Is Google Analytics (GA4) HIPAA Compliant in 2026?

Quick summary: No, Google Analytics is not HIPAA compliant. Google does not sign a Business Associate Agreement for GA4, and its own documentation says it makes no representation that the tool satisfies HIPAA requirements. That’s not something you can fix in the admin panel. Whether GA4 creates an actual violation for your organization depends on what your specific implementation sends, not on whether the tool exists on your site.

If you run a healthcare website and someone on your team just asked “wait, is Google Analytics HIPAA compliant?”, the short answer above is where every serious source lands. But the short answer isn’t the useful one. The useful question is what that means for the GA4 that’s probably already running on your site right now.

The Short Answer, and Why It’s Not the Whole Answer

Google Analytics HIPAA compliant status comes down to one fact: Google will not sign a Business Associate Agreement for GA4. A BAA is the legal contract HIPAA requires before a covered entity, meaning your practice, hospital, or healthcare organization, can share protected health information (PHI) with a vendor. No BAA means no legally sanctioned pathway for PHI to touch that vendor’s systems.

Google is explicit about this. Its own Analytics help documentation states that Google makes no representation that the service satisfies HIPAA requirements, and Analytics does not appear anywhere on the list of services covered under Google Cloud or Workspace’s HIPAA-eligible BAA. Google Cloud products like BigQuery, Cloud Storage, and the Cloud Healthcare API can be used under a BAA. Google Analytics, Google Tag Manager, and standard Google Ads conversion tracking cannot.

That single fact is why most articles stop at “GA4 is not HIPAA compliant” and move on. But that framing skips the part that actually matters for your website: not every visit to your site sends PHI, and not every use of GA4 is automatically a violation. Whether you have a problem depends on what your implementation is actually doing, page by page.

What Actually Makes Something PHI

Under HIPAA, protected health information is created when an identifier, like an IP address, an email, or a device ID, gets combined with health, treatment, or payment context. Neither half alone is automatically a problem.

An anonymous visit to your general homepage doesn’t reveal anything about anyone’s health. A page describing a treatment, service, or condition, viewed with no attached identifier, is just content. It’s the combination, an identifiable person tied to specific health context, that creates PHI.

This matters because a 2024 federal court ruling changed part of how this gets applied.

The AHA v. Becerra Ruling, Explained Plainly

In December 2022, HHS’s Office for Civil Rights issued guidance suggesting that even an IP address, paired with a visit to a public page about a specific health condition, could constitute PHI on its own. The American Hospital Association sued over that interpretation, arguing HHS had overstepped its authority.

On June 20, 2024, a federal court in Texas agreed, vacating that specific portion of the guidance. The ruling held that an IP address alone, on an unauthenticated public page, doesn’t reveal enough about a visitor’s actual intent to automatically count as PHI. HHS withdrew its appeal in August 2024.

Here’s the part most marketing articles get wrong: this ruling did not make public healthcare pages a free zone. It narrowed one specific, aggressive interpretation. The core distinction HHS still draws, and that the ruling didn’t touch, is this:

ContextRisk Level
Authenticated pages (patient portals, logged-in scheduling tools)High. Still treated as PHI. Long-settled area.
Appointment or registration forms, even public-facingHigh. Name, email, and reason-for-visit together are a clear identifier-plus-context combination.
A public page about a specific condition, with only an IP attachedLower federal HIPAA risk after the 2024 ruling, but still sensitive under platform policy.
General pages with no health-specific contentLow.

So “is Google Analytics HIPAA compliant” isn’t really a yes/no question about the tool. It’s a page-by-page question about what each part of your site is actually sending.

Why “Just Configure It Correctly” Doesn’t Solve This

A lot of healthcare marketing advice treats this as a settings problem: turn off Google Signals, mask IP addresses, adjust data retention, and you’re covered. That advice misses the actual issue.

GA4 configuration changes can reduce what identifiers get collected. They don’t change Google’s underlying vendor stance. Google still won’t sign a BAA for the product, and consent banners don’t retroactively fix data that was already collected before a visitor made a choice. HHS has also been direct on a related point: a privacy policy or cookie banner disclosing that tracking is in use does not, by itself, count as valid HIPAA authorization when authorization is actually required.

This is the same reason hashing patient emails before sending them to an ad platform doesn’t make that data “anonymous,” a related misconception worth its own explanation, but the short version is that a deterministic hash can still be matched back to a real person on the receiving end. Technical adjustments can reduce exposure. They don’t substitute for an architecture that controls what leaves your site in the first place.

What This Actually Means for Your Site

Enforcement in this space hasn’t been theoretical. The FTC has taken direct action against GoodRx ($1.5 million penalty) and BetterHelp ($7.8 million) for sharing health-related data with advertising platforms. Class-action settlements against health systems for pixel and analytics-related disclosures have run into eight figures, including a $12.225 million settlement involving Advocate Aurora Health and a $6.6 million settlement involving Novant Health, both tied to tracking technology on patient-facing pages.

