The guidance was vacated
In June 2024, a federal court vacated the HHS Office for Civil Rights guidance on online tracking technologies in AHA v. Becerra.
A runtime audit of your public-facing website: every tag and pixel that fires, who receives the data, and how it changes before and after consent.
Built for hospital and health system marketing teams - and written to be reviewed alongside legal and privacy.
There is no clear federal rule on tracking technology and health information right now. There is, however, a live and expensive record of what happens when a hospital website ships tags it cannot fully account for.
In June 2024, a federal court vacated the HHS Office for Civil Rights guidance on online tracking technologies in AHA v. Becerra.
Advocate Aurora Health settled pixel litigation for 12.225 million dollars. Class actions over hospital website tracking continue regardless of the federal guidance question.
OCR and the FTC jointly sent roughly 130 warning letters to hospital systems and telehealth providers about tracking technologies on their websites and portals.
Net effect: no settled federal standard, ongoing litigation risk, and marketing teams who removed measurement tools after the initial guidance - and now cannot say with confidence what their site sends, to whom, and under what conditions.
These are searched constantly, and most confident answers to them are wrong. The correct answer is almost always the same: it depends on configuration. An audit is how you find out what your configuration actually is.
It depends on how it is configured on the specific page, and what it is placed next to.
It depends on the pages it loads on and the parameters attached to each event.
It depends on the vendor agreement in place and what the number-swap script actually captures.
It depends on load order. A banner that blocks visually can still fire tags underneath it.
The engagement produces a single artifact: a documented record of what your public site actually does - capable of standing up in front of legal, a regulator, or a plaintiff's attorney.
Every script and pixel loading on public pages, catalogued by vendor, trigger, and page context.
What fires before a consent decision is made, and what changes after acceptance or rejection.
Where each request goes, and which identifiers, parameters, and page values travel with it.
Timestamped, reproducible records your legal and privacy officers can review and act on directly.
Findings ranked by exposure, so engineering and marketing fix the highest-risk items first.
The audit is a runtime capture on public pages only. No access to your patient portal, and no access to protected health information is required at any stage.
High-traffic public sites with dozens of legacy tags accumulated across departments and campaigns.
Multiple properties and marketing teams, each capable of adding a tag without central review.
Highly sensitive condition and treatment pages that draw the most scrutiny from regulators and plaintiffs.
Location and provider pages built by different agencies over time, rarely audited as a single system.
The audit runs on your public pages only. No PHI access, no portal access, no disruption to your live site during capture.
Request an audit