HIPAA Tracking · Living Guide
The State of HIPAA-Compliant Marketing Tracking
Last updated: July 13, 2026 · Reviewed monthly · Jump to changelog
By Jason Garrett, Founder, Coast Studio. I run performance marketing for telehealth and healthcare companies and have written on compliant tracking for Curve and Ours Privacy. This page is general information, not legal advice — decisions about your specific stack belong with your counsel.
The short answer
If you market a healthcare or health-adjacent business in mid-2026, here is the honest state of play:
The federal picture got murkier, not safer. A federal court struck down the most aggressive part of HHS's tracking guidance in 2024, and HHS dropped its appeal. Some marketers read that as a green light. It wasn't. HIPAA itself never changed — only one interpretation of it was vacated — and the enforcement risk simply moved to three other places: the FTC, state attorneys general, and plaintiff's lawyers. By our count, tracking-pixel cases have now cost U.S. healthcare organizations well over $100 million in settlements, and the pace of filings has not slowed.
What that means in practice:
- Client-side pixels (Meta pixel, GA4 tag, TikTok pixel) on pages or flows that reveal anything about a person's health remain a live liability — not primarily because of OCR, but because of state privacy laws with private rights of action and wiretapping-statute class actions.
- You can still measure and scale paid acquisition. The compliant architecture in 2026 is server-side collection, PHI scrubbing before anything reaches an ad platform, explicit consent where state law requires it, and BAAs with every vendor that touches identifiable data.
- "We're not a HIPAA covered entity" is not a defense. The FTC's GoodRx, BetterHelp, and Cerebral actions, and California's Healthline settlement, all targeted companies or publishers outside traditional HIPAA coverage.
The rest of this page walks through each layer — federal, FTC, state, and litigation — and ends with what a compliant stack actually looks like.
Quick reference: can I use it?
| Tool / tactic | On a healthcare site in 2026? | Conditions |
|---|---|---|
| Google Analytics 4 (client-side) | No, not on health-related pages or flows | Google does not sign a BAA for GA4. See our full GA4 breakdown |
| Meta pixel (client-side) | No, on any page that can reveal health status | The fact pattern behind most pixel litigation |
| Meta Conversions API | Yes, with controls | Server-side gateway, PHI scrubbing, consent, documented config |
| Google Tag Manager (client-side) | Risky | GTM itself isn't the issue; the tags it fires are |
| Server-side GTM / tracking gateway | Yes — the backbone of the compliant stack | Self-hosted or HIPAA-capable vendor with BAA |
| Google Ads conversion tracking | With controls | Offline/server-side imports of scrubbed, consented events |
| Retargeting off site visits to condition pages | No | State laws + litigation exposure, regardless of OCR status |
| Session recording / heatmaps on health flows | Generally no | Only with aggressive masking, consent, and a BAA-signing vendor |
| Call tracking | Only on a HIPAA-specific plan | Vendor must sign a BAA; recordings are PHI |
| Email/SMS to patients | Yes, within HIPAA marketing rules | Authorization for marketing uses; BAA with the platform |
Layer 1: HIPAA and the OCR guidance — what's actually left
December 2022: HHS's Office for Civil Rights published its bulletin on online tracking technologies, taking the position that when a visitor's IP address is combined with a visit to a webpage about health conditions or providers, that combination can be protected health information (PHI) — even on public, logged-out pages.
March 2024: OCR updated the guidance, softening the language but keeping the core theory.
June 20, 2024 — the turning point: In American Hospital Association v. Becerra, the U.S. District Court for the Northern District of Texas vacated the "proscribed combination" portion of the guidance — the claim that IP address + a visit to an unauthenticated, public health-related webpage is automatically individually identifiable health information. HHS initially appealed, then withdrew the appeal.
What survived, and still binds you today:
- Authenticated experiences are untouched. Tracking inside patient portals, logged-in telehealth apps, scheduling flows, or intake forms involves PHI under any reading of HIPAA. Third-party trackers there require a BAA or valid authorization — full stop.
- HIPAA itself never changed. The court vacated an interpretation, not the Privacy Rule. If tracking on your public pages does capture identifiable health information in context (a symptom checker, a condition-specific booking page tied to an identity), you're back inside HIPAA territory.
- OCR can still enforce case-by-case. Losing the bulletin's broadest theory doesn't stop enforcement built on ordinary HIPAA analysis.
The practical takeaway: the vacatur narrowed one federal theory about public pages. Everything else — and every other regulator — is still in play.
Layer 2: The FTC — the regulator for everyone HIPAA doesn't cover
If you're a DTC health brand, wellness app, supplement company, or health publisher, the FTC is your primary federal risk, and it has been aggressive:
| Action | Date | Outcome |
|---|---|---|
| GoodRx | Feb 2023 | $1.5M penalty — first-ever Health Breach Notification Rule enforcement, over ad-pixel data sharing |
| BetterHelp | 2023 | $7.8M for sharing health data with ad platforms |
| Premom (Easy Healthcare) | May 2023 | $100K penalty over app SDK data sharing |
| Cerebral | Apr 2024 | Order restricting use of health data for advertising |
| Healthline (CA AG, CCPA) | 2025 | $1.55M — the largest CCPA settlement at the time, and it reached a publisher for transmitting article titles that imply a diagnosis |
The pattern across all five: sending health-revealing signals to ad platforms via pixels and SDKs, exactly the behavior a default pixel install produces on a health site.
Layer 3: State law — where the private lawsuits come from
Washington's My Health My Data Act (MHMDA) is the most consequential marketing-privacy law in the country right now. In effect since March 2024, it defines "consumer health data" sweepingly, requires separate opt-in consent to collect health data and a second separate consent to share it, bans geofencing near health facilities outright, and — the part that changes everything — includes a private right of action. The first MHMDA class actions are already moving, including Maxwell v. Amazon, which alleges ad software inferred health status from location data.
Other states have followed — Nevada and Connecticut added consumer-health-data provisions, New York enacted its own health-data privacy law, and roughly twenty comprehensive state privacy laws are in effect in 2026, most treating health data as "sensitive" and requiring opt-in consent. If you market nationally, you effectively market under the strictest state's rules.
Layer 4: The class-action machine
While regulators moved in years, plaintiff's firms moved in weeks. The playbook: scan health-sector websites for pixels, then file under state wiretapping statutes (especially California's CIPA), consumer protection acts, or MHMDA. Representative outcomes: the consolidated In re Meta Pixel Healthcare Litigation, MarinHealth's $3M settlement, and settlements from Cerebral and RAYUS Radiology, with security researchers estimating over $100M in aggregate pixel-related payouts across U.S. healthcare. CIPA demand letters have become their own cottage industry — many health brands' first contact with this issue is a settlement demand, not a regulator.
What compliant tracking actually looks like in 2026
This is the architecture we implement for healthcare clients. None of it requires giving up paid acquisition — it requires re-plumbing how data reaches ad platforms.
- Inventory first. Crawl every page and flow; catalog every pixel, tag, and SDK and exactly what each transmits. Most organizations are shocked by what a default GTM container fires. (This audit is also your evidence of good faith if anything goes wrong.)
- Strip client-side trackers from anything health-revealing. Condition pages, symptom content, booking and intake flows, portals: no third-party JavaScript that phones home.
- Move measurement server-side. First-party collection into a server-side gateway (server-side GTM or a purpose-built platform such as Curve or Freshpaint), where you control what leaves.
- Scrub before you send. PHI redaction on every outbound event: no health-revealing URLs, page titles, or form values in what reaches Meta CAPI or Google's APIs — send the minimum needed to optimize (event, timestamp, hashed consented identifiers).
- Consent where required. MHMDA-grade opt-in for collecting/sharing health data, logged and documented — not a cookie banner formality.
- BAAs with everything that touches identifiable data. Analytics, CDP (e.g., Ours Privacy), call tracking, email/SMS. If a vendor won't sign one, they don't get identifiable data.
- Document and re-audit quarterly. Suppression configs, consent logs, data maps. Litigation risk is heavily driven by what you can prove you did.
Done right, healthcare brands still get conversion optimization, attribution, and scale — several of our clients measurably improved ROAS after the migration because server-side data is more complete than what ad blockers leave of client-side pixels.
FAQ
Is Google Analytics HIPAA compliant in 2026? No — Google will not sign a BAA for GA4, so it cannot be used where PHI is involved. On purely public, non-health-revealing pages the analysis is more nuanced after AHA v. Becerra, but state laws and litigation risk lead most healthcare organizations to replace or gate it. Full breakdown here.
Did the court ruling make the Meta pixel legal for healthcare sites? No. It vacated one federal interpretive theory about public webpages. Wiretapping class actions, MHMDA, the FTC, and HIPAA's application to authenticated pages are all unaffected — and they are where the actual dollars have been lost.
We're a wellness brand, not a covered entity. Does any of this apply? Yes. GoodRx, BetterHelp, Premom, and Healthline were all reached without traditional HIPAA coverage — via the FTC Act, the Health Breach Notification Rule, and state law. If your data can reveal health status, someone regulates it.
Can I still run retargeting? Not off health-revealing site behavior. Compliant alternatives exist — contextual targeting, consented first-party audiences with scrubbed identifiers, and platform-side broad targeting optimized by clean server-side conversion signals.
Is server-side tracking automatically HIPAA compliant? No — server-side is an architecture, not a compliance status. It becomes compliant through what you do with it: scrubbing, consent, BAAs, and documentation.
What should we do if we discover a pixel has been sending PHI? Stop the flow, preserve evidence, and get counsel involved immediately — breach notification obligations may apply and timelines are short. Then fix the architecture so it can't recur.
Not legal advice. This page summarizes a fast-moving area for marketing decision-makers; validate anything consequential with your privacy counsel. Spot an error or a development we haven't covered? Email me — this page gets corrected, with credit.
Work with us: Coast Studio runs HIPAA-aware performance marketing for telehealth, healthtech, and DTC health brands — including the tracking architecture described above. Start a conversation.
Changelog
- July 13, 2026 — Page launched. Current through the OCR guidance vacatur and appeal withdrawal, MHMDA litigation (incl. Maxwell v. Amazon), the Healthline CCPA settlement, and the 2026 state-law landscape.
The full diagnosis set
- Is Google Analytics HIPAA Compliant?
- Is the Meta (Facebook) Pixel HIPAA Compliant?
- Is the Meta Conversions API (CAPI) HIPAA Compliant?
- Is Google Tag Manager HIPAA Compliant?
- Is Google Ads Conversion Tracking HIPAA Compliant?
- Does HIPAA Apply to My Website If We Don't Collect PHI Online?
- Is the TikTok Pixel HIPAA Compliant?
- Is Hotjar HIPAA Compliant? (Session Recording & Heatmaps on Health Sites)
- Is CallRail HIPAA Compliant? (Call Tracking for Healthcare)
- Is HubSpot HIPAA Compliant for Healthcare Marketing?
- Is Klaviyo HIPAA Compliant for a Telehealth or Health Brand?
- Are Mixpanel and Amplitude HIPAA Compliant? (Product Analytics for Health Apps)
Jason Garrett
Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.
Connect on LinkedIn →HIPAA-compliant tracking, done right
Coast Studio runs privacy-compliant performance marketing for telehealth, healthtech, and DTC health brands — including the server-side tracking architecture described here.
Book a Consultation