1. Home
  2. Insights
  3. HIPAA compliant Google Analytics
Technical SEO

HIPAA Compliant Google Analytics: What Actually Works

There is no switch that makes HIPAA compliant Google Analytics. Google will not sign a business associate agreement for Analytics and tells regulated entities not to send it protected health information. What you can build is a measurement setup where Google never receives PHI, and still see which pages bring patients. This is how I design it.

What Google itself says

Google’s own help page on HIPAA and Google Analytics is unusually direct:

  • Google does not offer business associate agreements for Analytics.
  • HIPAA-regulated customers must not expose any data that may be PHI to Google.
  • Authenticated pages are likely to be HIPAA-covered, and Analytics tags should not be set on them.
  • Google makes no representation that Analytics satisfies HIPAA.

So the question is never “is GA4 compliant?”. It is “can I configure my site so GA4 only ever receives data that is not PHI?” For many practices the answer is yes, with work.

The HHS bulletin and the 2024 court ruling

HHS’s Office for Civil Rights published its bulletin on use of online tracking technologies in 2022 and revised it in 2024. On 20 June 2024, in American Hospital Association v. Becerra, a federal court vacated the part of the guidance that treated simply connecting an IP address with a visit to a public page about a health condition as enough to trigger HIPAA. HHS now notes it is evaluating its next steps.

What the ruling did not change:

  • Authenticated pages (patient portals, telehealth platforms) generally involve PHI. Vendors there need a BAA.
  • Public pages where the visitor gives health information are still in scope: appointment requests, symptom checkers, intake and registration forms.
  • A privacy policy notice is not a HIPAA authorisation.

In other words, the ruling reduced risk on your blog and condition pages. It did not make your booking funnel safe to track with standard tags.

If you are not a HIPAA covered entity

Many health businesses sit outside HIPAA: direct-to-consumer testing brands, wellness apps, some telehealth models. They face different, sometimes stricter, rules.

  • The FTC’s updated Health Breach Notification Rule treats an unauthorised disclosure of health data, including sharing it with advertising platforms, as a breach. The FTC cites its actions against GoodRx and the Premom app as examples.
  • Washington’s My Health My Data Act covers consumer health data broadly, including health information inferred from non-health data, requires a separate consumer health data privacy policy linked from the homepage, and is enforceable through private lawsuits as well as by the Attorney General.

For SEO measurement the practical design is the same as for a covered entity, so I build one architecture and apply it to both.

Where PHI leaks into analytics

In audits, these are the leaks I find most often:

LeakExampleFix
Page URLs and titles/book/?service=hiv-test or a thank-you page titled with the conditionGeneric confirmation URLs and titles; strip query strings before sending
Form fieldsEnhanced measurement or a pixel capturing field valuesDisable form interaction capture; never send field values
Site searchSearch terms such as a condition nameTurn off site search tracking or bucket terms server-side
Ad pixelsSocial and ad pixels on condition and booking pagesRemove from those templates or route through a consented, redacting server
Session replay and chatRecording tools on booking flowsExclude booking and portal paths entirely
IdentifiersUser IDs, emails or phone numbers in eventsNever send; use a random session key only

The architecture I use

  1. Map every template to a risk level. Public information pages (low), condition and service pages (medium: no ad pixels), booking, intake and portal (high: no third-party tags without a BAA).
  2. Put a server in the middle. Tags send to a first-party server container you control. There, URLs are generalised, query strings removed, IP addresses dropped, and only an allow-list of events goes out. The server is not magic; it just gives you one place to enforce the rules before data reaches a vendor.
  3. Measure conversions without the condition. A booking is recorded as “booking_completed” with the location, not the treatment. Calls are counted through a call tracking provider that will sign a BAA, or through Google Business Profile call reporting, which sits outside your site.
  4. Use a BAA-backed tool where you need detail. If the practice needs funnel analysis inside authenticated areas, that belongs in an analytics product whose vendor signs a BAA, not in GA4.
  5. Consent and documentation. A consent layer for non-essential tracking, and a written record of what each tag sends. That record is what a compliance officer or lawyer will ask for first.

How you still measure SEO properly

None of this stops you from knowing whether SEO is working. What I report on for healthcare clients:

  • Search Console for queries, clicks and pages: it contains no patient data.
  • Landing page to booking rate by page group (conditions, services, locations), not by individual condition where that would reveal health information.
  • Calls and direction requests from each Google Business Profile.
  • Booked appointments by source, reconciled monthly against the practice’s own system in aggregate.

This is exactly what my healthcare conversion tracking work sets up: numbers the owner can trust and a compliance officer can sign off.

Grey areas I avoid

Two workarounds get pitched to practices. The first is hashing emails or phone numbers and sending them to ad platforms “because hashed data is anonymous”. Hashed identifiers are designed to be matched, so I treat them as identifiers. The second is keeping full tracking and relying on the 2024 ruling. The ruling was narrow and HHS has signalled it is reviewing its position. I don’t use either approach.

If you are planning a redesign, fix this at the same time. My healthcare website migration checklist includes rebuilding tracking, because migrations are when leaks usually appear.

Where to start

Run a tag inventory: every script on every template, what it sends and where. Most practices find at least one pixel on a page it should not be on. That inventory is part of my healthcare SEO audit, and the rules by country are summarised in the compliance hub.

If you would like me to review your setup, book a strategy call.

Questions I get asked

Is GA4 HIPAA compliant?

No analytics product is compliant on its own. Google offers no BAA for Analytics, so GA4 can only be used where it never receives PHI.

Did the 2024 court ruling make tracking on hospital websites legal?

It vacated one part of the HHS guidance about public pages. Authenticated pages and pages where visitors submit health information are still covered.

Can I use Meta or other ad pixels on my practice website?

Not on booking, intake, portal or condition pages without a BAA and proper safeguards. I keep them off those templates entirely.

Is this legal advice?

No. It is how I design analytics for healthcare sites. Your compliance officer or counsel should approve the final setup.

Let’s talk

Want a second pair of eyes on your site?

A free 30-minute strategy call. I review your search footprint, local visibility and AI search presence before we speak, and tell you plainly what is achievable.

  • You speak with me directly, always
  • Your data stays private, never put into AI tools
  • If SEO isn’t your bottleneck, I’ll say so
Book a Free Strategy Call →
Free visibility checkI review your site before we speak