HIPAA Tracking · Q&A

Is the Meta (Facebook) Pixel HIPAA Compliant?

Last updated: July 13, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice — validate decisions about your stack with privacy counsel. Full legal landscape: The State of HIPAA Tracking.

No. The Meta pixel is not HIPAA compliant, and you should not run it on any page or flow that can reveal a visitor's health status. Meta does not sign Business Associate Agreements, and the client-side pixel transmits exactly the data combination — identity signals plus health-revealing page context — that has made it the most litigated tracking tool in American healthcare. If one tag on your site deserves removal today, it's this one.

Can you still run Meta ads profitably for a healthcare brand? Yes — but through a different pipe. More on that below.

Why the pixel fails

The pixel runs in the visitor's browser and sends Meta, by default: the full page URL and title ("/services/addiction-treatment/book"), button clicks and form interactions, and identifiers (_fbp/_fbc cookies, IP address, and hashed emails via Advanced Matching). On a healthcare site, that routinely pairs who someone is with what condition or care they were looking at — and since Meta won't sign a BAA, there is no lawful pathway for that data if it constitutes PHI.

Meta says its systems filter potentially sensitive health data. Researchers, regulators, and plaintiff's experts have repeatedly found those filters insufficient — and courts haven't treated "the recipient claims to discard it" as a defense.

The receipts

This isn't a theoretical risk; it's the dominant fact pattern in health-privacy enforcement and litigation: the consolidated In re Meta Pixel Healthcare Litigation; hospital settlements like MarinHealth's $3M; telehealth settlements including Cerebral and RAYUS Radiology; FTC actions against GoodRx ($1.5M) and BetterHelp ($7.8M) built on pixel/SDK data sharing; and a steady stream of state wiretapping (CIPA) demand letters. Aggregate pixel-related payouts across U.S. healthcare are estimated north of $100M.

Didn't the 2024 court ruling settle this?

AHA v. Becerra vacated one OCR theory about public, unauthenticated webpages. It did not touch authenticated flows (portals, booking, intake), state laws like Washington's My Health My Data Act (private right of action, separate opt-in consent for collecting and sharing health data), FTC jurisdiction, or wiretapping statutes — which is where the pixel cases are actually won. The ruling changed one regulator's leverage, not your risk profile.

How to keep Meta ads working — compliantly

You don't quit Meta; you change what reaches it:

  1. Remove the client-side pixel from all health-revealing and authenticated surfaces. For most healthcare sites the clean answer is: remove it everywhere.
  2. Move to the Conversions API through a server-side gateway — self-managed or purpose-built (this is exactly what platforms like Curve exist for).
  3. Scrub before sending: no health-revealing URLs, titles, or form values; only the minimal event data needed for optimization, with consented, hashed identifiers.
  4. Consent and documentation to the strictest standard you face (for national marketers, that's MHMDA-grade).

Clients who make this move typically keep — and often improve — event match quality and ROAS, because server-side events survive ad blockers and browser privacy features that eat client-side pixels. Full CAPI breakdown here.

FAQ

Can I keep the pixel just on non-health landing pages? In theory; in practice it's fragile. Pages drift, tags get copied, and a "safe" page one quarter hosts a condition-specific campaign the next. If you keep any client-side pixel, you need tag governance that treats every new page as a compliance decision.

Does a cookie banner make the pixel OK? No. Standard cookie consent doesn't create a BAA, and it generally doesn't meet MHMDA's requirement of separate, affirmative consent for collecting and for sharing consumer health data.

We're a wellness brand, not a covered entity — can we use it? HIPAA may not reach you, but the FTC and state laws do; GoodRx and BetterHelp were exactly this situation. The safe architecture is the same: server-side, scrubbed, consented.

Meta ads for a health brand, without the liability — that's our job.

JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

HIPAA-compliant tracking, done right

Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.

Book a Consultation