Jul 29 / Rebecca Herold

Tracking Tech in Healthcare Provider Websites Can Violate HIPAA

Healthcare providers, from the smallest clinic to the largest healthcare provider system, need to be concerned about the technologies (tech) they have implemented within their webpages. Many organizations do not realize that their contracted third parties hosting and managing their websites, or their own internal staff, have implemented tracking tech into their webpages, even within their patient portals. They often do so at the request of their marketing and sales departments, or at the urging of third parties who are supplying the provider organizations with supplies or services.

Tracking tech on healthcare websites, particularly within authenticated patient portals, can result in impermissible disclosures of protected health information (PHI) where data is transmitted to third parties without a valid HIPAA basis. Such data often includes not only identifiers, URLs, appointment information, health data, chat transcripts with doctors or nurses, user activity, lab results and more, they also often include data about the patient. Such data can include, but not be limited to, the type and version of computer or phone they are using, their location, date and time of activities, and even other websites they have visited. While tracking pixels on public-facing webpages can gather hundreds of personal data elements, within a patient portal that exposure increases exponentially, and so does the risk of HIPAA noncompliance.

HIPAA permits disclosures of PHI for treatment, payment, and healthcare operations (TPO), or with an explicit and valid authorization from each of the associated individuals. In practice, most advertising and marketing technology vendors do not qualify as business associates (BAs) and will not execute business associate agreements (BAAs). As a result, transmitting PHI to such vendors is typically high risk and often prohibited by HIPAA. 

In an authenticated portal, typically most of the accessible data may constitute PHI depending on what is exposed or transmitted. Tracking tech incorporated into the webpage code can be configured to dynamically capture and transmit sensitive details without a valid HIPAA basis and send the data on to the large tech companies providing the tracking tech, from where they then often share it with other entities as a paid service to them. 

Because the ad-tech entities generally refuse to execute BAAs or limit their data usage strictly to TPO, transmitting this data without explicit and valid patient authorization creates immense legal and regulatory risk. And regulatory enforcement and class-action litigation surrounding online tracking in healthcare are at an all-time high.

Every U.S. healthcare organization, and the BAs who support or manage their websites in some way, need to know where all the tracking tech is located within each webpage of a healthcare provider’s website, and then take appropriate actions to remove the tracking tech that is on the login page of the patient portals, and within each of the portal pages, unless legal counsel and executive management indicate it is acceptable on specific webpages.

Here are the recommended actions for you to take if you’ve just been notified that tracking tech are likely to be within your online webpages.  

Recommended Actions

  1. Activate an immediate online tracking tech "kill switch". Immediately disable all tracking tech within patient portals and all patient/user authentication areas. Such tracking tech include pixels (Meta Pixels), conversion APIs, custom scripts, SDKs, etc., within the patient authentication page and inside the patient portal. Do not wait for a full audit to stop active data transmissions.
  2. Initiate a formal incident response and evidence preservation process.
    1. Engage legal counsel early to help preserve privilege over the investigation and guide breach analysis and notifications.
    2. Also include key stakeholders from privacy, compliance, information security, IT, communications, and sourcing leadership.
    3. Preserve relevant evidence, including all portal login activity, server logs, webpage configurations, pixel data, tag management records and histories, webpage source code, associated URL paths, data flow documentation, and estimated user counts. Preserve this data strictly as directed by legal counsel.
  3. Conduct a comprehensive enterprise websites audit. Audit every public and private (authentication required) website property across your organization:
    1. Identify and document all tracking tech. All types of pixels, SDKs, cookies, APIs, conversion APIs, and all other types of tracking tech.
    2. Map data transmission. Determine and document precisely all the data elements that are transmitted, checking specifically for any of the specifically identified HIPAA identifiers along with URLs, search terms, form inputs, IP addresses, event data, and all other types of data that are associated with users’/patients’ activities on the associated webpage.
    3. Identify, document and map all third-party recipients of the tracking tech data, and the onward data flows.
  4. Perform a HIPAA breach risk assessment consistent with 45 CFR § 164.308. This is the section that includes the requirements for risk analysis (aka risk assessment).
    1. Evaluate the nature and extent of the PHI involved, who received, viewed or accessed the data, and the extent to which risk has been mitigated.
    2. Remediate risks by removing tracking tech where inappropriate, particularly in authenticated contexts, and limiting use on public pages to scenarios with a clear business purpose and no PHI exposure.
    3. Use this formal assessment to determine whether breach notification obligations are triggered under HIPAA, state data privacy statutes, other regulations, or the FTC Act, Section 5, Unfair and Deceptive Business Practices.
  5. Review vendor contracts & BAAs. Audit all associated third-party vendor relationships. Confirm whether signed BAAs exist and whether any disclosures could legitimately fall under permissible TPO disclosures or contractual support.
  6. Audit and reassess marketing and analytics governance and oversight practices.
    1. Review the audit findings with marketing leadership.
    2. Reassess all digital marketing practices, remove public-facing trackers that lack a valid business purpose or proper consent management, and establish a permanent governance process requiring written IT, security and privacy approval before any third-party script is deployed in the future.
    3. Establish governance controls, including the requirement of authorization to use tracking tech, to prevent deployment of tracking tech that could access or transmit PHI. Such controls should be included within change management, privacy review, and technical safeguards.


Prompt, well-documented remediation is your best defense. Regulators at the federal and state levels have increased scrutiny in this area, and enforcement risk is significant. More lawsuits are being filed for the impacts of unauthorized disclosure of PHI via online tracking tech, which is being claimed to be breaches as defined by HIPAA since it is unauthorized access to the associated patients’ PHI.

Based on extensive work with healthcare organizations on this issue, I have not identified a defensible TPO-based use case for advertising or marketing tracking tech within patient portals.