HIPAA Tracking · Q&A
Is Google Ads Conversion Tracking HIPAA Compliant?
Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
The default setup — Google's conversion tag firing in the browser on your thank-you and booking pages — is not HIPAA compliant. Google does not sign a BAA for Google Ads, and client-side conversion tags transmit click identifiers (gclid), IP, and page context from exactly the pages that reveal why someone came to you. But healthcare advertisers can absolutely measure Google Ads conversions compliantly — the pattern is server-side, scrubbed, consented imports instead of browser tags.
Where the default setup leaks
A standard implementation puts Google's tag on conversion pages — "appointment booked," "intake complete" — which are, by definition, the most health-revealing moments on your site. The tag joins the visitor's click ID (which ties back to the exact search or ad) with the conversion context. "Searched 'depression treatment near me,' clicked our ad, booked" is a health record in three data points, sitting in an ad platform with no BAA.
Remarketing tags and audience lists built from site behavior have the same problem, amplified — they exist specifically to profile visitors by what they viewed.
The compliant measurement pattern
- No client-side Google tags on health-revealing or authenticated pages. Conversion pages count.
- Capture conversions first-party — your form handler, scheduling system, or CRM records the conversion and the click ID.
- Import server-side, after scrubbing: send Google the click ID, conversion event, timestamp, and value — nothing describing the service, condition, or person. Offline Conversion Imports and the server-side Enhanced Conversions for Leads API both support this; identifiers like hashed emails flow only with logged, separate consent.
- Skip behavioral remarketing entirely. Health-behavior audiences are indefensible under state law regardless of import mechanics. Optimize with clean conversion signals and let Smart Bidding do the work targeting used to.
Note Google's own ad policies also restrict personalized advertising for health conditions — so behavioral health audiences aren't just a legal risk, they're a policy violation waiting on review.
Performance impact: minimal to none. Bidding algorithms need accurate conversion counts and values, not health context. Our healthcare accounts run on scrubbed server-side imports at full optimization capability.
FAQ
Is Enhanced Conversions HIPAA compliant? The browser-based version has the same problems as any client-side tag. The API/server-side version can fit the compliant pattern — hashed identifiers, only with consent, only with health context stripped.
Can we keep the conversion tag if our thank-you page URL is generic? A generic URL helps less than it seems — the click ID still ties the conversion to the ad and search term, and the tag still runs client-side with no BAA behind it. Server-side import is the durable answer.
Does this work with call conversions? Yes — call conversions imported from a BAA-signed call-tracking platform (see our call-tracking breakdown) into Google Ads, scrubbed the same way.
We run Google Ads for healthcare brands on exactly this architecture — talk to us.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation