Skip to content

BlogHow To Guides

HIPAA-Compliant Marketing Tracking and Analytics

Most pages ranking for this question are vendors implying a compliance they do not hold, and most people asking it are not covered by HIPAA at all. What the law actually reaches, why no configuration makes Google Analytics compliant, what the 2024 court ruling changed, and how to tell a real BAA from a compliance badge.

HIPAA-compliant marketing tracking and analytics, explained
Contents
  1. Quick summary
  2. Does it apply to you
  3. What becomes PHI
  4. Google Analytics
  5. The 2024 ruling
  6. The ad platforms
  7. Calls and forms
  8. What a stack needs
  9. Who signs a BAA
  10. If it does not apply
  11. Where we fit
  12. Further Reading
Summarise this article with AI

Opens the page with a ready prompt in:

Nothing is sent until you pick a service.

Search for HIPAA-compliant tracking and you get two kinds of page. Vendors with a compliance badge in the header and no business associate agreement behind it, and law firm explainers that describe the statute without ever saying which tool you may actually install.

Both skip the question that decides everything else: whether HIPAA reaches you at all. A large share of the people asking are med spas, wellness brands, supplement shops, fitness apps and clinics outside the United States, none of whom are covered by it, and many of whom have spent two years measuring nothing out of a fear that was never theirs.

This guide separates the two groups, then answers each one honestly. What becomes protected health information inside a tracking stack, why no configuration makes Google Analytics compliant, what the June 2024 court ruling did and did not change, what a compliant stack actually needs, and what to do instead when the law does not apply to you.

Quick Summary: What HIPAA Requires of Your Tracking

In short

HIPAA reaches you only if you are a covered entity (a US healthcare provider, health plan or clearinghouse) or a business associate handling protected health information on one's behalf. If you are, the rule is short and unforgiving: every vendor that touches PHI must sign a business associate agreement, and no amount of configuration substitutes for one. Google will not sign a BAA for Google Analytics or Google Ads, and Meta will not sign one at all, which is why no setup makes them compliant for a covered entity. There is no HIPAA certification, so a compliance badge on a vendor's site means nothing on its own; the only question worth asking is whether they will put a BAA in writing. If you are not a covered entity, none of this binds you, and the right framework is your own privacy law, which for most of the world is the GDPR.

First: Does HIPAA Apply to You at All?

HIPAA is not a general health privacy law. It is a law about a specific set of organisations and the vendors working for them, and its scope is much narrower than the way the word gets used in marketing.

  • Covered entities

    US healthcare providers who bill electronically, health plans and healthcare clearinghouses. Hospitals, clinics, dental and therapy practices, telehealth companies that bill insurance.

  • Business associates

    Anyone creating, receiving, maintaining or transmitting PHI on a covered entity's behalf. Your CRM, your call tracking, your analytics vendor, your agency.

  • Everyone else

    Med spas paying cash, supplement and wellness brands, fitness and mental wellness apps, and every healthcare business outside the United States. HIPAA does not reach them.

That third box is bigger than the industry admits. A cash-pay aesthetics clinic that never touches insurance is usually not a covered entity. A wellness app that no provider has hired is not one either. And a clinic in Munich, Zurich or Dubai is outside the statute entirely, whatever a US vendor's sales deck implies.

Not covered does not mean unregulated

The FTC's Health Breach Notification Rule reaches consumer health apps that HIPAA does not, several US states now have their own health data laws, and outside the US the GDPR treats health data as a special category under Art. 9 with its own consent requirements. Falling outside HIPAA changes which rulebook you read, not whether there is one.

So establish this before you buy anything. If you are a covered entity or a business associate, the BAA requirement below is absolute. If you are not, you are reading the wrong law, and the sections from "If HIPAA does not apply to you" onward are the ones written for you.

What Becomes PHI Inside a Tracking Stack

Protected health information is health information that identifies a person, held by a covered entity or its business associate. Marketers underestimate how easily ordinary tracking data crosses that line, because the identifier and the health context usually arrive separately and get joined by the tool rather than by anyone's decision.

  • The identifier is rarely a nameAn IP address, a cookie id, a device id, an advertising id or a hashed email all identify a person for this purpose. Removing the name removes very little.
  • The URL carries the diagnosisA page path like /treatments/fertility or a query string with a condition name is health information about whoever loaded it, and it travels with every pixel by default.
  • The appointment is the disclosureA booking confirmation that fires a conversion event with the specialty attached tells the recipient that this person is being treated for that thing.
  • The call recording is the whole recordCall tracking that records and transcribes a patient describing symptoms is holding clinical information, not a marketing touchpoint.

The pattern that produced the enforcement actions is the combination: a tracker that knows who somebody is, running on a page that says what they are being treated for, sending both to a company that never signed anything. The tool did not need a name to create the problem.

Is Google Analytics HIPAA Compliant?

No, and it cannot be made so. This is the most searched question in the topic and it has a one-word answer, but the reason matters more than the answer, because it applies identically to a dozen other tools.

Google signs business associate agreements for a defined list of HIPAA-eligible services under Google Workspace and Google Cloud. Google Analytics is not on that list, and neither is Google Ads. Google's own Analytics terms go further and prohibit sending it data that could be used to identify a person, with its HIPAA guidance telling customers not to use Analytics on pages where PHI is in play.

Google's own position, as published on its Cloud, Workspace and Analytics documentation

The workarounds that do not work

  • IP anonymisation. GA4 does not log IP addresses the way Universal Analytics did, and it still holds a client id that identifies a returning person. The BAA is what is missing, and this does not supply it.
  • Stripping PHI before it is sent. Genuinely de-identified data is out of HIPAA's scope, but the standard is the Safe Harbor or expert determination method in §164.514, not a judgement call about which fields look harmless. Most attempts fail on the identifiers nobody thought of.
  • Server-side GTM. Moving the tag to a server changes who sends the request, not who receives it. If the destination is still Google Analytics, the recipient still has not signed a BAA.
  • Consent from the patient. A HIPAA authorization for marketing use of PHI is a specific document with required elements. A cookie banner is not one, and treating it as one is the most common mistake in this area.

Nothing here is a criticism of Google

Google is unusually clear about this. It publishes the covered services list, excludes Analytics and Ads explicitly, and tells healthcare customers not to send PHI. The compliance failures in this field are almost never a vendor hiding something; they are a customer installing a tool the vendor already said not to install.

What the 2024 Court Ruling Changed, and What It Did Not

In December 2022 the HHS Office for Civil Rights published a bulletin on online tracking technologies, revised in March 2024. Its most aggressive claim was that an IP address collected on a public, unauthenticated page about a health condition was already individually identifiable health information, purely because of the page it was collected on. The industry called this the proscribed combination, and it would have made almost any analytics on a hospital website unlawful.

The American Hospital Association sued. On 20 June 2024 the US District Court for the Northern District of Texas held that OCR had exceeded its authority and vacated that part of the bulletin. OCR filed an appeal and then withdrew it on 29 August 2024, which left the vacatur standing.

So the ruling narrowed one aggressive interpretation on public pages. It did not legalise pixels in healthcare, and it did not touch the part of the exposure that has actually cost money. The settlements in this field have run into eight figures, and they were brought by plaintiffs' lawyers under wiretap statutes rather than by OCR under the bulletin. A page can be compliant with HIPAA and still be the subject of a class action.

The Ad Platforms Will Not Sign, and That Is the Whole Problem

Here is the structural bind that no tool solves. A covered entity's marketing goal is to send conversions back to Meta and Google so the algorithms optimise on patients rather than clicks. HIPAA says you may not disclose PHI to a party that has not signed a BAA. Meta does not sign BAAs. Google excludes Ads from its own. The two requirements cannot both be met.

  • A Conversions API does not fix it. Sending server to server changes the transport, not the recipient. Meta receives the same data with the same agreement in place, which is none.
  • Hashing does not fix it. A hashed email is precisely as identifying as the email to anyone holding the address, which is the entire reason the platforms can match on it. Hashing is data minimisation, not de-identification.
  • Offline conversion import does not fix it. Uploading a closed case with a treatment type attached is a disclosure of PHI in a file rather than in a pixel.

What covered entities do in practice is send less, not send differently: a conversion signal with no health context, fired from a page that reveals nothing, with the specialty and the outcome kept on their own side. You lose optimisation quality and you keep the licence. That is the trade, and a vendor who tells you there is no trade is describing something other than compliance.

Call Tracking and Form Tracking, the Two Most Overlooked Leaks

Analytics gets the attention, but the two systems that most reliably collect real clinical detail are the phone and the intake form, and they are usually bought by whoever runs marketing rather than by whoever owns compliance.

Call tracking

Dynamic number insertion itself is ordinary attribution plumbing. The exposure is what the platform does next: recording, transcription, keyword spotting and the AI summaries that are now on by default in most call tracking products. A recorded call in which somebody describes a symptom is clinical information sitting in a marketing vendor's account. Several call tracking vendors do offer a HIPAA plan with a BAA, and it usually turns recording and transcription off rather than securing them. For how the mechanism works in general, see tracking phone calls back to the ad.

Form tracking

Session replay and form analytics are the sharpest edge in the whole stack, because they capture keystrokes rather than submissions. A tool that records what somebody typed into a symptom field and then abandoned has collected information the person specifically chose not to give you. Field-level masking is the mitigation, and it needs to be an allowlist rather than a blocklist: anything not explicitly masked will eventually carry something it should not.

The rule of thumb that catches most of it

Walk the funnel and ask, at each tool, what a stranger holding this account could learn about one named person. If the answer includes anything about their health, that tool needs a BAA or it needs to stop collecting that field.

What a Compliant Stack Actually Needs

There is no HIPAA certification. No regulator inspects a vendor and issues a badge, which is why the badges on vendor websites are self-declared and worth nothing on their own. Compliance is a state you maintain, and for a marketing stack it comes down to four things.

1. A signed BAA with every vendor that touches PHI

This is the non-negotiable one. It has required content: permitted uses, safeguards, breach reporting to you without unreasonable delay and within 60 days, the same terms flowed down to the vendor's own subcontractors, and return or destruction of PHI when the contract ends. A GDPR data processing agreement is not a BAA. They cover different obligations under different law, and a vendor offering you a DPA when you asked for a BAA has answered a different question.

2. The Security Rule, including the half nobody buys

  • Technical safeguards: access control, audit logging, integrity controls, encryption in transit and at rest.
  • Administrative safeguards: a documented risk analysis, a named security official, workforce training, sanction and incident response policies. This is the half that gets cited in enforcement, and it is the half no software purchase provides.
  • Physical safeguards: facility access and device controls, which for a cloud stack largely transfer to the hosting provider under its own BAA.

3. Minimum necessary, applied to marketing data

Disclose the least PHI needed for the purpose. Applied to attribution, that usually means the conversion signal travels and the clinical context does not: the campaign learns that a booking happened, not what it was for.

4. A defensible record that the above is true

A vendor inventory with a BAA against each entry, a dated risk analysis, and evidence the policies are followed rather than filed. The penalty tiers were raised again with effect from 28 January 2026, and they scale with whether you knew: the top tier is willful neglect left uncorrected, which is what an undocumented programme looks like from the outside.

Which Tools Will Actually Sign a BAA

If you are a covered entity, this is the only vendor question that matters, and the answer is public for every serious tool. The table below is the state of play as of September 2026 and should be confirmed with each vendor in writing, because plan-level availability changes and a BAA is often gated behind an enterprise tier.

Confirm directly with each vendor. Availability is frequently plan-dependent, as of September 2026

Note the second row. No ad platform signs a BAA, which means the covered-entity playbook is never "find a compliant pixel". It is to keep PHI on your own side and send the platforms a signal that carries none of it.

If HIPAA Does Not Apply to You

This is the larger group, and it is the one being badly served by the current search results. If you are a cash-pay aesthetics clinic, a wellness or supplement brand, a fitness or mental wellness app, or a healthcare business anywhere outside the United States, HIPAA does not bind you, and building your marketing measurement as though it does costs you the ability to run a business.

What replaces it is the privacy law that does reach you, which for most of the world is the GDPR. Health data is a special category under Art. 9, which raises the bar on consent and on documentation, but it does not put measurement out of reach the way a misapplied HIPAA reading does.

  • Collect first-partyRun tracking on a subdomain you own so no third-party cookie is set and there is one inspectable point where data leaves your control.
  • Separate the signal from the contextSend the ad platform that a booking happened. Keep the treatment, the specialty and the page path on your own side. Good practice under any framework.
  • Get consent properlyGranular, genuinely refusable, and respected at the boundary rather than at the banner. Verify it by declining on your own site and checking that nothing arrived.
  • Document the flowA signed DPA, a current sub-processor list, a retention policy that is enforced, and a privacy notice a patient could actually follow.

Done this way you keep accurate attribution and a defensible position, which is the combination a misapplied HIPAA reading makes people believe they cannot have. The full version of this argument is in our guide to GDPR-compliant conversion tracking.

Where LeadJourney Fits, and Where It Does Not

We would rather answer this plainly than sell past it, because the fastest way to lose a healthcare buyer is to be caught implying a compliance you do not hold.

We do not sign business associate agreements today

LeadJourney is not built as a HIPAA business associate. We offer an Art. 28 GDPR data processing agreement, which is a different instrument under different law. If you are a US covered entity and PHI would flow into your attribution, we are not the right tool, and a vendor from the BAA table above is.

What we are built for is the group in the section above, and for the part of a covered entity's marketing that carries no PHI at all. Production infrastructure is in Frankfurt, inside the EU. Server-side tracking runs on your own subdomain, so no third-party cookie is set and the collection point is yours. Traffic is served over TLS, and OAuth tokens, two-factor secrets and personal data in the database are encrypted with AES-256-CBC. Every sub-processor with access to data is listed publicly on the GDPR page, and the control-by-control account is on the security page.

For a clinic in Europe, that combination is usually the whole answer: first-party collection, one processor with a signed agreement, EU residency, and campaigns credited with the appointments they produced. For a US covered entity it is a good stack for the marketing that never touches PHI, and the wrong stack for the marketing that does. Both of those sentences are true at once, and any vendor telling you only the first one is selling you a liability.

Further Reading

Carry on with GDPR-compliant conversion tracking, Consent Mode v2 for lead generation and tracking phone calls back to the ad. For our own documentation, see the GDPR and data protection page, the security page and the technical and organisational measures. If you run a practice or a clinic, the healthcare providers page covers the attribution side in your own vocabulary.

FAQ

Frequently Asked Questions

The questions healthcare marketers ask before they buy a tracking tool.

Is Google Analytics HIPAA compliant?

No, and it cannot be configured into compliance. Google signs business associate agreements for a defined list of HIPAA-eligible services in Google Cloud and Google Workspace, and Google Analytics is not on that list. Google Ads is excluded too. Google's own Analytics terms prohibit sending data that could identify a person, and its guidance tells customers not to use Analytics where PHI is in play. IP settings, consent mode and server-side tagging do not change this, because what is missing is the agreement, not a setting.

Does HIPAA apply to my clinic if I am outside the United States?

No. HIPAA is a US statute that binds US covered entities and their business associates. A clinic in Germany, Switzerland, the UAE or anywhere else outside the US is not covered by it. The framework that does apply is your own, which in the EU and UK means the GDPR, where health data is a special category under Art. 9 with stricter consent and documentation requirements.

Did the 2024 court ruling make pixels legal on healthcare websites?

No. On 20 June 2024 a federal court vacated the part of the OCR bulletin claiming that an IP address collected on a public page about a health condition was automatically identifiable health information, and OCR withdrew its appeal that August. Everything behind a patient login, every booking and intake form, and any data already carrying a name or contact detail was untouched. Private class actions under state wiretap laws also continue independently of the bulletin, and those are where the largest settlements have come from.

Is a GDPR data processing agreement the same as a BAA?

No. They come from different laws and cover different obligations. A BAA has required content under 45 CFR §164.504(e), including breach reporting within 60 days, flow-down of the same terms to subcontractors, and return or destruction of PHI at the end of the contract. A vendor who offers a DPA when you asked for a BAA has answered a different question, and for a covered entity that answer is not sufficient.

Can I make tracking compliant by hashing or anonymising the data?

Hashing does not do it. A hashed email identifies the same person to anyone holding that address, which is exactly why ad platforms can match on it, so it is data minimisation rather than de-identification. Genuine de-identification takes HIPAA out of scope, but the standard is the Safe Harbor method or expert determination under §164.514, not a judgement call about which fields look harmless. Most informal attempts fail on identifiers nobody considered.

Does LeadJourney sign a BAA?

Not today. LeadJourney is built as a GDPR processor and offers an Art. 28 data processing agreement, EU data residency in Frankfurt and a published sub-processor list. If you are a US covered entity and protected health information would flow into your attribution stack, you need a vendor that will sign a BAA, and we will say so rather than sell around it. For healthcare businesses outside the US, and for the marketing that carries no PHI, the GDPR framework is the relevant one and we are built for it.

Built for regulated marketing

Know which campaigns bring patients, without collecting what you should not.

First-party server-side attribution, hosted in Frankfurt, with a signed DPA and every sub-processor published. Accurate measurement that a compliance review can read.

LeadJourney dashboard showing lead sources, campaign performance and attributed revenue side by side