Most of the advice you will find on this subject describes a rule that no longer stands. In December 2022 the HHS Office for Civil Rights published a bulletin on the use of online tracking technologies by covered entities and business associates, updated in March 2024. Its most aggressive position was that HIPAA obligations attach where an online technology connects an individual’s IP address with a visit to an unauthenticated public web page addressing specific health conditions or health care providers.
In American Hospital Association v. Becerra, decided June 20, 2024, the United States District Court for the Northern District of Texas held that HHS had exceeded its authority and vacated that portion of the guidance, which the litigation called the proscribed combination. HHS withdrew its appeal on August 29, 2024. The vacated reading is not coming back through that document.
If your agency or your compliance vendor is still telling you that a pixel on your public marketing site creates protected health information because a visitor’s IP address touched a page about a treatment, they are quoting vacated guidance.
What survived
Be careful about how far you take this. The vacatur was specific.
| Status | |
|---|---|
| IP address plus an unauthenticated public page about a condition or provider | Vacated. Not a basis for HIPAA obligations under that guidance |
| Authenticated areas, such as a logged-in patient portal | Untouched. The analysis there is unchanged |
| The rest of the bulletin | Still stands as the agency’s stated position |
| FTC Act and the Health Breach Notification Rule | Unaffected by the ruling |
| State privacy and health-data statutes | Unaffected by the ruling |
So a tracker inside a portal where a patient has logged in, or on a page where a user submits a form identifying a condition, is a different question from a tracker on a general marketing page. The court did not bless the first, and it did not need to.
If you are not a covered entity, this analysis was never yours
Before spending anything on this, settle whether HIPAA applies to you at all. A cash-pay clinic that bills no insurer is frequently outside the definition in 45 CFR § 160.103, which we work through in HIPAA for med spas.
For those clinics the live exposure is the Federal Trade Commission rather than HHS: section 5 of the FTC Act, and the Health Breach Notification Rule at 16 CFR Part 318, whose 2024 amendments took effect July 29, 2024. The FTC has been the more active enforcer against health-adjacent tracking in any event, and the court ruling did nothing to it.
That is the practical inversion worth carrying: the ruling relieved covered entities of a reading, and left the regime that applies to most med spas exactly where it was.
What to do with your own site
- Separate the marketing site from anything authenticated. Different rules, different tooling decisions, and the boundary should be architectural rather than a matter of care.
- Inventory what is actually loading. Tag managers accumulate. The set of trackers running on your site is very likely not the set anyone chose.
- Keep trackers off the forms. Intake, symptom questionnaires and appointment requests carry what a user typed. This is where real exposure lives, and it is unaffected by the ruling.
- Read what the vendor does with it. A data-sharing arrangement that feeds an advertising platform is a disclosure question whichever regime applies to you.
- Match the disclosure to reality. Your privacy page should describe the trackers that are actually running, which is a cheap fix and a common gap. See how we describe ours at security and privacy.
- Where you are a covered entity, paper the vendor. See who in your stack needs a business associate agreement.
What this means for you
Re-check any decision made between December 2022 and mid-2024, because a lot of clinics ripped analytics off their marketing sites on the strength of guidance a court has since vacated, and they are flying blind on acquisition for no remaining reason. Then put the effort where it still matters: authenticated pages, form pages, and what your advertising vendors receive. And settle your covered-entity status first, because for most of this market the answer makes HHS guidance beside the point and the FTC the regulator that was always going to show up.
Related reading
Frequently asked questions
Can I use Meta Pixel or Google Analytics on my clinic website?
On general marketing pages the position is far more permissive than it was. The court in AHA v. Becerra vacated the guidance treating an IP address plus a visit to an unauthenticated public page as triggering HIPAA, and HHS withdrew its appeal in August 2024. Authenticated pages and form pages remain a different question.
What exactly did the court vacate?
The proscribed combination: the portion of the OCR bulletin providing that HIPAA obligations are triggered where an online technology connects an individual’s IP address with a visit to an unauthenticated public webpage addressing specific health conditions or health care providers.
Did HHS appeal the ruling?
No. HHS withdrew its appeal on August 29, 2024, so the district court’s vacatur of that portion of the bulletin stands.
Does the ruling apply to my patient portal?
No. The vacatur addressed unauthenticated public pages. Tracking inside an authenticated portal, where the user has identified themselves, was not what the court considered and is analyzed on its own terms.
What if my clinic is not a HIPAA covered entity?
Then this guidance was never the rule that applied to you. Section 5 of the FTC Act and the Health Breach Notification Rule at 16 CFR Part 318 apply instead, along with state privacy law, and none of that was affected by the ruling.
This is general information, not legal advice. Rules vary by state and change. Confirm your own facts with counsel.