Webclat / Healthcare
health.webclat.com
Tracking audits for healthcare organizations

Analytics your compliance team can sign off on.

A runtime audit of your public-facing website: every tag and pixel that fires, who receives the data, and how it changes before and after consent.

Built for hospital and health system marketing teams - and written to be reviewed alongside legal and privacy.

Built for academic medical centers · NCI-designated cancer centers · multi-hospital health systems · specialty practice groups
YOUR PUBLIC SITE condition pages find-a-doctor locations appointment request TAGS: 23 DETECTED CONSENT GATE ad platform pixel session replay analytics call tracking FIRES BEFORE CONSENT GATED BY CONSENT
Illustrative. The audit documents which of these paths exist on your site.

The record

01 / The record

There is no clear federal rule on tracking technology and health information right now. There is, however, a live and expensive record of what happens when a hospital website ships tags it cannot fully account for.

DEC 2022 OCR tracking bulletin issued JUN 2024 Guidance vacated - AHA v. Becerra TODAY Class actions continue
EXHIBIT 01

The guidance was vacated

In June 2024, a federal court vacated the HHS Office for Civil Rights guidance on online tracking technologies in AHA v. Becerra.

AHA v. BECERRA / N.D. TEX. / JUN 2024
EXHIBIT 02

The litigation did not stop

Advocate Aurora Health settled pixel litigation for 12.225 million dollars. Class actions over hospital website tracking continue regardless of the federal guidance question.

ADVOCATE AURORA HEALTH / SETTLEMENT / $12,225,000
EXHIBIT 03

Regulators are still writing letters

OCR and the FTC jointly sent roughly 130 warning letters to hospital systems and telehealth providers about tracking technologies on their websites and portals.

OCR + FTC / JOINT WARNING LETTERS / N ≈ 130

Net effect: no settled federal standard, ongoing litigation risk, and marketing teams who removed measurement tools after the initial guidance - and now cannot say with confidence what their site sends, to whom, and under what conditions.

The questions

02 / The questions

These are searched constantly, and most confident answers to them are wrong. The correct answer is almost always the same: it depends on configuration. An audit is how you find out what your configuration actually is.

Is Google Analytics HIPAA compliant?

It depends on how it is configured on the specific page, and what it is placed next to.

Is our Meta pixel sending patient data?

It depends on the pages it loads on and the parameters attached to each event.

Can we run call tracking under HIPAA?

It depends on the vendor agreement in place and what the number-swap script actually captures.

What does our consent banner actually block?

It depends on load order. A banner that blocks visually can still fire tags underneath it.

The audit

03 / The audit

The engagement produces a single artifact: a documented record of what your public site actually does - capable of standing up in front of legal, a regulator, or a plaintiff's attorney.

3.1

Full tag and pixel inventory

Every script and pixel loading on public pages, catalogued by vendor, trigger, and page context.

3.2

Pre / post-consent behavioral diff

What fires before a consent decision is made, and what changes after acceptance or rejection.

3.3

Third-party data-flow map

Where each request goes, and which identifiers, parameters, and page values travel with it.

3.4

Evidence-grade findings document

Timestamped, reproducible records your legal and privacy officers can review and act on directly.

3.5

Remediation priorities

Findings ranked by exposure, so engineering and marketing fix the highest-risk items first.

SPECIMEN / PRE-POST CONSENT DIFF BEFORE CONSENT DECISION analytics.js pixel.gif?ev=PageView replay.record() num-swap.js audience-sync 5 REQUESTS OBSERVED AFTER "REJECT ALL" analytics.js pixel.gif?ev=PageView STILL FIRES replay.record() num-swap.js STILL FIRES audience-sync 2 REQUESTS SURVIVED REJECTION The diff is the finding: what your consent banner claims to block, measured against what the browser actually sent.
Illustrative specimen - not data from any client engagement.
METHOD NOTE

The audit is a runtime capture on public pages only. No access to your patient portal, and no access to protected health information is required at any stage.

Who it is for

04 / Scope
IN SCOPE - PUBLIC PAGES homepage condition pages locations providers campaigns appointment forms RUNTIME CAPTURE RUNS HERE OUT OF SCOPE patient portal MyChart / EHR clinical systems PHI datasets NO ACCESS
The boundary is the method: nothing behind authentication is touched.
04.1

Hospitals

High-traffic public sites with dozens of legacy tags accumulated across departments and campaigns.

04.2

Health systems

Multiple properties and marketing teams, each capable of adding a tag without central review.

04.3

Cancer centers

Highly sensitive condition and treatment pages that draw the most scrutiny from regulators and plaintiffs.

04.4

Multi-location specialty practices

Location and provider pages built by different agencies over time, rarely audited as a single system.

05 / Next step

Bring your privacy officer. We will show you the record together.

The audit runs on your public pages only. No PHI access, no portal access, no disruption to your live site during capture.

Request an audit