HIPAA Tracking · Q&A
Meta CAPI, Google Offline Conversions, and PHI: What You Can Send
Last updated: October 6, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Send Meta and Google the conversion, and keep the patient on your servers. A server-side event becomes PHI when it pairs an identifier with health context, and neither Meta nor Google signs a BAA for its ad products. The safe payload is the same short list on both platforms: a generic event name, a timestamp, a value, and a click ID.
The platforms split on identifiers. Meta accepts hashed emails, and a health advertiser should send them only with separate, logged consent and a generic event. Google's own policy excludes health conversions from enhanced conversions, so on Google the click ID is the whole payload.
The test: identifier plus health context
HIPAA protects individually identifiable health information that a covered entity or business associate holds or transmits (45 CFR 160.103). In a conversion pipeline, that definition comes down to two questions about every event:
- Does any field identify the person? Email, phone, name, IP address, a patient or CRM ID, and a click ID that ties the event to one ad click all count.
- Does any field reveal health context? A URL like
/anxiety-treatment/book, a content name like “GLP-1 consult,” an event calledTRT_Purchase, and a value that maps to one drug’s price all count.
An event that answers yes to both is the problem, whichever tool carried it. The FTC made that point in its July 2026 complaint against Hims & Hers, which names the Conversions API alongside the pixel.
Field by field: what to send
| Data | Meta CAPI field | Google Ads field | Rule |
|---|---|---|---|
| Event name | event_name |
Conversion action name | Send. Keep it generic: Lead, Schedule, Purchase. Never name the service. |
| Timestamp | event_time |
conversion_date_time |
Send. |
| Value and currency | value, currency |
conversion_value, currency_code |
Send. Use a standard or blended value when an exact price would reveal the treatment. |
| Click ID | fbc (built from fbclid) |
gclid |
Send with a generic event. It lets each platform credit the right ad. |
| Page URL | event_source_url |
Set by the tag; absent from an import | Strip to the domain or a neutral path, and drop query strings. Health words in URLs are the most common leak. |
| Content and product fields | custom_data: content_name, content_category, content_ids |
No import equivalent | Never send a value that names a condition, drug, device, or service. |
| Hashed email and phone | user_data: em, ph |
user_identifiers (enhanced conversions for leads) |
Meta: only with separate, logged consent and a generic event. Google: leave out of health conversions. Google’s customer data policy excludes them from enhanced conversions. |
| IP address and user agent | client_ip_address, client_user_agent |
Unneeded for imports | Treat as identifiers. Drop them unless consent covers the share. |
| Internal IDs | external_id, event_id |
order_id |
Use a random event ID for deduplication. Never send a patient ID, MRN, or CRM ID that maps to a record. |
| Diagnosis, symptoms, medications, intake answers, lab results | Any field | Any field | Never. |
| Customer lists | Custom Audiences (customer list) | Customer Match | Keep patient lists off both. Google closes Customer Match to health advertisers by policy. |
Hashing is a matching technique
Meta and Google ask for SHA-256 hashed emails and phone numbers so they can match them to accounts. The hash exists to make that match work, so it hides nothing from the company doing the matching.
HIPAA’s de-identification standard (45 CFR 164.514) requires either removing 18 identifier types, email addresses and phone numbers among them, or a formal expert determination. A hashed email meets neither test. Treat a hashed identifier as an identifier, and keep it away from health context.
Meta CAPI: you control the payload, and Meta’s terms hold you to it
The Conversions API sends events from your server, so you decide every field. That control is the reason to use it. Three facts set the rules for health advertisers:
- Meta’s terms already prohibit health data. The Business Tools Terms (updated May 20, 2026) require advertisers to warrant that their data excludes anything that “includes or is based on, directly or otherwise, health information.”
- Regulators have named CAPI. The complaint in FTC, California, and Utah v. Hims & Hers (No. 3:26-cv-07871-VC, N.D. Cal.) alleges that roughly 8 million registration and purchase events reached Meta through the pixel and the Conversions API, each pairing an identifier with a custom parameter naming the treatment. Hims disputes the claims. Detail: Is the Meta Conversions API HIPAA compliant?
