A laptop showing a website analytics dashboard, the kind of Google Analytics tracking a medical practice runs and needs to keep HIPAA compliant
Standard website analytics were built to track shoppers, not patients. On a healthcare site, the difference matters a lot. Photo via Unsplash.

A dermatology practice forwarded us an email last year that made the owner's stomach drop. It was from a law firm, and it was fishing for patients who had visited the practice's website, looked at an acne or a skin cancer page, and later seen an ad for something related. The pitch to those patients was simple: your doctor's website may have shared your health interest with Facebook, and you might be owed money. Nobody at the practice had done anything shady. They had hired a web person, that person installed the usual tracking, and that was that. The lawyers found it anyway.

So let us answer the question that brings most owners here. Is Google Analytics HIPAA compliant? On its own, no, not in the way most practices are running it. And the Meta Pixel sitting next to it is usually worse. That does not mean you have to fly blind. It means the standard, out of the box install that a general web shop drops on your site was built to track online shoppers, and a patient is not a shopper.

Why the usual tracking is a problem on a healthcare site

Google Analytics and the Meta Pixel exist to answer one question for advertisers: who did what, so we can show them more ads. To do that well, they hoover up everything they can reach. Page URLs. Form fields. Button clicks. The IP address of the device. On a store selling sneakers, that is harmless. On a medical website, that same behavior can tie a real person to a real health concern and ship it off to a company that runs an ad network, without anyone noticing.

Picture a patient filling out a request on your site for a specific treatment. Their name and email are in the form. The page URL names the condition. A raw pixel can grab all of it and send it to a third party you have no agreement with. That bundle, an identity plus a health interest, is the exact thing HIPAA exists to protect. Google's own terms even tell you never to send it data it could use to identify a person, and Google will not sign a Business Associate Agreement for standard Analytics. Meta will not sign one for its pixel either. When a vendor refuses to sign a BAA, that is your signal that they were never meant to touch patient data.

$100M+ the amount tracking pixel violations have cost the US healthcare industry in fines, settlements and class actions, according to security firm Feroot's 2024 analysis. The pixels were usually installed by a web developer, not the practice.

The regulators noticed, and the bills got real

This is not a hypothetical risk cooked up by nervous lawyers. It has already been enforced, repeatedly, and the numbers are not small.

The Federal Trade Commission went first and hit companies that most people assumed were careful. In 2023 the FTC ordered GoodRx to pay a 1.5 million dollar civil penalty for sharing users' health data with advertisers through tracking tools, and separately fined the therapy app BetterHelp 7.8 million dollars for the same kind of thing. GoodRx later added a 25 million dollar class action settlement on top. In 2026 the FTC went further and sued Hims and Hers, alleging it routed patient data to Meta without proper consent. The message from the agency has been consistent for years: if a patient's health information leaks to an ad platform, someone is going to pay for it.

Hospitals felt it through a different door. Class action firms filed a wave of lawsuits arguing that the Meta Pixel on hospital websites had shared patient information, and the U.S. Department of Health and Human Services put out formal guidance on online tracking technologies warning that this was a HIPAA violation. For a while, the safe read was simple: get these trackers off anything remotely sensitive.

What the 2024 court ruling actually changed

Then it got more nuanced, and this is the part practice owners keep getting wrong in both directions. In June 2024, a federal court in Texas sided with the American Hospital Association and vacated the part of the HHS bulletin that treated an IP address plus a visit to a public webpage about a condition as automatically protected health information. The court said the agency had overstepped. HHS later withdrew its appeal, so that narrower reading is where things stand now.

Some marketers took that as a green light and told their clients tracking was fine again. It is not that simple. Here is what the ruling did not touch, and it is most of what matters:

So the honest summary is this. The 2024 decision removed an overreach and gave you a little breathing room on plain, anonymous traffic counting. It did not make it safe to feed patient data to Google or Meta. Anyone telling you otherwise is reading the headline, not the ruling.

A quick gut check for your own site

Open your website and ask three things. One, is there a Meta Pixel or Google Analytics tag on your appointment request and contact pages? Two, do those pages carry the patient's name, email, or the specific service they want? Three, did anyone ever configure the tracking to strip that data out before it leaves your site? If the answer is yes, yes, and probably not, you are carrying the same risk that produced those settlements. It is fixable, but it will not fix itself.

You do not have to choose between numbers and safety

Here is the good news, because owners often assume the only safe option is to rip out all tracking and market blind. That is not the trade. You can measure everything you actually need without ever handing a patient's identity to an ad platform. The trick is to measure the visit, not the person.

In practice that means a few specific moves. Keep protected health information off the pages your analytics can read, so a form on a general contact page instead of a page named after a diagnosis. Track anonymous events, a form started, a call button tapped, a booking link clicked, rather than who did them. Use server side tracking that scrubs names, emails, and other identifiers before anything is sent onward. And reconcile which leads became booked patients inside your own system, where the data is already protected, instead of asking Meta to connect those dots for you. Done right, you get cleaner attribution than a raw pixel ever gave you, because you are tying real booked revenue to its source instead of guessing from ad platform events. We walk through the mechanics in our guide on how to track where your patients come from without the exposure.

This same thinking is why Meta itself clamped down on healthcare advertising. If you run paid campaigns, the pixel restrictions are their own headache, and we covered how to work inside them in our piece on the Meta healthcare ad restrictions for 2026. The pattern is the same across the board: the platforms and the regulators are both pushing practices toward tracking that respects patient privacy, and the practices that already do it are the ones sleeping fine.

$7.8M the civil penalty the FTC levied on BetterHelp in 2023 for sharing users' health information with advertisers through tracking tools. GoodRx paid 1.5 million dollars in the same wave. Source: Federal Trade Commission.

Where EtherealMinds fits

We build and run marketing for healthcare practices only, which means this is not an edge case for us, it is the whole job. When we take over a practice's website, one of the first things we audit is exactly what its trackers are collecting and where they are sending it, because a site that leaks patient data in the background is a lawsuit with a countdown on it, no matter how pretty it looks. We set up measurement that keeps protected health information off the ad platforms, uses server side tracking, and signs the right agreements where they are needed, so you get real, trustworthy numbers instead of a liability dressed up as a dashboard.

Then we wire that clean tracking into a full patient acquisition system, so you can see which campaigns actually book patients and grow the ones that work, all without a law firm's fishing email ever landing in your inbox. If you want the broader view on doing this safely, our take on HIPAA compliant healthcare marketing connects the dots. The goal is boring in the best way: grow the practice, keep the patients' trust, and never make the news for the wrong reason.

Standard analytics were built for people selling products. You are caring for patients, and their privacy is part of the care. Track like it, and you get the numbers and the peace of mind. Both are on the table. You just have to set it up on purpose.

Not sure what your website is sending to Google and Meta?

Book a free strategy call. We will look at exactly what your site's tracking is collecting, flag anything that puts you at risk, and show you how to measure your marketing the clean, HIPAA safe way. No scare tactics and no jargon, just a clear read on where you stand.

Book a free strategy call →