it's the first thing we run for new clients.
Want the inventory done for you? It's our standard first engagement.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation