47.66° N 117.43° W Summit · Profitable Growth
Medical Practice Marketing · Compliance limits
Can a medical practice use Google Ads conversion tracking without violating HIPAA?
Yes, a practice can run Google Ads conversion tracking, with three changes to the default setup. Every vendor receiving a patient identifier belongs under a business associate agreement, nothing leaving your systems should indicate why they sought care, and health-based audience features stay off. Google signs no BAA covering Ads, so send it a click id.
I am a marketer, not a lawyer, and nothing here is legal advice. What your practice is permitted to disclose is a decision for your own counsel or compliance officer. This page is written to give that conversation something specific to start from, because “is Google Ads HIPAA compliant” is not a question anyone can answer as asked.
The question is wrong, and the wrong version is what gets practices in trouble
There’s no such thing as a HIPAA-compliant advertising platform. HIPAA regulates covered entities and their business associates. It doesn’t certify software.
Google is not a covered entity, and it doesn’t sign business associate agreements for Google Ads. Its own documentation says so for the adjacent measurement product: Google “does not offer Business Associate Agreements in connection with this service” (Google Analytics help). Google does sign BAAs for Workspace and Cloud, which is why the scoping matters and why “Google signs no BAA” is too broad a thing to say. Ads is not on the covered list. There are contractual data-processing terms, so it isn’t a lawless void, but there’s no business-associate obligation.
So the real question is narrower: what can leave the practice, who can receive it, and under what agreement. Asked that way, conversion tracking stops being a yes-or-no and becomes a list of specific decisions.
What makes the data protected, and where that line moved
The statutory definition at 45 CFR 160.103 is individually identifiable health information: information, including demographic information, that relates to health, health care, or payment for health care, and identifies the individual or gives a reasonable basis to identify them.
So an identifier alone isn’t protected. An identifier plus a relation to the seeking of care is where it gets interesting.
Here’s the part most write-ups on this are two years out of date on. From 2022, OCR guidance treated an IP address combined with a visit to an unauthenticated public page about a specific condition as protected. In June 2024 a federal court vacated that specific combination in American Hospital Association v. Becerra, and HHS dropped its appeal that August. The rest of the bulletin, including authenticated patient portals, still stands.
That matters for how strongly anyone can argue the page-view case. It does not touch the case this page is actually about. Somebody who calls the practice, or submits a form, has handed you an identifier in the act of seeking care, and no court vacated that. Build for the strong version and the weak version takes care of itself.
The three changes to a default install
Every vendor touching an identifier is one I’d expect your compliance officer to want covered. Call tracking, the form handler, the scheduling widget, analytics, and the mailbox the lead notification lands in. Each receives a name or a number attached to somebody contacting a healthcare provider. The test isn’t whether the tool is reputable. It’s whether the vendor signs a business associate agreement and whether the plan you’re actually paying for is the one that agreement covers, which is frequently a higher tier than the one a practice signed up on.
Nothing leaving your systems says why. The platform receives a click id or a hashed identifier, a timestamp, and a value. Not a condition, a procedure, a department, or a page. This extends further than people expect: a conversion action named after a procedure carries the same information as a field containing it, and so does an account where the only campaign importing bookings is the one named for a single condition.
Health-based audience features stay off. Remarketing, Customer Match and lookalikes all work by assembling a group around a behavior, and when the behavior is reading about a condition, the audience is the disclosure. That’s a platform-policy question with its own answer in whether a practice can run remarketing.
What you can still measure
Almost everything that matters, which surprises people who assumed compliance meant flying blind.
You can count conversions. A call over a qualifying duration, a form submission, a booking click, all countable with no identifier reaching the platform at all. Standard conversion counting requires only the event.
You can attribute those to keywords, ads and campaigns, because the click identifier does that work and a click identifier is not a patient identifier. It’s a random string Google generated when it served the ad.
You can import the outcome. If the practice knows which callers became patients, that can go back as an offline conversion. The version that sends the click id and no personal identifier at all is the one a practice should reach for first, and the mechanics are in how to track booked patients without sending PHI.
What you give up is the audience layer and the granular ecommerce-style reporting where the platform knows what somebody looked at. In a practice, that layer was never worth what it costs.
The order to do it in
Vendors first. Until the agreements are in place, every improvement to the measurement increases the volume moving through a tool that shouldn’t have it. I’ve watched a practice spend a month perfecting a tracking setup while every patient enquiry routed through an unsigned vendor the whole time, and the month of work made the exposure larger rather than smaller.
Then the event layer: count what happens, attribute it to the click, send nothing personal.
Then the outcome import, once the practice can actually tell you which enquiries became patients. That last part is usually a front-office workflow problem rather than a technical one, and it’s worth solving before it gets automated.
Where practices get caught
The tracking pixel on the confirmation page is the classic. A scheduling confirmation firing an analytics or advertising tag while the URL still carries the appointment type is sending the condition in the page path, and nobody looks at the page path.
Session recording and heatmap tools are second. They’re almost never covered by an agreement, they capture form contents by default, and they’re usually installed by whoever built the website rather than by anyone thinking about patients.
Third is the notification email. A form handler that emails the enquiry to the front desk has transmitted the whole thing, including whatever the patient typed in the message box, through whatever mail path that vendor uses. Delivery working isn’t the same as the disclosure being permitted, and the two get conflated constantly because one is visible and the other isn’t.
What to do this week
Write down every tool that receives a name, an email or a phone number from somebody contacting the practice. Include the ones nobody thinks of as medical software, because those are the uncovered ones.
For each, find the agreement or find out there isn’t one. That list is the actual position, and it’s nearly always different from what the practice believes it is.
The measurement architecture underneath all of this, for any business that books by phone rather than by checkout, is The Lead Quality Stack.
Related questions
-
Can a medical practice run remarketing or Customer Match ads?
Google blocks the audiences you build for restricted health advertising, and Meta bars health data in audience criteria. What that closes, and what stays open.
Read the answer
-
Why do my healthcare keywords and ads keep getting restricted in Google Ads?
Four systems restrict a practice's ads: the personalized ads policy, the content policy, certification gates, and your state medical board. Which is which.
Read the answer
-
Can I record and score patient phone calls for marketing?
Call scoring shows which keywords produce real appointments. What recording requires, why the transcript beats the audio, and where the model should run.
Read the answer
-
Do I need a BAA with my call tracking provider?
Call tracking hands a vendor patient identifiers. What a business associate agreement covers, why the plan tier matters, and what recording adds on top.
Read the answer
Back to the full medical practice marketing: the compliance library
Want this diagnosed in your account?
Same diagnosis,
run on your account.
Thirty minutes on the phone. I look at your spend, your tracking, and your search-term reports before the call. You walk out with a clear list of what is leaking and what to fix first.