HIPAA-Sensitive Conversion Tracking | Healthcare PPC

HIPAA-sensitive advertising infrastructure

Turning tracking off isn’t privacy. It’s just flying blind.

Healthcare organisations are usually offered two bad options: leave every tag running and hope nothing sensitive escapes, or strip it all out and lose the conversion data campaigns depend on. Neither is the only choice. The work is deciding deliberately what leaves your site, rather than letting the default decide for you.

  • BAA-covered call tracking
  • Documented data flows
  • Built for compliance review

The problem

Standard tracking was built for shopping carts, not patients.

Analytics tags and advertising pixels were designed to report everything they can observe. They don’t distinguish between someone comparing running shoes and someone reading about a diagnosis, and they weren’t built to ask whether a page, a form field or a URL implies something about a person’s health.

Google does not offer a Business Associate Agreement for Google Analytics or Google Ads, and its own documentation states it makes no representation that Analytics satisfies HIPAA requirements. Meta operates its own restrictions around sensitive-category data. That doesn’t make either platform unusable in healthcare — it means the responsibility for what gets transmitted sits with the implementation, not the platform.

Removing tracking entirely closes one pathway, but it also removes the conversion feedback that bidding depends on. Acquisition costs tend to climb while the ability to explain why disappears.

The useful question isn’t whether to measure. It’s what is the minimum signal that makes advertising accountable without sending data that shouldn’t be sent.

The architecture

One event. Two records.

A single appointment request produces a complete business record. The advertising platform needs a small fraction of it. Once you separate those two things deliberately, most of the tension between privacy and measurement disappears.

Stays inside

The business record

Held in systems your organisation controls or has an agreement covering. Complete, because your practice genuinely needs it.

  • Name and contact details
  • Reason for the visit or service requested
  • The page or form the request came from
  • Appointment date, time and provider
  • Call recording and transcript, where retained
  • Treatment and revenue recorded in the CRM

Field labels are generic illustrations of record types, not a specification of any particular implementation.

Crosses the boundary

The marketing signal

Deliberately selected and deliberately thin. Enough for bidding and reporting to work, and nothing beyond that.

  • That a qualified conversion occurred
  • The campaign or source that earned it
  • Keyword or placement, where available
  • Timestamp
  • An abstracted value tier, where appropriate

Not every implementation forwards every one of these. What crosses is decided during design and reviewed before launch.

The point is that what crosses is chosen, not defaulted. Standard tag setups forward whatever they can observe because nobody told them otherwise. A privacy-aware architecture inverts that: nothing crosses unless there’s a reason for it to, and the reason is written down.

Where things currently stand

The federal picture narrowed. It didn’t disappear.

A lot of healthcare marketing advice still reflects guidance that has since changed, and a lot more treats a single court ruling as though it settled everything. Neither is accurate. Here is what actually happened, with dates.

December 2022, revised March 2024

HHS Office for Civil Rights issued guidance on the use of online tracking technologies by HIPAA-regulated entities.

20 June 2024

A federal district court vacated a portion of that guidance — specifically the part treating an IP address combined with a visit to an unauthenticated public webpage as protected health information.

August 2024

HHS filed a notice of appeal, then voluntarily withdrew it later the same month. The vacatur of that portion stands.

What was not vacated

The remainder of the guidance, including the portions concerning authenticated pages and patient portals, was left in place.

Separately from all of this

State privacy, wiretap and consumer-protection laws operate independently of the federal HIPAA question, and were not affected by the ruling.

Layer one

What the documentation says

Published guidance, court records, and the platforms’ own terms. Verifiable, dated, and citable.

We tell you what these say. We don’t tell you what they mean for your organisation.

Layer two

What we do operationally

Design and implement a tracking architecture that minimises what reaches advertising platforms, then verify what actually gets transmitted.

This is an engineering deliverable with documentation attached.

Layer three

What requires your judgment

Whether a given configuration meets your organisation’s obligations is a determination for your privacy, compliance or legal advisor.

We build it to be reviewed by them, and we hand over the documentation they’ll ask for.

Where sensitive data actually appears

Three places, three different problems.

Most of the risk in healthcare marketing measurement isn’t in the ad account. It’s in the three systems that sit between a click and a patient.

Channel 01

Phone calls

For most practices, calls are the primary appointment channel — and an untracked call can’t be attributed to the campaign that produced it. But a conversation may contain almost anything.

We implement call tracking through CallRail’s Healthcare plan, under which CallRail will enter into a Business Associate Agreement. Healthcare accounts apply their own controls, including session timeouts and restrictions on integrations that transmit protected health information to third parties.

The distinction Attribution data is marketing data: source, campaign, keyword where available, time, duration, answered status. Call content is not. The conversation stays inside the covered environment; only a de-identified event such as a qualified call is forwarded onward.

Channel 02

Forms & appointment requests

A submission usually contains a name, contact details, and often a reason for the request. That’s a business record, and it belongs in systems your organisation controls.

Where the form implementation, script placement or tag architecture is itself the problem, that becomes a web development conversation rather than a tagging one.

The distinction The submission is a business record. The marketing signal derived from it is a separate, deliberately abstracted artefact. We don’t pipe complete form submissions into advertising platforms, analytics tools, or general-purpose automation.

Channel 03

CRM & offline outcomes

The most valuable marketing data usually lives furthest from the ad account: which enquiries became patients, and what that was worth. It also sits alongside the most sensitive records you hold.

Where your systems support it, offline conversion feedback can close that loop without the underlying record leaving your environment.

The distinction The outcome can be fed back as a signal. The record behind it doesn’t need to travel with it. What gets returned to the platform is the fact of a conversion and its attribution, not the clinical or personal context.

Implementation

Two ways to build the filtering layer.

There isn’t one correct setup for every organisation. Both approaches aim at the same outcome — keeping identifiers and health context out of advertising platforms while forwarding a permitted, de-identified conversion signal. Which one fits depends on your current stack, your compliance requirements, your budget, and how much infrastructure you want to own.

Option A

Managed privacy platform

Platforms such as Freshpaint or Ours Privacy

A healthcare-focused privacy platform sits between your website and the advertising platforms, filtering and de-identifying before conversion data is forwarded.

  • Faster to implement, with vendor-supported workflows
  • Healthcare-focused governance built into the product
  • Business Associate Agreement available where applicable
  • Configured against your specific pages and forms
  • Less infrastructure for your team to own

Subscription purchased directly from the provider. Both vendors price through their sales teams rather than publishing rates, so cost is confirmed with them during selection. Coast333 has no exclusive relationship with either; they’re named as current examples of the category.

Best fit: practices that want a supported solution without hosting their own infrastructure.

Option B

Self-controlled environment

Typically built with tools such as Matomo and RudderStack

A private environment your organisation owns, where detailed analytics stay in infrastructure you control and only approved events are forwarded onward.

  • More direct control over where data lives and what moves
  • Infrastructure ownership rather than a subscription dependency
  • Greater technical flexibility for unusual requirements
  • More implementation and maintenance responsibility on your side

Ongoing infrastructure cost varies by hosting provider, analytics stack, usage and maintenance requirements. Self-hosting does not by itself create compliance — configuration and governance determine whether the architecture is suitable.

Best fit: organisations prioritising data ownership and direct control over the stack.

We select the architecture with you rather than for you, and either path is documented so your privacy, compliance or legal advisor can review it before launch.

Straight talk

What this service does, and what nobody can promise.

Healthcare marketing is full of agencies using “HIPAA compliant” as a badge. It’s worth being precise about where the line actually sits, because the distinction matters more here than almost anywhere else in marketing.

What we do

  • Assess what your current tags, forms and call handling actually transmit
  • Design a tracking architecture that minimises what reaches advertising platforms
  • Implement it, using either a managed platform or a self-controlled environment
  • Restore de-identified conversion signals so campaigns can still be optimised
  • Verify end to end what data actually leaves the site, and where it goes
  • Document the data flows so your advisors can review them

What no agency can promise

  • That your organisation is HIPAA compliant — that’s not an agency’s determination to make
  • Zero legal or regulatory exposure
  • That Google Ads or Meta Ads themselves become HIPAA-compliant tools
  • That hashing an identifier makes it safe to send anywhere
  • Perfect privacy and perfect attribution at the same time

That last one deserves saying plainly: privacy-aware measurement is less granular than an unrestricted setup. You give up some resolution in exchange for controlling what leaves. We think that’s the right trade for a healthcare organisation, but we’d rather you hear it from us before you buy than discover it in month two.

How it runs

Four stages, then it’s monitored.

Most of the value sits in the two stages people skip: knowing what’s being sent today, and confirming what’s being sent after the change.

Stage 01

Tracking & data-flow assessment

An audit of current tags, forms, call handling and CRM connections, mapping what data is collected today and where it goes. Most practices have never had this written down, and the assessment is frequently the first time anyone can answer the question precisely.

Stage 02

Architecture selection & setup

Choosing between the managed and self-controlled approach based on your stack and requirements, then implementing it — including call attribution where phone calls matter to your funnel.

Stage 03

Testing & verification

The stage that separates this from a tag installation. The question isn’t whether the tag fired — it’s what data actually left the site, and where it arrived.

