Curve Compliance FAQ: HIPAA-Compliant Ad Tracking Answered
Answers about Curve Compliance: what it does, the BAA, what data it collects and sends, consent, site speed, setup and what to share with your legal team.
Curve Compliance is a HIPAA-compliant ad tracking and attribution platform for healthcare organizations. It replaces the ad pixels on your site with one script, decides what each ad platform is allowed to receive, and sends conversions to Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn server-side, with a BAA on every plan. Below are direct answers to the questions marketers, practice owners and compliance teams ask most, from what Curve Compliance collects to what to send your legal team.
Book a call. Curve's team sets up Curve Compliance for you, typically live in about a week, and will walk through your own site and funnel on the call. Book a call with Curve.
Frequently Asked Questions
What is Curve Compliance?
Curve Compliance is conversion tracking built for healthcare marketing. One script on your site reports what visitors do to Curve's servers instead of to ad platforms. Curve Compliance turns the actions you choose into conversions and sends them to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn from its own servers, with a fixed list of fields for each platform. It also keeps the ad click when a patient books on a scheduler and credits bookings and visits back to the ad.
Who is Curve Compliance for?
Healthcare businesses that advertise and handle health information: clinics, telehealth brands, med spas, dental practices and DSOs, therapy and mental health practices, and multi-location groups. Marketing agencies use Curve Compliance to run tracking for several healthcare clients from one login. See Curve Compliance for telehealth and Curve Compliance for agencies.
How is Curve Compliance different from a CDP?
A customer data platform is built to collect data and route it to many tools. Curve Compliance is built for one job: getting conversions to ad platforms without health information. Events reach Curve's servers first, they go to the destinations you connect where each event's mapping allows it, and each platform receives a fixed list of permitted fields. A field that isn't on a platform's list can't leave, whatever the event contains. Curve Compliance works alongside your CRM and tag manager.
Is Curve Compliance HIPAA compliant?
Curve Compliance is built for HIPAA-regulated healthcare marketing and signs a Business Associate Agreement on every plan, covering the data Curve stores for you. Meta, Google Ads, TikTok and Microsoft Advertising do not sign BAAs, so Curve Compliance controls what they receive: neutral event names, a fixed list of fields per platform, PHI-like pattern detection, and contact identifiers off by default and SHA-256 hashed when enabled.
What data does Curve Compliance collect?
On each event, the Curve Compliance script sends the page address, page title and referring page, session details, an anonymous visitor ID that is not a name or an email, ad click IDs and UTM parameters when advertising consent allows, and the browser's user-agent. Before the page address leaves the browser, it redacts parts that look like contact, health, search or quiz data. The script leaves form fields alone, and form events send the milestone, such as "form submitted", never the answers.
How does Curve Compliance measure marketing performance?
Campaign Reporting in Curve Compliance puts ad spend from Google Ads and Meta next to the conversions Curve tracked, for every platform, campaign, ad set and ad, with revenue, ROAS and CPA. Five attribution models show how credit moves between ads, Deep Mode lists the conversions behind any number, and a prospect journey shows one person's ad clicks and visits in order. With HubSpot or WhatConverts connected, CRM revenue and close rate appear too.
Why is healthcare marketing so hard to measure?
Three reasons. Pixels come off healthcare sites because they can send health information to ad platforms, and the conversions they reported go with them. Patients book on schedulers and EHRs on other websites, where the ad click is lost. And the outcome that matters, an attended visit, happens days later in a system the ad platform never sees. Curve Compliance covers all three with server-side conversions, bridge tokens and outcomes credited back from webhooks, Keragon and offline uploads.
Do I need engineering help to use Curve Compliance?
No. Curve's team does the setup: the script, the scheduler connections, the event mapping for each ad platform and the BAA. Installing Curve Compliance means adding one snippet to your site, and after that your marketing team works in the Curve Compliance dashboard.
Will Curve Compliance slow down my website?
The Curve Compliance script loads asynchronously, so it doesn't block your page from rendering. It also replaces the Meta Pixel and other ad pixels on the pages it covers, so one script takes the place of several.
Does Curve Compliance send data to third-party tools?
Curve Compliance forwards events to the ad and analytics destinations you connect, and no others. Each event goes to a platform when its mapping allows it, and each platform receives a fixed list of permitted fields; everything else is stripped before sending. Values that look like an email address or a Social Security number are dropped wherever they appear, and Event Logs show every send.
How does Curve Compliance protect patient privacy?
In layers. The pixels that send page contents from the patient's browser come off your site. Events go to Curve's servers, where PHI-like patterns are flagged so they can be stopped at the source. Each ad platform receives a fixed list of fields under neutral event names, contact identifiers are off by default and SHA-256 hashed when enabled, and page titles, free text and form answers are never sent. A BAA covers what Curve Compliance stores.
Do I need a consent banner if I use Curve Compliance?
That depends on where your visitors are and which laws apply to you, so it's a question for your legal or privacy contact. Once you decide, Curve Compliance's consent management enforces it: it applies the rule for each visitor's region, shows a banner where opt-in is required, records every decision, honors Global Privacy Control, and holds back tracking and ad forwarding for visitors who haven't allowed it. You can also keep your existing consent tool.
Isn't a consent banner enough to stay HIPAA compliant?
No. The HHS online tracking bulletin says "Website banners that ask users to accept or reject a website's use of tracking technologies, such as cookies, do not constitute a valid HIPAA authorization." A banner records a preference. Curve Compliance controls what actually reaches each platform. See consent management vs HIPAA authorization.
How do I know if my website is leaking PHI?
Start with Curve Compliance's free website scan, which lists the pixels and trackers on a page. Then check what each one sends from your booking, intake and condition pages. Curve's team reviews what your site sends to Meta, Google and TikTok with you and shows what is likely triggering a flag. Once Curve Compliance is live, its Compliance Info screen counts any event that carries PHI-like values.
Why not just remove all tracking from our site?
Removing pixels stops them sending page contents to ad platforms, but Meta and Google then stop learning which clicks turn into patients, and your own reports lose the link between spend and bookings. Curve Compliance keeps both: conversions reach the platforms server-side without health information, and Campaign Reporting shows which campaigns bring in patients.
What support does Curve Compliance provide during implementation?
Curve's team does the implementation for you, typically live in about a week. It installs the script with your web person, sets up bridge tokens for your scheduler and incoming webhooks for outcomes, maps each event for each ad platform, checks delivery in Event Logs, and signs the BAA. If you connect an EHR through Keragon, the team helps with the field mappings. Book a call to scope yours.
What can I share with my legal, compliance or security team?
The BAA Curve Compliance signs, the list of fields each ad platform receives, and how consent choices are enforced. The BAA directory shows which other tools in your stack sign a BAA, with each vendor's own wording and a source link. The About Curve Compliance page covers the company and how the product works, and the HHS tracking bulletin, annotated covers the regulatory background.
Which booking systems and EHRs does Curve Compliance work with?
Plain booking links to IntakeQ, Calendly, Acuity, Jane App, OptiMantra, Boulevard, ZocDoc, Mindbody, Vagaro, Square, Setmore and Booker keep the ad click automatically, and Curve's team sets up GoHighLevel and embedded widgets. EHR and intake tools such as Healthie, Athenahealth and OptiMantra connect to Curve Compliance through Keragon. Booking systems, CRMs and call tracking can send outcomes by webhook, and any system can return them by CSV upload.
How much does Curve Compliance charge?
Curve Compliance is usage-based, and a BAA comes with every plan. Book a call and Curve's team will go through it for your site.
How does Curve Compliance compare with Freshpaint?
Both put a BAA-covered layer between your website and the ad platforms. Freshpaint says it "offers a Business Associate Agreement (BAA)" and describes a "block-by-default" approach. Curve Compliance signs a BAA on every plan, gives each ad platform a fixed list of fields, carries the ad click through schedulers with bridge tokens, and has its team do the setup, typically live in about a week. See Curve vs Freshpaint for small practices.
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit