Privacy

Tracking pixels and cookie banners on a practice booking page

A booking form that sends the reason for a visit to an ad platform is a privacy problem, whatever the cookie banner says. Here is what the regulators have published, and what changed in 2024.

By Mariya Di Luzio, Founder and Creative Strategist · Published · 6 min read

The short answer

Keep advertising pixels off booking pages, intake forms and patient portals. HHS says tracking code on a page where patients schedule appointments may collect protected health information, and that a cookie banner is not a valid HIPAA authorization. A 2024 court ruling narrowed part of that guidance, but not the part about forms patients fill in.1

Key takeaways

  • Patient portals and logged-in pages: HHS says tracking code there generally has access to protected health information.1
  • Booking and symptom forms without a login may still expose protected health information when a patient types an email or a reason for the visit.1
  • A cookie consent banner does not count as a HIPAA authorization.1
  • Practices outside HIPAA, such as many health coaches, still answer to the FTC, which has fined companies for sharing health data with ad platforms.245

What a tracking pixel does on a booking page

A tracking pixel is a small piece of code from an advertising or analytics platform, such as the Meta pixel or Google Analytics. HHS defines a tracking technology as "a script or code on a website or mobile app used to gather information about users or their actions".1 When a patient loads the page, the code reports back to the platform: which page, which buttons, often the IP address, and sometimes what was typed into a form.

On a blog post, that is ordinary analytics. On a page titled "Book your fertility consultation", with a form asking for an email and the reason for the visit, the same code can tell an ad platform that an identifiable person is seeking a specific kind of care.

What HHS says, and what the court changed

In its bulletin on online tracking, the HHS Office for Civil Rights separates three situations.1

  • Logged-in pages, such as a patient portal or telehealth platform. Tracking code there "generally" has access to protected health information, including IP address, appointment dates and even diagnosis or prescription information.1
  • Pages without a login where patients act. HHS says tracking on a page "that permits individuals to schedule appointments or use a symptom-checker tool" may collect protected health information, for example the email address or the reason for seeking care that the patient types or selects.1
  • Public information pages, such as a page about a condition or a list of your practitioners.

The third item is where the law moved. On June 20, 2024, a federal court in Texas, in American Hospital Association v. Becerra, vacated the guidance "to the extent it provides that HIPAA obligations are triggered" when technology connects an IP address with a visit to an unauthenticated public page about health conditions or providers. HHS added that note to the top of the bulletin and said it is "evaluating its next steps".1

Read that narrowly. The court removed the idea that a visit alone, matched to an IP address, is protected health information. It did not remove the rest of the bulletin, and a booking form where someone enters their details and reason for visiting is not a mere visit. My position: treat any page with a form a patient fills in as off limits for advertising pixels, whatever the next court decides.

Why the cookie banner does not fix it

Many practices believe a consent banner covers them. HHS disagrees in plain words: "Website banners that ask users to accept or reject a website’s use of tracking technologies, such as cookies, do not constitute a valid HIPAA authorization."1 The bulletin adds that it is not enough for a tracking vendor to promise to strip or de-identify the data after receiving it.1

For a covered practice, the lawful routes are narrow: a tracking vendor that signs a business associate agreement and only receives data for a permitted purpose, or a real HIPAA authorization from each patient before the data goes out.1 Most advertising platforms do not sign business associate agreements, which in practice means their pixels do not belong on those pages.

If your practice is not covered by HIPAA

Health coaches, many nutritionists and some wellness studios do not bill insurance and are not HIPAA covered entities. That does not put their data outside the law. In July 2023 the FTC and HHS jointly wrote to about 130 hospital systems and telehealth providers about the Meta pixel and Google Analytics, and the FTC stated that "companies not covered by HIPAA still have a responsibility to protect against the unauthorized disclosure of personal health information".2

The FTC also enforces the Health Breach Notification Rule, which covers vendors of personal health records and related apps outside HIPAA. Under the rule, "sharing of covered information without an individual’s authorization" counts as a breach that triggers notification, and violations can bring civil penalties of up to $53,088 each.3 A coach running a client app or an online food and symptom log should read that rule closely.

Two cases show what enforcement looks like. GoodRx paid a $1.5 million civil penalty in the first action under that rule, for sharing prescription and health condition information with Facebook, Google and others.4 BetterHelp was ordered to pay $7.8 million for disclosing email addresses, IP addresses and health questionnaire answers to Facebook, Snapchat, Criteo and Pinterest for advertising.5 Neither is a small practice, but the mechanism is the one found on many practice sites.

Where tracking code can sit on a practice website
Page typeWhat HHS says it may collectAdvertising pixel?
Patient portal or telehealth loginGenerally has access to protected health informationNo
Booking page or intake formMay collect email, reason for visit and other details patients enterNo
Symptom checker or quizMay collect the symptoms a patient entersNo
Condition or service page, no formThe part of the guidance covering visits alone was vacated in 2024Your call, with caution
Blog post, about page, contact detailsGeneral public informationGenerally acceptable

What to do this week

  1. List every script on the site. Open your tag manager and your booking tool’s settings, and write down each pixel, analytics tag and chat widget, and the pages it fires on.
  2. Remove advertising pixels from booking, intake, portal and symptom pages. Most tag managers let you exclude pages by URL.
  3. Check your booking vendor. Many third-party schedulers let you paste in your own pixel. If you did that years ago, it is still there.
  4. Ask any analytics or booking vendor that touches patient data whether it will sign a business associate agreement. If it will not, it should not receive that data.
  5. Measure campaigns another way: count bookings in the scheduling system itself, and compare them with ad spend by week.

Fewer scripts also means a faster site, covered in site speed for practice websites. Mapping every script on the site is part of a technical and compliance rebuild. This post explains published HHS and FTC guidance. It is not legal advice, and a practice that has already shared patient data through a pixel should speak to a lawyer about notification duties.

Questions practice owners ask

Can a health practice use the Meta pixel on its website?

Not on booking pages, intake forms, patient portals or symptom tools. HHS says tracking code on those pages may collect protected health information, and most advertising platforms do not sign business associate agreements. On general pages with no forms, such as blog posts, the risk is lower.

Does a cookie consent banner make tracking HIPAA compliant?

No. The HHS bulletin on online tracking states that banners asking users to accept or reject cookies do not constitute a valid HIPAA authorization.

What did the 2024 court ruling on the HHS tracking guidance change?

In American Hospital Association v. Becerra, decided June 20, 2024, a federal court in Texas vacated the part of the guidance saying HIPAA is triggered when technology links an IP address to a visit to a public page about health conditions or providers. The rest of the bulletin, including its statements on portals, booking forms and banners, remains on the HHS site.

My coaching practice is not covered by HIPAA. Do these rules apply to me?

HIPAA may not, but the FTC Act does, and the FTC’s Health Breach Notification Rule covers many health apps and personal health record vendors outside HIPAA. The FTC has stated that companies not covered by HIPAA still have to protect against unauthorized disclosure of health information.


Sources, and how much weight each one carries

  1. U.S. Department of Health and Human Services, Office for Civil Rights, "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates", bulletin, with the note on American Hospital Association v. Becerra (N.D. Tex. June 20, 2024).
    Official regulator guidance. Partly vacated by a federal court in 2024; the page states which part.
  2. Federal Trade Commission, "FTC and HHS Warn Hospital Systems and Telehealth Providers about Privacy and Security Risks from Online Tracking Technologies", press release, July 20, 2023.
    Official regulator announcement. Source of the roughly 130 letters and the statement on non-HIPAA companies.
  3. Federal Trade Commission, "Complying with FTC’s Health Breach Notification Rule", business guidance.
    Official regulator guidance on who the rule covers, what counts as a breach and the penalty maximum.
  4. Federal Trade Commission, "FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Info for Advertising", press release, February 1, 2023.
    Official regulator announcement of a settled case. The first action under the Health Breach Notification Rule.
  5. Federal Trade Commission, "FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising", press release, July 14, 2023.
    Official regulator announcement of a final order in a settled case.

This article is about marketing, website and compliance practice. It is not medical or legal advice, and nothing in it is intended to diagnose, treat, cure or prevent any disease. For a decision about your own practice, speak with a qualified attorney or the relevant regulator.

Do you know what your booking page sends to Meta?

The free check looks at your site, your listings and what AI assistants repeat about your practice. Then thirty minutes on a call to go through it, including any questions about tracking.

Run the free check

Free check · findings by email within one working day

What does AI say about your practice?

  1. 1 Tell me what a patient would search for, and where.
  2. 2 An AI assistant searches the live web and answers, as a patient would see it.
  3. 3 I read the result and email you the findings, with what they mean.

The search it will run

Your name, email and practice go to the studio so the findings can be sent. Nothing else, never sold, never used for advertising. How data is handled.

This is one question. The full check asks a fixed list of 25, across four assistants, and records every answer word for word. We go through it on the call.

More insights