Your marketing team just installed your biggest HIPAA liability

by

CallRail
July 31, 2026

Your marketing team dropped a Meta pixel on the new patient intake page eight months ago to track ad conversions. Nobody's checked it since. That's the healthcare tracking pixel compliance problem hiding on most practice websites right now. Not a hacker. Not ransomware. Just a pixel most teams haven't thought to shield.

Healthcare data security made headlines in 2024 when the Change Healthcare breach compromised more than 100 million people's records. That was an attack from outside. The bigger risk right now is one your own marketing team installed — and the Department of Health and Human Services (HHS) is preparing a HIPAA Security Rule update that raises the bar on this kind of exposure.

Here's what's changing, what your setup may already be exposing, and what to fix before an audit catches it first.

What the incoming HIPAA Security Rule means for your tracking setup

The Office for Civil Rights (OCR) has proposed changes to the Security Rule that would tighten cybersecurity requirements for anyone handling protected health information, or PHI. While the rule isn't final, the direction is clear — fewer optional safeguards, more mandatory ones, and closer scrutiny of every vendor and tool that touches patient data.

This is a different fight than the one healthcare marketers already had. OCR issued guidance in 2022 restricting how tracking technology could be used on patient-facing pages, and a federal court struck down part of that guidance in 2024.

This update is part of the Security Rule, not guidance, so it carries the force of the law. Expect technical safeguards that used to be optional to become requirements, which is not the kind of thing you can skip if the budget's tight.

How a tracking pixel becomes a HIPAA problem

Meta and Google pixels aren't built for healthcare — they're built to share as much data as possible, which is how they target ads more precisely. Dropped directly on an appointment page, a symptom checker, or a service line page, that pixel can send a visitor's IP address, device details, and the exact page they viewed straight to a third party.

That combination can count as PHI. A visit to your oncology page isn't just page data, it's a signal about someone's health. If that signal leaves your site unshielded and lands with a vendor that never signed a business associate agreement (BAA), you've created exactly the kind of third-party data sharing OCR has been writing rules around for years.

Regulators have already scrutinized health systems over this exact kind of pixel-based data sharing. The setup that felt fine two years ago might not hold up to a fresh look, especially once the new Security Rule takes effect.

A quick self-audit checklist

Start here, before the rule finalizes and before an auditor asks first.

unchecked Find every page with a native Meta or Google pixel that also collects appointment requests, symptom entries, or service line data.

unchecked Confirm which vendors receive pixel data and whether each one has a signed BAA.

unchecked Turn off pixels on any page where a visitor's condition, service line, or appointment type could be inferred from the URL or page content.

unchecked Route call and form data through a tool built for healthcare, one that strips personal and protected health information before it reaches your ad platforms.

unchecked Check your consent and disclosure language. Consent requirements for call recording and tracking vary by state.

6 common questions from healthcare marketers

Here are six questions that come up most often once healthcare marketers start auditing their own tracking setup.

1. Can I still use tracking pixels on my website?

Only on purely public pages, like your homepage. Almost every other page carries risk. Some are obvious, like a condition-specific page or a symptom checker, and some are easy to miss, like a contact page, since visitors there are often prospective patients. Route those through a tool built for healthcare that gives you enough data for your campaigns without exposing PHI.

2. Do I need to turn off AI features to stay compliant?

No — not the ones built to protect you. Features that strip personal and protected health information from call transcripts and recordings before anyone sees them are a safeguard, not a risk. Turning them off removes protection instead of adding it. Your tracking pixel is a far more likely source of exposure than a properly configured call tracking feature.

3. Are third-party integrations safe to use?

Only if they're built for healthcare data and backed by a signed BAA. Confirm any integration connecting to a page that touches patient data has one in place before you turn it on.

4. What counts as protected health information on my website?

Page visits, appointment requests, and specific service line details can all count, especially once they're combined with an IP address or device ID that identifies a visitor. That combination is what turns a routine page visit into a health disclosure.

5. Do I need to wait for the final rule before making changes?

No. Shielding pixels, confirming BAAs, and auditing what data leaves your site are worth doing now. They'll hold up regardless of how the final rule reads.

6. What if my agency manages our tracking setup?

Your practice is still the covered entity — the agency isn't off the hook for your compliance. Any agency with access to tools or pages that touch patient data needs a signed BAA before they start. Standard agency contracts don't include that automatically, so confirm it's in place before your next campaign goes live.

How to keep your patient data protected

The exposure doesn't stop at your website. Your practice records every call — capturing symptoms, names, and appointment details — and without a signed BAA, that information faces the same audit risk as an unshielded pixel. CallRail's Healthcare Plan includes that agreement, and Call Tracking automatically strips PHI from transcripts and recordings before anyone reviews them.

If your ad platforms are part of the problem, the CallRail Freshpaint integration is part of the fix. It routes your CallRail data through Freshpaint first, cleansing PHI before it reaches Meta, Google, or any other ad platform.

The same protection extends to your records systems. Keragon connects CallRail's calls, texts, and forms to a patient records system (EHR), customer database (CRM), or scheduling system, no code required. Both integrations support HIPAA compliance, so your marketing data keeps flowing without compromising patient privacy.

Fix your tracking pixel before an audit exposes it

Breaches make headlines, but an unshielded tracking pixel is what's more likely to trigger an audit at your practice.

Work through the checklist, confirm your vendor agreements, and make sure the tools handling your patient data are built for healthcare.

Meet the author

CallRail
Serving more than 225,000 companies worldwide, CallRail is the lead engagement platform that makes it easy for businesses of all sizes to market with confidence.