Custom Intent Audiences for Healthcare: Building HIPAA-Compliant Google Ads Targeting
Google Ads custom segments (the audience product previously known as Custom Intent) let healthcare advertisers reach users actively researching specific products and services based on the keywords...
Google Ads custom segments (the audience product previously known as Custom Intent) let healthcare advertisers reach users actively researching specific products and services based on the keywords they search, the URLs they visit, and the apps they use.[1] That precision is exactly what makes them attractive, and exactly what makes them risky. Sensitive health interest categories sit at the center of Google's Personalized Advertising policy, and OCR has spent the past three years aggressively scrutinizing how covered entities transmit data to ad platforms.[2]
This guide explains how to use custom intent audiences healthcare marketers can deploy without violating HIPAA, what Google's policy actually permits, and how to build a compliant tracking stack that still produces measurable conversions. It is built for marketing leads at medical practices, multi-location groups, digital health companies, and agencies that manage HIPAA Google Ads targeting for regulated clients.
Google Ads as a Healthcare Acquisition Channel
Why Google Ads Matters for Patient Acquisition
Google Search remains the dominant entry point for patients researching symptoms, comparing providers, and booking appointments. Custom segments amplify that intent signal by letting advertisers build audiences from keywords prospective patients enter, websites they visit, and apps they use on mobile.[3] For Display, Demand Gen, Gmail, and YouTube campaigns, that capability is one of the few ways to reach high-intent prospects without relying on the remarketing tools that healthcare advertisers are largely prohibited from using.
Healthcare Advertising Policies on Google Ads
Google classifies a wide range of medical topics as sensitive. The Health category in the Personalized Advertising policy covers physical or mental health conditions (including sexual and chronic health), products and procedures to treat chronic conditions, intimate body parts and functions, and invasive procedures like cosmetic surgery and injections.[4]
One policy nuance matters for B2B planning: Google's Personalized Advertising policy clarifies that the Health sensitive interest category excludes content directed at healthcare professionals in their professional capacity, restoring limited HCP targeting paths.[5] For deeper B2B strategy, see our guide on HCP targeting expansion for B2B healthcare advertising.
The operational rule for consumer healthcare advertisers is clear: Custom Segment audiences using sensitive creative assets or pointing to sensitive landing pages will only serve with Display campaigns to non-sensitive audiences or contextually, and all other campaigns using such custom segments will not be eligible to serve.[4]
Platform Terminology Healthcare Marketers Need
- Custom Segments: Google's rebrand of Custom Intent and Custom Affinity, unified in 2021 into a single audience type built from keywords, URLs, and apps.
- In-market segments: Predefined Google audiences reaching users with recent purchase intent, including curated health-related segments.[6]
- Your data segments: Formerly "remarketing"; reaches users who have already interacted with your business.
- Audience signals: Hints applied to Performance Max campaigns, since PMax does not allow direct audience targeting.[1]
HIPAA Compliance Deep Dive for Google Ads
How Data Flows from Healthcare Sites to Google
A standard Google Ads conversion setup uses the Google tag (gtag.js) or Google Tag Manager to fire client-side events when a user submits a form, books an appointment, or completes a checkout. Each event carries a payload: page URL, referrer, click identifiers (gclid, gbraid, wbraid), browser fingerprint, device ID, and IP address. If the URL contains a condition name or appointment type, or the form payload includes the patient's name, email, or reason for visit, that data has now left the covered entity's environment and entered Google's ad systems.
Server-side tracking via the Google Ads API (Enhanced Conversions for Leads, offline conversion imports) gives the covered entity a control point to strip identifiers before they ever leave its servers. Client-side tags do not offer that control.
Where PHI Exposure Occurs in Custom Intent Audiences Healthcare Campaigns
OCR's 2024 tracking technologies guidance identifies several risk vectors. If tracking technologies collect an individual's email address or reason for seeking care when the individual visits a webpage and makes an appointment with a provider or enters symptoms into a tool to obtain a health analysis, HIPAA applies and the entity needs either a BAA with the vendor or the user's authorization.[7] The guidance also makes clear that disclosures to ad-tech vendors for marketing purposes require HIPAA-compliant authorization, and covered entities may only disclose health information to digital tracking vendors who first sign a business associate agreement.[8]
One important nuance: in American Hospital Association v. Becerra, the US District Court for the Northern District of Texas vacated the portion of OCR's bulletin that treated an IP address plus a visit to an unauthenticated public webpage about a health condition as automatically triggering HIPAA obligations.[9] The rest of the bulletin, including the rules for authenticated portals, appointment scheduling, symptom checkers, and any combination of identifiers with health-seeking activity, remains in effect. OCR has also stated it is prioritizing HIPAA Security Rule compliance in investigations involving online tracking.[2]
Compliant vs. Non-Compliant Google Ads Features
- Standard Google tag (gtag.js) on health pages: Not compliant out of the box. Captures URLs, IP, device ID, and any unredacted form fields.
- Google Ads API / Enhanced Conversions for Leads with server-side hashing: Can be compliant when PHI is stripped before transmission and only hashed, non-PHI identifiers reach Google.
