A treatment program starts running ads, the ads need conversion data, and someone pastes a Meta Pixel and a Google tag into the site header. Many tracking problems on behavioral health sites start that way, as a marketing default that nobody ever reviewed as a decision about patient data.

On a hardware store website, a pixel reports that a visitor looked at drills. On an addiction treatment website, the same pixel can report that a visitor read the opioid detox page, opened the insurance verification form and tapped "Call admissions." On a behavioral health site, the pages a person reads and the forms they open can reveal what care they are looking for, so the default marketing setup is the wrong setup.

This is general information, not legal advice. Confirm your obligations with a healthcare privacy attorney.

What is a tracking pixel, and why does it matter more here?

A tracking pixel is third-party code that reports what a visitor does on your site back to the company that wrote it. The HHS Office for Civil Rights (OCR) groups pixels with cookies, session replay scripts and fingerprinting scripts under one label: online tracking technologies.

The report usually includes the page URL, the button clicked and an identifier such as an IP address or cookie. Some setups add form values, hashed email addresses or custom event names.

A URL like /alcohol-detox/verify-insurance says more than most form fields. OCR's bulletin warns that these disclosures can reveal diagnoses and how often a person sees a therapist.

What did HHS say about tracking technologies in 2022 and 2024?

HHS said HIPAA applies when a tracking tool sends protected health information (PHI) to a vendor, and that the vendor then needs a business associate agreement (BAA) or the patient's written authorization. OCR issued the bulletin in December 2022 and revised it on March 18, 2024, as the federal court's opinion lays out.

The points that matter most are still on the HHS page today:

  • Tracking on logged-in pages, such as patient portals and telehealth platforms, generally has access to PHI.
  • Public pages where someone books an appointment or enters symptoms may send PHI, including the reason for seeking care.
  • A vendor that receives PHI on your behalf is a business associate, and a BAA is required.
  • Listing the vendor in your privacy policy does not permit the disclosure.
  • A cookie banner is not a valid HIPAA authorization.
  • An impermissible disclosure to a tracking vendor is presumed to be a breach unless you can show a low probability of compromise.

HIPAA reaches a provider that sends health information electronically in connection with standard transactions, such as insurance claims. If your program bills insurance, assume HIPAA applies and confirm it with counsel.

What did the court vacate in American Hospital Association v. Becerra?

The court vacated one narrow piece: the position that HIPAA is triggered when a tracking tool connects an IP address with a visit to a public page about specific health conditions or providers. On June 20, 2024, the U.S. District Court for the Northern District of Texas (No. 4:23-cv-01110) declared that piece unlawful as beyond HHS's authority under HIPAA. The opinion calls it the "Proscribed Combination." The court denied a permanent injunction but ordered vacatur. HHS withdrew its appeal in August 2024, so the ruling stands.

A footnote in the opinion says the vacatur should not be read to limit the rest of the HHS document.

Vacated: an IP address plus a visit to a public condition or provider page, by itself, as a HIPAA trigger.

Left in place: portals, appointment and symptom forms, credentials or registration details entered on login and registration pages, the BAA requirement, the cookie banner point and the breach presumption.

The ruling narrowed the guidance. It did not clear the pixel. The conversion events a treatment center cares about most (form submissions, insurance checks and booking flows) sit on the side the court left alone.

The bulletin itself is guidance, and HHS says it does not carry the force of law. The HIPAA rules underneath it do.

Does the FTC regulate health data that HIPAA does not cover?

Yes. The FTC Act bars deceptive and unfair practices, including broken privacy promises. The FTC's Health Breach Notification Rule covers health apps and similar services outside HIPAA, and its April 2024 amendments confirm that an unauthorized disclosure counts as a breach, not only a hack.

The enforcement record reads like a list of marketing defaults:

  • GoodRx, February 2023: the first enforcement action under the Health Breach Notification Rule, with a $1.5 million civil penalty, after the FTC alleged the company shared health data with Facebook, Google and others and failed to report it.
  • BetterHelp, March 2023: $7.8 million for consumers after the FTC alleged the online counseling service shared email addresses, IP addresses and health questionnaire information with Facebook, Snapchat, Criteo and Pinterest.
  • Cerebral, April 2024: a settlement requiring more than $7 million in payments, after the FTC alleged the telehealth firm sent sensitive data on nearly 3.2 million consumers to LinkedIn, Snapchat and TikTok through tracking tools.
  • An online alcohol addiction treatment company, April 2024: a court order, entered in June 2024, banning it from sharing health data for advertising, plus a $2.5 million civil penalty under the Opioid Addiction Recovery Fraud Prevention Act, suspended because the company could not pay.

The last case holds the detail worth remembering. According to the FTC, the company named its pixel events things like "Paid: Weekly Therapy" and sent them to ad platforms with email and IP addresses attached. The event name was the leak, and it is an easy one to miss because event names look like analytics housekeeping rather than patient data.

The statute in that case matters to addiction programs in particular. The Opioid Addiction Recovery Fraud Prevention Act applies specifically to substance use disorder treatment services.

Does 42 CFR Part 2 apply to an addiction treatment website?

It can apply to what the website collects, and in several respects it is stricter than HIPAA. Part 2 protects records of the identity, diagnosis, prognosis or treatment of patients in federally assisted substance use disorder programs. Its definition of patient includes anyone who has applied for diagnosis, treatment or referral. A person does not have to be admitted to fall inside that definition.

Part 2 also limits acknowledging that an identified person is a patient at a facility publicly identified as providing only substance use disorder services. That takes written consent or a court order.

A February 2024 final rule aligned Part 2 breach notification and penalties with HIPAA. Compliance was required by February 16, 2026.

We found no federal guidance that applies Part 2 to website pixels specifically. The risk is still plain. A pixel that tells an ad platform an identifiable person submitted an intake form on a substance use disorder program's site is close to identifying an applicant. As a precaution, treat intake data as Part 2 data.

Which state laws cover health data from websites?

Washington's My Health My Data Act is the broadest. Under RCW 19.373, a covered business needs consent to collect consumer health data and a separate consent to share it. The law also bars using a geofence of 2,000 feet or less around a place that provides in-person health care to track visitors, collect their health data or send them ads. Violations are enforced through Washington's Consumer Protection Act, and the state Attorney General notes that consumers can sue. Most provisions took effect March 31, 2024 (June 30, 2024 for small businesses), and the geofence ban took effect July 23, 2023.

Data that is already PHI under HIPAA is exempt. Website data that is not PHI may not be.

Nevada added its own consumer health data provisions in 2023, now in NRS Chapter 603A. If you advertise across state lines, check the law of every state you target, not only the state where you are licensed.

Have hospitals been sued over the Meta Pixel?

Yes, and a wave of suits followed the reporting. In June 2022, The Markup tested the websites of Newsweek's top 100 hospitals. On 33 of them, the Meta Pixel sent data to Facebook when a visitor clicked to schedule an appointment. It also found the pixel inside the password-protected patient portals of seven health systems.

By September 2022, at least five class actions had been filed against Meta, one alleging the pixel collected patient information from at least 664 hospital websites. The federal cases against Meta proceed as In re Meta Pixel Healthcare Litigation, No. 3:22-cv-03580 (N.D. Cal.).

Behavioral health was not spared. In June 2023, The Markup found that more than 30 of 186 local crisis center websites in the 988 network sent visitor data to Facebook, including clicks on crisis call and text buttons.

Where do tracking leaks happen on a behavioral health website?

They happen wherever a visitor tells you something about their own care:

  • Contact and intake forms. Some pixel settings capture form values or hashed email addresses automatically.
  • Insurance verification forms. Payer, member ID and date of birth, often on a page whose URL names the program.
  • Chat widgets. The transcript lives on the vendor's servers, along with whatever the person typed.
  • Call tracking. Dynamic numbers tie a call to the ad, keyword and page. Recordings raise the same question as chat.
  • Thank-you page URLs. A URL like /thank-you?program=detox&payer=aetna goes to every tag that fires on that page.
  • Session replay. OCR describes these scripts as recording mouse movements, clicks and typing.
  • Event names and page titles. "Detox intake submitted" is a disclosure. "Form submitted" is not.
  • Tag managers. One container lets anyone with access add a new tag to every page without a developer review.

What does a safer tracking setup look like?

Start by keeping third-party ad pixels off condition, program, intake, insurance, booking and thank-you pages. If you cannot control where a pixel fires, remove it.

Analytics is the harder call. Google says it does not offer BAAs for Google Analytics and that HIPAA-regulated customers may only use it on pages that are not HIPAA-covered. The usual alternatives are server-side measurement or a privacy-focused tool that reports counts, not people.

Form processors, chat, call tracking, scheduling and email delivery can all end up holding PHI. Each one that does needs a signed BAA, and a vendor that will not sign does not get PHI.

Then check what actually fires, using the Network tab test described in the FAQ below. Add linkedin and any other vendor you use to the filter.

Your ad platforms will report fewer conversions, and their automated bidding will have less to learn from. Count admissions in your own systems instead. A detox page that converts a little less measurably is a business problem. A detox page that tells an ad platform who needs detox is a legal one.

What belongs on a tracking checklist for a treatment or therapy website?

  • Inventory every script, pixel and tag on the site, including anything inside a tag manager.
  • Remove ad pixels from condition, program, intake, insurance, booking, portal and thank-you pages.
  • Strip program names, payers and conditions from URLs and query strings.
  • Rename events so they describe an action, not a diagnosis.
  • Turn off automatic form capture and session replay on any page with a form.
  • Confirm a signed BAA with each vendor that touches PHI.
  • Check consumer health data laws in every state you advertise in.
  • Test with developer tools after every launch, redesign and new campaign.
  • Have a healthcare privacy attorney review the final setup.

Frequently asked questions

Is the Meta Pixel HIPAA compliant on a healthcare website?

Not by default. HHS says a vendor that receives protected health information needs a business associate agreement or the patient's HIPAA authorization, and a cookie banner is not an authorization. If a pixel fires on intake, insurance, booking or thank-you pages, assume it may be receiving PHI.

Can a therapy practice use Google Analytics?

Only with care. Google says it does not offer business associate agreements for Google Analytics and that HIPAA-regulated customers may only use it on pages that are not HIPAA-covered. Keep it off forms, booking flows, portals and pages tied to a visitor's own care.

Did the 2024 court ruling make tracking pixels legal for healthcare websites?

No. The court vacated one piece of the HHS guidance: that an IP address plus a visit to a public page about a condition or provider is enough to trigger HIPAA. The rest of the guidance, including portals, appointment and symptom forms, and business associate agreements, was left in place.

Does 42 CFR Part 2 apply to an addiction treatment website?

It can apply to the records the site collects. Part 2 protects records that identify a patient of a federally assisted substance use disorder program, and its definition of patient includes anyone who has applied for diagnosis, treatment or referral at the program. We found no federal guidance applying Part 2 to pixels specifically, so as a precaution, treat intake data as Part 2 data.

How do I check what my website sends to Meta or Google?

Open the site in a private browser window, open the developer tools Network tab, and filter for facebook, google, tiktok and similar domains. Then fill out your own forms with fake data and read what each request contains.

Where to start

Begin with the four pages where a visitor tells you the most: the intake form, the insurance check, the booking flow and the thank-you page that follows them. Run the Network tab test on those pages first. If an ad platform receives anything there, fix that before the next campaign launches. The rest of the checklist can follow.


Related reading: LegitScript Certification for Addiction Treatment Websites · SEO for Medical Practices · Therapist Websites

Planning a new behavioral health website?
Tracking decisions belong in the plan, not in a cleanup after launch. We build for a flat fee. No per-lead, per-call or per-admission pricing.

Behavioral Health Websites Get a Quote