Skip to main content
Guide

How to Make Facebook Ads HIPAA Compliant and Keep Tracking

Why the Meta Pixel is a HIPAA problem, where PHI leaks, what HHS says after AHA v. Becerra, and how Curve Compliance keeps Facebook conversion tracking.

8 min read

To make Facebook ads HIPAA compliant and keep conversion tracking, take the Meta Pixel off pages that handle health information and send conversions to Meta server-side instead, through a vendor that signs a BAA with you, using neutral event names, a fixed list of fields and hashed identifiers. Meta's own terms bar health information, so the work is controlling what Meta receives. Curve Compliance does this for clinics and telehealth brands. It replaces the pixel, sends conversions through Meta Conversions API, credits bookings to the ads that brought them in, and signs a BAA on every plan.

Book a call. Curve Compliance sends your Meta conversions server-side in place of the pixel, with neutral event names, PHI-like pattern detection and SHA-256 hashed identifiers, and signs a BAA on every plan. Book a call with Curve.

Why the Meta Pixel is a HIPAA problem

Meta does not sign a BAA, and its terms rule health data out. Section 1.h of Meta's Business Tools Terms says advertisers will not share data that "includes or is based on, directly or otherwise, health information," and adds: "The names you choose and criteria you establish for your events, conversions, and any custom audiences you create must not reflect, imply or be based on any category of information described in this Section 1.h." See Meta's entry in the BAA directory.

The pixel itself is the second problem. It runs in your visitor's browser and sends what it sees straight to Meta. You don't sit between the two, so whatever is on the page can go with each event, and you see what went only afterwards, if at all. On a healthcare site, the page often is the health information: the service, the condition or the booking step. Why healthcare sites remove the Meta Pixel goes through it page by page.

Where PHI leaks in Facebook tracking

Leak pointWhat Meta can receiveExample
Page URLsThe full address, including the path and query stringA weight loss consult page, or a site search for a symptom
Page titlesThe title of the page the event fired onA title such as "Book Your Anxiety Assessment"
Form fieldsOn some setups, the contents of a formA reason-for-visit answer or a quiz response
Automatic advanced matchingContact details the pixel finds in forms on the page, such as email and phone, hashedAn email typed into a booking form on a fertility page, tied to that page
Event namesWhatever the event is calledA custom event named depression_consult_booked

Hashing an email does not fix a leak. A hashed email is how Meta matches the event to a person, and the page it came from still says why they were there. Booking widgets are where many of these leaks sit, because the booking step is where names, emails and reasons for a visit meet the pixel.

Why sharing it with Meta is a HIPAA issue, and what changed in 2024

Sharing tracking data becomes a HIPAA issue when it relates to a person's health or care, identifies them, and goes from a covered entity to a vendor without the patient's authorization or a BAA. The HHS Office for Civil Rights applied that to tracking in its online tracking bulletin of December 2022, revised in March 2024: "Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors." The bulletin says tracking on public pages that let people book appointments or use a symptom checker "may have access to PHI in certain circumstances," and that tracking on logged-in pages such as patient portals generally does.

On June 20, 2024, in American Hospital Association v. Becerra, Judge Mark Pittman of the Northern District of Texas vacated one piece of the bulletin: the position that connecting a visitor's IP address with a visit to a public, unauthenticated page about a health condition or provider is enough, on its own, to trigger HIPAA. HHS appealed, and the appeal was dismissed. The rest of the bulletin stands, including the rules on booking and intake forms, patient portals, apps, BAAs and cookie banners, and that is where most clinic Facebook conversions happen. The HHS tracking bulletin, annotated after AHA v. Becerra goes passage by passage.

Low, medium and high-risk Facebook campaigns

Risk depends on what the landing page and the conversion reveal, not on the ad alone. Three examples:

RiskExample campaignWhat a pixel could send MetaThe safer setup
LowerA dental group promoting new-patient cleanings, landing on its homepageA page view on a general page. Lower is not zero: the same pixel usually fires on the booking pages too.Send the booking server-side under a neutral event name
MediumA med spa promoting injectable consultations, landing on a treatment page with a booking formThe treatment in the URL and page title, and a lead event tied to a hashed emailA neutral event name, your site address with no path, and contact fields off by default
HighA telehealth brand promoting weight loss medication through an eligibility quizQuiz answers in URLs or form fields, a condition in the page title, and a purchase event at checkoutNo pixel anywhere in the funnel; server-side conversions with neutral names, PHI-like pattern detection and no form answers

