How to make your tracking HIPAA-Compliant: strategies for healthcare companies

Maryna Semidubarska

Maryna Semidubarska

Author
Updated
Sep 4, 2026
i

Key takeaways:

  • Traditional browser tracking can send sensitive health information directly to third-party platforms.
  • Organizations subject to HIPAA must keep protected health information (PHI) out of Google Analytics.
  • With a controlled tracking setup, you send only approved data to each platform. It is also important to remove direct browser tags from sensitive flows.
  • You can host the server setup on Stape and sign a business associate agreement (BAA) for covered services.

Google Analytics can be part of a HIPAA-aligned measurement setup only when Google does not receive protected health information (PHI). Healthcare teams therefore need to decide which pages can use Google Analytics and what information each tracking request sends.

One way to control what reaches Google Analytics is to route approved tracking requests through server Google Tag Manager (server GTM). You can host your server GTM container on Stape and set rules for what it sends to Google Analytics. 

This guide explains how browser tracking can expose health data, how to build a more controlled data flow, and how Stape supports the technical setup. It also explains which decisions still require privacy or legal review.

This article is not legal advice. Ask your privacy or legal team to approve which data can be shared, the vendor roles, and the de-identification method for your setup.

Start with scope: what HIPAA covers and what counts as PHI

HIPAA (Health Insurance Portability and Accountability Act) is a United States law that aims to protect patients' privacy and security concerning their medical information and health records. It applies to two groups:

  • Covered entities include certain healthcare providers that send claims or billing information electronically, such as doctors, clinics, hospitals, and pharmacies. They also include health insurance companies, government programs such as Medicare and Medicaid, and healthcare clearinghouses that prepare health data for electronic exchange.
  • Business associates are people or companies that handle protected health information for a covered entity, such as billing companies or cloud providers.

Protected health information, or PHI, is individually identifiable information about a person's health, care, or payment for care that is held or transmitted by a covered entity or business associate. When that information is electronic, it is electronic protected health information, or ePHI. A name, email address, medical record number, IP address, device identifier, full URL, appointment date, or unique code can become part of PHI when it is connected to health or care information.

If a vendor handles PHI for a covered entity as part of its service, the vendor is generally a business associate and needs a business associate agreement (BAA) before it receives the data. A BAA explains how the vendor can use and protect PHI. 

On a Custom plan, you can also sign a Business Associate Agreement (BAA) with Stape for covered services. The BAA defines Stape’s responsibilities when it handles PHI on behalf of your organization.

A public page is not automatically HIPAA-covered just because it discusses a health condition. Context matters. The risk changes when a visitor logs in, books care, enters symptoms, creates an account, or shares any other detail that connects the person to healthcare.

For Canadian healthcare teams

Many Canadian businesses follow PIPEDA, the federal privacy law for personal information. Provincial laws may apply instead of PIPEDA or alongside it, and some provinces have additional rules for health information. A Canadian company may also need to follow parts of HIPAA if it handles PHI for a US covered entity as a business associate.

How client-side pixels can disclose health data

Client-side pixels can disclose health data because they send tracking requests directly from a visitor’s browser to Google, Meta, or another platform. Your organization has no controlled server step where it can inspect or remove sensitive fields before the platform receives them. Depending on the tag and its settings, the request can include the page URL, page title, referrer, IP address, cookies, device IDs, form values, and event details.

This creates several common risk points for healthcare websites and apps:

  • A clinic booking page can send an email address, selected provider, appointment date, and event name to a third party.
  • A telehealth flow can expose a patient portal login, visit type, questionnaire answer, or URL that contains a medical term.
  • A direct-to-consumer (DTC) health cart can connect an order ID or email with a fertility test, prescription product, or device for a health condition.
  • A mobile health app can connect an advertising ID or device ID with health events recorded inside the app.

The word “pixel” can make this sound small, while the network request behind it can carry a detailed payload. 

Why Google Analytics cannot receive PHI and advertising platforms restrict health data

Organizations subject to HIPAA must keep PHI out of Google Analytics. Google does not offer a BAA for Google Analytics and does not represent the service as meeting HIPAA requirements.

Google Analytics 4 (GA4) can still be used on pages that are not HIPAA-covered when legal and technical review confirms that Google receives no PHI. Review every field in the request, including IDs, URLs, event names, user properties, campaign parameters, and free-text values.

Meta and other advertising platforms have their own data restrictions. Meta’s Business Tools Terms prohibit businesses from sending health information and other sensitive data through tools such as Meta Pixel. Review every analytics and advertising destination separately.

Your privacy or legal team should decide which data each platform can receive. The technical team can then build and test the tracking setup against those rules.