We inspect the requests themselves, confirm that filtering is applied before transmission rather than after, and confirm that the permitted conversion signals are genuinely reaching your ad accounts.

The output is documentation of what flows where, which is what a compliance stakeholder will ask for and what most implementations cannot produce.

Stage 04

Ongoing monitoring

Tags get added, platforms change policies, sites get updated by other people. Where monitoring is part of the engagement, we watch for drift so a change made six months from now doesn’t quietly undo the architecture.

Fit check

Who this is for.

A strong fit

  • You run or plan to run paid advertising for a healthcare organisation
  • You’re not certain what your current tracking actually transmits
  • You turned tracking off and lost useful attribution as a result
  • You have compliance, IT or legal stakeholders who need documented data flows
  • Meaningful volume comes through phone calls, not only web forms
  • You can coordinate marketing, website, technical and compliance stakeholders

Probably not

  • You’re looking for legal advice rather than a technical implementation
  • You want a guarantee of HIPAA compliance
  • You want detailed health data sent into advertising platforms for targeting
  • You’re unwilling to change tracking practices that create exposure
  • You expect attribution to be as complete as an unrestricted setup
  • You need a certified compliance audit, which is a different profession

Questions

Healthcare tracking FAQs.

Is Google Analytics (GA4) HIPAA compliant?

Google does not offer a Business Associate Agreement for Google Analytics, and its own documentation states it makes no representation that Analytics satisfies HIPAA requirements. So it isn’t a HIPAA-eligible service.

That doesn’t automatically mean every healthcare organisation must remove GA4 from every page. The real question is what a given implementation transmits, from which pages, with what context attached. That’s what the assessment establishes. We’ve written this up in more detail in Is Google Analytics (GA4) HIPAA Compliant in 2026?

Can healthcare organisations run Google Ads at all?

Advertising and measurement are separate questions, and conflating them causes a lot of unnecessary panic. Plenty of healthcare organisations advertise. What needs care is the conversion-measurement architecture underneath — what data is transmitted, to whom, under what configuration, and with what health or identity context attached.

What about the Meta Pixel and Conversions API?

Meta operates its own restrictions around sensitive-category data, and neither the Pixel nor the Conversions API is universally safe or universally unsafe. As with Google, what matters is the implementation and what it sends. If paid social is part of your mix, that connects to paid social as a channel, but the tracking architecture question is the same one this page describes.

Does hashing patient data make it safe to send?

No, and it’s one of the most common misconceptions in healthcare marketing. Hashing is not anonymisation. A deterministic hash produces the same output every time, so a platform hashing its own records the same way can still match them — which means the identifier is still functionally an identifier.

Hashing also does nothing about the health context attached to it. It isn’t a substitute for deciding what should cross the boundary in the first place.

Can we still track calls?

Yes, and for most practices it’s the most important thing to get right. We implement call tracking through CallRail’s Healthcare plan, under which CallRail will enter into a Business Associate Agreement and healthcare-specific account controls apply. Attribution data — source, campaign, keyword where available, time, duration, answered status — is marketing data. The conversation is not, and only a de-identified conversion event is forwarded to advertising platforms. Available recording, transcription and integration capabilities should be confirmed for the specific plan you select.

What does CallRail’s Healthcare plan cost?

Healthcare plans currently start at $150 per month, purchased directly from CallRail. Final cost varies with tracking number volume, call volume and the features selected, and pricing can change — confirm current rates with CallRail before budgeting. Setup and configuration are included with either architecture above.

What happens if we just turn all conversion tracking off?

It closes one disclosure pathway, and for some organisations that’s a reasonable interim decision. But it also removes the conversion feedback that bidding algorithms rely on, so acquisition costs tend to rise while the ability to explain performance disappears. The point of a privacy-aware architecture is to avoid that trade rather than accept it.

Do you make our organisation HIPAA compliant?

No. That’s not something a marketing agency can do or should claim. We build and document a tracking architecture designed to minimise what reaches advertising platforms, and we verify what it actually transmits. Whether that meets your organisation’s obligations is a determination for your privacy, compliance or legal advisor — which is exactly why we document it in a form they can review.

Does this replace our current PPC management?

No, it sits underneath it. This is the measurement infrastructure beneath your existing or planned campaigns. If you’re already a lead generation client it’s part of the same engagement; if you’re not, we can implement it as a standalone project and coordinate with your current agency.

Next step

Find out what your setup is actually sending.

We’ll walk through your current tags, forms and call handling, show you where patient-sensitive information could be reaching an advertising platform, and describe what a privacy-aware architecture would look like for your organisation. If you’d rather read first, start with the GA4 question. More context on the wider service at paid advertising, or see industries we work in.