HIPAA-Compliant Marketing

The OCR Tracking Guidance Was Vacated. Here’s What Still Applies (2026)

Most articles about HIPAA and website tracking are wrong, and they're wrong in a specific, checkable way: they were written before June 2024 and never updated. They'll tell you that OCR says any tracking pixel on any page of your website creates protected health information. A federal court threw that theory out almost two years ago.

But here's the part that matters: the practices that got fined didn't get fined for the part that was vacated. The University of Rochester Medical Center paid $2.85 million over tracking-tool disclosures. Froedtert Health paid $2 million. Cerebral got hit by the FTC — not OCR — for sharing patient intake data with ad platforms. Every one of those cases survives the court ruling intact.

So the honest 2026 answer has two halves. The government lost the argument that visiting a webpage is health information. It never lost — and is still actively winning — the argument that what patients type into your website is. This article walks through exactly where the line sits now.

What OCR's December 2022 bulletin actually said

In December 2022, HHS's Office for Civil Rights published its "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates" bulletin. The core claims:

  • Authenticated pages (patient portals, logged-in scheduling): tracking tools that capture data here are handling PHI. Full stop.
  • Unauthenticated pages (your homepage, service pages, blog): OCR asserted that an IP address combined with a visit to a health-related page constitutes individually identifiable health information (IIHI) — because the visit itself implies something about the visitor's health.
  • Consequence: any tracking vendor receiving that data (Google, Meta, Hotjar, anyone) needed a Business Associate Agreement, and almost none of them will sign one.

That second bullet — the "proscribed combination" of IP address + unauthenticated page visit — was the radical part. Read literally, it meant a journalist researching diabetes on a hospital's website was generating PHI. Hospitals sued.

What the court vacated in AHA v. Becerra (June 2024)

In American Hospital Association v. Becerra, the U.S. District Court for the Northern District of Texas ruled in June 2024 that OCR's proscribed-combination theory exceeded HIPAA's statutory definition of IIHI — and vacated that portion of the guidance.

The court's logic is straightforward: IIHI must relate to an individual's health condition, care, or payment. A visit to a public webpage about knee replacement doesn't tell anyone whether the visitor has a bad knee, is a medical student, or is shopping for their mother. Inferring health status from a page URL, the court held, stretches the statute past its text.

What this means in practice:

  • An IP address plus a public page visit is not, by itself, PHI under HIPAA. The federal theory that made every analytics tag on every public page a violation is gone.
  • OCR revised its guidance to reflect the ruling and did not successfully resurrect the vacated theory. The proscribed-combination standard is not the law in 2026.
  • The rest of the bulletin was not vacated. This is the part the stale articles' more panicked cousins now get wrong in the opposite direction.

If a vendor or consultant tells you in 2026 that "OCR says any pixel on your homepage is a HIPAA violation," they are citing dead law. If they tell you "the guidance was struck down, tracking is fine now," they are misreading a narrow ruling as a blanket amnesty. Both are wrong. Here's what's still standing.

What still applies: the five layers that survived

1. HIPAA itself never went anywhere

The vacatur killed one interpretive theory in one guidance document. It did not amend the Privacy Rule. Anything that was PHI before the bulletin is PHI after the vacatur:

  • Authenticated pages. A tracking tool inside your patient portal, logged-in booking flow, or telehealth session is capturing data from a known patient in a treatment context. That is PHI under any reading of the statute. No court touched this.
  • Form submissions and appointment requests. When a visitor types their name, phone number, and "I'd like a consultation for TMS therapy" into your contact form, you now hold identifiable information that relates to seeking care. If your form plugin, tag manager, or pixel transmits those field values — or the confirmation page leaks them in a URL — to an ad platform without a BAA, that's a disclosure problem the AHA ruling does nothing to protect.
  • Anything that identifies a specific person as your patient. Retargeting lists built from patient email addresses, conversion uploads containing raw contact info, chat transcripts piped to a third-party widget vendor — all still squarely regulated.

The pattern in real enforcement matches this line exactly. The URMC and Froedtert resolutions involved patient information reaching third-party tracking vendors — not anonymous homepage traffic.

2. The FTC, which never needed OCR's theory

The Federal Trade Commission brought its biggest health-tracking cases under FTC Act §5 (unfair/deceptive practices) and the Health Breach Notification Rule — authorities completely untouched by AHA v. Becerra:

  • GoodRx (2023): $1.5 million penalty for sharing health data with Meta and Google despite promising not to. First-ever HBNR enforcement.
  • BetterHelp (2023): $7.8 million for sharing therapy intake answers with ad platforms.
  • Cerebral (2024): over $7 million, plus restrictions on using patient data for advertising at all.

Notice what these have in common: none of the defendants were traditional HIPAA covered entities for the conduct at issue, and none of the cases relied on the vacated IP-address theory. They relied on the companies actually sending patient-provided health information to advertisers. If your practice does that, the FTC's theory fits you regardless of what happened in the Northern District of Texas. And even if you're a HIPAA covered entity outside the HBNR's direct reach, §5 deception claims — "we promised privacy, we sent the data to Meta anyway" — apply to everyone with a privacy policy.

3. State privacy law, which is stricter than HIPAA ever was

The most aggressive health-privacy regime in the country right now isn't federal:

  • Washington's My Health My Data Act (MHMDA) covers "consumer health data" far beyond HIPAA's scope — including inferences about health drawn from browsing behavior, the very thing the federal court said HIPAA doesn't reach. It requires opt-in consent before collection, near-prohibits selling health data, and carries a private right of action. It applies to businesses handling data of Washington residents, not just Washington businesses.
  • California's CCPA/CPRA and CMIA treat health information as sensitive data with heightened obligations, and CMIA suits over pixel disclosures are active.
  • Nevada, Connecticut, and a growing list of states have MHMDA-style consumer health data laws.

If your practice advertises to patients in these states — and if you run Google or Meta ads, you almost certainly do — the vacated federal theory is irrelevant to your actual exposure.

4. Class-action pixel litigation

Plaintiffs' firms filed hundreds of lawsuits against health systems over Meta Pixel and analytics disclosures, and the vacatur did not shut them down — because the strongest claims were never pure HIPAA theories (HIPAA has no private right of action). They're wiretapping claims under state law (California's CIPA, Pennsylvania's WESCA), breach of confidence, and consumer-protection claims. Discovery in these cases turns on one question: did identifiable patient interactions — portal logins, appointment bookings, form fills — reach a third party? If your tag configuration says yes, a court ruling about anonymous IP addresses will not save you.

5. Ad-platform policy

Google and Meta both restrict health-related targeting and remarketing under their own policies, independent of any law. Meta's health-data filtering can silently degrade or disable events it flags; Google restricts personalized ads for health conditions. Your marketing has to work within these rules anyway — which is an argument for architectures that send platforms clean conversion events rather than raw user data. (More on that in our healthcare retargeting playbook.)

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

The 2026 decision rule: page views are arguable, form data is not

Strip away the case citations and the operational rule is simple:

Anonymous traffic on public pages — a visitor reading your "What is Invisalign?" post — is no longer federally presumed to be PHI. Reasonable practices can run analytics on it, though state law (especially MHMDA) still counsels care about health inferences and third-party sharing.

Identified patient interactions — logins, bookings, form submissions, chats, calls — are regulated by everything at once: HIPAA, the FTC, state law, and the plaintiffs' bar. The only safe architecture is one where that data structurally cannot reach an ad or analytics vendor.

That second category is where every real fine and every real settlement has come from. It's also where most practice websites are misconfigured, because the default installation of every marketing tool — Meta Pixel, GA4, tag manager auto-events, form plugins — vacuums up form fields, button text, and URL parameters indiscriminately.

The ungated checklist: what to fix on your site this quarter

You don't need a subscription or a sales call to act on this. Work through the list:

  1. Inventory every third-party script. Open your site, check DevTools → Network, and list every domain receiving requests. Compare against what you think is installed. (Our 10-minute PHI leak self-audit walks this step by step.)
  2. Get every tracker off authenticated pages. Portal, booking confirmation, telehealth — no pixels, no session recorders, no exceptions. This part of OCR's guidance was not vacated.
  3. Check what your forms transmit. Submit a test entry and watch the network tab. If field values, or a thank-you URL containing them, hit facebook.com or google-analytics.com, you have an active disclosure — the GoodRx/BetterHelp fact pattern.
  4. Kill URL leakage. Appointment types, condition names, and patient identifiers in query strings get captured by default page-view tracking. Confirmation pages should carry no patient-specific parameters.
  5. Audit auto-event features. GTM's auto-event listeners, Meta's automatic advanced matching, and GA4's enhanced measurement all scrape form fields and clicked text unless configured not to. "We never set that up" is how most leaks happen.
  6. Update your privacy policy to match reality — a mismatch is itself an FTC §5 problem.
  7. Map your state exposure. If you take patients from Washington, California, Nevada, or Connecticut, review consent requirements under their health-data laws, not just HIPAA.
  8. Move conversion tracking server-side, behind a filter. The durable fix isn't deleting analytics — it's an architecture where ad platforms receive conversion events and never form contents.

How compliant practices still measure marketing

This is where most compliance articles end with "so basically, stop tracking." That's wrong too — practices that fly blind on attribution waste ad budget, and nothing in HIPAA requires it.

The architecture that survives every layer above looks like this, and it's how we build every PilotPractice client site:

  • One first-party tracking script instead of a pile of vendor pixels — with a strict allowlist that captures UTM parameters and ad click IDs, not form fields or free text.
  • Server-side conversion delivery. When a lead books or converts, the ad platform gets a conversion event matched by click ID. It never receives the form contents — what the patient wrote, what condition they asked about, what service they booked. The platforms get the signal they need to optimize; the sensitive substance stays inside the practice's system.
  • Retraction jobs, so if something is ever sent in error or a contact is reclassified, the upload can be pulled back rather than living in an ad account forever.

The result: full-funnel attribution — which ad, which keyword, which landing page produced which booked patient — with the categories of data that produced the URMC, Froedtert, GoodRx, and BetterHelp cases structurally excluded from what leaves your site. The same design carries over to HIPAA-safe analytics and retargeting without patient lists; the Meta Pixel question has the same shape.

The bottom line

The vacatur was real and it mattered: the theory that anonymous public-page visits are federal PHI is dead, and any article still asserting it is out of date. But nothing that actually cost a practice money was built on that theory. Authenticated pages, form data, patient-identified disclosures to ad platforms — those are enforced today by OCR, the FTC, state attorneys general, and class-action plaintiffs simultaneously.

Read the ruling as permission to measure your marketing, not as permission to leak your intake forms.

If you'd rather not become a part-time privacy lawyer to run your practice's marketing: this is what we do. PilotPractice runs the whole channel — ads, site, tracking, booking — on infrastructure where the compliant architecture is the default, not a configuration project. Start with the 2026 HIPAA-compliant marketing guide, or book a demo and we'll audit your current tracking live on the call.

Security and compliance documentation: trust.pilotpractice.com.

See it live on your own practice

EHR-integrated booking, HIPAA-safe tracking, and marketing that reports in kept appointments — in one platform.Book a Demo

Let’s Discuss Your Growth

Monthly Email Blast Cardiologist Marketing Company Banner
Virtual Patient Coordinator Impact
Client: Just Go Lipo in Scottsdale, AZ
Woman in blue bikini with text 'TOP MIAMI PLASTIC SURGERY CENTER' on dark blue background
Shirtless man with sunglasses at beach with text 'Look Good, Feel Good'
Woman's face showing eye makeup with velyss logo and 'SAY IT WITH YOUR EYES' text
Revive Surgical Institute website homepage showcasing cosmetic and plastic surgery services in Miami with before and after gallery and patient testimonials
Exert Clinic Website
New! Voice AI