What recent healthcare privacy cases show

Recent healthcare privacy cases show that tracking failures can lead to enforcement or private lawsuits. HHS enforces HIPAA. The FTC and state authorities can act under other privacy and consumer protection laws.

How to build HIPAA-aligned tracking with Stape

You can build a HIPAA-aligned tracking architecture by hosting your server GTM container on Stape and routing only events approved by your privacy or legal team through it before they reach analytics platforms. 

​​You can sign a business associate agreement (BAA) with Stape. Contact our Sales team at sales@stape.io to request the agreement and confirm which services it covers.

Stape provides the following technical capabilities:

  • Server GTM Hosting. You host your server GTM container on Stape and set separate rules for what each platform receives.
  • Anonymizer. For GA4 requests routed through server GTM, Anonymizer can remove, mask, or change selected fields before they reach Google.
  • Account access. Login activity history records recent account logins. Two-factor authentication and passkeys help protect sign-in. Single Sign-On (SSO) lets your company manage Stape access through its identity provider, including removing access when an employee leaves.
  • Hosting locations. Multiple server locations let you choose where your server GTM container runs. With Stape Europe, you host your container on EU servers from Scaleway, a European cloud provider. This gives your team a defined processing location to document in its HIPAA risk assessment when internal policies limit where data may be processed. 
  • Testing. Stape Logs show incoming requests and, when enabled, outgoing requests processed by server GTM. 

These capabilities help your team apply an approved data plan. They do not replace legal approval or testing of the full data flow.

HIPAA compliance is highly context-dependent, and requirements can vary depending on the specific client, data flow, and use case.

How to build HIPAA-aligned tracking with Stape

What healthcare case studies show

Healthcare teams still need useful analytics after sensitive data is removed from advertising and analytics payloads. The following Stape case studies show measurement outcomes from controlled server-side implementations. 

OMRON Healthcare EMEA improved data completeness by 25% to 35%

Hellenic Technologies rebuilt OMRON Healthcare EMEA's measurement setup with country-level Google Tag Manager containers, server-side GA4 tagging, enhanced conversions, and a consent framework. The project reported:

  • 25% to 35% higher tracking data completeness and accuracy
  • 20% to 30% higher user event capture
  • 15% to 25% higher conversion tracking reliability
  • 20% to 30% higher marketing attribution precision
  • Consent opt-in rates above 50%

A healthcare client reduced unassigned GA4 sessions from 41.09% to 3.3%

Stape Care rebuilt an existing server-side setup with a structured data layerConsent Mode integration, stable event triggers, Custom Loader, and Cookie Keeper. The project reported:

  • Unassigned GA4 sessions fell from 41.09% to 3.3%
  • Engaged sessions grew by 244.9%
  • Tracked key events grew by 195.7%
  • The number of tracked events increased from 2 to 11

How to implement a HIPAA-aligned tracking setup

Your team can implement a HIPAA-aligned tracking setup by turning the approved data rules into a tested data flow.

  1. Confirm the scope and purpose. Record which legal entity collects the data, why each event is needed, and which law or contract applies.
  2. Map every data flow. List each website, app, and backend source. Include browser tags, forms, booking widgets, chat tools, session replay, customer relationship management (CRM) updates, and request logs. Mark every request that bypasses server GTM.
  3. Classify and approve the data. Mark fields that identify a person or reveal health context. Ask your privacy or legal team to approve what each destination can receive.
  4. Review vendors and BAAs. Confirm that each disclosure is permitted. If a vendor handles PHI as a business associate, sign a BAA before the data enters its service. If it does not offer a BAA, keep PHI out.
  5. Configure the data path. Route approved events through server GTM. Set separate rules for the fields each destination can receive.
  6. Remove or restrict direct browser tags. Do not leave Meta Pixel or another tag active on pages or actions where it can send PHI or prohibited health data directly.
  7. Apply the approved data controls. Send only the necessary data. For GA4 requests, configure Anonymizer to remove, mask, or change the approved fields.
  8. Protect access and transmission. Require strong sign-in controls, restrict access, use encrypted connections, and set log-retention rules.
  9. Handle cookie consent and HIPAA authorization separately. A cookie banner is not a valid HIPAA authorization.
  10. Test and document the setup. Inspect the data inside incoming and outgoing requests. Record vendor decisions, BAA coverage, field rules, and approvals. Repeat the same checks after every tracking change.

Want to switch to the server side?Sign up now!

Maryna Semidubarska

Maryna Semidubarska

Author

Maryna is a Content Manager with expertise in GTM and GA4. She creates clear, engaging content that helps businesses optimize tracking and improve analytics for better marketing results.

Comments

Try Stape for all things server-side