
HIPAA website compliance: health pages and ad trackers
At a glance
US-12High45 CFR Part 164 (esp. 164.502, 164.508); 16 CFR Part 318; FTC Act §5 (15 U.S.C. 45)
Peeky looks at pages about health, symptoms, treatment or appointments for advertising and analytics tools that receive an identifier from the visitor's browser.
Last checked against the source:
The rule
Two federal regimes sit behind this check, and which one applies depends on who runs the site.
HIPAA binds covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with covered transactions) and their business associates. Under the Privacy Rule, a covered entity or business associate “may not use or disclose protected health information, except as permitted or required by this subpart” (45 CFR 164.502(a)). Protected health information is individually identifiable health information, meaning information that relates to a person’s health, care or payment for care and either identifies them or gives “a reasonable basis to believe the information can be used to identify the individual” (45 CFR 160.103).
For marketing, section 164.508(a)(3) requires an authorization for “any use or disclosure of protected health information for marketing”, with narrow exceptions.
For websites, HHS’s Office for Civil Rights set out its reading in a bulletin on online tracking technologies. It says a regulated entity may not use tracking technologies in a way that results in impermissible disclosures of protected health information to tracking vendors, and that a vendor receiving it on the entity’s behalf is a business associate that needs an agreement. A part of that bulletin did not survive: on 20 June 2024 the Northern District of Texas, in American Hospital Association v. Becerra, vacated the guidance to the extent it said HIPAA is triggered where a tool links an IP address to a visit to an unauthenticated public page about health conditions or providers. Pages where a visitor enters an email address, a symptom or a reason for an appointment were not part of what was vacated, and the bulletin still treats those as capable of involving protected health information.
Outside HIPAA, the FTC fills the gap. The Health Breach Notification Rule applies to “vendors of personal health records, PHR related entities, and third party service providers” and expressly “does not apply to HIPAA-covered entities” (16 CFR 318.1(a)).
Since the amendments published on 30 May 2024 (89 FR 47054), the rule defines a breach of security to include “an unauthorized acquisition of unsecured PHR identifiable health information in a personal health record that occurs as a result of a data breach or an unauthorized disclosure”. “Health care services or supplies” now includes any online service that “provides mechanisms to track diseases, health conditions, diagnoses or diagnostic testing, treatment, medications, vital signs, symptoms, bodily functions, fitness, fertility, sexual health, sleep, mental health, genetic information, diet, or that provides other health-related services or tools.” After a discovery, section 318.3 requires notice to affected individuals, to the FTC and, for larger events, to the media. Section 318.4 sets the deadline at no later than 60 calendar days after discovery, and the FTC’s announcement of the final rule says the same.
Enforcement under the rule runs through the FTC Act: any violation “shall be treated as a violation of a rule promulgated under section 18 of the Federal Trade Commission Act”, which carries civil penalties adjusted for inflation (16 CFR 318.7). HIPAA civil money penalties are set in tiers by culpability (45 CFR 160.404).
The FTC does not need the Health Breach Notification Rule to act. Its BetterHelp announcement, a month after GoodRx, rests on allegations that the company broke its own privacy promises, and the press release does not mention the rule. The FTC’s second Health Breach Notification Rule case, Premom, followed in May 2023 under a proposed order. The California Attorney General reached a health publisher through the CCPA, as the Healthline matter shows.
What PeekWell checks and how
US-12 asks one question about pages that are about health: does an advertising or analytics tool receive an identifier from them? It applies where a site has been marked as health-adjacent, and it is skipped for other sites.
The scan loads public pages in a clean browser and records every network request and cookie, as in the other tracker checks. Where the site is health-adjacent, it classifies each page’s context to work out which pages are about health. Tracker detection is deterministic: request domains and cookie names are matched against a maintained list of advertising and analytics tools. A finding appears when a tool on that list is seen on a health-context page, sending something that identifies the browser or the person. A language model helps with the page classification and the wording of the report. It does not decide that a tool fired.
The tracker detection is the same as in EU-01 and US-02. What differs is the page it cares about: a tracker on a contact page and one on a page about a diagnosis are different observations.
The scan has limits, and the report says so. It sees only public pages and nothing behind a sign-in, so it cannot see the patient portals where the HHS bulletin sees the most risk. It does not submit forms, test passwords or open addresses nobody linked to. It does not decide whether you are a covered entity, a business associate or a vendor of personal health records, and it does not read contracts, so it cannot know whether a business associate agreement or an authorization exists. Collection on a server or inside an app is outside what a browser visit can see, and page classification can be wrong. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
These cases share a pattern: a health service promised privacy, and an ad pixel or software kit sent identifiers and health details to an ad platform. The FTC alleged that GoodRx shared prescription and condition information with Facebook, Google, Criteo, Branch and Twilio, and used it to target ads. BetterHelp was alleged to have shared email addresses, IP addresses and questionnaire answers with four ad platforms. Monument was alleged to have told users their information was “100% confidential” while pixels sent details to Meta and Google.
The outcomes were similar. The proposed orders would ban sharing health data for advertising, require consent for other sharing, and direct the companies to seek deletion of data already shared. GoodRx agreed to a $1.5 million civil penalty, and under BetterHelp’s proposed order $7.8 million was to fund partial consumer refunds. Monument’s proposed order carried a $2.5 million penalty that was suspended because of its stated inability to pay, with the full sum due if its financial statements proved untrue, and it needed court approval.
A publisher was not outside this. The California Attorney General’s Healthline settlement concerned article titles such as “You’ve Been Newly Diagnosed with MS. What’s Next?”, which could reveal a diagnosis to advertisers, and an opt-out that was alleged not to work.
For a company the practical points are these. A health promise in a privacy notice becomes a fact an authority can compare with network traffic. Sharing may be a notifiable event under the FTC rule. And a pixel’s data has already left once the page loads. Removing a pixel later stops new sharing but does not recall what was sent.
Smaller companies and larger companies
Neither rule has a minimum company size, and the FTC rule applies “irrespective of any jurisdictional tests” (16 CFR 318.1(a)). Monument is the smaller company in the cases listed here.
In a small company, the problem usually begins with a growth tool. A telehealth startup, a clinic with a template site or a wellness app adds the Meta Pixel and Google tags to measure ads, and the same snippet runs on the page where visitors choose a condition or pick a treatment.
In a larger company the pieces are spread out. A hospital group or a health publisher has a tag manager with dozens of tags owned by different teams, several domains, and a mix of authenticated and public pages. A tag approved for the marketing site can end up on a page that asks for symptoms after a template change.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
GoodRx Holdings, Inc.
The FTC alleged that GoodRx shared users' health information, including prescription medications and health conditions, with Facebook, Google, Criteo, Branch and Twilio, despite promising not to, and used it to target health-related ads on Facebook and Instagram. The FTC said this was the first time it had brought a case under the Health Breach Notification Rule. The proposed order bans sharing health data with third parties for advertising.
Read the FTC (United States) publication about GoodRx Holdings, Inc.BetterHelp, Inc.
The FTC alleged that BetterHelp promised to keep consumers' health information private, then shared email addresses, IP addresses and answers to its health questionnaire with Facebook, Snapchat, Criteo and Pinterest for advertising. The proposed order bans sharing health data for advertising and requires consent before other disclosures. The FTC's announcement does not mention the Health Breach Notification Rule.
Read the FTC (United States) publication about BetterHelp, Inc.Healthline Media LLC
The California Attorney General said its investigation found that Healthline kept sharing data with some advertising third parties even when consumers opted out, and shared article titles suggesting a diagnosis to target ads. The complaint alleges the consent banner did not disable tracking cookies when a box was unchecked.
Read the California Attorney General (United States) publication about Healthline Media LLC
Smaller companies
Monument, Inc.
The FTC alleged that Monument, a New York-based alcohol addiction treatment service that told users their information was 100% confidential, disclosed health details to Meta, Google and other ad platforms through tracking pixels. According to the complaint, as many as 84,000 users were affected.
Read the FTC (United States) publication about Monument, Inc.
How to fix it
The aim is to make sure only the tools you have chosen see health pages, and that you can say why.
- Decide which rulebook applies. Ask your legal adviser whether you are a covered entity or business associate under HIPAA, a vendor of personal health records under the FTC rule, or neither. Steps 2 to 4 help in all three cases.
- List what loads on each health page. Open a private window with the browser’s network tab open and visit your condition, treatment, symptom checker and booking pages. Note every third party that receives a request, and what is in it: cookie IDs, advertising IDs, email addresses, form values and page titles or URLs that name a condition.
- Remove or restrict advertising tags on those pages. In your tag manager, set advertising and retargeting tags to exclude health-context pages, or remove them. Where a tool is needed, check whether the vendor offers settings for sensitive data and read what it says about health categories.
- Strip what names a condition. Keep diagnosis words out of URLs, page titles and event names that go to analytics.
- Match the contracts and the notice. If you are a regulated entity and a vendor handles protected health information for you, confirm there is a business associate agreement. Check that the privacy notice describes what actually leaves the site, since the FTC cases rest on promises that did not match.
- Re-scan. Clear cookies and storage, reload and run a scan again. The finding should disappear once no advertising or analytics tool receives an identifier from a health-context page.
Whether a particular setup satisfies HIPAA or the FTC rule is a question for your legal adviser, and Peeky reports only what it sees.
Questions
Does HIPAA apply to my health website?
Only if your organisation is a covered entity (a health plan, a clearinghouse, or a provider that sends health information electronically in connection with standard transactions) or a business associate of one. A wellness app, a coaching service or a content site is usually outside HIPAA, though other rules may reach it.
The definitions are in 45 CFR 160.103. The rule explains where the line falls.
Is the Meta Pixel allowed on a HIPAA-regulated site?
Not where it sends protected health information to the vendor without a permitted basis. HHS's bulletin says a regulated entity may not use tracking tools in a way that results in impermissible disclosures, and that sending PHI to a vendor for marketing needs a HIPAA authorization.
A vendor that handles PHI on the entity's behalf would also need a business associate agreement. A court has vacated one part of the bulletin, covered in the rule.
What is the FTC Health Breach Notification Rule?
It is a rule in 16 CFR Part 318 that applies to health apps and similar services that sit outside HIPAA. It requires them to notify people, and the FTC, after an unauthorized acquisition of identifiable health information. Since the 2024 amendments, a sharing of that information without the person's authorization counts as one.
Did the FTC use the Health Breach Notification Rule against BetterHelp?
The FTC's announcement does not mention it. It describes a $7.8 million payment for consumer refunds under a proposed order that would ban the sharing of health data for advertising, based on allegations that BetterHelp broke its privacy promises. GoodRx, announced a month earlier, was the first action the FTC brought under the Health Breach Notification Rule.
How does Peeky check for health pages that send data to ad tools?
Peeky opens your public pages in a clean browser, works out which ones are about health, and notes any ad or analytics tool that gets an identifier from them. It never signs in, fills in a form or books anything. It cannot tell whether HIPAA applies to you. How a scan works has the full path.
Filed with
The rule
HIPAA Privacy Rule, 45 CFR 164.502 (general rules) and 164.508 (authorizations for marketing and sale)
Read the rule (HIPAA Privacy Rule, 45 CFR 164.502 (general rules) and 164.508 (authorizations for marketing and sale))Sources
- 45 CFR 164.502, Uses and disclosures of protected health information: general rules (eCFR, current)
- 45 CFR 164.508, Uses and disclosures for which an authorization is required (eCFR, current)
- 45 CFR 160.103, Definitions (covered entity, protected health information; eCFR, current)
- 45 CFR 160.404, Amount of a civil money penalty (eCFR, current)
- 16 CFR Part 318, Health Breach Notification Rule (eCFR, current)
- HHS OCR, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates (content last reviewed 26 June 2024)
- FTC, FTC Finalizes Changes to the Health Breach Notification Rule (26 April 2024)
- FTC, Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule (August 2024)
- FTC, FTC Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising (1 February 2023)
- FTC, FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others for Targeted Advertising (2 March 2023)
- FTC, Ovulation Tracking App Premom Will be Barred from Sharing Health Data for Advertising Under Proposed FTC Order (17 May 2023)
- FTC, Alcohol Addiction Treatment Firm will be Banned from Disclosing Health Data for Advertising to Settle FTC Charges (11 April 2024)
- California Attorney General, Attorney General Bonta Announces Largest CCPA Settlement to Date, Secures $1.55 Million from Healthline.com (1 July 2025)
Last checked against the source:
For information only. Not legal advice.


