HIPAA-Compliant Marketing

Is Hotjar HIPAA Compliant? (And Microsoft Clarity, Heatmaps in General) (2026)

Short answer: no. Hotjar does not sign a Business Associate Agreement, which means a medical practice cannot legally run it on any page where protected health information might appear. Microsoft Clarity — the free alternative everyone switches to — is no better. And "heatmaps in general" are among the riskiest tracking tools a practice can install, because they don't just log a pageview. They record what your visitors do.

If that sounds theoretical, look at the enforcement record. The University of Rochester Medical Center paid $2.85 million over tracking-technology disclosures. Froedtert Health paid $2 million. OCR's original tracking guidance was partially vacated by a federal court in the Northern District of Texas in June 2024 — more on that below — but the settlements stand, HIPAA itself never changed, and state attorneys general and class-action firms have picked up exactly where the guidance left off. In 2026, "the guidance got vacated" is not a defense. The statute is.

What Hotjar and Clarity actually capture

Marketers think of heatmaps as anonymous aggregate blobs. They aren't. Session-recording tools capture, per visitor:

  • Every page URL viewed — including /services/std-testing/, /conditions/erectile-dysfunction/, /book-appointment/. A URL path plus an IP address is enough to infer a health condition tied to an individual.
  • Mouse movements, scrolls, and clicks — which treatment card someone hovered over, which FAQ they expanded, how long they lingered on pricing for a specific procedure.
  • Form interactions. Both tools claim to mask keystrokes by default, but masking depends on correct configuration of every input on every form, forever. One unmasked field — a message box, a date-of-birth picker, a custom intake plugin the masking rules don't recognize — and you're shipping typed PHI to a third-party server with no BAA. Session-replay tools have been caught capturing "masked" data repeatedly across industries.
  • Device fingerprint and IP address — the identifiers that turn "someone looked at addiction treatment" into "this person looked at addiction treatment."

Under HIPAA, when a covered entity's website discloses individually identifiable information connected to health status or the seeking of care, that combination can constitute PHI. A visitor researching a condition on your practice's site is not a random web user — they're plausibly a patient or prospective patient. That's precisely the fact pattern behind the URMC and Froedtert settlements and the wave of hospital-website class actions still being filed today.

"But Hotjar says it's GDPR compliant"

GDPR is not HIPAA. Hotjar's privacy documentation is built for European consent law: it talks about lawful basis, cookie consent, and data-processing agreements. None of that satisfies HIPAA's requirement that a business associate — any vendor that receives PHI on your behalf — sign a BAA and implement the Security Rule's safeguards. Hotjar (now part of Contentsquare) does not offer a BAA on its standard products. No BAA, no legal disclosure of PHI. It's that binary.

Is Microsoft Clarity HIPAA compliant?

Also no. Clarity is free, which makes it the tool practices install without thinking, but Microsoft does not extend its healthcare BAA to Clarity. Clarity records sessions, builds heatmaps, and — because it's free — the product's business model is feeding behavioral signal back into Microsoft's advertising ecosystem. That's the exact "tracking technology transmitting visitor data to an advertising-adjacent third party" scenario regulators and plaintiffs' attorneys target. Free is not a mitigating factor; it's an aggravating one.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

What about the vacated OCR guidance?

In June 2024, a federal court in the Northern District of Texas vacated the portion of OCR's online-tracking guidance that treated a visitor's IP address plus a visit to an unauthenticated health-content page as automatically PHI. That ruling narrowed one aggressive interpretation. It did not:

  • Change the HIPAA statute or the Privacy Rule.
  • Touch authenticated pages (patient portals, booking flows, intake forms) — where session recorders capture the most.
  • Stop state privacy laws (Washington's My Health My Data, California's CMIA) or wiretapping-statute class actions, which don't depend on OCR's guidance at all.
  • Undo a single settlement.

Read our full breakdown: The OCR tracking guidance was vacated — here's what still applies. The operational conclusion is unchanged: a tool that records individual patient behavior and ships it to a vendor without a BAA is a liability, guidance or no guidance.

The heatmap decision checklist

Before any session-recording or heatmap tool goes on a medical practice website, it has to clear every one of these. No exceptions, no "just for a month."

  1. Will the vendor sign a BAA? Hotjar: no. Clarity: no. If no, stop here.
  2. Does it record pages where health intent is visible? Condition pages, service pages, booking, intake, portal. On a practice site, that's essentially everything.
  3. Can it capture form input? If the tool touches the DOM of a form, assume yes — masking is a configuration you will eventually get wrong, not a guarantee.
  4. Does it capture IP address or a persistent device identifier? Both tools do.
  5. Does data leave your control? Recordings sit on the vendor's servers, viewable by their staff, subject to their retention policies.
  6. Is there a disclosed, audited data flow? Could you tell a regulator exactly what left the site, when, and to whom? With third-party replay scripts, you can't.
  7. Is the insight worth the exposure? "Where do people click" is answerable without recording identifiable individuals — see below.

If a tool fails item 1, items 2–7 are academic. Hotjar and Clarity fail item 1.

How to get the UX answers without the exposure

Here's the part most "is it compliant" articles skip: you installed Hotjar for a reason. You wanted to know where visitors drop off, which CTAs get ignored, whether the booking flow leaks. Those are legitimate, revenue-relevant questions. The compliant way to answer them is to collect behavioral events you define, first-party, with no third-party script watching the session.

That's how PilotPractice does it. Our sites run a single first-party tracking script — no Hotjar, no Clarity, no tag soup. It captures campaign attribution through a strict UTM and click-ID allowlist, stitches visits with a first-party visitor ID, and answers the ad-platform question via offline conversion uploads: Google and Meta learn that a conversion happened, never what a form said or which condition page someone read. If something is captured that shouldn't have been, retraction jobs pull it back out of the pipeline. And instead of replaying booking sessions, our EHR-integrated booking widget emits micro-event tracking — step reached, step abandoned, slot viewed — so you get funnel drop-off analysis with defined, minimal, first-party events rather than a video of a patient typing.

You lose the voyeuristic session replay. You keep every decision the replay was supposed to inform — and you can hand an auditor the exact list of what your site collects.

The verdict, and what to do Monday

  • Hotjar: not HIPAA compliant. No BAA. Remove it from every practice site.
  • Microsoft Clarity: not HIPAA compliant. No BAA, and free-tool economics make it worse. Remove it.
  • Heatmaps in general: compliant only if the data never identifies an individual and never leaves your control — which rules out every mainstream replay vendor in 2026.

Then rebuild the measurement you actually need: first-party events, allowlisted attribution, conversion signals without content. That's the stack behind everything we run — same architecture that powers our HIPAA-safe retargeting playbook and the tracking layer described in the full 2026 HIPAA-compliant marketing guide.

Not sure what's on your site right now? Run our free PHI leak scanner — it flags Hotjar, Clarity, and every other third-party tracker transmitting visitor data off your domain, in about a minute, no email gate.

Want it handled? PilotPractice builds and runs the whole compliant stack — site, tracking, booking, follow-up — for medical practices. Book a demo and we'll show you your funnel data without a single session recorder on the page.


All compliance infrastructure documented at trust.pilotpractice.com.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI