Agency Client Reporting Without PHI: A Template
A section by section template for healthcare client reports that carry campaign performance and outcomes without moving any protected health information.
A healthcare client report can carry every number an agency needs to defend its work without containing a single piece of protected health information, and the way to get there is to build the report out of counts and rates rather than records. Curve is the HIPAA-compliant tracking, attribution, and analytics layer that produces those aggregate numbers for agencies, with a signed BAA on every plan. The template below defines each section of the report and, more importantly, what each section is allowed to contain.
The rule that governs every section
One test decides whether a number belongs in a client report: could a reader use this row, alone or combined with the rest of the deck, to work out that a specific person sought a specific kind of care?
Aggregates pass that test easily. "412 consultation requests at $63 each" tells the client everything and identifies nobody. Records fail it immediately. A lead export with names, emails, and the service line each person enquired about is a list of health interests attached to identities, and it is PHI whether it lives in a spreadsheet, a slide, or a shared drive.
The awkward middle is small numbers. A campaign that produced two conversions in a rural market, broken out by a service line that only one clinician provides, can identify people to anyone who knows the market. Set a suppression floor and hold it. Under a threshold you choose in advance (many agencies use five), report the segment as "fewer than 5" rather than the exact count, or roll it up into a broader category.
The second rule is about where the report goes. A client report is a document that gets emailed, forwarded to a board member, uploaded to a shared folder, and occasionally pasted into a chat tool that has never signed anything. Build it so that forwarding it carelessly is not a breach.
Section 1: Summary and period
Open with the reporting period, the accounts covered, and four to six headline numbers. Spend, leads or conversions, cost per conversion, and the outcome metric the client actually cares about (booked appointments, arrived appointments, started treatment).
May contain: totals, rates, period over period change, budget pacing.
May not contain: anything at the level of an individual, including a named example of a "great lead this month."
Write the headline in plain language above the numbers. "Spend held flat, cost per booked consultation fell from $118 to $94, driven by the search account." Account directors who write that line every month get renewed more often than ones who ship a dashboard screenshot.
Section 2: Channel and campaign performance
The workhorse section. Impressions, clicks, cost, conversions, cost per conversion, by channel and then by campaign.
May contain: platform metrics and Curve-side conversion counts, side by side, with the difference explained.
May not contain: campaign names that disclose clinical detail about the people in them. This is the section where agencies leak by habit. A campaign named "HIV PrEP retargeting, prior consult abandoners" is descriptive internally and a disclosure when it appears in a document that names the client and shows an audience size. Use neutral campaign names in the ad accounts, and the report inherits them.
Show platform-reported and independently tracked conversions in the same view. They will differ, because platforms attribute on their own windows and models. Explaining the gap once, in every report, ends the recurring argument about which number is real.
Section 3: Conversion detail by event
Break conversions down by the event that fired: form submissions, calls, chat starts, booking completions. Use the same neutral event names your tracking sends to the platforms.
May contain: counts and conversion rates per event, per landing page group, per device.
May not contain: form field contents, chat transcripts, call recordings, or any sample of what people typed. Nobody needs the free-text field to run a media account, and free-text is where PHI hides.
Landing page breakdowns deserve care. A URL like /treatments/addiction-recovery/intake is a clinical disclosure when it appears next to a conversion count of one. Group pages into categories for reporting, or apply the suppression floor.
Section 4: Outcomes from the client's systems
The section that separates a media report from a marketing report. Booked, arrived, and converted counts come from the client's CRM, practice management system, or EHR, uploaded or webhooked into the measurement layer and matched back to the click that produced them.
May contain: counts by stage, stage to stage conversion rates, cost per arrived appointment, average lag from click to booking.
May not contain: patient identifiers of any kind, appointment dates tied to a person, or clinician names paired with volumes low enough to be re-identifying.
This is also the section that changes the conversation about budget. Cost per lead compares agencies. Cost per arrived appointment compares realities, and it is the number that survives a client's finance review.
Section 5: Compliance posture
A short standing section, four or five lines, that most agencies omit and every healthcare client appreciates.
- Which tracking is live on the client's properties, and whether any non-compliant script has appeared since last month.
- Which destinations are receiving conversion data, and what fields each one receives.
- Any PHI-pattern alerts raised during the period and how they were resolved.
- BAA status: who has signed one, and which vendors in the stack operate without one and why that is acceptable.
Include it because it is the cheapest trust you will ever buy, and because it forces the agency to actually check. Marketing teams add scripts. A heat map tool, a chat widget, a new analytics trial, added by someone at the client who never told you, is the most common way a compliant setup stops being compliant. A monthly line item catches it within thirty days instead of at deposition.
Section 6: Actions and next period
What you changed, what you are changing, and what you need from the client. Keep it to three to five items with owners and dates. No PHI question arises here, which is exactly why it should not be the only section anyone reads.
How Curve produces this report without PHI
Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare, and healthcare marketing agencies are one of its core segments. The reason the template above is practical rather than aspirational is that the underlying data is already aggregated and already governed.
- Per-destination field mapping. Only explicitly mapped fields forward to a given ad platform. The default is that nothing goes, so what reaches Meta or Google is what someone deliberately chose to send.
- Neutral event aliases. Your team sees descriptive event names internally. Ad platforms, and the report sections that inherit platform naming, see neutral ones.
- Identifier hashing. Contact identifiers are SHA-256 hashed per each platform's conversion API requirements before anything leaves.
- PHI-pattern detection. Payloads containing PHI-shaped values (SSNs, MRN-style IDs, dates, long numeric sequences) are flagged as a monitoring layer, which is what feeds section 5.
- Offline conversion uploads and incoming webhooks. Outcomes come back from the CRM or practice management system matched on email, click ID, or bridge token, so section 4 exists at all. Incoming data cannot override protected core attribution and contact fields.
- Bridge tokens. Attribution survives when a patient clicks out to a separate booking or intake tool such as IntakeQ, Calendly, or Jane App, which is where most healthcare funnels lose the chain.
- Signed BAA on every plan, which is what lets an agency put the measurement layer inside the covered chain rather than beside it.
Curve forwards clean conversions server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok, Microsoft, LinkedIn, and GA4. Related reading: HIPAA-compliant conversion tracking setup and why client-side pixels create exposure.
Delivery, storage, and retention
The document itself is part of the compliance surface. Three decisions to make once and apply to every healthcare account.
Format. A PDF or a link to a live dashboard, not a spreadsheet of rows. Spreadsheets invite drilling down, and drilling down is how aggregate reporting turns into record-level reporting.
Channel. Send through a system that is covered or that carries nothing sensitive. If the report is genuinely aggregate, ordinary email is defensible. That defense collapses the moment someone attaches a lead export "just this once."
Retention. Decide how long report copies live in your drive and enforce it. Agencies accumulate years of client decks in shared folders that outlive both the contract and the staff who made them. Offboarding a client should include disposing of their reporting artifacts on a documented schedule.
Frequently asked questions
Can we include a lead list if the client asks for one?
The client is entitled to their own leads, but that delivery is not a report. Route it through the client's CRM directly, so the leads land in a covered system rather than in an agency deck. If the agency is handling that routing on the client's behalf, it needs a BAA and the leads should never sit in a slide or a shared spreadsheet.
Are conversion counts by service line PHI?
Aggregate counts are not PHI. They become a re-identification risk when the counts are small enough, or the geography narrow enough, that a reader can infer who is in them. Apply a suppression floor and roll up thin segments.
Can we screenshot the ad platform dashboard into the report?
Usually yes, since ad platform reporting is already aggregate. Check audience names and campaign names in the screenshot first, because those often carry the clinical detail the rest of the report was careful to omit.
Does the agency need a BAA to produce these reports?
If the agency touches PHI on the client's behalf at any point, including access to the CRM, call recordings, or form submissions, it is a business associate and needs one. Producing an aggregate report does not remove the obligation created by the access required to produce it.
What do we do when platform numbers and tracked numbers disagree?
Show both and explain the mechanism once per report. Platforms attribute on modeled and view-through windows; a server-side measurement layer counts what it received and matched. Neither is wrong; they answer different questions.
How do we report on call conversions safely?
Report call counts, durations bucketed, and outcome status. Never transcripts or recordings, which are unambiguously PHI and belong only in systems whose vendors have signed a BAA.
Where to start
Take one existing client report and mark every element against the rule at the top: aggregate or record. Most agency decks are already close, and the failures cluster in three places (campaign names, landing page URLs, and the lead export appended at the back).
Then fix the source rather than the document. Neutral event and campaign naming, per-destination field mapping, and outcomes returned as counts make a PHI-free report the default output instead of a monthly editing exercise. Curve provides that layer for agencies, with a signed BAA on every plan. Run the free compliance scanner against a client site to see what is currently firing, or visit curvecompliance.com to talk through a reporting setup across your healthcare book.
Reviewed August 2026. Ad platform conversion APIs and healthcare advertising policies change frequently. Verify current requirements before implementation.
Related articles
- GuideHow Healthcare Agencies Answer What's Working: Client Reporting Without Leaking PHI
- GuideWhat Is Curve AI Analyst: Talk to Healthcare Analytics and Campaign Reporting
- GuideHealthcare Performance Max Campaigns: PHI Risks and the 2026 Audit Framework
- GuideGoogle Ads Call Reporting for Clinics: PHI-Safe Setup
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit