HIPAA Compliant Website: Forms, Trackers and Hosting After the 2024 Ruling
·

A HIPAA compliant website doesn’t exist as a product you can buy or a badge you can display. HIPAA applies to information, and a website falls under it when it collects, stores or passes along identifiable health information on behalf of a covered healthcare organization. So the useful question for a COO or marketing head is where on your site that information appears, and which vendors can see it. For most multi-location operators the answer sits in the forms, the tracking scripts and the hosting.
This is the guide we’d give an executive before a redesign or a vendor review. It draws on the text of the rules and HHS guidance, plus the federal court decision that changed how the tracking rules read. Where we couldn’t open a primary source, we say so.
This isn’t legal advice. Your privacy officer and healthcare counsel decide what applies to your organization.
Does HIPAA apply to your website at all?
It depends on who runs the site and what the site touches. The regulation defines a covered entity as a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with certain transactions (45 CFR 160.103). A business associate is a person who creates, receives, maintains or transmits protected health information on a covered entity’s behalf. Your web agency, your hosting company and your form tool can all land in that second group.
Protected health information is individually identifiable health information: details that relate to a person’s health or payment for care and either identify them or could reasonably be used to identify them. A page describing your cardiology services is marketing. A form where a person types their name, email address and the reason for the visit joins identity and health in one submission.
Where the tracking-technology rule stands
In December 2022 HHS’s Office for Civil Rights published a bulletin on online tracking technologies, revised in 2024. The part that drew attention said a regulated entity’s website could disclose protected health information to a tracking vendor even on a public page. The American Hospital Association and others sued.
On June 20, 2024, in American Hospital Association v. Becerra (N.D. Tex.), the court vacated one piece of that guidance. It called that piece the “Proscribed Combination,” where a technology “connects (1) an individual’s IP address with (2) a visit to a UPW addressing specific health conditions or healthcare providers,” with UPW meaning an unauthenticated public webpage. The judge was careful about scope. A footnote says the bulletin “contains an array of guidance for covered entities, much of which is both legally and pragmatically sound,” and that the court’s analysis “concerns only the Proscribed Combination and the Revised Bulletin’s attempt to apply HIPAA obligations to this ostensibly new IIHI context.” According to a law firm’s summary, OCR withdrew its appeal on August 29, 2024.
The version of the bulletin circulating after the ruling carries a note at the top saying HHS “is evaluating its next steps.” We read a copy of the document because hhs.gov blocks automated requests, and we found no newer OCR tracker guidance. Check the HHS page itself before you rely on this.
What survived matters more for your forms than what was struck. The post-ruling text still says tracking technologies on a regulated entity’s user-authenticated pages “generally have access to PHI.” It also keeps this language for public pages that take input:
Tracking technologies on a regulated entity’s unauthenticated webpage that permits individuals to schedule appointments or use a symptom-checker tool without entering credentials may have access to PHI in certain circumstances.
In that situation the document says the entity is disclosing PHI to the vendor and “the HIPAA Rules apply.” A tracking vendor that receives PHI on the entity’s behalf is a business associate, and the bulletin says a business associate agreement is required. The ruling removed the argument that visiting a condition page is enough.
A Health Affairs study from the University of Pennsylvania, published in April 2023, ran a census of US nonfederal acute care hospital websites, and found third-party tracking on 98.6% of them. A JAMA Network Open study published in April 2024 looked at 100 hospitals between November 2023 and January 2024. It found 96.0% of the hospital websites sent user information to third parties, while only 71.0% had a publicly accessible privacy policy. Both studies looked at hospitals, so the numbers don’t automatically describe a dental group or a behavioral health operator.
What a web form does to your HIPAA scope
A form raises two questions. Where does the submitted data go, and what else is running on the page while someone types?
A contact or appointment form that emails its contents to a staff inbox through an ordinary mail service has sent identifiable health information through that service. If the form saves entries in the WordPress database, the database lives on a server with a hosting company. If it hands the entry to a CRM, the CRM now holds it. Each of those is a business associate relationship when the data is PHI, and each needs a signed agreement. A form plugin that stores entries on a vendor’s servers needs one too.
A form that asks for a reason for the visit, on a page carrying an advertising pixel, can send that text to the ad platform along with the visitor’s identifiers. That is the situation the bulletin’s appointment-page language covers.
One option is to collect only what you need to book a call and keep the clinical detail for a secured portal after login. Another is to host the forms on a vendor that signs a BAA and run no third-party marketing scripts on those pages. A third is to build the intake inside your own application on infrastructure you’ve covered with agreements. Which one fits depends on volume, on your EHR and on how much your intake team wants in advance. Our software development work for regulated organizations usually starts with a data-flow map of every form.
Analytics, pixels and ad platforms
Whether Google Analytics is HIPAA compliant has an answer from Google itself. Its help page says Google “makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with this service.” It adds that “authenticated pages are likely to be HIPAA-covered and customers should not set Google Analytics tags on those pages.” Google’s page also tells customers not to use the tool in a way that involves its access to PHI, and to work with legal counsel to find pages unrelated to the provision of health care services. Whether analytics belongs on any page that touches care is a call for your counsel, and where PHI could flow there is no BAA to cover it.
Meta’s position is similar. Its Business Tools Terms, dated November 3, 2025, say you shall not share business tool data that “includes or is based, directly or in any other way, on health information, financial information, consumer report information or other sensitive information categories.” Since the platform’s own terms bar health data, a covered entity has little reason to expect it to sign as a business associate. Google Ads treats health as a sensitive category as well. Its policy bars advertiser-curated audiences for health-related ads, which includes customer match, your data segments, audience expansion and lookalike segments.
The exposure also reaches past HIPAA. The FTC enforces a separate Health Breach Notification Rule against companies HIPAA doesn’t cover, and its final 2024 amendments clarify that the rule applies to health apps and similar technologies outside HIPAA.
GoodRx agreed in 2023 to a $1.5 million civil penalty after the FTC said it shared users’ prescription medications and health conditions with advertising platforms including Facebook, Google and Criteo. BetterHelp settled an FTC Act case for $7.8 million to consumers over allegations that it shared email addresses, IP addresses and health questionnaire information with Facebook, Snapchat, Criteo and Pinterest. In July 2023 the FTC and OCR sent a joint letter naming “the Meta/Facebook pixel and Google Analytics” and warning that “even if you are not covered by HIPAA, you still have an obligation to protect against impermissible disclosures of personal health information under the FTC Act and the FTC Health Breach Notification Rule.”
We found no OCR enforcement action specifically about web trackers, and we’d treat that as a gap in the record. OCR has put its position in writing, and the FTC has acted on similar facts.
Hosting and other vendors
We found no federal agency that certifies hosting as HIPAA compliant. The rules ask for a written agreement and your own safeguards. Under 45 CFR 164.502(e) a covered entity may let a business associate handle PHI if it gets satisfactory assurance the information will be safeguarded, and the assurance must be documented in a written contract or other written arrangement. Section 164.308(b) says the same for electronic PHI.
HHS’s cloud computing guidance addresses encrypted data. It says a cloud provider that stores ePHI for a covered entity is a business associate “even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data.” The conduit exception, which covers pure transmission services like a postal carrier, is “limited to transmission-only services.” A web host that stores your forms or your patient portal doesn’t qualify. A BAA doesn’t replace the customer’s own risk analysis, which the guidance says is still required.
On the technical side, the Security Rule’s section 164.312 covers access control, audit controls, integrity, authentication and transmission security. Encryption is listed there as addressable, which means you must assess whether it is reasonable and appropriate and implement it if so. If not, you document why and put an equivalent measure in place where one is reasonable and appropriate (45 CFR 164.306(d)(3)). HHS proposed tightening the Security Rule in a notice published January 6, 2025. As of the Fall 2025 regulatory agenda it sat in the long-term category with a final action date of July 2027. We couldn’t confirm the proposed text, so we don’t describe it.
Choose a host that will sign a BAA and tell you in writing which services it covers, since a BAA may cover only some of a vendor’s services. Changing hosts is also a migration, and redirects, indexing and page speed move with it, so plan it like any redesign that affects search.
Marketing content and patient stories
The Privacy Rule says a covered entity “must obtain an authorization for any use or disclosure of protected health information for marketing,” with narrow exceptions for face-to-face communication and promotional gifts of nominal value (45 CFR 164.508(a)(3)). Marketing is defined in 45 CFR 164.501 as a communication about a product or service that encourages people to buy or use it.
HHS doesn’t have a testimonial rule that we could open, so what follows is our reading of the general rule. A patient story with a name, a photo or enough detail to identify the person discloses protected health information, and the safe route is a signed authorization before it goes on the site. The same applies to before-and-after images and video. Keep a log of who approved what and when.
What a mistake costs
The civil penalties for HIPAA violations are set in tiers and adjusted each year for inflation. The adjustment published in the Federal Register on January 28, 2026 puts the range at $145 up to $73,011 per violation for the lowest tier, where the entity didn’t know, and $2,190,294 as the calendar-year cap for identical violations. The top tier, willful neglect that isn’t corrected, starts at $73,011 per violation. Those are the amounts in the regulation. A 2019 HHS notice says the department uses enforcement discretion on the annual caps instead of applying one limit to all four tiers, so the top figure is a ceiling and not what an unknowing violation usually costs. The FTC figures above are separate from these.
A checklist for the next vendor review
- List every form on the site, what each one asks, and where each entry goes (inbox, database, CRM, scheduling tool). Cut free-text clinical fields from public pages, and confirm a signed BAA for each recipient that handles PHI.
- Run a scan for every third-party script on form pages, appointment pages, symptom checkers and portal login pages. Remove advertising pixels from those pages.
- Keep Google Analytics off authenticated pages. Decide in writing, with counsel, what analytics if any runs on pages related to care or on pages that collect input.
- Ask your host and agency for a BAA and for a written list of services it covers.
- Confirm access controls, audit logging and encryption in transit, and document your decision on encryption at rest.
- Get authorizations on file before any patient story, photo or video goes live.
- Review accessibility on the same pages while you’re at it. Our accessibility guide covers that review.
- Write down who owns this review and when it repeats, because plugins and marketing tags change after launch.
If you’d like someone to check a specific form or tag setup before you commit to a rebuild, our website review covers this kind of data-flow check.
Sources
- Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, HHS Office for Civil Rights, original December 2022, post-ruling edition (copy of the HHS document). Supports the authenticated-page, appointment-page and BAA statements.
- American Hospital Association v. Becerra, No. 4:23-cv-01110-P, US District Court, N.D. Texas, 2024.
- OCR withdraws appeal in AHA v. Becerra, McDermott Will & Schulte, 2024. Supports the appeal withdrawal date.
- 45 CFR 160.103, Legal Information Institute, current.
- 45 CFR 164.312, 164.306, 164.501, 164.502, 164.508 and 164.308, Legal Information Institute, current. Support the technical safeguards, business associate assurances and the marketing authorization rule.
- Guidance on HIPAA and Cloud Computing, HHS, 2016 (copy of the HHS document). Supports the cloud provider and conduit statements.
- HIPAA and Google Analytics, Google Analytics Help, current.
- Health in personalized advertising, Google Ads policy, current.
- Meta Business Tools Terms, Meta, effective November 3, 2025.
- GoodRx enforcement action, Federal Trade Commission, February 2023.
- BetterHelp action, Federal Trade Commission, March 2023.
- FTC finalizes changes to the Health Breach Notification Rule, Federal Trade Commission, April 2024.
- FTC and OCR joint letter on third-party trackers, Federal Trade Commission and HHS OCR, July 2023.
- Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, HHS, Federal Register, April 2019. Supports the statement on annual caps.
- Annual Civil Monetary Penalties Inflation Adjustment, HHS, Federal Register, January 2026.
- HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, Federal Register document 2024-30983, January 2025, and the Fall 2025 Unified Agenda entry RIN 0945-AA22, reginfo.gov. Supports the publication date and the agenda listing only.
- Friedman et al., “Widespread Third-Party Tracking On Hospital Websites Poses Privacy Risks For Patients And Legal Liability For Hospitals,” Health Affairs, April 2023, DOI 10.1377/hlthaff.2022.01205.
- User Information Sharing and Hospital Website Privacy Policies, JAMA Network Open, April 2024.