Skip to main content
Guide

Bing Conversion Tracking vs Google Ads: HIPAA Differences Healthcare Marketers Should Know

Microsoft's search engine reaches a significant share of U.S. desktop search traffic, and the audience skews toward affluent, desktop-using professionals, a demographic many healthcare practices want...

13 min read

Microsoft's search engine reaches a significant share of U.S. desktop search traffic, and the audience skews toward affluent, desktop-using professionals, a demographic many healthcare practices want to reach. The problem: Bing conversion tracking HIPAA obligations differ in meaningful ways from Google's, neither vendor signs a Business Associate Agreement for advertising, and the controls available to filter Protected Health Information (PHI) are not equivalent on the two platforms. This guide breaks down the real differences between Microsoft Ads and Google Ads healthcare compliance, where each platform exposes PHI by default, and how to configure tracking on both without triggering an OCR investigation.

Platform Overview for Healthcare

Why Microsoft Advertising Matters for Healthcare

Bing's user base is meaningful for healthcare marketers, particularly on desktop where Microsoft's share is materially higher than its overall search share. For high-ticket healthcare services like dental implants, plastic surgery, fertility, and concierge medicine, that audience composition matters because purchasing power and intent both correlate with desktop search behavior.

The platform is also less crowded than Google. Healthcare consistently ranks among the most expensive verticals in paid search, and Microsoft Advertising frequently delivers lower CPCs for the same keywords, which is one reason healthcare marketers run parallel campaigns across both networks.

Healthcare Advertising Policies

Microsoft tightened its healthcare rules to mirror Google's beginning in 2024. [1]Google updated and reorganized its Ads Healthcare and Medicines policy effective December 2024 to clarify scope and add new examples. Advertisers now comply with similar certification and content policies across both platforms, including a certification process and specialized verification for health-related products and services.

Like Google, Microsoft requires pharmaceutical sellers to receive LegitScript certification, although it also accepts accreditation from the National Association of Boards of Pharmacy (NABP). Brands are not allowed to advertise in ways that create the impression of direct health targeting, using language like "your condition" or "your symptoms." Weight-loss product claims are heavily restricted on both networks, and certain supplements are outright disapproved.

Platform-Specific Terminology

  • UET (Universal Event Tracking): Microsoft Advertising's tag-based tracking system that, when placed on a website, records user actions. The Bing equivalent of the Google tag.
  • Conversion Goals: Microsoft's term for the events you count as conversions (purchases, lead form fills, page views).
  • UET Consent Mode: Microsoft's consent signal framework. [2]Failing to send valid consent signals by May 5, 2025 impacts advertising performance for site visits originating from the EEA, UK, and Switzerland.
  • Offline Conversion Import (OCI): Server-side conversion uploads that allow you to send hashed conversion data to Microsoft without a browser pixel.
  • Xandr: Microsoft's demand-side platform, which has its own consumer health data notice under Washington's My Health My Data Act.

Bing Conversion Tracking HIPAA Deep Dive vs. Google Ads

How Data Flows on Each Platform

Both Google Ads and Microsoft Ads default to client-side tracking. A JavaScript snippet loads in the visitor's browser, sets cookies, and transmits event data directly to the ad platform's servers. The UET tag is a JavaScript snippet that logs user behavior, device data, and conversions. Microsoft Ads collects device information including IP address, operating system, and browser type; search history; ad interactions; and location data based on IP address.

Google's setup is similar but has expanded server-side options. The Google Ads API and Enhanced Conversions allow advertisers to send hashed first-party data from their own servers. Server-side tracking is more HIPAA-compliant because it processes data on your secure servers before sending it to advertising platforms, allowing PHI stripping and data sanitization before any information reaches third parties. Microsoft offers Offline Conversion Import via the Bing Ads API as its server-side equivalent, but the implementation differs in important ways covered below.

PHI Exposure Risks

The default tracking behavior on both platforms can capture PHI without any developer doing anything wrong. Native tools like the Google Ads Conversion Tracking tag can inadvertently capture PHI, such as IP addresses combined with visits to specific medical condition pages. Features like remarketing and lookalike audiences are inherently problematic for healthcare because they rely on tracking user behavior related to health status.

Specific exposure points to audit on both networks:

  • URL parameters: Appointment booking flows that pass condition names, provider specialties, or patient identifiers in the query string.
  • Page titles and content: A condition-specific landing page URL combined with an IP address can constitute PHI under HHS's tracking technologies guidance. [3]OCR's bulletin states that regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules. (Note: a 2024 federal court vacated the portion of OCR's guidance that automatically tied IP addresses on unauthenticated public webpages to PHI status, but the underlying disclosure rules still apply when health context is present.) [4]
  • Form fields: Name, email, phone, and reason-for-visit fields captured by auto-tracking features.
  • IP address: Default tracking often collects IP addresses, device information, and browsing history alongside health-related search terms, all of which can qualify as PHI under HIPAA when combined with health context.
  • Remarketing audience membership: A user added to a "booked dermatology consult" audience now has their browsing tied to a health-related list.

The BAA Problem: Both Platforms Refuse

The single most important compliance fact for healthcare marketers: neither platform will sign a BAA for advertising. Microsoft does not offer a business associate agreement for Microsoft Advertising, and Google Ads is explicitly excluded from the BAAs Google signs for Google Cloud and Workspace. Without a BAA, any transmission of PHI to either ad platform is an impermissible disclosure under HIPAA. [5]OCR's revised bulletin reminds covered entities that they may only disclose health information to digital tracking vendors who first sign a business associate agreement.

Compliant vs. Non-Compliant Features (Microsoft Ads vs Google Ads)

  • UET tag (standard, client-side): Not compliant. Loads by default and transmits IP, URLs, and form data to Microsoft.
  • Google Ads conversion tag (standard, client-side): Not compliant. Same risk profile as UET.
  • Bing Offline Conversion Import (server-side): Can be compliant with proper PHI filtering before upload.
  • Google Ads API / Enhanced Conversions for Leads (server-side): Can be compliant when the data layer strips PHI before hashing and upload.
  • Microsoft remarketing lists: Generally not compliant. Lists built from health-page visits expose audience membership tied to conditions.
  • Google remarketing / Customer Match: Generally not compliant for healthcare. Building lookalike or remarketing audiences from condition-related behavior discloses sensitive medical context to a partner without a BAA.
  • Microsoft consent mode: Helpful for GDPR but does not solve HIPAA. Cookie consent banners address GDPR and CCPA but do not create a BAA. Even if users click "accept all," HIPAA still requires either a BAA with the vendor or a valid HIPAA authorization.
  • Google Consent Mode v2: Same limitation as Microsoft's. Useful for EU privacy law, not a HIPAA solution.

Key Difference: Consent Modeling

Google and Microsoft handle denied consent differently, and the gap matters for measurement. [2]Microsoft's Consent Mode adjusts cookie access based on the user's consent status; if consent is denied, UET does not read first-party cookies. Google, by contrast, uses modeling to estimate conversions for non-consented users, giving advertisers partial visibility into performance. For healthcare advertisers running aggressive consent gating to reduce PHI exposure, Bing's reported conversion volume will look lower than Google's even when underlying performance is identical.

Step-by-Step Compliant Setup

Pre-Implementation Audit

  1. Inventory every tag. Use a tag inspector to identify UET, Google Ads conversion tags, GA4, Meta Pixel, chat widgets, session replay, and call tracking scripts firing on your domain.
  2. Map PHI exposure points. List every page where condition names, provider specialties, or patient details appear in URLs, titles, or form fields.
  3. Document data flows. For each tag, document what data leaves the browser, what destination receives it, and whether a BAA covers that destination.
  4. Review vendor agreements. Confirm in writing which vendors will and will not sign BAAs. Microsoft and Google advertising will not. Plan accordingly.

For a deeper walkthrough of the Microsoft-specific audit, see Curve's guide to Microsoft Ads for Healthcare: Bing Search Compliance and Campaign Setup for Medical Practices.

Compliant Tracking Configuration for Bing Conversion Tracking HIPAA Workflows

  1. Remove or block the standard UET tag on any page that could expose PHI (appointment requests, condition pages, patient portal). The same applies to Google's gtag.js.
  2. Route conversions server-side. For Bing, use the Bing Ads API's Offline Conversion Import. For Google, use the Google Ads API with Enhanced Conversions for Leads. In both cases, your server sends only sanitized event data after PHI is stripped.
  3. Configure PHI stripping rules. At minimum, strip names, email addresses, phone numbers, full IP addresses, full date of birth, condition-specific URL parameters, and any patient or appointment identifiers before transmission.
  4. Define conversion events around outcomes, not conditions. Track "Lead Submitted" or "Appointment Booked" as generic events. Do not pass the specialty or condition as an event parameter.

For Google-specific implementation patterns, see Curve's deep dive on whether Google Ads conversion tracking is HIPAA compliant and how server-side solutions address client-side risks.

Campaign Structure for Compliance

  • Disable auto-tagging of sensitive parameters. In Microsoft Ads, review URL options at the account, campaign, and ad group level. In Google Ads, audit final URL suffixes and tracking templates.
  • Disable Google Signals in any linked GA4 property. Configure GA4 with these safeguards: disable Google Signals to prevent cross-device tracking that could identify patients, enable IP anonymization, exclude any URL parameters that contain patient information from being collected, and avoid using User-ID features unless your implementation has been reviewed for HIPAA compliance.
  • Skip remarketing for condition-specific audiences. Build audiences only from generic site-wide visits or branded conversion events, never from condition pages.
  • Avoid call recording. Do not use call recording or call transcription features if calls may contain PHI. If you use a third-party call tracking service, ensure it has signed a BAA and that call recordings are stored in HIPAA-compliant environments.

Verification and Testing

  • Use Microsoft's UET Tag Helper and Google Tag Assistant to confirm no payloads contain PHI.
  • Inspect outgoing network requests in browser developer tools on every conversion event.
  • Document the audit trail: keep dated screenshots of payloads, server logs of stripped fields, and a written PHI-stripping policy.
  • Re-test after every site change. A single new form field or query parameter can reintroduce exposure.

Campaign Strategies That Convert

Ad Types for Healthcare

Both platforms support search, shopping (for medical products), responsive display, and audience ads. For HIPAA-sensitive practices, search remains the safest format because targeting is keyword-based rather than profile-based. Microsoft's LinkedIn Profile Targeting layer (job function, industry, company) is a useful B2B option for medical device, pharma, and HCP-targeted campaigns. Google Ads also offers limited healthcare professional (HCP) targeting for eligible advertisers, expanding compliant B2B options within the healthcare category.

Targeting Without PHI

  • Use keyword intent, not health condition audiences. Bidding on "sleep study near me" is fine. Building a remarketing list of users who visited the sleep apnea page is not.
  • Geo-target broadly. ZIP-code level targeting around a clinic is acceptable. Combining ZIP and condition page visits is risky.
  • Use first-party intent signals. Generic site visitors (excluding condition pages) are safer audience seeds than condition-specific visitors.
  • Avoid in-market health audiences for sensitive specialties. Layering "in-market: addiction treatment" with location and device data creates inference risk.

Conversion Tracking Done Right

Track outcome events, not diagnostic context:

  • Safe to track: appointment request submitted, click-to-call, directions requested, generic thank-you page view.
  • Requires server-side handling: phone-call conversions, offline appointment confirmations imported from your CRM or EHR.
  • Avoid: passing the specialty, condition, provider name, or any patient identifier as an event parameter or conversion value label.

For practices handling walk-in or same-day appointment attribution, see Curve's guide on Google Ads offline conversions for healthcare.

Common Mistakes to Avoid in Bing Conversion Tracking HIPAA Setups

Mistake 1: Treating cookie consent as HIPAA compliance. The two regimes do not overlap. A consent banner satisfies GDPR or CCPA, not HIPAA's BAA requirement for disclosures to business associates.

Mistake 2: Leaving the UET tag firing on patient portal pages. Patient portals are a high-risk surface. Any tracking script on a logged-in patient experience transmits authenticated session context that can easily qualify as PHI.

Mistake 3: Building remarketing lists from condition pages. Audience membership tied to "visited the oncology page" is itself a disclosure of health information when transmitted to an ad platform with no BAA.

Mistake 4: Assuming Microsoft's smaller scale means smaller risk. OCR enforcement does not distinguish by ad platform. [5]OCR has stated it is prioritizing compliance with the HIPAA Security Rule in investigations into the use of online tracking technologies, which means even smaller campaigns are exposed to enforcement risk when tags transmit identifiable health context.

Mistake 5: Ignoring FTC actions on top of HIPAA. [6]The Federal Trade Commission required BetterHelp to pay $7.8 million for sharing consumers' sensitive health data, including email addresses, IP addresses, and answers to health questionnaires, with platforms such as Facebook and Snapchat for advertising. The proposed order also bans BetterHelp from sharing personal information with certain third parties for re-targeting. The FTC's Health Breach Notification Rule applies even to entities not covered by HIPAA, which means digital-first health brands face overlapping exposure from two federal regulators.

Self-audit checklist:

  • Have you confirmed in writing that neither Google nor Microsoft will sign a BAA for ads?
  • Is the UET tag blocked or absent on condition pages, intake forms, and authenticated portal pages?
  • Are all conversions routed server-side with PHI stripped before transmission?
  • Have you reviewed every URL parameter, page title, and form field for condition or identifier exposure?
  • Do you have dated documentation of your PHI-stripping logic and test payloads?
  • Have you reviewed your remarketing audiences for condition-derived membership?

For a forward-looking view of where enforcement is heading, review OCR Enforcement 2026: New Leadership Priorities Every Healthcare Marketer Must Know.

FAQ

Is Microsoft Ads advertising HIPAA compliant for healthcare?

Not by default. Microsoft does not sign a business associate agreement for Microsoft Advertising, so any transmission of PHI to Microsoft through the standard UET tag is an impermissible disclosure under HIPAA. Healthcare practices can still use Microsoft Ads, but only if they implement server-side conversion tracking, strip PHI before any data reaches Microsoft, and avoid building audience lists from condition-specific behavior.

How do I set up compliant Bing conversion tracking?

Replace the standard client-side UET tag with server-side conversion uploads through the Bing Ads API's Offline Conversion Import. Sanitize all event data on your server first: remove names, emails, phone numbers, IP addresses, condition identifiers, and any URL parameters that could constitute PHI. Document the stripping rules, keep audit logs, and re-verify after every site change.

Can healthcare practices use Microsoft Ads or Google Ads remarketing?

Generally no, especially for condition-specific or specialty-specific audiences. Remarketing or lookalike audiences built from health-page visits disclose sensitive medical context to a partner without a BAA. Some practices use generic, site-wide audiences excluding condition pages, but legal review is strongly recommended before launching any remarketing in healthcare.

What are the penalties for HIPAA violations involving ad tracking?

[7]HHS updated its civil monetary penalty amounts in the Federal Register effective January 28, 2026, applying the 2025 cost-of-living multiplier of 1.02598. [8]Under the current tiered structure, per-violation penalties run from a minimum in the low hundreds of dollars (lack of knowledge) up to a maximum of $2,190,294 per violation for willful neglect not corrected. Per-violation fines can add up quickly when many records or pages are affected, which is why large-scale tracking failures carry significant exposure.

Does Microsoft's UET Consent Mode satisfy HIPAA?

No. [2]UET Consent Mode addresses GDPR-style consent and became mandatory on May 5, 2025 for advertisers running campaigns targeting users in the EEA, UK, and Switzerland. It does not create a business associate relationship between you and Microsoft, and it does not prevent PHI from being transmitted by a user who clicks "accept all." HIPAA requires either a BAA with the tracking vendor or a valid patient authorization, neither of which a consent banner provides.

Simplify Microsoft Ads and Google Ads Compliance with Curve

Manual server-side tracking, custom PHI-stripping logic, and parallel implementations across Bing and Google can consume more than 20 hours of engineering time per platform, and a single missed parameter reintroduces risk. Curve replaces the client-side pixel with a server-side pipeline that strips PHI before any data reaches Microsoft or Google, signs a BAA with your practice, and works across both networks from one implementation. See how Curve automates compliant Microsoft Ads and Google Ads tracking.

Sources

  1. Google Ads Policy Help, Update to Healthcare and Medicines Policy (December 2024)
  2. Microsoft Advertising, Providing user consent signals on your Microsoft campaigns by May 5, 2025
  3. HHS Office for Civil Rights, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
  4. Dentons Health Law, Federal Court Overturns HHS Guidance on Online Tracking Technologies
  5. Dentons Health Law, HHS-OCR Revises its Guidance on Use of Online Tracking Technologies
  6. FTC, FTC to Ban BetterHelp from Revealing Consumers' Data, Including Sensitive Mental Health Information, to Facebook and Others
  7. Federal Register, Annual Civil Monetary Penalties Inflation Adjustment (January 28, 2026)
  8. HIPAA Journal, HIPAA Violation Fines (Updated for 2026)

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit