Website Tracking Privacy Risks: Do You Know What Your Websites Are Sharing?
Website tracking privacy risks can remain hidden across a health provider’s digital estate until a patient, regulator, or plaintiff discovers them.
A pixel installed for one advertising campaign, a script introduced through a plugin, or an analytics tool added by an outside agency can continue operating long after anyone remembers approving it, creating a website tracking privacy risk.
Privacy and compliance teams may not know every tool that is operating, what information it collects, or where that information is sent. For a health system managing multiple hospitals, locations, subdomains, service-line websites, and campaign pages, one forgotten or incorrectly configured script can affect hundreds or thousands of webpages.
Request a complimentary web scan* to understand what’s running on your website, and whether it matches what you promised.
Health system websites are constantly being updated
A large healthcare organization may operate a main corporate website alongside hospital websites, provider directories, service-line pages, campaign landing pages, patient portal login pages, recruitment sites, blogs, mobile applications, and websites inherited through acquisitions. Different marketing teams, agencies, developers, and technology vendors may all be able to introduce new code.
The result is a constantly changing web environment in which compliance, privacy, and information security teams may not have a complete picture of every third-party technology operating across the organization.
Website tracking is widespread in healthcare
Research suggests that third-party data transfers are present on the overwhelming majority of hospital websites.
A 2024 study of a nationally representative sample of 100 nonfederal acute care hospitals found that 96% of their websites transferred user information to at least one third party. The websites communicated with a median of nine third-party domains, and 86% had at least one third-party cookie.
Only 71 of the 100 hospital websites had a publicly accessible website privacy policy. Among those 71 policies, just 40 specifically identified third-party companies or services receiving user information.
The findings highlight an important distinction. Having a privacy policy does not necessarily mean that the organization knows everything its website is doing or that the policy accurately describes current activity.
A privacy policy may have been correct when it was written but subsequently become outdated as new technologies, vendors, campaigns, and websites were introduced.
Why larger healthcare organizations face greater challenges
Health systems and multi-location healthcare groups can have hundreds of people involved in their digital operations. Marketing may select an analytics platform, an agency may deploy advertising pixels, a service line may introduce a new scheduling application, and a recently acquired practice may continue using its existing website technology.
Each decision may appear reasonable in isolation. Collectively, however, they can create a complex and poorly documented network of data connections.
Common problems include:
- No central inventory of websites, subdomains, microsites, and landing pages
- Different privacy and consent practices across affiliated organizations
- Inconsistent use of tag management systems
- Technologies added without privacy, security, or legal review
- Inherited tracking code following mergers and acquisitions
- Expired campaigns with active tags
- Privacy policies that do not reflect actual website behavior
- Vendors introducing additional subprocesses or technologies
- Unclear responsibility for approving and monitoring website tools
A review of the main health system homepage will not necessarily reveal what is happening on a specialty clinic website, an appointment page, a recruitment portal, or a location-specific landing page.
When does website tracking become a HIPAA issue?
The HIPAA Rules apply when information collected through tracking technologies or disclosed to tracking technology vendors includes PHI.
Pages that deserve particularly careful examination include:
- Authenticated patient portals
- Patient portal login and registration pages
- Online appointment scheduling pages
- Symptom checkers
- Provider search tools
- Pages that collect an email address or other identifying information
- Forms through which an individual describes a condition or reason for seeking care
- Pages containing treatment, prescription, billing, or medical record information
The Department of Health and Human Services’ Office for Civil Rights states that a privacy policy, website notice, or terms of use document does not, by itself, make a disclosure of PHI permissible. OCR also states that an ordinary cookie consent banner is not a HIPAA-compliant authorization.
If a tracking vendor creates, receives, maintains, or transmits PHI on behalf of a regulated entity for a covered function, the vendor may be a business associate. The organization must determine whether the disclosure is permitted and whether an appropriate Business Associate Agreement is required.
Simply asking a vendor to remove or de-identify information after receiving it does not necessarily resolve the problem. If PHI has already been disclosed to the vendor, the disclosure itself must have a lawful basis.
The solution for website tracking privacy risks
Automated website privacy monitoring tools can help close the visibility gap. Tools can scan public-facing pages for third-party scripts and cookies, identify external technologies operating across websites and subdomains, and flag activity that may require further investigation.
They can also compare observed website behavior with statements in the organization’s privacy policy and monitor for changes over time.
These tools do not replace legal analysis or determine whether a disclosure violates HIPAA, but they can help privacy, compliance, marketing, and technology teams find potential risks sooner, prioritize their response, and demonstrate ongoing oversight.
Get a free web scan by filling in the form on this page and receive a report the details any hidden compliance risks on your website with a high, medium or low score for each.
Get a complimentary scan that identifies third-party scripts by risk level: high, medium, or low.
Not every visit to a healthcare webpage involves PHI
The legal position is more nuanced than some early reporting on tracking technologies suggested.
In June 2024, a federal court vacated part of OCR’s tracking technology guidance in *American Hospital Association v. Becerra*. The court rejected the position that an IP address combined with a visit to a public, unauthenticated webpage about a particular condition or healthcare provider was sufficient, by itself, to trigger HIPAA obligations.
OCR’s current guidance acknowledges that a visit to a public healthcare webpage does not automatically constitute a disclosure of individually identifiable health information simply because a tracking technology connects the visit with an IP address.
For example, someone may visit an oncology page because they are conducting academic research, helping a relative, reading the news, or looking for employment. The webpage visit alone does not establish that the visitor has cancer or is seeking cancer treatment.
However, the court decision did not create a general exemption for healthcare websites. HIPAA may still apply when identifiable information is connected with an individual’s health, care, or payment for care. Information entered into an appointment form, registration page, symptom checker, or authenticated portal presents a substantially different risk from an anonymous visit to a general information page.
Regulatory and litigation risks extend beyond HIPAA
In July 2023, OCR and the Federal Trade Commission sent joint warning letters to approximately 130 hospital systems and telehealth providers. The letters drew attention to technologies such as Meta Pixel and Google Analytics and warned that they could disclose sensitive health information to third parties.
The FTC can take action when an organization makes misleading privacy promises or uses and discloses consumer health information in ways that are unfair or deceptive. State consumer protection, privacy, and wiretapping laws may also apply.
This means an organization should not conclude that a tracking activity is low risk merely because the information does not meet the HIPAA definition of PHI.
The enforcement record illustrates the wider exposure:
– The New York Attorney General reached a $300,000 settlement with NewYork-Presbyterian Hospital after alleging that advertising tools collected and disclosed information when website visitors searched for doctors or booked appointments. The settlement required policy changes, deletion requests, and enhanced privacy safeguards.
– The FTC alleged that GoodRx disclosed health information to Facebook, Google, and other companies contrary to its privacy promises. GoodRx agreed to a $1.5 million civil penalty and restrictions on sharing health information for advertising.
– BetterHelp agreed to pay $7.8 million to resolve FTC allegations involving the disclosure of email addresses, IP addresses, and health questionnaire information for advertising purposes.
Private litigation has created additional risk. Plaintiffs have pursued claims under federal and state wiretapping, privacy, consumer protection, and contract laws. Not every claim has succeeded, and the outcomes frequently depend on the information involved, the wording of the relevant statute, the consent process, and how the technology operated.
The absence of a successful HIPAA enforcement action does not therefore mean that an organization has no exposure.
A cookie banner is not a complete solution
Consent management is important, particularly under state privacy laws, but a banner cannot compensate for a lack of technical visibility.
An organization needs to establish:
– Which technologies operate before a visitor makes a choice
– Whether rejected technologies are actually prevented from loading
– Whether the consent mechanism covers every relevant website and subdomain
– Whether a visitor’s preferences are passed to connected systems
– Whether the policy accurately identifies the information collected and its recipients
– Whether HIPAA authorization or another legal permission is required
A banner may tell visitors that cookies are used, but it does not answer whether a particular script is receiving an appointment event, a patient identifier, or information entered into a form.
A one-time website audit provides only a snapshot
Large healthcare websites change continually. New pages are published, campaigns launch, vendors update code, plugins change, and acquired organizations introduce additional domains.
A review conducted today may not reflect the organization’s website next month.
Effective oversight therefore requires both an initial inventory and continuing monitoring. The organization should be able to identify:
– New scripts and external domains
– Changes to cookies and tracking behavior
– New pages handling potentially sensitive information
– Differences between locations, brands, or subdomains
– Technologies that reappear after they were removed
– Changes that create conflicts with the privacy policy
– Unapproved additions made through a tag manager or plugin
Historical records can also help an organization determine when a technology first appeared, which pages were affected, and whether remedial or breach assessment work may be necessary.
Establishing effective website privacy governance
A health system should treat its public website environment as part of its wider privacy and security program.
A practical governance process should include:
1. **Identify the complete web estate.** Document websites, subdomains, microsites, mobile applications, landing pages, portals, and inherited digital properties.
2. **Inventory third-party technologies.** Identify scripts, cookies, pixels, plugins, embedded content, and the external domains with which each property communicates.
3. **Prioritize higher-risk pages.** Focus on scheduling, registration, provider search, symptom, portal, payment, and form pages.
4. **Document purpose and ownership.** Every technology should have a defined business purpose and an internal owner.
5. **Assess the information involved.** Determine what data is collected, when it is transmitted, and whether it may include PHI or other sensitive information.
6. **Review vendors and agreements.** Establish whether the recipient is a business associate, whether a BAA is required, and whether the proposed use is permitted.
7. **Compare behavior with published promises.** Website activity, consent choices, privacy policies, and notices should be consistent.
8. **Control future changes.** New tracking technologies should require appropriate marketing, privacy, security, and legal approval before deployment.
9. **Monitor continuously.** Repeat scans and investigate material changes instead of relying solely on periodic manual audits.
10. **Document decisions and remediation.** Maintain evidence of findings, approvals, risk assessments, corrective actions, and ongoing oversight.
## Visibility is the foundation of control
Healthcare organizations do not have to abandon digital analytics, advertising, or website personalization. These technologies can help patients find services and allow organizations to understand whether their communications are effective.
The essential requirement is visibility.
A health system cannot assess a technology it does not know is present, enforce a policy it cannot test, or control a disclosure it cannot see. Understanding what operates across the organization’s websites, where information is sent, and whether those activities match the organization’s obligations is the first step toward using digital marketing technology responsibly.
Patient Journey Risk
Healthcare websites have become an important part of the patient journey. Visitors use them to research symptoms, compare services, find doctors, schedule appointments, complete forms, access patient portals, watch educational videos, use chat tools, and locate nearby facilities.
These functions often depend on third-party technologies, including:
- Analytics platforms
- Advertising and conversion pixels
- Tag management systems
- Appointment scheduling applications
- Embedded forms
- Chat and chatbot services
- Session replay technologies
- Heatmaps
- Maps and location services
- Embedded videos
- A/B testing and personalization tools
- Social media integrations
Many of these tools provide genuine operational or marketing value. The risk arises when an organization does not fully understand what information a technology collects, when it activates, where the information is sent, or what the receiving company is permitted to do with it.
A technology added to measure conversions on one campaign page may later be deployed across an entire website. A script introduced by a plugin may communicate with additional companies that were not part of the original approval. A tool removed from the visible marketing stack may continue operating through a tag manager or legacy page template.
On a large and frequently updated web estate, these changes can be difficult to identify through manual reviews alone.
What information can website technologies collect?
The information disclosed to a third party will depend on the technology, its configuration, and the page on which it operates. It can potentially include:
– The URL and title of the page visited
– The visitor’s IP address and approximate location
– Device and browser information
– Cookie identifiers
– Advertising identifiers
– Buttons, links, or menu options selected
– Search terms
– Form field activity
– Appointment-related events
– Information used to identify or recognize returning visitors
The presence of a third-party script does not automatically mean that Protected Health Information has been disclosed or that a law has been violated. The organization must examine the information involved, the context in which it was collected, the purpose of the disclosure, the recipient, and the applicable legal authority.
However, it is impossible to perform that assessment if the organization does not know the technology is present.
*Web Scan report provided using Ours Privacy technology
Find Hidden Compliance Risks on Your Websites
Get a FREE Web Scan Report
Your complimentary report will identify third-party scripts by risk level: high, medium, or low.
Your Privacy Respected
HIPAA Journal Privacy Policy
HIPAA Journal featured on