- Meta filters health events on its own. Since January 2025, Meta has classified health and wellness data sources into restriction tiers and limited lower-funnel standard events for many of them. Its classifier reads URLs and parameters, so a clean payload also protects your classification. See Meta’s health and wellness restrictions.
Google Ads: import the click ID and stop there
Google offers three ways to report a conversion from your own systems:
- Offline conversion import: a server-side upload keyed on the gclid.
- Enhanced conversions for leads: the same upload plus hashed customer data.
- Enhanced conversions for web: the browser tag plus hashed customer data.
Only the first fits a health advertiser. Google’s customer data policies state that “conversions related to sensitive categories can’t be used for measurement in enhanced conversions.” The sensitive categories include health and medical information, with purchases of medical services, prescription drugs, and medical devices as Google’s own examples. The rule applies whatever your consent flow says.
A gclid import with a generic conversion action, a timestamp, and a value sends no customer data. Google’s upload API requires user identifiers only when you opt into enhanced conversions for leads.
Google also signs no BAA for Google Ads or Google Analytics. Its BAA covers Google Cloud products and leaves both out, and its Analytics help page tells HIPAA-regulated entities to keep PHI away from the product. Why Google draws these lines where it does: Why Google Ads treats health data differently from Meta.
Where HHS guidance stands in 2026
The HHS Office for Civil Rights bulletin on tracking technologies (December 2022, revised March 2024) still frames the issue, with one large exception. In American Hospital Association v. Becerra (N.D. Tex., June 20, 2024), the court vacated the bulletin’s position that an IP address combined with a visit to an unauthenticated public page about a health condition is PHI. HHS dropped its appeal in August 2024. The guidance on patient portals, authenticated pages, and telehealth flows still stands, and those pages produce most conversions.
The ruling narrowed HIPAA’s reach and left the rest of your exposure in place. The FTC Act, the FTC’s Health Breach Notification Rule, Washington’s My Health My Data Act, and California’s privacy laws reach health data that HIPAA never covered. A DTC health brand outside HIPAA faces the same field-level test. See FTC rules for non-covered entities and Washington’s My Health My Data Act.
Checklist before you send an event
- Map every field in your CAPI and Google payloads, including defaults your gateway adds.
- Rename events and Google conversion actions so no name describes a service.
- Strip page URLs to the domain or a neutral path, and drop query strings.
- Remove content, product, and category fields that name a condition, drug, or device.
- Send hashed identifiers to Meta only for users with separate, logged consent. Send none to Google for health conversions, and leave enhanced conversions off.
- Keep the gateway configuration, the consent log, and the data map on file. That record is what you show a regulator or plaintiff’s counsel.
FAQ
Is a gclid or fbclid PHI? A click ID carries no name or email, and it ties the conversion to the ad and search that produced it. On a campaign built around one condition, that link can reveal health context by itself. Pair click IDs with generic event names, and have counsel review single-condition campaigns.
Can we send hashed emails to Meta if users consent? Consent matters under state laws like Washington’s My Health My Data Act, which requires separate consent to share health data. Meta’s terms bar health information regardless of consent. Send hashed identifiers only with a generic event and no health context, for users whose logged consent covers ad-platform sharing.
Can we use enhanced conversions for leads if the event name is generic? Google’s policy turns on what the conversion relates to, whatever you name it. A purchase of a medical service, a prescription, or a medical device falls outside enhanced conversions measurement. Use a gclid-only import.
Does server-side tracking make this compliant? Server-side tracking gives you one place to strip fields, and the stripping does the work. The Hims complaint treats the Conversions API and the pixel as two routes for the same data.
Do we need a BAA with Meta or Google? Neither company offers one for its ad products. The architecture has to keep PHI out of the payload, because no contract will cover it.
Want a field-level review of your CAPI and Google payloads? Coast Studio audits and rebuilds this pipeline.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and edtech. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation