What a tracking pixel does on a booking page
A tracking pixel is a small piece of code from an advertising or analytics platform, such as the Meta pixel or Google Analytics. HHS defines a tracking technology as "a script or code on a website or mobile app used to gather information about users or their actions".1 When a patient loads the page, the code reports back to the platform: which page, which buttons, often the IP address, and sometimes what was typed into a form.
On a blog post, that is ordinary analytics. On a page titled "Book your fertility consultation", with a form asking for an email and the reason for the visit, the same code can tell an ad platform that an identifiable person is seeking a specific kind of care.
What HHS says, and what the court changed
In its bulletin on online tracking, the HHS Office for Civil Rights separates three situations.1
- Logged-in pages, such as a patient portal or telehealth platform. Tracking code there "generally" has access to protected health information, including IP address, appointment dates and even diagnosis or prescription information.1
- Pages without a login where patients act. HHS says tracking on a page "that permits individuals to schedule appointments or use a symptom-checker tool" may collect protected health information, for example the email address or the reason for seeking care that the patient types or selects.1
- Public information pages, such as a page about a condition or a list of your practitioners.
The third item is where the law moved. On June 20, 2024, a federal court in Texas, in American Hospital Association v. Becerra, vacated the guidance "to the extent it provides that HIPAA obligations are triggered" when technology connects an IP address with a visit to an unauthenticated public page about health conditions or providers. HHS added that note to the top of the bulletin and said it is "evaluating its next steps".1
Read that narrowly. The court removed the idea that a visit alone, matched to an IP address, is protected health information. It did not remove the rest of the bulletin, and a booking form where someone enters their details and reason for visiting is not a mere visit. My position: treat any page with a form a patient fills in as off limits for advertising pixels, whatever the next court decides.
Why the cookie banner does not fix it
Many practices believe a consent banner covers them. HHS disagrees in plain words: "Website banners that ask users to accept or reject a website’s use of tracking technologies, such as cookies, do not constitute a valid HIPAA authorization."1 The bulletin adds that it is not enough for a tracking vendor to promise to strip or de-identify the data after receiving it.1
For a covered practice, the lawful routes are narrow: a tracking vendor that signs a business associate agreement and only receives data for a permitted purpose, or a real HIPAA authorization from each patient before the data goes out.1 Most advertising platforms do not sign business associate agreements, which in practice means their pixels do not belong on those pages.
If your practice is not covered by HIPAA
Health coaches, many nutritionists and some wellness studios do not bill insurance and are not HIPAA covered entities. That does not put their data outside the law. In July 2023 the FTC and HHS jointly wrote to about 130 hospital systems and telehealth providers about the Meta pixel and Google Analytics, and the FTC stated that "companies not covered by HIPAA still have a responsibility to protect against the unauthorized disclosure of personal health information".2
The FTC also enforces the Health Breach Notification Rule, which covers vendors of personal health records and related apps outside HIPAA. Under the rule, "sharing of covered information without an individual’s authorization" counts as a breach that triggers notification, and violations can bring civil penalties of up to $53,088 each.3 A coach running a client app or an online food and symptom log should read that rule closely.
Two cases show what enforcement looks like. GoodRx paid a $1.5 million civil penalty in the first action under that rule, for sharing prescription and health condition information with Facebook, Google and others.4 BetterHelp was ordered to pay $7.8 million for disclosing email addresses, IP addresses and health questionnaire answers to Facebook, Snapchat, Criteo and Pinterest for advertising.5 Neither is a small practice, but the mechanism is the one found on many practice sites.
| Page type | What HHS says it may collect | Advertising pixel? |
|---|---|---|
| Patient portal or telehealth login | Generally has access to protected health information | No |
| Booking page or intake form | May collect email, reason for visit and other details patients enter | No |
| Symptom checker or quiz | May collect the symptoms a patient enters | No |
| Condition or service page, no form | The part of the guidance covering visits alone was vacated in 2024 | Your call, with caution |
| Blog post, about page, contact details | General public information | Generally acceptable |
What to do this week
- List every script on the site. Open your tag manager and your booking tool’s settings, and write down each pixel, analytics tag and chat widget, and the pages it fires on.
- Remove advertising pixels from booking, intake, portal and symptom pages. Most tag managers let you exclude pages by URL.
- Check your booking vendor. Many third-party schedulers let you paste in your own pixel. If you did that years ago, it is still there.
- Ask any analytics or booking vendor that touches patient data whether it will sign a business associate agreement. If it will not, it should not receive that data.
- Measure campaigns another way: count bookings in the scheduling system itself, and compare them with ad spend by week.
Fewer scripts also means a faster site, covered in site speed for practice websites. Mapping every script on the site is part of a technical and compliance rebuild. This post explains published HHS and FTC guidance. It is not legal advice, and a practice that has already shared patient data through a pixel should speak to a lawyer about notification duties.