Problem · Healthcare
We think our website forms and tracking might be violating HIPAA.
You are probably right. A name plus a condition or a treatment request is protected health information, and once a covered entity collects it, every system that touches it needs a business associate agreement: the form tool, the email that delivers it, the CRM, and the call recording vendor. Most consumer form builders and every ad pixel will not sign one. The settlements over exactly this ran $6.6 million to $18.4 million.
How people search thisis my website contact form hipaa compliant · meta pixel hipaa violation medical practice · hipaa compliant web forms for doctors · google analytics hipaa medical website · call tracking hipaa consent
The HIPAA form and call stack add on at $750 a month on any tier: BAA covered forms, call tracking with spoken consent, consent language, server side conversion tracking, and no third party pixels on any page where a patient can book. Pricing is published.
What counts as PHI on your site
A name plus a condition. A phone number plus the treatment page it was submitted from. An email address on a request for a knee replacement consult. Each is PHI the moment it is submitted. A Calendly or Typeform embedded on a treatment page with no BAA, a Meta pixel firing on the thank you page after a consult request, call recording with no spoken consent, and a CRM full of conditions because it was just marketing: each is fixable in a week, and each is a settlement waiting for a plaintiff's firm.
What the 2024 ruling changed and what it did not
On June 20, 2024, in American Hospital Association v. Becerra, a federal court vacated the part of HHS guidance that treated a pixel connecting an IP address to a public condition page as PHI, and HHS dropped its appeal in August 2024. The rest stands: tracking on authenticated pages, portals, and scheduling flows is still PHI, and sharing it with a vendor that has no BAA is still a violation. The ruling made pixels arguable on a blog post. It did not make them safe on a booking page.
The covered stack
Forms that post to a BAA covered backend, not to a form builder's servers. Notification email through a provider under BAA, with the contents in the secured system and only a link in the email. Call tracking and recording from a vendor that signs a BAA, with consent spoken before recording. Consent text on every form. No third party pixels on any page where a patient can book, request, or log in. Conversion tracking server side, so the ad platform learns a conversion happened and nothing about who. You still get cost per booked consultation by campaign.
Questions on this problem
You lose remarketing lists built from patients, which you should not have. Server side conversions still report cost per booked consultation by campaign, which is the number that matters.
Send the URL of your best converting landing page. We can tell you in ten minutes what is firing on it and which vendors would need a BAA.
Only if the email, the CRM, and the call vendor are covered too. PHI is exposed at the weakest link, not the first one.
George Stoff, Founder and Lead Engineer
Thirty years building software, brands, and demand. On every account.