Insights · Control
HIPAA-safe analytics for clinic websites in 2026
Mo Ismail · 2026-10-03
Every practice wants to know which pages, ads and articles bring booked visits. Every practice also needs to keep health information private. For a few years, those two goals collided on clinic websites. Here is where things stand in late 2026, in plain language.
This is general information, not legal advice. Ask your counsel about your specific setup.
What happened with the HHS tracking guidance
In 2022, the U.S. Department of Health and Human Services (HHS) published guidance saying that tracking tools on many hospital and clinic web pages could expose PHI (Protected Health Information) and break HIPAA.
In June 2024, a federal court in Texas vacated part of that guidance. The court found that tracking on public, unauthenticated pages (pages anyone can see without logging in) did not, by itself, create protected health information in the way the guidance claimed. In August 2024, HHS dropped its appeal.
What is still restricted
The ruling did not make all tracking safe:
- Pages behind a login, such as patient portals, are still covered. Tracking scripts there remain a serious risk.
- Forms that collect health details can still expose PHI if the answers are passed to third parties.
- State privacy laws and private lawsuits continue, separate from HHS.
- The FTC Health Breach Notification Rule covers many health apps and sites that are not under HIPAA. Since July 2024 it clearly treats unauthorized sharing of health data as a breach, with penalties up to $51,744 per violation.
Ad platforms set their own limits
Separately from the law, platforms have tightened their own rules. Since January 2025, Meta has restricted how health and wellness advertisers can use conversion tracking, especially lower-funnel events like form submissions. Many clinics found that campaigns optimized for conversions stopped working the way they used to.
A practical setup
Here is the setup I recommend as a starting point for most cash-pay practices:
| Area | Recommendation |
|---|---|
| Public pages | Basic, privacy-friendly analytics. Count visits and clicks, not people's health details |
| Forms | Don't ask about conditions, symptoms or medications on marketing forms |
| Thank-you and result pages | No ad pixels on pages that reveal what someone submitted |
| Patient portals | No marketing or ad tracking at all |
| Ad conversions | Send only non-health events, ideally from your own server so you control the data |
| Vendors | If a tool might ever see patient data, it must sign a BAA. Many popular tools, including Google Analytics 4, do not |
Why "server-side" helps
Server-side tracking means your own server sends events to analytics or ad platforms, instead of letting every third-party script read the page in the visitor's browser. You decide exactly which fields leave your site. It takes more setup, but it turns tracking from "whatever the script grabs" into a list you can review.
A twice-a-year check
Scripts creep in. A plugin update adds a pixel, a vendor adds a feature, a new landing page copies old code. Twice a year, list every script on your site, note which pages it runs on, and remove anything you can't explain. It is one of the cheapest risk controls a practice can run.
If you want a quick view of where your site stands, the last question in the free Readiness Score covers tracking, and the Practice Diagnostic includes a full review.
Key takeaways
- Keep ad pixels off patient portals and form-result pages
- Never send health details in analytics or ad events
- Check whether your analytics vendor signs a BAA before using it near patient data
- Prefer setups where you control what leaves your site
- Review your scripts at least twice a year
General information only, not legal or medical advice.