HIPAA Tracking · Q&A
Is Google Tag Manager HIPAA Compliant?
Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Google Tag Manager is neither compliant nor non-compliant — it's a delivery truck, and the compliance question is the cargo. Client-side GTM on a healthcare site is risky because it makes firing third-party trackers effortless and invisible: one marketer, one afternoon, one new tag, and your condition pages are streaming data to an ad platform nobody vetted. Server-side GTM, run in your own cloud environment, is the opposite: it's one of the standard backbones of a compliant healthcare stack.
Same product family, opposite risk profiles. Here's how to think about each.
Client-side GTM: the governance problem
The container itself sends little to Google. The problem is what it enables. In practice, client-side GTM containers on healthcare sites accumulate tags for years — old pixels, abandoned experiments, an SDK someone added for a campaign in 2023. When pixel-litigation plaintiffs crawl health websites, GTM containers are where the skeletons live.
If you keep client-side GTM at all: audit the container quarterly, require a compliance sign-off for every new tag, and never let it run on authenticated or health-revealing surfaces (portals, booking, intake, condition pages).
Server-side GTM: the compliant backbone
Server-side GTM moves tag execution off the visitor's browser and into a container you host — typically on Google Cloud, which (unlike GA4 or Google Ads) is BAA-eligible, meaning the infrastructure your events land on can sit under a signed Google Cloud BAA. From there:
- Events arrive first-party, at your own subdomain.
- You decide what each destination receives — this is where PHI scrubbing rules live.
- Ad platforms (Meta CAPI, Google Ads APIs) get minimal, consented conversion events instead of raw browser data.
Two honest caveats. First, server-side GTM is an architecture, not a compliance status — an unfiltered relay that forwards full URLs downstream is just a more expensive pixel. Second, it needs real maintenance: scrubbing rules are code, and code rots. Purpose-built healthcare gateways (e.g., Curve) trade flexibility for guarantees; self-managed sGTM trades the opposite. We build both — the right choice is a team-capability question, not a tooling religion.
FAQ
Does Google sign a BAA for Google Tag Manager? Not for GTM itself — but GTM isn't where data is stored. Server-side GTM runs on Google Cloud infrastructure, which can be covered under a Google Cloud BAA. The client-side GTM script has no BAA path, which is one more reason to keep it off PHI-adjacent surfaces.
Is server-side GTM enough to make GA4 compliant? No. You can use sGTM to strip data before it reaches GA4, but Google still won't sign a BAA for GA4 — see the full GA4 breakdown. sGTM's value is controlling what reaches ad platforms and BAA-signed analytics tools.
We just deleted GTM entirely. Overkill? Understandable but usually unnecessary — you lose legitimate measurement without addressing the underlying question of what data flows where. A governed server-side setup gives you both control and evidence of control.
Container audit + server-side migration is a fixed-scope engagement for us — talk to Coast Studio.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation