HIPAA Tracking · Q&A

Is Hotjar HIPAA Compliant? (Session Recording & Heatmaps on Health Sites)

Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.

Generally no. Session-recording and heatmap tools are among the riskiest trackers a health site can run, because they don't sample data — they watch: mouse movements, scrolls, clicks, and form interactions, replayable per visitor. Hotjar does not offer a BAA as of this writing, which closes the HIPAA path for any surface involving PHI. And on a health site, the pages where you most want CRO insight — booking flows, intake forms, condition pages — are precisely the ones a recording tool must not see.

Why recording is a different category of risk

A pixel leaks metadata; a session recorder captures behavior. Default configurations can capture text as it's typed into forms (before submission — "abandoned" entries included), which condition page someone lingered on, and the whole visit narrative stitched to an identifier. Wiretapping-statute class actions (California's CIPA especially) have targeted session-replay tools by name for years, on the theory that recording a visitor's interactions without proper consent is an interception. Health context turns that from a privacy claim into a health-privacy claim, with the settlement math to match.

Masking features exist and vendors lean on them heavily. Treat masking the way engineers treat any manually-maintained suppression list: fragile. One new form field, one redesigned page, one selector that no longer matches, and the recorder captures what it shouldn't. Masking is a mitigation, not an architecture.

What health CRO teams actually do

  • Choose a vendor that signs a BAA and can be locked down — PostHog, for example, offers BAAs (and self-hosting for teams that want data never to leave their infrastructure). Enterprise replay vendors increasingly have healthcare configurations; the BAA is the gate.
  • Allowlist, don't blocklist: record only explicitly approved non-health surfaces, rather than recording everything and masking the sensitive bits.
  • Never record authenticated or intake flows. Use aggregate funnel analytics (from your BAA-signed analytics stack), moderated user testing with consenting participants, and prototype testing to optimize those.
  • Get consent where state law requires it — for health-adjacent recording, MHMDA-grade opt-in is the safe bar, and it doubles as your CIPA defense.

FAQ

Will Hotjar sign a BAA? As of this writing, no — Hotjar doesn't offer one, which alone rules it out for PHI-involving surfaces. If that changes, the allowlist-and-consent architecture above still applies.

Are heatmaps safer than recordings? Somewhat — aggregated heatmaps are less identifying than individual replays — but the same script collects the underlying interaction data, so the vendor and configuration questions don't change.

Can we run recording only on our marketing site, not the app? That's the right instinct, but "marketing site" and "health-revealing" overlap heavily in healthcare (condition pages, service pages, booking entry points). Allowlist specific pages, don't exempt whole domains.

CRO for health brands without the recording liability — Coast Studio.

JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

HIPAA-compliant tracking, done right

Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.

Book a Consultation