Is an IP Address PHI Under HIPAA?
Last updated: August 10, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
On its own, no. Joined to a visit to a health-related page, it can be — and that combination is where the risk lives. An IP address is one of HIPAA's 18 identifiers. The question is never the IP alone; it is what the IP is paired with when it leaves your site.
The combination that matters
In December 2022, OCR took the position that when a visitor's IP address is combined with a visit to a page about a health condition or provider, that pairing is individually identifiable health information. The identifier plus the health context is the disclosure. A pixel that sends both to a vendor without a BAA is the fact pattern behind most healthcare pixel litigation.
What AHA v. Becerra changed — and didn't
In June 2024 the U.S. District Court for the Northern District of Texas vacated the "proscribed combination" theory as applied to unauthenticated public pages. That narrowed one federal interpretation. It did not erase the risk. Behind login — a patient portal, an intake flow — third-party trackers still require a BAA or authorization, full stop. And the vacatur did nothing to state wiretapping laws, MHMDA, or the FTC, which is where the actual lawsuits now come from.
The practical line for a marketer
Treat an IP address as PHI whenever it can be paired with a health signal and sent off your infrastructure. That means: no client-side pixel on condition pages, no health-revealing URLs in event payloads, and BAAs with anything that receives identifiable data. The safe posture did not change when the court ruled — the litigation just moved venues.
FAQ
Does masking the last octet of the IP fix it?
No. Truncation does not change the payload's health context, and it is the pairing that creates the exposure. See why IP anonymization doesn't save GA4.
So after Becerra, are public health pages safe to pixel?
The federal theory narrowed, but state wiretapping suits and MHMDA proceed regardless. Most health organizations keep the strict posture because the lawsuits did not stop.
Is IP the only identifier to worry about?
No — cookie IDs, device IDs, and hashed emails carry the same problem when paired with health context.
Sorting out your exposure?
Coast Studio runs compliance-first paid media for regulated health brands — we map your legal exposure and build tracking that holds up. Not legal advice.
Book a Consultation