- Remarketing / "Your data" segments: Generally off-limits for consumer healthcare. Audiences built from visits to pages about specific conditions, symptoms, or treatments fall under Google's sensitive interest restrictions.[4]
- Customer Match (uploaded patient lists): High risk. Uploading a list derived from PHI to Google constitutes a disclosure and requires a BAA, which Google does not sign for Google Ads.
- Custom Segments based on keywords/URLs/apps: Compliant in concept, because audiences are built from generalized intent signals rather than identified patient data, as long as the campaign does not pair them with sensitive creative or landing pages in ways the policy prohibits.
- Lookalike / Similar audiences: Removed for most use cases on Google Ads; even where available, seeding from PHI-derived lists is non-compliant.
Step-by-Step Compliant Setup
Pre-Implementation Audit
- Inventory every tag firing on the site, including Google tag, Floodlight, Google Tag Manager containers, and any third-party scripts loaded by your CMS.
- Map data flows for each conversion event: what data enters the dataLayer, what gets posted to Google, and whether any URL parameter or form field can carry PHI.
- Identify PHI exposure points, especially confirmation pages where URLs include condition names, provider names, or appointment types.
- Review vendor agreements. Google does not sign BAAs for Google Ads, so any direct flow of PHI to Google Ads is an impermissible disclosure unless the user has signed a HIPAA-compliant authorization.
Compliant Tracking Configuration
- Remove or restrict the standard Google tag on pages that handle PHI (intake forms, scheduling, patient portals, symptom checkers).
- Route conversions server-side through the Google Ads API using Enhanced Conversions for Leads or offline conversion imports. Send only the gclid plus hashed, non-PHI identifiers your system has generated.
- Configure PHI stripping rules at the server. URL parameters, form field names like condition, diagnosis, provider, email, phone, dob, and any free-text reason fields should be filtered before any payload is constructed for Google.
- Define conversion events that describe business outcomes (Lead, Booking, Qualified Consult) without descriptive labels that reveal condition or treatment.
This is where Curve's no-code implementation matters. Manually rebuilding a server-side tagging architecture, writing PHI redaction logic, validating it across every form variant, and maintaining it as the site changes typically consumes 20+ engineering hours per property. Curve handles PHI stripping, server-side transmission via the Google Ads API, and signs a BAA with the covered entity, so the compliance gap closes without engineering rework.
Campaign Structure for Compliance
- Account-level: Disable Google Signals on any GA4 property tied to ad personalization on PHI-containing pages. Restrict ad personalization for sensitive properties.
- Campaign-level: Avoid Display and Demand Gen formats that pair sensitive landing pages with custom segments unless you've reviewed Google's restricted targeting rules for that combination.[4]
- Ad group level: Use custom segments as positive intent signals (keywords, competitor URLs, professional association sites) rather than building audiences from your own site visitors.
- Audience creation: Build custom segments from public-domain search behavior (e.g., "physical therapy near me," "pelvic floor specialist," "Invisalign cost"), not from CRM exports.
Verification and Testing
- Use the browser network panel and Tag Assistant to confirm no PHI parameters appear in the outgoing request payload on form submissions.
- Inspect the server-side container's incoming and outgoing payload logs to validate that PHI fields are dropped before the API call.
- Document the data flow diagram, redaction ruleset, and test results as part of your Security Rule risk analysis. OCR's principal interest is ensuring regulated entities have identified, assessed, and mitigated risks to ePHI when using online tracking technologies.[2]
- Schedule quarterly audits, since site changes routinely reintroduce PHI into URL parameters and form payloads.
Custom Intent Audiences Healthcare Strategies That Convert
Ad Types That Work for Healthcare
Search remains the highest-intent format. For prospecting beyond Search, custom segments paired with YouTube and Demand Gen are the most controllable formats because they let you define audiences from upstream behavior (keywords, competitor URLs) rather than retargeting your own site visitors. Custom segments can be applied to Display, Demand Gen, Gmail, and Video campaigns, and used as audience signals on Performance Max.[1]
Targeting Without PHI
Build custom segments using only public, non-identified intent signals:
- Search-term seeds: Enter terms your ideal patient would search on Google properties. These function as search-driven intent signals on Search, YouTube, and Demand Gen, and as interest signals on Display.[3]
- Competitor URLs: Add domains of competing practices, comparison sites, and provider directories. Google identifies users with similar browsing patterns.
- Adjacent apps: Reference apps your audience likely uses (insurance member apps, fitness trackers, wellness tools).
- Geographic layering: Use service-area targeting at the city or radius level. Avoid ZIP-level targeting in combination with sensitive creative.
What to avoid: building segments that infer a specific health condition for the user. A healthcare advertiser cannot reach people based on inferred medical status under Google's sensitive interest restrictions; the policy is engineered around present intent, not past health behavior.[4]
For specialty-specific approaches, see our deeper guides on in-market audience targeting for physical therapy, mental health search targeting for psychiatry practices, and safe Google Display Network targeting for healthcare.
Conversion Tracking Done Right
- Track business outcomes, not clinical detail: Lead, Scheduled Consult, Qualified Lead, Booking Confirmed.
- Assign conversion values tied to average patient LTV by service line, computed server-side, so Smart Bidding can optimize without seeing the underlying clinical category.
- Use Enhanced Conversions for Leads with first-party hashed identifiers that are not derived from PHI fields.
- Attribute through offline imports when the conversion event happens after a clinical interaction, since this prevents real-time payloads from carrying treatment information.
Common Mistakes to Avoid
Firing the Google tag on appointment confirmation pages with descriptive URLs. A URL like /confirmation?service=oncology-consult sent to Google constitutes disclosure of health-related activity. Strip the parameter or redirect to a generic URL before the tag fires.
Uploading a patient list to Customer Match. Any list derived from PHI is a disclosure to Google. Google does not sign BAAs for Google Ads, making this a clear impermissible disclosure under HIPAA.[8]
Building custom segments from your own site's URL patterns. Seeding a segment with yoursite.com/conditions/depression-treatment teaches Google's models to associate users with that condition. Use competitor and category-level URLs instead.
Naming conversion events with clinical terms. "Diabetes_Lead_Submit" passed back through the API carries diagnostic information. Use neutral event names.
Ignoring enforcement risk. OCR confirmed that 22 investigations of data breaches and complaints resulted in civil monetary penalties or settlements in 2024, making it one of the busiest years for HIPAA enforcement.[10] Tracking technology disclosures remain an active investigation theme alongside ransomware and right-of-access cases.
Self-audit checklist:
- No Google tag fires on authenticated patient portal pages.
- No URL parameter on a conversion page contains condition, procedure, or provider names.
- No form field labeled with clinical content is allowed into the dataLayer.
- Conversion events use generic business labels.
- No Customer Match list is sourced from CRM or EHR data without separate authorization.
- Server-side container logs are reviewed quarterly.
- A BAA is in place with every vendor that touches PHI in the tracking stack.
FAQ
Is Google Ads HIPAA compliant for healthcare advertisers?
Google Ads itself is not HIPAA compliant, and Google does not sign business associate agreements for the Google Ads product. Covered entities can still advertise on Google Ads compliantly by ensuring no PHI is transmitted to Google, which generally requires server-side tracking via the Google Ads API with PHI stripped before transmission, and by working with a vendor that will sign a BAA for the tracking layer.
How do I set up compliant Google Ads conversion tracking?
Replace client-side tags on PHI-handling pages with a server-side architecture that captures the gclid, applies PHI redaction at the server, and transmits hashed identifiers to Google via Enhanced Conversions for Leads or offline conversion imports. Validate the outbound payload contains no condition, treatment, provider, email, or phone data unless it has been irreversibly hashed and is permitted under your authorization framework.
Can healthcare practices use Google Ads remarketing?
Generally no. Google's Personalized Advertising policy restricts audiences built from visits to pages about specific conditions, symptoms, or treatments, which eliminates most consumer-healthcare remarketing use cases.[4] Custom segments built from external keywords, competitor URLs, and apps are the more defensible alternative for reaching high-intent prospects, and for Meta-based comparisons see our analysis of when broad targeting beats custom audiences.
What are the penalties for Google Ads HIPAA violations?
OCR has settled or imposed civil money penalties in 152 cases totaling roughly $144.8 million to date, with annual penalty tiers adjusted for inflation and the maximum Tier 4 penalty (willful neglect, uncorrected) running into the millions per violation category per year.[11] Beyond OCR, state attorneys general and class-action plaintiffs have pursued damages over pixel-based disclosures to ad platforms.
Are custom intent audiences different from custom segments?
They are the same product under different names. Google blended Custom Intent and Custom Affinity into Custom Segments in 2021, although the older terminology is still widely used. Newly created custom audiences use the AUTO type rather than INTEREST or PURCHASE_INTENT.[3]
Simplify Google Ads Compliance with Curve
Stop worrying about PHI exposure in your Google Ads tracking. See how Curve automates compliant Google Ads tracking with PHI stripping, server-side transmission via the Google Ads API, no-code setup, and signed BAAs.
Sources
- Google Ads Help: About custom segments
- HHS OCR: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- Google Ads API: Custom Audiences
- Google Advertising Policies: Health in personalized advertising
- Google Advertising Policies: Update to the Personalized advertising policy
- Google Ads Help: About audience segments
- Norton Rose Fulbright Data Protection Report: HHS updates online tracker guidance
- Dentons On Call: HHS-OCR Revises its Guidance on Use of Online Tracking Technologies
- Nixon Peabody: Portions of OCR's bulletin on online tracking technologies deemed unlawful
- HIPAA Journal: HIPAA Violation Fines
- HHS OCR: Enforcement Highlights
Related articles
- GuideGoogle Ads Healthcare Audience Targeting: Which Segments Are HIPAA-Safe (and Which Leak PHI)
- GuideHealthcare In-Market vs Affinity Audiences: Which Google Ads Segment Converts
- GuideGoogle Ads "Health Services" In-Market Audience: HIPAA-Safe Targeting for 2026
- GuidePhysical Therapy Google Ads: In-Market Audience Targeting That Fills Your Schedule
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit