Home / Insights / Healthcare

Healthcare

HIPAA-Aware Marketing Analytics for Healthcare Sites

Analytics on healthcare sites is a data-governance question before it is a marketing question. HHS says tracking technologies on authenticated pages generally touch PHI and that vendors receiving PHI are business associates requiring a BAA, while a June 2024 court order vacated part of that bulletin covering IP-plus-unauthenticated-page visits. Build measurement that avoids sensitive identifiers regardless of how the rest of the guidance evolves.

Why this is different from ordinary analytics governance

Most sites treat analytics as a marketing tool. Healthcare sites have to treat it as a data-governance surface first, because the same pixels and tags that measure a campaign can also transmit protected health information.

That reframing changes who should own the decision: an analytics implementation on a healthcare site is a compliance decision with a marketing component, not the reverse, and the sign-off process should reflect that ordering.

None of the guidance above should be read as clinical advice; it addresses marketing, advertising, privacy, and patient education only, and any clinical question should go to a licensed provider.

  • Where guidance in this space is still evolving, as with tracking technology rules, default to the most conservative reading available rather than the most permissive one, since the cost of over-caution is far lower than the cost of a real violation.

What HHS says

HHS states that individually identifiable health information collected on a regulated entity's website or app generally is PHI, even absent an existing relationship or treatment or billing detail. [HHS OCR, Use of online tracking technologies by HIPAA covered entities]

Tracking technologies on user-authenticated pages generally have access to PHI, so those pages must be configured to comply with the Privacy Rule and secured under the Security Rule. [HHS OCR]

Website banners asking users to accept or reject cookies do not constitute a valid HIPAA authorization, and privacy-policy disclosure alone does not permit disclosures of PHI. [HHS OCR]

  • Tracking vendors that create, receive, maintain, or transmit PHI are business associates and require a signed BAA; a vendor's promise to strip or de-identify PHI after receipt is insufficient. [HHS OCR]
  • OCR states it is prioritizing HIPAA Security Rule compliance in investigations into the use of online tracking technologies. [HHS OCR]

What the 2024 court order changed

On June 20, 2024, the U.S. District Court for the Northern District of Texas vacated the portion of HHS guidance applying HIPAA where technology connects an IP address with a visit to an unauthenticated page addressing specific health conditions or providers, in American Hospital Association v. Becerra. [HHS OCR]

That narrowing applies specifically to the IP-address-plus-unauthenticated-page scenario, and does not change the guidance on authenticated pages, so most patient portal and account-area tracking decisions are unaffected by the ruling.

Practices that build compliance into the workflow from the outset tend to spend less time on rework later, since retrofitting consent language or claim substantiation after publication is far more expensive than designing for it up front.

Where the FTC picks up non-HIPAA entities

The FTC's first Health Breach Notification Rule enforcement action, against GoodRx, involved sharing prescription and health-condition data with Facebook, Google, Criteo, Branch, and Twilio, resulting in a $1.5 million civil penalty. [FTC press release, January 31, 2023]

Assign clear ownership for compliance review inside the marketing function itself, rather than treating it as something legal handles entirely separately, since the fastest catches happen when the person writing the content already knows the rules.

Designing a leakage-resistant stack

Build an event taxonomy with no condition-level detail, and make sure no data Google could recognize as PII is passed to Analytics, including in URLs, titles, custom dimensions, and campaign parameters. [Google Analytics Help, Best practices to avoid sending PII]

Design the taxonomy once, in writing, and require any new tag or integration to be checked against it before deployment, rather than relying on individual judgment call by call, since inconsistent judgment across a marketing team is how leakage tends to happen.

Train every new hire who touches patient-facing marketing on this rulebook specifically, rather than assuming general marketing experience transfers cleanly, since the constraints in this category diverge sharply from ordinary consumer marketing practice.

A tag audit you can run quarterly

Every quarter, inventory every tag and pixel on authenticated and unauthenticated pages, confirm BAAs are in place wherever PHI could flow, and re-test that no identifying parameters have crept back into analytics.

Keep a running file of every claim made in marketing materials along with its supporting evidence, so a compliance review or an unexpected audit can be answered quickly rather than reconstructed after the fact.

Frequently asked questions

Is the HHS tracking bulletin still in force?

Partly; a portion was vacated in June 2024 and HHS said it was evaluating next steps (HHS OCR, https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html).

Does a cookie banner make pixels compliant?

No (HHS OCR, https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html).

Do I need a BAA with an analytics vendor?

If the vendor receives PHI, yes (HHS OCR, https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html).

What if we are not HIPAA-covered?

The FTC's Health Breach Notification Rule can apply to health apps and PHR-related entities, with 60-day individual notice duties (FTC, https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0).

Can we still measure marketing?

Yes, with event taxonomies that exclude condition-level and identifying detail (Google, https://support.google.com/analytics/answer/6366371).

Primary sources

Policy and statistical claims in this guide are grounded in the sources below. Access dates and policy details can change, so verify regulated guidance before acting.

Seven clients. One of them could be you.

Tell us what you're building and what's stalled. If we're not the right fit, we'll say so on the call - and point you somewhere better.

Start a project