Help Marketing?

HIPAA Website Tracking Rules for Practices in 2026

Home Blog HIPAA Website Tracking Rules for Practices in 2026

post-featured-img

The New Rules of Healthcare Website Tracking: What Practices Can and Can’t Measure in 2026

MFG Wellness: Where Healthcare Meets Marketing

The most consequential document in healthcare digital marketing right now is not a search algorithm update. It is a bulletin from the HHS Office for Civil Rights that was issued in December 2022, rewritten in March 2024, and partially struck down in federal court three months later — leaving many practices unsure which version governs their analytics stack.

The published text of OCR’s guidance on online tracking technologies now carries a court notice. In June 2024, the U.S. District Court for the Northern District of Texas vacated the portion holding that HIPAA obligations were triggered whenever a tracking tool connected a visitor’s IP address to a visit to an unauthenticated page about a health condition or a provider. The guidance states that this combination is not by itself individually identifiable health information — unless the visit relates to that person’s past, present, or future health, care, or payment for care.

What Survived Is Still Restrictive

The narrowing was real but narrow. Nearly everything else stands, and it constrains standard marketing practice.

Tracking on logged-in patient portals is treated as having access to protected health information. Unauthenticated pages that let someone book an appointment or enter symptoms into a checker can transmit PHI the moment a patient types. Vendors receiving that data are business associates and require signed agreements — and OCR is explicit that a cookie consent banner does not constitute valid HIPAA authorization. Disclosing PHI to a tracking vendor for marketing purposes without authorization is impermissible, and where no agreement and no permission exist, there is a presumption of a breach requiring notification.

OCR has also signaled where it looks first, stating that it is prioritizing HIPAA Security Rule compliance in tracking investigations — specifically whether entities identified, assessed, and mitigated risk.

This is why AI-era visibility work and compliance cannot be planned separately, a tension explored in AI Search Has Become Healthcare’s Front Door — and Most Practices Aren’t in the Room.

HIPAA Is Not the Only Regulator

Practices treating the court ruling as an all-clear are watching one agency. Federal Trade Commission business guidance makes clear that the FTC Act applies to HIPAA-covered entities and business associates alongside HIPAA — and that its definition of health information is deliberately broad, reaching browsing behavior and location data that merely support an inference about someone’s health.

The FTC points to its actions against BetterHelp, GoodRx, and Premom as establishing that sharing consumer health information for advertising without affirmative express consent may be an unfair practice. It also warns against tracking that contradicts a site’s own privacy promises, and against claims like “HIPAA Compliant” or “HIPAA Certified.”

Practices outside HIPAA — cash-pay wellness, some app-based services — do not escape. The FTC’s Health Breach Notification Rule reaches vendors of personal health records and related entities not covered by HIPAA.

Frequently Asked Questions

Can we run Google Analytics on a healthcare website?

It depends entirely on which pages and what gets transmitted. General pages about location or hours carry low exposure; portal logins, symptom tools, and appointment flows are where PHI enters the picture.

Isn’t a cookie consent banner enough?

No. OCR states directly that banners asking users to accept or reject tracking do not constitute a valid HIPAA authorization.

Did the 2024 court ruling make tracking pixels acceptable again?

No. The court vacated one specific proposition about IP addresses on unauthenticated pages. Business associate agreements, authorization requirements, and breach notification obligations were untouched.

We’re a cash-pay wellness business, not HIPAA-covered. Does this apply?

The HIPAA rules may not, but the FTC Act does, and the Health Breach Notification Rule may. Non-covered entities have been the subject of the FTC’s most prominent health-privacy enforcement.

Disclaimer: This article is for general informational purposes and does not constitute legal advice. Practices should consult qualified healthcare counsel regarding their specific compliance obligations.

MFG Wellness: Built Exclusively for Healthcare

We build and maintain healthcare websites with compliance considerations designed in from the start, not retrofitted after a vendor review.

Our Services Include:

Need a second look at your setup? Contact MFG Wellness to review how your website currently handles patient data and analytics.

Works Cited

“Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule.” Federal Trade Commission, Aug. 2024, www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach. Accessed 4 Aug. 2026.

“Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates.” U.S. Department of Health and Human Services, Office for Civil Rights, 18 Mar. 2024, www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html. Accessed 4 Aug. 2026.

Related Articles

    Request a Quote



    Scroll to Top