HIPAA Tracking · Playbook
How to Run Meta Ads for a Telehealth Company Without Violating HIPAA
Last updated: August 10, 2026 · By Jason Garrett, Founder, Coast Studio. Not legal advice — review your setup with healthcare counsel. Full legal landscape: The State of HIPAA Tracking.
You can run Meta ads for telehealth. You cannot run them the way a DTC brand does. The pixel-on-every-page, retarget-everyone, lookalike-from-your-customer-list setup sends protected health information to a company that refuses to sign a BAA — and regulators, plaintiff firms, and Meta itself now police that pipeline. The compliant version routes every event through a scrubbing layer, targets broad, and measures with modeled data. This playbook covers the full build.
Why telehealth is the hardest case on Meta
A telehealth company faces three referees at once.
HIPAA and OCR. Most telehealth companies are covered entities. OCR's online-tracking guidance (December 2022, revised March 2024) treats identifiers sent from health-related pages as PHI. A court vacated part of that theory in AHA v. Becerra (June 2024), and the rest survives — along with the underlying Privacy Rule, which never left. Our living guide tracks the current status.
The FTC and the states. GoodRx, BetterHelp, and Cerebral each paid for sharing health data with ad platforms, and none of those cases needed HIPAA. Washington's My Health My Data Act adds a private right of action and an opt-in consent standard that reaches most telehealth marketing. California's CIPA keeps a cottage industry of demand letters running.
Meta's own restriction system. Since January 2025, Meta auto-classifies health and wellness ad accounts into restriction tiers. Telehealth typically lands where Purchase and Lead events get blocked, custom parameters get dropped, and URLs get stripped after the domain. Mental health, weight management (GLP-1 included), reproductive health, and addiction treatment land in the strictest tier — and Meta reclassifies accounts without notice. We cover the restriction system itself in the 2026 restriction playbook.
The result: you must protect data Meta should never see, using an ad account Meta has already handicapped. Plan for both from day one.
Step 1: Classify your exposure
Answer three questions before touching Ads Manager.
- Are you a covered entity or business associate? A telehealth company providing care and billing insurance almost certainly is. A cash-pay wellness brand may fall outside HIPAA and still answer to the FTC and state law. See Does HIPAA apply to my website?
- Which Meta tier are you in? Check Events Manager for the restriction notice on your domain. Your tier decides which events you can optimize toward.
- Where do your users live? Washington and a growing list of states require opt-in consent before any health data touches an ad platform.
Write the answers down. Every later decision keys off them.
Step 2: Split the marketing site from the care experience
Draw a hard line between your marketing pages and everything behind login.
- Marketing site: public condition and service pages, pricing, FAQs. Ad tags may run here, subject to the scrubbing rules below.
- Care experience: intake forms, scheduling, patient portal, visit flows. Ad platform code never runs here. No pixel, no CAPI events, nothing.
Intake is the common failure. The moment a visitor types a condition into a form on a page carrying the pixel, you have transmitted PHI. Keep the form on a tag-free domain or subdomain.
Step 3: Rebuild measurement server-side, behind a scrubbing gateway
Meta's Conversions API lets you control every field that leaves your servers — which makes it the foundation of compliant tracking, and only that. CAPI alone is not HIPAA compliance; Meta still signs no BAA. The architecture that works:
- Remove the browser pixel from any page where the URL, title, or content reveals a condition. On the strictest read, remove it everywhere and go pure server-side. See our Meta pixel analysis.
- Route CAPI through a scrubbing layer — a purpose-built gateway like Curve, or self-managed server-side GTM under a BAA with your host. The gateway strips health-revealing URLs, page titles, form values, and custom parameters before anything reaches Meta.
- Send the minimum: event name, timestamp, value, and — only with logged, opt-in consent — hashed email or phone.
- Use a neutral event taxonomy.
signup_completeoptimizes as well asdepression_consult_bookedand discloses nothing. Neutral events also survive Meta's tier filters that block health-flagged parameters. - Sanitize URLs.
/treatments/depression-medicationleaks in the event payload and trips Meta's classifier. Route condition pages through neutral paths and keep condition detail in on-page content. - Document everything: scrubbing configuration, consent records, data maps. When counsel or a regulator asks what Meta receives, the answer should be a one-page spec.
Step 4: Target without patient data
Patient data stays out of the ad account. That rules out:
- Custom audiences from patient lists. Uploading patient emails to Meta discloses PHI, consent form or none in most cases.
- Lookalikes seeded from patients. The seed is the disclosure.
- Retargeting from condition pages. The audience definition itself encodes health status, and your tier has throttled these pools anyway.
What replaces them:
- Broad targeting with creative as the filter. Meta's delivery system finds your buyer when the creative names the problem plainly. This is where the platform already forces most telehealth accounts, and it works.
- Consented prospect lists. Newsletter subscribers and content leads who opted in to advertising use, gathered before any care relationship exists.
- Engagement audiences built from ad and page interactions inside Meta, which involve no patient data of yours.
Step 5: Write creative that clears both reviewers
Your creative passes through Meta review and, effectively, regulator review. Rules that keep both happy:
- Sell access and convenience: "See a licensed provider this week, from home."
- Keep diagnoses out of testimonials. Outcome claims tied to a named condition invite FTC scrutiny and Meta rejection.
- Match the landing page to the ad's level of specificity, and keep tags off any page that names a condition next to a form.
- For prescription services, keep your LegitScript certification current; Meta requires it for telehealth ads involving prescription drugs.
Step 6: Get consent before the first event fires
Run a consent management platform on the marketing site. For visitors from opt-in states, fire ad tags only after affirmative consent — the MHMDA standard, which we expect more states to copy. Log consent with timestamps and tie those logs to the identifiers you send through CAPI. Consent gates also shrink your CIPA surface.
Step 7: Measure ROAS without the surveillance
With thin event data, measurement moves up a level:
- Modeled and aggregate reporting inside Meta covers day-to-day optimization.
- Geo holdouts and incrementality tests answer the budget question — did Meta drive signups — without any user-level data leaving your walls.
- First-party attribution (a compliant analytics stack plus "how did you hear about us?" at signup) closes the loop inside systems you control under BAAs.
CFOs accept this faster than most marketers expect. A clean geo-lift readout beats a ROAS column built on data you were never allowed to send.
Already running the standard setup?
Turn off the pixel today, inventory 12 months of transmitted data with counsel, and decide on breach notification before you rebuild. Speed matters here; the plaintiff bar reads Events Manager configurations too.
FAQ
Can I retarget website visitors at all? General-brand pages (home, pricing, how-it-works) carry lower risk than condition pages, and some counsel signs off on retargeting from them with consent gating. Condition-page retargeting fails the test. Many telehealth companies skip retargeting and let broad targeting do the work.
Do lookalike audiences from a "marketing list" work? Only if the list predates any care relationship and every contact opted in to ad use. A list exported from your EHR fails no matter what the consent form said.
Does using Curve or a similar gateway make me HIPAA compliant? It makes your ad pipeline defensible. Compliance covers your whole organization — policies, BAAs, training, the rest. The gateway solves the tracking piece.
Do I need a BAA with Meta? You would, if Meta signed them. It does not, which is why nothing that qualifies as PHI can reach Meta at all.
Want the rebuild done right? This is a core Coast Studio build.
Related
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →Meta ads for telehealth, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side architecture and compliant campaign structure described here.
Book a Consultation