None of those cases required someone to prove GA4 was configured wrong. They turned on what data actually left the organization’s systems and where it went.

For most healthcare organizations, that translates to a fairly practical split:

  • Authenticated pages, scheduling tools, and intake forms should not run standard GA4 at all. This is the highest-risk category and the one every enforcement action to date has focused on.
  • General informational pages carry lower federal HIPAA risk after the 2024 ruling, but Google’s own advertising policies and platforms like Meta impose separate, independent restrictions on health-related data that apply regardless of the HIPAA analysis.
  • Anywhere conversion data needs to reach Google Ads or Meta for campaign optimization, that data needs to pass through a layer that filters out identifiers and health context before it’s forwarded, not straight from your site.

That third point is the one most healthcare marketing setups get wrong, and it’s a different problem from “is GA4 installed.” You can remove Google Analytics entirely and still have a tracking problem, because your Google Ads and Meta conversion tags are often sending similar signals directly, with no filtering layer in between.

What “Fixing This” Actually Looks Like

There are two credible paths, and neither of them is “just don’t use analytics.”

A managed privacy platform (tools like Freshpaint or Ours Privacy) sits between your website and Google/Meta, filtering and de-identifying data before anything reaches the ad platforms. This is the faster, more turnkey path for most practices.

A self-hosted environment using something like Matomo for analytics and RudderStack to control what gets forwarded gives you full ownership of the underlying data, at the cost of more setup and ongoing management.

Both approaches share the same underlying logic HHS itself has explicitly acknowledged as valid: a business associate operating under a BAA can receive identifiable data, strip out what’s sensitive, and pass only de-identified information downstream to a non-BAA vendor like Google or Meta. That’s the architecture. GA4 isn’t the enemy here, an unfiltered pipeline into it is.

Frequently Asked Questions

Is Google Analytics HIPAA compliant if I turn off Google Signals? No. Turning off Google Signals reduces certain identifiers Google collects for its own advertising purposes, but it doesn’t change Google’s refusal to sign a BAA for Analytics, and it doesn’t stop PHI from being transmitted if your pages are sending it in the first place.

Can I use GA4 on any part of a healthcare website? Generally, general informational pages carry lower risk, especially after the 2024 court ruling narrowed federal guidance on public pages. Authenticated pages, scheduling tools, and any page collecting appointment or intake information are a different story and should not run standard GA4.

Does Google offer a BAA for any of its products? Yes, for specific Google Cloud and Workspace services like BigQuery, Cloud Storage, and the Cloud Healthcare API. Google Analytics, Google Tag Manager, and Google Ads conversion tracking are explicitly not included.

Is a HIPAA-compliant version of Google Analytics available? No. There is no HIPAA-eligible tier or configuration of Google Analytics. Organizations that need PHI-safe measurement typically route data through a BAA-covered intermediary before anything reaches GA4, or replace it with self-hosted analytics on infrastructure they control.

What should I do if GA4 is already running on my healthcare website? Start by identifying which pages collect or display PHI-adjacent information, such as scheduling tools, intake forms, and condition-specific pages tied to a login. Those pages need GA4 removed or replaced with a filtered, BAA-covered alternative. General content pages carry lower risk but should still be reviewed as part of a full tracking audit.

Where This Leaves You

“Is Google Analytics HIPAA compliant” has a simple answer and a complicated one. The simple answer is no, Google won’t sign a BAA for it. The complicated answer is that your actual risk depends on exactly what each page on your site is sending, and that GA4 is usually only one piece of a bigger tracking picture that includes your Google Ads and Meta pixels too.

If you’re not sure what your current setup is actually sending to Google and Meta, that’s the first thing worth finding out before making any changes.

See how Coast333 builds HIPAA-sensitive conversion tracking →

David Cote

David Cote

The founder of Coast333, he helps small businesses and faith-driven organizations cut through the noise with marketing strategies that actually work — no fluff, no guesswork. With a background in digital marketing and leadership, his focus is on clarity, consistency, and action. When he’s not helping businesses grow, he’s investing in his faith, family, and community in Lake County, Florida.

Abstract visualization of multiple overlapping data panels and charts converging into one clear view, representing synthesized marketing campaign benchmarks across SEO, PPC, and social media

What 12 Real Marketing Campaigns Actually Taught Us

A Coast333 Marketing Report What 12 Real Marketing Campaigns Actually Taught Us An honest look at what actually moved the needle across a dozen documented SEO, PPC, and social media campaigns, segmented by channel, with real ranges instead of misleading averages. Last…

Diagram illustrating what does a good marketing agency actually do, showing diagnosis before execution

What Does a Good Marketing Agency Actually Do?

Table of ContentsThe Fundamental Shift: Tactical Vendor vs. Revenue PartnerThe 30-Day Onboarding and Discovery StandardMarketing Diagnosis: Is Marketing Actually Your Problem?Modern Tactical Execution: What Elite Agencies Actually DeliverReporting That Matters:…

Let’s Get Started

Ready To Make a Real Change? Let’s Build this Thing Together!