ProductCustomersPlatformJournalGlossaryMigrateFor CliniciansSecurity>_  Agent viewGet Started
Guide

HIPAA and your marketing stack: pixels, analytics, and ads for telehealth brands

The default DTC toolkit — Meta pixel, GA4, session replay, retargeting — was built for e-commerce. Point it at a health funnel without thinking and you are transmitting health information to ad platforms, which is exactly what regulators and class-action firms have spent the last few years punishing.

Golden padlock resting on a computer keyboardPhotograph via Unsplash
TL;DR

The line that matters is where a visitor becomes identifiable as a person seeking care. Marketing pages (blog, pricing, general landing pages) can run standard analytics. Intake, checkout, patient portals, and any URL or event that encodes a condition or product-of-interest cannot feed third-party ad and analytics tools — that combination of identifiers plus health context is what HIPAA (for covered entities and business associates), the FTC's health-data enforcement, and state privacy laws all reach. Split the funnel at the intake door: full marketing stack outside, first-party measurement inside, server-side conversions stripped to non-health events, and BAAs where a vendor touches PHI.

Why the default stack is a problem

A pixel is code that sends what a visitor does — URLs, button clicks, form fields, sometimes everything — to the platform that served the ad. On a sneaker store that is harmless. On a telehealth funnel, the URL alone (/intake/glp1-weight-loss/step-3) plus the platform’s identifiers equals “this identifiable person is seeking weight-loss treatment” — which is protected health information when a covered entity or its vendor transmits it, and “health data” under the FTC’s and several states’ regimes regardless.

This is not theoretical. OCR issued guidance on online tracking by HIPAA-regulated entities; the FTC reached settlements with GoodRx and BetterHelp over sharing health data with advertising platforms; and hundreds of pixel class actions have followed hospital systems and DTC brands alike. Reviewers at LegitScript now look for analytics on pages that collect health information.

The map: what can run where

ZoneExamplesThird-party pixels / analyticsNotes
MarketingHomepage, blog, pricing, condition-agnostic landing pagesYes, configured carefullyAvoid URL parameters or events that pre-declare a condition for an identified user
Condition landing pages/glp1, /trt campaign pagesGray — minimizeVisiting is weaker signal than acting; strip custom events, consider first-party only
Intake and checkoutQuestionnaires, payment, schedulingNoFirst-party measurement only; server-side conversion stripped of health context
Patient surfacesPortal, messaging, resultsNo, everSession replay tools included
MARKETING ZONECLINICAL ZONEAds + pixelsplatform stackBlog · pricingstandard analyticsclickDoorintakeIntakefirst-party onlyCheckoutno 3rd-party tagsPortalneverserver-side conversion: click ID + value, no health context
Split the funnel at the intake door: the ad stack lives outside; inside is first-party only, with a stripped server-side conversion event going back.

Building the compliant funnel

  1. Split at the intake door. Marketing site and clinical funnel on separate surfaces (or at minimum separate tag configurations), so the ad stack physically cannot see past the door.
  2. First-party measurement inside. Your own analytics, your own event stream, under your control and your BAAs where vendors touch it.
  3. Server-side conversions, stripped. Send the platforms a purchase/lead event with click ID and value — no condition, no product name, no dosage. You keep optimization; they don’t get diagnoses.
  4. Audit the tag manager quarterly. Pixels accrete. Someone’s A/B tool from last year is someone else’s lawsuit.
  5. Mind retargeting lists. Building an audience of “people who started the TRT intake” is exactly the disclosure the enforcement actions describe. Retarget from marketing-page behavior only.
  6. Write it down. A data map of what each tool receives, on which pages, under which agreement — the artifact every reviewer, auditor, and acquirer asks for.

Already running pixels? Remediate in this order

Most funnels were assembled before anyone drew the map above, so finding tags in the wrong zone is common — and discovery is routine, because plaintiff firms run the same scanners you do. The order of operations matters:

  1. Inventory before you touch anything. Pull the tag manager and every hardcoded script, page by page — you cannot assess what you have not mapped, and the inventory itself becomes the compliance artifact.
  2. Stop the bleeding. Remove third-party tags from intake, checkout, portal, and scheduling the same week. This is configuration, not engineering, and every day they run extends the lookback.
  3. Assess the lookback with counsel. What was sent, to whom, for how long, and whether it triggers breach-notification duties under HIPAA or the FTC’s rule is a legal call, not a marketing one. Bring the inventory, not a guess.
  4. Rebuild measurement deliberately. Stand up first-party analytics inside the funnel and stripped server-side conversions before the growth team feels the attribution loss and quietly re-adds the pixel.
  5. Add a gate. New tags go through a review that asks two questions — what does it receive, and on which pages — before anything ships. That gate is the difference between a remediation and a cycle.

The upside of doing it right

Constraint breeds advantage here: brands forced off third-party pixels build first-party funnels with cleaner attribution, own their data outright, and sail through diligence. And the failure mode for getting it wrong is not just fines — it is losing the ad account and the certification that paid acquisition depends on, mid-growth.

Lithos keeps the clinical funnel — intake, identity, encounters, records — on infrastructure covered by a BAA, cleanly separated from your marketing surfaces, with an event stream you can measure first-party. This article is general information, not legal advice; review your specific stack with counsel. Related: HIPAA, security at Lithos.

Frequently asked questions

Can a telehealth company use the Meta pixel or GA4?

On general marketing pages, with care. Not on intake, checkout, portal, or scheduling flows, and not configured so URLs, events, or custom parameters reveal that an identified person sought a condition or treatment. Regulators have treated identifier-plus-health-context transmissions to ad platforms as unlawful disclosures.

Does HIPAA apply to our marketing site if we are cash-pay?

HIPAA applies to covered entities and their business associates; a DTC brand’s medical group and platform typically are covered or handle PHI as associates. Even where HIPAA arguably does not reach a page, the FTC Act, the FTC’s Health Breach Notification Rule, and state health-privacy laws (like Washington’s My Health My Data) cover much of the same conduct. Build to the strictest applicable line.

How do we measure ads without a pixel on checkout?

First-party analytics inside the funnel, plus server-side conversion APIs that send only what you choose — a conversion event with click ID, stripped of condition, product, and health context. Model the middle of the funnel from your own data rather than the platform’s.

What is the risk if we get this wrong?

OCR enforcement and its online-tracking guidance for regulated entities; FTC actions like those against GoodRx and BetterHelp (bans and fines for sharing health data with ad platforms); state-law private rights of action; and a steady stream of pixel class actions. Ad accounts and LegitScript certification are also exposed.

Get started

From first call to first patient, in weeks.

A 15-minute intro call, sandbox credentials the same day, go-live in 3–4 weeks — new launches and existing patient bases alike.