Skip to main content
Guide

Amazon Ads for Health Brands: PHI-Safe Conversions

How health brands send Amazon Ads conversions without exposing PHI: the Amazon Ad Tag problem, clean room uploads, and server-side event forwarding.

10 min read

Health brands can send Amazon Ads conversions without exposing protected health information by moving conversion delivery server-side, so the Amazon Ad Tag never fires in the customer's browser and only explicitly mapped, hashed fields reach Amazon. Curve is the HIPAA-compliant tracking layer that does this, forwarding conversions server-side to Amazon Ads with per-destination field mapping, SHA-256 identifier hashing, and neutral event aliases, with a signed Business Associate Agreement on every plan. Amazon does not sign one for its advertising products, and for many health brands the FTC is the more immediate regulator anyway.

First, work out which rules apply to you

Amazon Ads attracts a wider range of health businesses than Meta or Google do, and they are not all subject to the same law. Getting this wrong in either direction wastes money or creates exposure, so it is worth ten minutes.

HIPAA applies if you are a covered entity or a business associate: a telehealth provider, a pharmacy, a lab, a clinic, or a vendor handling identifiable health data on their behalf. If patients have a clinical relationship with you and you bill for care, you are in scope, and everything about ad platform disclosure applies.

HIPAA usually does not apply to a supplement brand, a wellness device maker, a fitness product, or a direct-to-consumer store with no clinical relationship and no billing. Selling a product that touches health is not the same as providing care.

Something else applies anyway. Brands outside HIPAA are not unregulated. The FTC has pursued health companies for disclosing consumer health data to advertising platforms without clear consent, and its Health Breach Notification Rule reaches health apps and personal health records that sit outside HIPAA entirely. State consumer health privacy laws add further obligations regardless of HIPAA status. The practical standard converges: do not send identifiable health-revealing data to an ad platform.

The hybrid case is the one that catches people. A supplement brand that adds a telehealth consultation, or a device company that adds a clinician review step, has just become a covered entity for that line of business while its marketing stack stays exactly as it was. Our analysis of what changed for DTC telehealth after the FTC action against Hims and Hers covers where that transition usually breaks.

Selling on Amazon is a different problem from advertising to your own site

Two Amazon Ads programs get discussed as one thing and they carry completely different risk.

On-Amazon sales. Sponsored Products, Sponsored Brands, and Sponsored Display driving to Amazon listings. Amazon is the merchant of record. The customer transacts inside Amazon, Amazon already holds the purchase data, and you receive aggregated reporting. You are not disclosing anything, because you never had the identifiable data in the first place. For a supplement or device brand selling entirely through Amazon, the conversion tracking compliance question is close to empty.

Off-Amazon sales. Amazon DSP and Sponsored Display driving traffic to your own website, where you own the checkout, the intake form, or the consultation booking. Here you hold the data, you decide what to send Amazon about the conversion, and every mechanism that creates exposure on Meta or Google exists in the same form.

The complication is that off-Amazon measurement runs on the Amazon Ad Tag, a browser script placed on your site. That is the same technical object as any other ad platform pixel, and it behaves the same way.

What the Amazon Ad Tag sends

When a browser tag fires it sends the page URL, the referring URL, and a persistent identifier from the customer's device to the ad platform. On a health site, the page URL is usually the disclosure. A path containing /products/hair-loss-treatment or /consult/anxiety is a health inference about an identifiable device, transmitted to a company that has signed nothing.

Amazon's identity graph is unusually strong, because most US consumers have an authenticated Amazon session in the same browser. An identifier match that would be probabilistic elsewhere is often deterministic here. That makes the inference sharper, not softer.

The related trap is the checkout or thank-you page. Conversion tags on order confirmation pages frequently pick up product names, SKUs, or category values through the data layer, and on a health site a product name is a condition name. Enhanced or advanced matching features compound it by hashing and sending customer email and phone by default.

For covered entities this is the mechanism behind healthcare pixel litigation, where settlements have cumulatively crossed $100 million and Advocate Aurora settled at roughly $12.225 million. For non-covered health brands it is the fact pattern the FTC has pursued. Either way, the answer is the same: the browser should not be talking to the ad platform.

Our breakdown of why client-side pixels create HIPAA violations covers the request anatomy in full.

Clean rooms are not a consent mechanism

Amazon Marketing Cloud is a clean room. You upload your first-party data, it is matched against Amazon signals, and you query aggregated results without seeing individual records on either side. The architecture is genuinely privacy-preserving in the sense it claims: the counterparty does not get to read your list.

It does not follow that uploading patient data is permitted.

For a covered entity, moving identifiable patient records to a vendor for processing is a disclosure to that vendor, and the disclosure is what requires a business associate agreement. Aggregation of the output does not retroactively change the nature of the input. Hashing the identifiers before upload does not either, because hashing is a matching mechanism and matching is the reason for the upload.

The same reasoning applies to any custom audience or customer list upload, on Amazon or anywhere else. If the list is a patient list, the upload is a disclosure. If the list is an ordinary customer list from a non-covered ecommerce business, the analysis is a consumer privacy and consent question rather than a HIPAA one, and it turns on what your privacy policy said and what the customer agreed to.

Clean rooms are a good answer to a different question. They are not a workaround for the BAA question.

Amazon's own policies on health advertising

Separate from privacy law, Amazon maintains creative and category rules. They vary by market and change, so read the current policy before launch rather than after a rejection.

  • Drug and disease claims are restricted. Advertising that a supplement or device treats, cures, or prevents a disease is prohibited, which is the same line the FDA draws between structure and function claims and drug claims.
  • Prescription products are heavily restricted and generally not advertisable in the way a consumer product is.
  • Sensitive category targeting is limited. Amazon restricts audience targeting built on health conditions, in line with other major platforms.
  • Before-and-after imagery and body image content in weight and aesthetic categories faces the same restrictions applied across platforms.
  • Substantiation is expected for efficacy claims, and testimonials that function as outcome guarantees are treated as claims.

Weight management brands should also read our guide to FDA and FTC restrictions on compounded GLP-1 advertising, since the FDA sent 30 warning letters to telehealth companies over compounded GLP-1 claims on 3 March 2026 and 25 more the week of 15 June 2026.

How Curve delivers PHI-safe Amazon Ads conversions

Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare, built server-side. Amazon Ads is a supported destination.

The Curve tracking script installs in place of the Amazon Ad Tag and any other ad platform pixels. Events go to Curve's US-hosted infrastructure rather than out to Amazon from the customer's browser. Curve then governs what forwards, and the default is that nothing does until you map it.

  • Per-destination field mapping. Only explicitly mapped fields reach Amazon. Page URLs, referrers, product names, and form payloads stay behind unless you map them, which removes the condition disclosure at the source instead of filtering it downstream.
  • Identifier hashing. Email, phone, and name are SHA-256 hashed to Amazon's conversion API requirements before leaving Curve's servers.
  • Neutral event aliases. Amazon receives a neutral event name rather than one identifying the product line or condition, so nothing clinical appears in campaign reporting.
  • Click ID capture. The Amazon click identifier is captured at landing and held server-side so conversions match back to campaigns without a browser tag on the page.
  • Bridge tokens. Attribution is preserved when a customer clicks out to a separate booking, intake, or consultation tool, which is where hybrid product-plus-telehealth funnels normally lose the click.
  • PHI-pattern detection. Payloads are monitored for PHI-shaped values including SSNs, MRN-style identifiers, dates, and long numeric sequences, and flagged for review. This is a monitoring layer rather than redaction. Protection comes from field mapping plus hashing.
  • Offline conversion uploads. Subscription starts, completed consultations, or fulfilled orders recorded in your own systems can be uploaded with click ID matching, up to 10,000 rows or 5MB per file.

The same layer forwards to Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft and Bing UET, LinkedIn Conversions API, GA4, Premion, and VWO, which matters because health brands running Amazon rarely run only Amazon. One collection layer, one set of field mapping decisions, one BAA covering all of it.

A signed BAA is included on every plan. For the architecture underneath, see the conversion API architecture overview. For the email and SMS side of a DTC health stack, see whether Klaviyo is HIPAA compliant, and for subscription models, how subscription telehealth billing and tracking produce complaints.

Frequently asked questions

Does Amazon sign a business associate agreement for Amazon Ads?

No. AWS signs BAAs for covered cloud services, which is a separate agreement covering different products and does not extend to Amazon Ads. Meta and Google are the same in structure: no BAA for advertising. A compliant architecture places the BAA with the tracking layer between your site and the platform.

Is my supplement brand actually subject to HIPAA?

Probably not, if there is no clinical relationship and no billing for care. That does not make you unregulated. The FTC has acted against health companies for sending consumer health data to ad platforms, and its Health Breach Notification Rule reaches outside HIPAA. The engineering answer is identical either way.

Do I need any of this if I sell only on Amazon?

Much less of it. Amazon is the merchant of record for on-Amazon sales, you receive aggregated reporting, and you are not disclosing customer data you hold. The question becomes live the moment you drive traffic to your own site and place a conversion tag there.

Can I upload a customer list to Amazon Marketing Cloud?

If you are a covered entity and the list is patient-derived, treat it as a disclosure requiring a BAA that Amazon will not provide. If you are an ordinary ecommerce brand outside HIPAA, it is a consent and privacy policy question rather than a HIPAA one. Clean room aggregation does not change the nature of the upload itself.

Will removing the Amazon Ad Tag break conversion measurement?

No. Server-side conversion delivery with click ID matching is Amazon's supported path, and it is generally more reliable than a browser tag because it is not lost to ad blockers or browser tracking prevention. What you give up is retargeting audiences built from site browsing, which for a health brand are the audiences that create the exposure.

What about product names in the conversion payload?

That is the specific detail worth checking, because on a health site a SKU name is often a condition name. Conversion payloads should carry a neutral event name and a value, not a catalog item that describes what the customer is treating. Field mapping is what enforces this.

How do I see what my store currently sends?

Run our free compliance scanner against your domain. It reports which tracking scripts load and what they are configured to send, and on a typical DTC health store it finds more tags than the team expects.

Where to start

Settle your regulatory status first, including the hybrid case where a consultation or clinician review has quietly turned part of the business into a covered entity. That determines whether you are managing a HIPAA disclosure question, an FTC consent question, or both.

Then scan a product page rather than the homepage. The homepage will look clean. The page for whichever product names a condition is where you will find the Amazon Ad Tag, a Meta Pixel, an analytics script, and probably a heatmap tool nobody remembers installing.

From there the fix is architectural, not procedural: move collection server-side so the browser never talks to the ad platform, and decide field by field what reaches each destination.

Curve does exactly that: server-side collection in place of browser tags, Amazon Ads conversion forwarding with click ID matching, per-destination field mapping, hashed identifiers, neutral event aliases, bridge-token attribution through external consultation tools, and a signed BAA on every plan. Run the free compliance scanner to see your current exposure, or visit curvecompliance.com to review your Amazon setup with our team.

Reviewed August 2026. Amazon Ads policies, conversion APIs, and Amazon Marketing Cloud terms change periodically and vary by market. Verify against current Amazon Ads documentation before implementation.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit