HIPAA Tracking · Q&A

Is Google Analytics HIPAA Compliant?

Last updated: July 13, 2026

By Jason Garrett, Founder, Coast Studio — performance marketing for healthcare and telehealth brands. Not legal advice; architecture decisions for your stack belong with your privacy counsel.

No. Google Analytics is not HIPAA compliant, and it cannot be made HIPAA compliant for any page or flow that involves protected health information, because Google does not sign a Business Associate Agreement (BAA) for GA4. No configuration — not IP anonymization, not Consent Mode, not data-retention settings — changes that. If GA4 can receive data that identifies a person and says something about their health, care, or payment for care, it does not belong there.

That's the verdict. The useful part is understanding where the line actually sits, because "just delete Google Analytics" is wrong too — and expensive in lost measurement.

Why GA4 fails the HIPAA test

HIPAA lets a covered entity share PHI with a vendor only under a BAA, in which the vendor accepts HIPAA obligations. Google explicitly excludes Google Analytics from the products it will cover under a BAA (it offers BAAs for certain Google Cloud and Workspace services — not GA4). Without a BAA, sending PHI to Google Analytics is an impermissible disclosure. Full stop.

And GA4 receives more than most teams realize. By default it can capture full page URLs and titles ("/conditions/hiv-testing/schedule"), form interactions, click IDs that tie back to ad accounts, device identifiers, and — before processing — IP addresses. On a healthcare site, combinations like identity signal + health-revealing page context are exactly what regulators and plaintiff's lawyers call health data.

"But we turned on IP anonymization"

This is the most persistent myth in healthcare analytics, so let's kill it properly:

  1. A BAA still doesn't exist. Anonymizing one field doesn't create a contract Google refuses to sign.
  2. IP was never the only identifier. Client IDs, user IDs, click IDs (gclid), and device signals still flow.
  3. The health-revealing context is the URL and page title, not the IP. Masking who's asking doesn't help much when the payload says what they were asking about.

Didn't a court ruling change all this?

Partially — and it's worth being precise, because this is where marketers get overconfident. In June 2024, in American Hospital Association v. Becerra, a federal court vacated the portion of HHS's tracking guidance that treated IP address + a visit to a public, unauthenticated health-related webpage as automatically protected health information, and HHS later withdrew its appeal.

What that ruling did not do:

  • It didn't touch authenticated experiences — portals, logged-in telehealth, scheduling, intake. Analytics there involves PHI under any reading, and GA4 remains off-limits.
  • It didn't change state law. Washington's My Health My Data Act (with a private right of action), plus roughly twenty comprehensive state privacy laws in effect in 2026, restrict health-data collection and sharing independent of HIPAA.
  • It didn't slow the class-action machine — wiretapping-statute suits over web tracking have cost U.S. healthcare organizations over $100M in settlements, and analytics tools appear in those complaints alongside ad pixels.
  • It didn't rule that public-page analytics is safe — only that OCR's blanket theory overreached.

So post-ruling, the sober read is: GA4 on a purely informational blog page about, say, your company's funding announcement is a low-risk judgment call. GA4 anywhere a visitor's behavior reveals something about their health is a liability with four different owners: OCR, the FTC, state AGs, and plaintiff's firms. (The full landscape is on our continuously updated State of HIPAA Tracking page.)

What healthcare marketers actually use in 2026

You don't give up measurement — you change the plumbing:

  • HIPAA-capable analytics with a BAA. Purpose-built platforms (e.g., Freshpaint for event routing, Piwik PRO for GA-style analytics, Ours Privacy as a HIPAA-compliant CDP) that sign BAAs and give you control over what's collected and where it goes.
  • Server-side collection with PHI scrubbing. First-party data into a server-side gateway; health-revealing URLs, titles, and form values stripped before anything reaches Google or Meta. This is how you keep conversion optimization and ROAS measurement without handing raw visitor data to ad platforms. (Tools like Curve exist specifically for the ad-tracking half of this.)
  • Consent done to the strictest standard you face — for national marketers that effectively means MHMDA-grade separate opt-ins for collection and sharing of health data.
  • A gated GA4 pattern, if you keep it at all: GA4 restricted to genuinely non-health pages, with server-side controls guaranteeing nothing health-revealing can reach it. Most of our clients eventually conclude the split-stack complexity isn't worth it and consolidate on a compliant platform.

Migration checklist

  1. Inventory every tag on every page (crawl it — don't trust the GTM container list).
  2. Classify pages/flows: health-revealing vs. not, authenticated vs. not.
  3. Remove GA4 (and all client-side third-party tags) from health-revealing and authenticated surfaces immediately — this is the exposure, and it's fixable in a day.
  4. Stand up the replacement: BAA-signed analytics + server-side gateway + scrubbing rules.
  5. Rebuild ad-platform conversion feeds from scrubbed server-side events.
  6. Document everything: what you removed, when, what replaced it, and your consent logs.

FAQ

Can I use GA4 if my practice never puts patient data on the website? If no page, URL, or form on your site can reveal anything about a visitor's health status or care-seeking, your HIPAA exposure via GA4 is limited — but confirm the "never" with a real crawl (appointment forms and condition pages usually break the assumption), and remember state privacy laws apply to "consumer health data" far beyond HIPAA's definition of PHI.

Is Google Analytics 360 (the paid version) HIPAA compliant? No — the BAA problem is identical. Paying for GA doesn't change Google's terms.

Will Google ever sign a BAA for GA4? Nothing suggests it. Google's BAA covers select Cloud/Workspace products; Analytics has been consistently excluded for years.

Is Piwik PRO (or Matomo) automatically HIPAA compliant? No tool is automatically compliant. These platforms can be operated compliantly — BAA (or self-hosting), appropriate configuration, access controls — which is exactly what GA4 can't offer.

What about Google Ads conversion tracking — same problem? Related but distinct: the compliant pattern is server-side import of scrubbed, consented conversion events rather than client-side tags on health pages. That deserves its own guide — see the flagship page for the architecture.


Questions about your specific stack? This is what we do at Coast Studio — get in touch, or start with the free tracking-audit checklist.

JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

HIPAA-compliant tracking, done right

Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.

Book a Consultation