Hospitals, clinics and health apps in the US have spent the last few years removing tracking pixels, settling lawsuits and rewriting privacy notices. The rules are clearer than they were, but they're spread across several laws, and GA4 sits right in the middle of them.
HIPAA and tracking.
HIPAA applies to covered entities, such as healthcare providers and health plans, and to the business associates who handle health information for them.
In December 2022, the Office for Civil Rights at the Department of Health and Human Services published a bulletin on online tracking. Its message was that tracking tools on a provider's website or app can send protected health information to companies like Google and Meta, and that this needs a business associate agreement or the patient's authorisation.
Part of that bulletin was struck down. In June 2024, a federal court in Texas ruled, in a case brought by the American Hospital Association, that an IP address combined with a visit to a public page about a condition or a provider isn't automatically protected health information. The government didn't appeal.
What remained matters more for most sites:
- Logged-in areas. Patient portals, booking systems and apps where people sign in are still treated as handling protected health information.
- Forms. Pages where people enter health details, such as symptom checkers or appointment requests, still count.
- Agreements. A tracking vendor that receives protected health information still needs a business associate agreement.
Where GA4 fits.
Google's terms for Google Analytics say it isn't intended to create HIPAA obligations, and that covered entities and business associates mustn't use it with protected health information unless Google has agreed in writing. In practice, Google doesn't sign a business associate agreement for GA4.
That doesn't mean a health provider can't use GA4 anywhere. It means GA4 must never receive protected health information, so it stays off logged-in areas and health forms, and what it does collect on public pages is checked.
Not covered by HIPAA? Other laws apply.
Many health businesses aren't covered entities at all: wellness apps, test kit brands, supplement shops and telehealth start-ups selling directly to consumers. They aren't outside the rules.
- The Federal Trade Commission has taken action against health companies for sharing health data with advertising platforms, and its Health Breach Notification Rule covers many health apps.
- Washington's My Health My Data Act, in force since March 2024, needs consent before collecting consumer health data, defines that data broadly, and lets consumers sue. Nevada and Connecticut have similar rules.
- State privacy laws treat health data as sensitive, and several require opt-in consent for it.
Lawsuits under wiretapping laws have also targeted health sites heavily. That's covered in why US businesses are sued over tracking pixels.
What to check.
- Map your site into zones: public information pages, forms and logged-in areas. Decide what tracking is allowed in each.
- Remove advertising pixels from forms and logged-in areas. Check the tag manager and the site code, as pixels often hide in both.
- Read what your tags send. Page addresses, titles, search terms and button labels can all describe a condition.
- Turn off automatic form tracking and session recording where people type health details.
- Consider server-side tagging, so data passes through a server you control and can be cleaned before any vendor sees it.
- Keep evidence. A record of what each tag sends, tested and dated, is what a regulator or a court will ask for.
What counts as protected health information on your site, and which agreements you need, is for your lawyers and compliance team. Marc Alexander makes the tracking match their decisions, and the GA4 for healthcare page covers how. The GA4 mini audit shows what your tags send today.