The HIPAA-compliant Facebook ads workflow

Instead of your site talking to Meta directly, the data goes from your site to Curve Compliance and then to Meta Conversions API, and Curve Compliance decides what Meta receives. Step by step:

  1. Remove the pixel. Take the Meta Pixel base code off every page Curve Compliance covers, so nothing reaches Meta from the patient's browser. Moving off the pixel safely covers the order of operations.
  2. Install one script. The Curve Compliance script reports page views, the events you configure and the visitor's ad click IDs to Curve's servers. Before the page address leaves the browser, it redacts parts that look like contact, health, search or quiz data.
  3. Check every event for PHI. Curve Compliance screens incoming events for PHI-like patterns, such as a condition name or an email in a URL, and flags them on its Compliance Info screen so they can be stopped at the source. Curve's team helps find the event and change it.
  4. Map neutral events. Each conversion gets a name that says nothing about care, such as booking_complete, never weight_loss_consult. Meta's terms apply this to event names as well as to the data.
  5. Send a fixed list of fields. Meta receives the event name and time, the fbclid and Meta cookies, your site address with no page path or query string, an anonymous visitor ID, the user-agent and a value if there is one. Email, phone and other contact fields are off by default and SHA-256 hashed when enabled. Page titles, free text and form answers are never sent.
  6. Credit the bookings. Bridge tokens keep the ad click when a patient books in IntakeQ, Calendly, Jane App or another scheduler, and outcomes from webhooks, Keragon or offline uploads are credited to the original click, so Meta learns from bookings and visits, not just page views.
  7. Check what Meta accepted. Event Logs in Curve Compliance show each event sent to Meta and whether Meta accepted it.

Where a visitor has declined advertising on your consent banner, Meta receives the event with contact fields removed. That is the difference between server-side tracking and a compliant setup: server-side is the route, and the field list, the event names, the consent rules and the BAA are what keep health information out.

Meta's Health and wellness restrictions

Meta can place a website or dataset in its Health and wellness data source category, and the category can carry one of three restrictions: core setup, which limits custom parameters and the parts of URLs after the domain; a restriction on certain standard events; or full restrictions. Meta assigns the category itself. No tracking tool removes it, and sending events server-side doesn't change it, because Conversions API events land in the same dataset. What the right setup does is keep campaigns optimizing on the events Meta still accepts and keep bookings and attended visits in your own reporting, so budget decisions don't depend on what Meta can see. Curve Compliance does both, and its Campaign Reporting puts Meta spend next to the bookings Curve tracked. See what "data sharing restrictions applied" means.

Book a call. Curve's team will look at what your site sends Meta today, show what is likely triggering a flag, and set up server-side tracking that keeps your campaigns measured. Book a call with Curve.

Frequently Asked Questions

Are Facebook ads HIPAA compliant?

The ads themselves can be. The risk is the Meta Pixel on pages that handle health information, because it sends page addresses, titles and sometimes form contents to Meta from the patient's browser. Curve Compliance replaces the pixel with server-side conversions that carry a neutral event name, a fixed list of fields and hashed identifiers, under a BAA it signs on every plan.

Does Meta sign a BAA?

No. Meta's Business Tools Terms say advertisers will not share data that includes or is based on health information. Send Meta conversions that carry none, through a vendor that signs a BAA with you, such as Curve Compliance.

Is the Meta Conversions API HIPAA compliant on its own?

No. The Conversions API is a route, and it carries whatever you send it. What matters is what goes into each event. Curve Compliance sends a fixed list of fields to Meta, under neutral event names, with identifiers SHA-256 hashed when enabled, and detects PHI-like patterns before data reaches Meta.

Did the 2024 court ruling end the HHS tracking rules?

No. AHA v. Becerra vacated one position: that an IP address plus a visit to a public page about a health condition or provider is enough, on its own, to trigger HIPAA. The rules on booking and intake forms, patient portals, apps, BAAs and cookie banners still apply.

What happens to tracking if Meta restricts my dataset?

Campaigns can keep running on the events Meta still accepts. Curve Compliance keeps sending those events server-side and keeps every booking in Campaign Reporting, so you can still see which ads bring in patients.

How long does it take to move off the Meta Pixel?

Curve's team does the setup for you, typically live in about a week, including the script, the event mapping for Meta and your other ad platforms, the scheduler connections and the BAA.

Next step

Check your own site

See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.

Or book a tracking audit

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit