HIPAA and Tracking Pixels

Summary
When a HIPAA covered entity or business associate uses a tracking pixel that sends protected health information (PHI) to a vendor, the disclosure is impermissible unless the patient authorized it, or a business associate agreement and a Privacy Rule permission apply. HHS says trackers on logged-in pages generally access PHI. A 2024 ruling vacated only its public-page part.
HIPAA is the US health privacy law. It covers healthcare providers, health plans, and healthcare clearinghouses, called covered entities, plus the vendors that handle PHI for them, called business associates. A tracking pixel is a small piece of code, such as the Meta Pixel or a Google tag, that reports what a visitor does on a page back to the company that made it.
The sections below cover when a tracking pixel violates HIPAA, what AHA v. Becerra changed, and what the rest of the HHS guidance says. They also cover the risks beyond HIPAA for health-related tracking, and how to check whether your tags are sending PHI.
When does a tracking pixel violate HIPAA?
A pixel creates a HIPAA problem when three things are true at once. The site belongs to a covered entity or business associate. The pixel sends PHI, meaning health information tied to someone who can be identified. And the patient has not given a valid HIPAA authorization, while the vendor receiving it either has no BAA or there is no applicable Privacy Rule permission.

HHS’s stated position, in its guidance as revised on March 18, 2024, is that a signed BAA and an applicable Privacy Rule permission must both be in place before any PHI is disclosed to a tracking vendor without patients’ authorizations. So in practice the question for most healthcare sites is simple: is PHI reaching a vendor’s tag without a BAA and a Privacy Rule permission in place?
The same logic applies to mobile apps. HHS’s stated position in the same guidance is that information collected by a regulated entity’s mobile app generally is PHI, and the HIPAA Rules apply to any PHI the app uses or discloses.
What did AHA v. Becerra change?
On December 1, 2022, the HHS Office for Civil Rights (OCR), which enforces HIPAA, published guidance on online tracking technologies, and revised it on March 18, 2024. Part of that guidance said HIPAA obligations are triggered when an online technology connects an individual’s IP address with a visit to an unauthenticated public page addressing specific health conditions or healthcare providers. The court called this the “Proscribed Combination.”
What the court order did. On June 20, 2024, in American Hospital Association v. Becerra, Judge Mark T. Pittman of the U.S. District Court for the Northern District of Texas declared that part unlawful and vacated it. The order covers only that part of the guidance. HHS appealed to the Fifth Circuit, then withdrew its notice of appeal on August 29, 2024, so the ruling stands.
The ruling may be read narrowly: an IP address plus a visit to a public page about a condition or a doctor no longer triggers HIPAA obligations under the guidance on that basis alone. Some commentators read the court’s reasoning more broadly, so this isn’t settled law, and future cases could change it. Either way, healthcare sites should not read the ruling as permission to run any tag anywhere, because the court did not vacate the rest of the guidance.
What HHS says. HHS’s page now carries a notice about the court’s order and says “HHS is evaluating its next steps in light of that order.” It does not say whether the rest of its guidance remains in effect. As of September 2026, HHS has not revised the guidance since the ruling.
What does the rest of the HHS guidance say?
Authenticated pages. Pages behind a login, such as a patient portal, a logged-in scheduler, or a telehealth account, are where the guidance is strongest, and the court’s order did not address them. HHS’s stated position, as of its March 18, 2024 guidance, is that tracking technologies on these pages generally have access to PHI, and that tracking technology vendors are business associates if they create, receive, maintain, or transmit PHI on behalf of a regulated entity.
Information the visitor enters. A public page can still produce PHI when a visitor types or selects something on it. HHS’s stated position in that guidance is that when a tracker on a regulated entity’s page collects what a visitor types or selects, such as an email address or reason for seeking care in an appointment form or symptom checker, that is a disclosure of PHI. HHS treats information collected on login and registration pages the same way.
BAAs and permissions must come first. HHS’s stated position is that any disclosure of PHI to a tracking vendor without individuals’ authorizations requires a signed BAA and an applicable Privacy Rule permission, both in place before any PHI is disclosed. A vendor’s promise to strip or de-identify data before saving it does not count. A BAA alone does not make tracking compliant.
Cookie banners are not authorization. In the words of the HHS guidance, as revised on March 18, 2024: “Website banners that ask users to accept or reject a website’s use of tracking technologies, such as cookies, do not constitute a valid HIPAA authorization.” A consent banner can matter under other laws. It does not solve a HIPAA problem.
Is HIPAA the only risk for health-related tracking?
No. Other exposures do not depend on the HHS guidance at all, so the 2024 ruling does not reduce them.
State wiretap laws, such as the California Invasion of Privacy Act (CIPA), let visitors sue when a third party captures their activity without consent. Many health-pixel lawsuits run on these laws.
The FTC’s Health Breach Notification Rule covers health apps and similar services outside HIPAA, and since July 2024 its text says an unauthorized disclosure, not just a hack, can be a breach that requires notice. Washington’s My Health My Data Act, in force since 2024, requires authorization before consumer health data is sold, and allows private lawsuits as well as Attorney General enforcement.
For the lawsuits and settlements themselves, see Enforcement Watch: health pixel lawsuits. For the wiretap theory in detail, see CIPA and website tracking.
How to check whether your tags are sending PHI
The useful question is what your tags actually transmit, page by page. A tag inventory or a vendor’s documentation tells you what a tag is capable of collecting. Only the real payload, the data the tag sends when it fires, tells you whether PHI left your site.

DataTrue answers that by running your live site the way a visitor would, in a real browser, and recording what every tag sends. A Coverage test crawls the whole site and reports what is tagged on every page, including tags added outside your tag manager. A Simulation test walks a defined journey, such as logging into the portal or booking an appointment, and checks what fires at each step and in each consent state. Sensitive Data Detection inspects the payloads for personal and health data. Because the tests use fictitious personas, invented patients with fake names and details, you can test a portal or intake form without using anyone’s real health information.
Tests run on a schedule against the live site, with alerts when something changes, such as a tag your policy doesn’t allow on the portal after a release. The output is a timestamped record of which tags sent what, on which pages, which shows a compliance officer where the exposure is and when the tag stopped sending the data. DataTrue gives teams tools to help them become and stay compliant. It does not certify HIPAA compliance.
What should healthcare sites do?
- Map your pages into two groups. Authenticated pages and pages where visitors enter health details go in the high-risk group. Public information pages go in the lower-risk group.
- Keep non-BAA tags off the high-risk group entirely, and confirm with testing that they are actually off, since tags often return through a template change or a new campaign.
- Get a signed BAA, and confirm a Privacy Rule permission applies, before any PHI reaches a vendor on high-risk pages, and confirm the vendor’s product supports HIPAA use. A BAA alone does not make tracking compliant.
- Review public pages as well. The court ruling narrowed HIPAA exposure there. State wiretap laws such as CIPA still apply.
- Monitor continuously. A site that was clean at the last audit can change with the next release.
- Confirm with your own counsel how all of this applies to your own pages and data flows.
For the specific case of Google Analytics, see Is Google Analytics HIPAA compliant?.
Questions
Do tracking pixels violate HIPAA?
They can. A pixel violates HIPAA when a covered entity or business associate uses it to send protected health information to a vendor without the patient’s HIPAA authorization, unless the vendor has signed a business associate agreement and a Privacy Rule permission applies. That risk is highest on logged-in pages such as patient portals.
Did the AHA v. Becerra ruling make tracking pixels legal on healthcare websites?
No. The June 2024 ruling vacated only the part of HHS guidance under which an IP address plus a visit to a public page about specific health conditions or providers triggers HIPAA obligations. HHS withdrew its appeal in August 2024. The court did not vacate the rest of the guidance, including on logged-in pages and on information visitors enter. That remains HHS’s stated position as of its March 18, 2024 revision, though HHS says it is evaluating its next steps. State wiretap laws such as CIPA are unaffected.
Does HIPAA apply to tracking on a hospital’s public web pages?
Less than before 2024. Since the court ruling, a visit to a public page about a condition, tied only to an IP address, doesn’t trigger HIPAA obligations under the guidance by itself. But a public page can still send PHI when a visitor enters health details, such as in a symptom checker or appointment form.
Does a cookie consent banner satisfy HIPAA?
No. HHS’s stated position, in its guidance as revised on March 18, 2024, is that website banners asking users to accept or reject tracking technologies do not constitute a valid HIPAA authorization.
Can a vendor fix the problem by de-identifying data before saving it?
No. HHS’s stated position, as of its March 18, 2024 guidance, is that the business associate agreement and an applicable Privacy Rule permission must be in place before PHI is disclosed. A vendor’s promise to de-identify data before saving it does not replace them.
Find personal data in your tags before an ad platform does
DataTrue fills your forms with test personas and reads each tag request for emails, names and card numbers. A leak shows up in a test, with the tag and the page that sent it.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
