HIPAA Tracking · Q&A
Is the Meta Conversions API (CAPI) HIPAA Compliant?
Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.
Not by itself — Meta still doesn't sign BAAs, so nothing about CAPI is inherently HIPAA compliant. But CAPI is the mechanism that makes compliant Meta advertising possible, because unlike the pixel, it puts you in control of every field that leaves your infrastructure. The pixel broadcasts whatever the browser sees; CAPI sends only what your server chooses to send. Compliance lives in that choice.
The distinction that matters
A client-side pixel is a firehose you can't filter: URLs, titles, click data, and identifiers flow to Meta from the visitor's browser. CAPI inverts the model — events go first to your server (or a gateway you control), where they can be inspected, stripped, and minimized before anything reaches Meta.
That inversion is the whole game. It's why "we replaced the pixel with CAPI" can be either a genuine compliance fix or a cosmetic one, depending entirely on what your implementation forwards. A naive CAPI setup that relays full page URLs and un-consented identifiers has the pixel's problems with extra steps.
What a defensible CAPI implementation looks like
- A server-side gateway you control — server-side GTM in your own cloud environment, or a purpose-built healthcare gateway like Curve, which exists precisely to scrub PHI from ad-platform event streams.
- PHI scrubbing as a hard rule, not a habit: no health-revealing URLs, page titles, form values, or custom parameters. Event name, timestamp, and value only.
- Identifiers only with consent: hashed emails/phones flow only for users whose separate, logged consent covers sharing — MHMDA's standard, which is the strictest you'll face nationally.
- Data minimization by default: send the least Meta needs to optimize. Match quality scores are not a compliance KPI.
- Documentation: the scrubbing config, the consent log, and a data map. In litigation, provable architecture is the difference between a nuisance letter and a settlement.
Does stripping all that data kill performance?
No — and this surprises people. Server-side events survive ad blockers, Safari's tracking prevention, and cookie decay that silently eat 20-40% of client-side pixel events. Most healthcare accounts we've migrated see equal or better event volume and ROAS after the move, with optimization running on clean conversion counts rather than granular (and radioactive) behavioral detail.
FAQ
Is CAPI a substitute for a BAA with Meta? No. There is no BAA with Meta, which is why nothing identifying a patient and their health status can be sent — with or without CAPI. The architecture works by ensuring what reaches Meta isn't PHI in the first place.
Can I run the pixel and CAPI together like Meta recommends? Meta's "redundant setup" advice is written for e-commerce, not healthcare. Running the pixel alongside CAPI reintroduces exactly the client-side leak you were fixing. Healthcare setups should be CAPI-only.
Do I need a vendor, or can we build this ourselves? Self-managed server-side GTM works if you have the engineering discipline to maintain scrubbing rules forever. Purpose-built gateways cost money but make the scrubbing a product guarantee instead of a tribal-knowledge script. We implement both; the right answer depends on your team.
Want the migration done right? This is a core Coast Studio build.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation