Key takeaways:
Google Analytics can be part of a HIPAA-aligned measurement setup only when Google does not receive protected health information (PHI). Healthcare teams therefore need to decide which pages can use Google Analytics and what information each tracking request sends.
One way to control what reaches Google Analytics is to route approved tracking requests through server Google Tag Manager (server GTM). You can host your server GTM container on Stape and set rules for what it sends to Google Analytics.
This guide explains how browser tracking can expose health data, how to build a more controlled data flow, and how Stape supports the technical setup. It also explains which decisions still require privacy or legal review.
This article is not legal advice. Ask your privacy or legal team to approve which data can be shared, the vendor roles, and the de-identification method for your setup.
HIPAA (Health Insurance Portability and Accountability Act) is a United States law that aims to protect patients' privacy and security concerning their medical information and health records. It applies to two groups:
Protected health information, or PHI, is individually identifiable information about a person's health, care, or payment for care that is held or transmitted by a covered entity or business associate. When that information is electronic, it is electronic protected health information, or ePHI. A name, email address, medical record number, IP address, device identifier, full URL, appointment date, or unique code can become part of PHI when it is connected to health or care information.
If a vendor handles PHI for a covered entity as part of its service, the vendor is generally a business associate and needs a business associate agreement (BAA) before it receives the data. A BAA explains how the vendor can use and protect PHI.
On a Custom plan, you can also sign a Business Associate Agreement (BAA) with Stape for covered services. The BAA defines Stape’s responsibilities when it handles PHI on behalf of your organization.
A public page is not automatically HIPAA-covered just because it discusses a health condition. Context matters. The risk changes when a visitor logs in, books care, enters symptoms, creates an account, or shares any other detail that connects the person to healthcare.
Many Canadian businesses follow PIPEDA, the federal privacy law for personal information. Provincial laws may apply instead of PIPEDA or alongside it, and some provinces have additional rules for health information. A Canadian company may also need to follow parts of HIPAA if it handles PHI for a US covered entity as a business associate.
Client-side pixels can disclose health data because they send tracking requests directly from a visitor’s browser to Google, Meta, or another platform. Your organization has no controlled server step where it can inspect or remove sensitive fields before the platform receives them. Depending on the tag and its settings, the request can include the page URL, page title, referrer, IP address, cookies, device IDs, form values, and event details.
This creates several common risk points for healthcare websites and apps:
The word “pixel” can make this sound small, while the network request behind it can carry a detailed payload.
Organizations subject to HIPAA must keep PHI out of Google Analytics. Google does not offer a BAA for Google Analytics and does not represent the service as meeting HIPAA requirements.
Google Analytics 4 (GA4) can still be used on pages that are not HIPAA-covered when legal and technical review confirms that Google receives no PHI. Review every field in the request, including IDs, URLs, event names, user properties, campaign parameters, and free-text values.
Meta and other advertising platforms have their own data restrictions. Meta’s Business Tools Terms prohibit businesses from sending health information and other sensitive data through tools such as Meta Pixel. Review every analytics and advertising destination separately.
Your privacy or legal team should decide which data each platform can receive. The technical team can then build and test the tracking setup against those rules.
Recent healthcare privacy cases show that tracking failures can lead to enforcement or private lawsuits. HHS enforces HIPAA. The FTC and state authorities can act under other privacy and consumer protection laws.
You can build a HIPAA-aligned tracking architecture by hosting your server GTM container on Stape and routing only events approved by your privacy or legal team through it before they reach analytics platforms.
You can sign a business associate agreement (BAA) with Stape. Contact our Sales team at sales@stape.io to request the agreement and confirm which services it covers.
Stape provides the following technical capabilities:
These capabilities help your team apply an approved data plan. They do not replace legal approval or testing of the full data flow.
HIPAA compliance is highly context-dependent, and requirements can vary depending on the specific client, data flow, and use case.

Healthcare teams still need useful analytics after sensitive data is removed from advertising and analytics payloads. The following Stape case studies show measurement outcomes from controlled server-side implementations.
Hellenic Technologies rebuilt OMRON Healthcare EMEA's measurement setup with country-level Google Tag Manager containers, server-side GA4 tagging, enhanced conversions, and a consent framework. The project reported:
See the full OMRON Healthcare EMEA tracking accuracy case study.
Stape Care rebuilt an existing server-side setup with a structured data layer, Consent Mode integration, stable event triggers, Custom Loader, and Cookie Keeper. The project reported:
See how the team achieved 38% attribution recovery for a healthcare client.
Your team can implement a HIPAA-aligned tracking setup by turning the approved data rules into a tested data flow.
Comments