Meta flagged my custom audience or lookalike for health information
Your custom audiences or lookalike audiences will be flagged and cannot be used for running ad campaigns if they include information that is not allowed under our terms.
On this page
Meta flagged your audience because the audience, or the information it was built from, references something Meta's terms don't allow, and a specific health condition is Meta's own example. A flagged custom or lookalike audience can't be used in new campaigns, and Meta says ad sets already using it should be edited or paused and moved to a different audience. If a lookalike was flagged because of its seed audience, Meta says you have to resolve the seed first. Remove the prohibited information or build a new audience without it, and request a review if you believe the flag is wrong.
Curve helps you clean up the website data your audiences are built on. Curve's team reviews what your website sends to Meta, Google and TikTok with you and shows what's likely triggering the flag, and Curve detects PHI-like patterns before data reaches an ad platform. Personal identifiers in your conversions are SHA-256 hashed as the platforms' APIs require, and a BAA is signed on every plan. Book a call with Curve.
What gets an audience flagged
Meta's rule: "Advertisers must ensure their audiences don't share information that is not allowed under our terms. For example, references to specific health conditions (e.g., arthritis) or financial status (e.g., credit score) aren't allowed." The test reaches past the audience name to how the audience was built, because names and criteria for Custom Audiences "must not reflect, imply, or be based on any prohibited information." On a clinic or telehealth account, check these first:
- Website audiences whose rules match a condition or treatment in a URL, such as everyone who visited a condition-named page.
- Audiences built on a custom event or parameter whose name or value refers to a condition.
- Customer lists drawn from the patients of one condition-specific program or service. A list of people treated for a condition is based on that condition.
- Audience names that state a condition, even when the rule behind them is clean.
Lookalikes follow their seed
Meta's instruction for lookalikes: "If the underlying custom audience (also known as the seed audience) of your lookalike audience is flagged, you will need to resolve the issue with the underlying custom audience on which the lookalike audience is built." Rebuilding the lookalike from the same seed is unlikely to help. Fix the seed, or build a new lookalike from a seed that carries no condition.
What the flag does
- New campaigns: "You won't be able to use flagged custom audiences when creating new campaigns."
- Running ad sets: Meta says that if an active campaign uses a flagged audience, "you should edit or pause it and choose a different audience to avoid performance and delivery issues."
- Audience growth: LiveRamp's relay of Meta's notice, which announced proactive restrictions from September 2, 2025, says "Custom audiences will not receive new users", so a flagged audience stops growing.
- Everything else: ad sets on audiences that carry no prohibited information are not affected by this flag.
How to resolve it
- In Ads Manager, select the ad account and open Audiences in the left-hand menu. Open each flagged audience and read its name, its source and its rules.
- Remove what isn't allowed. Meta's options are to review the audience "and remove any information that is not allowed under our terms", to create a new audience without it, or to choose a different existing audience that is clean.
- For each flagged lookalike, resolve the seed first, then create the lookalike again from the clean seed.
- Edit or pause every active ad set that uses a flagged audience, and move it to a clean one.
- If you believe the flag is wrong, request a review from Ads Manager under the campaigns table, or in Audience Manager on the summary tab of the affected audience.
Customer lists and hashing
Meta says "Some customer information parameters must be hashed prior to transmission to Meta" and "Meta requires the hash method to be SHA-256." Hashing is the format Meta's API requires for those fields. It doesn't change what a list is: a list of people treated for a condition is still based on that condition after every email in it has been hashed. So the question for any list is what put each person on it, not how their identifiers are formatted.
For the wider rules on what healthcare custom audiences may contain, see the custom audiences compliance checklist. If URL-based audiences stopped filling after your dataset went into core setup, rather than after a flag, that is a different problem: see what still works under core setup.
Talk to Curve
A flagged audience is often the visible end of condition data flowing from your site into Meta. Curve's team will review what your site sends with you, show what's likely triggering the flag, and rebuild your conversion tracking server-side with PHI-like patterns detected before data reaches an ad platform. To see what your audiences are really built on, book a call with Curve.
How Curve helps
- Curve's team reviews what your website sends to Meta, Google and TikTok with you and shows what's likely triggering the flag.
- Curve detects PHI-like patterns before data reaches an ad platform.
- Personal identifiers are SHA-256 hashed as the platforms' APIs require.
- Rebuilds your conversion tracking so it's HIPAA-compliant and keeps campaigns optimizing, sending conversions server-side to Meta Conversions API, Google Ads, TikTok, Microsoft and LinkedIn.
- Signs a BAA on every plan.
Frequently asked questions
Why was my lookalike flagged when I never added health data to it?
A lookalike is built from a seed audience, and Meta says a flagged seed has to be resolved before the lookalike can be. Check the seed's name, rules and source.
Can I keep running ad sets that use a flagged audience?
Meta says you should edit or pause them and choose a different audience to avoid performance and delivery issues. Flagged audiences can't be used in new campaigns at all.
Does hashing a patient list make it acceptable?
No. Hashing is the SHA-256 format Meta requires for customer information, and it doesn't change what the list is based on. A list built from patients of a condition-specific service is still based on that condition.
Where do I request a review?
In Ads Manager under the campaigns table, or in Audience Manager on the summary tab of the affected audience. Request one when the audience genuinely includes no non-permitted information.
How does Curve help with flagged audiences?
Curve's team reviews what your website sends with you and shows what's likely triggering the flag, and Curve detects PHI-like patterns before data reaches an ad platform. Personal identifiers are SHA-256 hashed as the platforms' APIs require, under a BAA signed on every plan.
Sources
- Meta Business Help Center: Understand restrictions on certain custom audiences
- Meta Business Help Center: About prohibited information
- LiveRamp: Upcoming Meta Restrictions on Certain Custom Audiences and Custom Conversions (7/17/25)
Last verified
Related pages
- Meta Flagged My Custom Conversion for Health InformationWhy Meta flags custom conversions that suggest a health condition, what the flag does to running campaigns, and how to rebuild or request a review.
- Event Parameters Blocked in Meta: Unblock or Keep Blocking?What Meta's "Event parameters blocked" diagnostic means, how to review it, when to unblock or keep blocking, and why repeats lead to core setup.
- Meta Core Setup for Health Businesses: What Still WorksMeta core setup strips custom parameters and everything after the domain. What still works for a health business, why it happened, and what to fix first.
- Meta Removed Potentially Prohibited Information: Next StepsWhat Meta's prohibited information notice means for a health business, where to find what was removed, how to fix it, and why you must never re-send it.
- Meta Blocked My Custom Events Until I Review ThemWhy Meta blocks every custom event once a dataset has data restrictions, which events to confirm, which to keep blocked, and why renaming is not a fix.
- Does Server-Side Tracking Get Around Health Restrictions?No. Meta restricts health data by data source, not by route, and forbids re-sending removed data. Here is what server-side tracking is really for.
Talk to Curve about the data side of your restriction
Book a call and Curve's team will look at what your site sends to Meta, Google and TikTok, and show you the compliant setup that keeps your campaigns optimizing.
Book a call