HIPAA-sensitive advertising infrastructure
Turning tracking off isn’t privacy. It’s just flying blind.
Healthcare organisations are usually offered two bad options: leave every tag running and hope nothing sensitive escapes, or strip it all out and lose the conversion data campaigns depend on. Neither is the only choice. The work is deciding deliberately what leaves your site, rather than letting the default decide for you.
The problem
Standard tracking was built for shopping carts, not patients.
Analytics tags and advertising pixels were designed to report everything they can observe. They don’t distinguish between someone comparing running shoes and someone reading about a diagnosis, and they weren’t built to ask whether a page, a form field or a URL implies something about a person’s health.
Google does not offer a Business Associate Agreement for Google Analytics or Google Ads, and its own documentation states it makes no representation that Analytics satisfies HIPAA requirements. Meta operates its own restrictions around sensitive-category data. That doesn’t make either platform unusable in healthcare — it means the responsibility for what gets transmitted sits with the implementation, not the platform.
Removing tracking entirely closes one pathway, but it also removes the conversion feedback that bidding depends on. Acquisition costs tend to climb while the ability to explain why disappears.
The useful question isn’t whether to measure. It’s what is the minimum signal that makes advertising accountable without sending data that shouldn’t be sent.
The architecture
One event. Two records.
A single appointment request produces a complete business record. The advertising platform needs a small fraction of it. Once you separate those two things deliberately, most of the tension between privacy and measurement disappears.
Stays inside
The business record
Held in systems your organisation controls or has an agreement covering. Complete, because your practice genuinely needs it.
- Name and contact details
- Reason for the visit or service requested
- The page or form the request came from
- Appointment date, time and provider
- Call recording and transcript, where retained
- Treatment and revenue recorded in the CRM
Field labels are generic illustrations of record types, not a specification of any particular implementation.
Crosses the boundary
The marketing signal
Deliberately selected and deliberately thin. Enough for bidding and reporting to work, and nothing beyond that.
- That a qualified conversion occurred
- The campaign or source that earned it
- Keyword or placement, where available
- Timestamp
- An abstracted value tier, where appropriate
Not every implementation forwards every one of these. What crosses is decided during design and reviewed before launch.
The point is that what crosses is chosen, not defaulted. Standard tag setups forward whatever they can observe because nobody told them otherwise. A privacy-aware architecture inverts that: nothing crosses unless there’s a reason for it to, and the reason is written down.
Where things currently stand
The federal picture narrowed. It didn’t disappear.
A lot of healthcare marketing advice still reflects guidance that has since changed, and a lot more treats a single court ruling as though it settled everything. Neither is accurate. Here is what actually happened, with dates.
HHS Office for Civil Rights issued guidance on the use of online tracking technologies by HIPAA-regulated entities.
A federal district court vacated a portion of that guidance — specifically the part treating an IP address combined with a visit to an unauthenticated public webpage as protected health information.
HHS filed a notice of appeal, then voluntarily withdrew it later the same month. The vacatur of that portion stands.
The remainder of the guidance, including the portions concerning authenticated pages and patient portals, was left in place.
State privacy, wiretap and consumer-protection laws operate independently of the federal HIPAA question, and were not affected by the ruling.
Layer one
What the documentation says
Published guidance, court records, and the platforms’ own terms. Verifiable, dated, and citable.
We tell you what these say. We don’t tell you what they mean for your organisation.
Layer two
What we do operationally
Design and implement a tracking architecture that minimises what reaches advertising platforms, then verify what actually gets transmitted.
This is an engineering deliverable with documentation attached.
Layer three
What requires your judgment
Whether a given configuration meets your organisation’s obligations is a determination for your privacy, compliance or legal advisor.
We build it to be reviewed by them, and we hand over the documentation they’ll ask for.
Where sensitive data actually appears
Three places, three different problems.
Most of the risk in healthcare marketing measurement isn’t in the ad account. It’s in the three systems that sit between a click and a patient.
Channel 01
Phone calls
For most practices, calls are the primary appointment channel — and an untracked call can’t be attributed to the campaign that produced it. But a conversation may contain almost anything.
We implement call tracking through CallRail’s Healthcare plan, under which CallRail will enter into a Business Associate Agreement. Healthcare accounts apply their own controls, including session timeouts and restrictions on integrations that transmit protected health information to third parties.
Channel 02
Forms & appointment requests
A submission usually contains a name, contact details, and often a reason for the request. That’s a business record, and it belongs in systems your organisation controls.
Where the form implementation, script placement or tag architecture is itself the problem, that becomes a web development conversation rather than a tagging one.
Channel 03
CRM & offline outcomes
The most valuable marketing data usually lives furthest from the ad account: which enquiries became patients, and what that was worth. It also sits alongside the most sensitive records you hold.
Where your systems support it, offline conversion feedback can close that loop without the underlying record leaving your environment.
Implementation
Two ways to build the filtering layer.
There isn’t one correct setup for every organisation. Both approaches aim at the same outcome — keeping identifiers and health context out of advertising platforms while forwarding a permitted, de-identified conversion signal. Which one fits depends on your current stack, your compliance requirements, your budget, and how much infrastructure you want to own.
Straight talk
What this service does, and what nobody can promise.
Healthcare marketing is full of agencies using “HIPAA compliant” as a badge. It’s worth being precise about where the line actually sits, because the distinction matters more here than almost anywhere else in marketing.
What we do
- Assess what your current tags, forms and call handling actually transmit
- Design a tracking architecture that minimises what reaches advertising platforms
- Implement it, using either a managed platform or a self-controlled environment
- Restore de-identified conversion signals so campaigns can still be optimised
- Verify end to end what data actually leaves the site, and where it goes
- Document the data flows so your advisors can review them
What no agency can promise
- That your organisation is HIPAA compliant — that’s not an agency’s determination to make
- Zero legal or regulatory exposure
- That Google Ads or Meta Ads themselves become HIPAA-compliant tools
- That hashing an identifier makes it safe to send anywhere
- Perfect privacy and perfect attribution at the same time
That last one deserves saying plainly: privacy-aware measurement is less granular than an unrestricted setup. You give up some resolution in exchange for controlling what leaves. We think that’s the right trade for a healthcare organisation, but we’d rather you hear it from us before you buy than discover it in month two.
How it runs
Four stages, then it’s monitored.
Most of the value sits in the two stages people skip: knowing what’s being sent today, and confirming what’s being sent after the change.
Tracking & data-flow assessment
An audit of current tags, forms, call handling and CRM connections, mapping what data is collected today and where it goes. Most practices have never had this written down, and the assessment is frequently the first time anyone can answer the question precisely.
Architecture selection & setup
Choosing between the managed and self-controlled approach based on your stack and requirements, then implementing it — including call attribution where phone calls matter to your funnel.
Testing & verification
The stage that separates this from a tag installation. The question isn’t whether the tag fired — it’s what data actually left the site, and where it arrived.
We inspect the requests themselves, confirm that filtering is applied before transmission rather than after, and confirm that the permitted conversion signals are genuinely reaching your ad accounts.
The output is documentation of what flows where, which is what a compliance stakeholder will ask for and what most implementations cannot produce.
Ongoing monitoring
Tags get added, platforms change policies, sites get updated by other people. Where monitoring is part of the engagement, we watch for drift so a change made six months from now doesn’t quietly undo the architecture.
Fit check
Who this is for.
A strong fit
- You run or plan to run paid advertising for a healthcare organisation
- You’re not certain what your current tracking actually transmits
- You turned tracking off and lost useful attribution as a result
- You have compliance, IT or legal stakeholders who need documented data flows
- Meaningful volume comes through phone calls, not only web forms
- You can coordinate marketing, website, technical and compliance stakeholders
Probably not
- You’re looking for legal advice rather than a technical implementation
- You want a guarantee of HIPAA compliance
- You want detailed health data sent into advertising platforms for targeting
- You’re unwilling to change tracking practices that create exposure
- You expect attribution to be as complete as an unrestricted setup
- You need a certified compliance audit, which is a different profession
Questions
Healthcare tracking FAQs.
Is Google Analytics (GA4) HIPAA compliant?
Google does not offer a Business Associate Agreement for Google Analytics, and its own documentation states it makes no representation that Analytics satisfies HIPAA requirements. So it isn’t a HIPAA-eligible service.
That doesn’t automatically mean every healthcare organisation must remove GA4 from every page. The real question is what a given implementation transmits, from which pages, with what context attached. That’s what the assessment establishes. We’ve written this up in more detail in Is Google Analytics (GA4) HIPAA Compliant in 2026?
Can healthcare organisations run Google Ads at all?
Advertising and measurement are separate questions, and conflating them causes a lot of unnecessary panic. Plenty of healthcare organisations advertise. What needs care is the conversion-measurement architecture underneath — what data is transmitted, to whom, under what configuration, and with what health or identity context attached.
What about the Meta Pixel and Conversions API?
Meta operates its own restrictions around sensitive-category data, and neither the Pixel nor the Conversions API is universally safe or universally unsafe. As with Google, what matters is the implementation and what it sends. If paid social is part of your mix, that connects to paid social as a channel, but the tracking architecture question is the same one this page describes.
Does hashing patient data make it safe to send?
No, and it’s one of the most common misconceptions in healthcare marketing. Hashing is not anonymisation. A deterministic hash produces the same output every time, so a platform hashing its own records the same way can still match them — which means the identifier is still functionally an identifier.
Hashing also does nothing about the health context attached to it. It isn’t a substitute for deciding what should cross the boundary in the first place.
Can we still track calls?
Yes, and for most practices it’s the most important thing to get right. We implement call tracking through CallRail’s Healthcare plan, under which CallRail will enter into a Business Associate Agreement and healthcare-specific account controls apply. Attribution data — source, campaign, keyword where available, time, duration, answered status — is marketing data. The conversation is not, and only a de-identified conversion event is forwarded to advertising platforms. Available recording, transcription and integration capabilities should be confirmed for the specific plan you select.
What does CallRail’s Healthcare plan cost?
Healthcare plans currently start at $150 per month, purchased directly from CallRail. Final cost varies with tracking number volume, call volume and the features selected, and pricing can change — confirm current rates with CallRail before budgeting. Setup and configuration are included with either architecture above.
What happens if we just turn all conversion tracking off?
It closes one disclosure pathway, and for some organisations that’s a reasonable interim decision. But it also removes the conversion feedback that bidding algorithms rely on, so acquisition costs tend to rise while the ability to explain performance disappears. The point of a privacy-aware architecture is to avoid that trade rather than accept it.
Do you make our organisation HIPAA compliant?
No. That’s not something a marketing agency can do or should claim. We build and document a tracking architecture designed to minimise what reaches advertising platforms, and we verify what it actually transmits. Whether that meets your organisation’s obligations is a determination for your privacy, compliance or legal advisor — which is exactly why we document it in a form they can review.
Does this replace our current PPC management?
No, it sits underneath it. This is the measurement infrastructure beneath your existing or planned campaigns. If you’re already a lead generation client it’s part of the same engagement; if you’re not, we can implement it as a standalone project and coordinate with your current agency.
Next step
Find out what your setup is actually sending.
We’ll walk through your current tags, forms and call handling, show you where patient-sensitive information could be reaching an advertising platform, and describe what a privacy-aware architecture would look like for your organisation. If you’d rather read first, start with the GA4 question. More context on the wider service at paid advertising, or see industries we work in.