Coast Studio
Book a Consultation
  • Methodology
  • Growth LabsEcommerce & DTC Scale Regulated MarketsHealth, Fintech & Legal
  • Creative
  • Case Studies
  • Blog
  • About
  • Methodology
  • Growth Labs
  • Regulated Markets
  • Creative
  • Case Studies
  • Blog
  • About
  • Book Consultation →
Home / Blog / Is an IP Address PHI Under HIPAA?

HIPAA Tracking · Q&A

Is an IP Address PHI Under HIPAA?

Last updated: August 10, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.

On its own, no. Joined to a visit to a health-related page, it can be — and that combination is where the risk lives. An IP address is one of HIPAA's 18 identifiers. The question is never the IP alone; it is what the IP is paired with when it leaves your site.

The combination that matters

In December 2022, OCR took the position that when a visitor's IP address is combined with a visit to a page about a health condition or provider, that pairing is individually identifiable health information. The identifier plus the health context is the disclosure. A pixel that sends both to a vendor without a BAA is the fact pattern behind most healthcare pixel litigation.

What AHA v. Becerra changed — and didn't

In June 2024 the U.S. District Court for the Northern District of Texas vacated the "proscribed combination" theory as applied to unauthenticated public pages. That narrowed one federal interpretation. It did not erase the risk. Behind login — a patient portal, an intake flow — third-party trackers still require a BAA or authorization, full stop. And the vacatur did nothing to state wiretapping laws, MHMDA, or the FTC, which is where the actual lawsuits now come from.

The practical line for a marketer

Treat an IP address as PHI whenever it can be paired with a health signal and sent off your infrastructure. That means: no client-side pixel on condition pages, no health-revealing URLs in event payloads, and BAAs with anything that receives identifiable data. The safe posture did not change when the court ruled — the litigation just moved venues.

FAQ

Does masking the last octet of the IP fix it? No. Truncation does not change the payload's health context, and it is the pairing that creates the exposure. See why IP anonymization doesn't save GA4.

So after Becerra, are public health pages safe to pixel? The federal theory narrowed, but state wiretapping suits and MHMDA proceed regardless. Most health organizations keep the strict posture because the lawsuits did not stop.

Is IP the only identifier to worry about? No — cookie IDs, device IDs, and hashed emails carry the same problem when paired with health context.

Related

  • The State of HIPAA-Compliant Marketing Tracking
  • Is the Meta Pixel HIPAA Compliant?
  • Does HIPAA Apply to My Website?
  • Healthcare Pixel Audit Checklist
JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

Sorting out your exposure?

Coast Studio runs compliance-first paid media for regulated health brands — we map your legal exposure and build tracking that holds up. Not legal advice.

Book a Consultation
Coast Studio

© 2026 Left Coast Agency, LLC.

AboutJason GarrettBlogPrivacyTermsContact
Google Partner