Free HIPAA Website Scanners Compared: What Each One Checks
Free HIPAA website scanners compared: what each one checks, whether it needs an email, and what a scan can and cannot tell a clinic.
Free HIPAA website scanners from Curve Compliance, HIPAASCAN, Sounder and Freshpaint, along with general privacy checkers such as The Markup's Blacklight, load your public web pages and list the tracking pixels and scripts that can send visitor data to Meta, Google, TikTok and other vendors. The Curve Compliance scanner is free, shows an overall risk level in seconds with no email, and matches each page against 75 known tracking scripts in 11 categories. When a scan turns up ad pixels, Curve Compliance replaces them with server-side conversion tracking under a BAA on every plan. This guide compares nine free scanners on what each checks and whether it needs an email, as checked on October 10, 2026.
Book a call. Found the Meta Pixel or a Google tag on your site? Curve's team will review what your website sends to Meta, Google and TikTok with you and show what's likely triggering a flag. Curve signs a BAA on every plan, and most customers are live in about a week. Book a call with Curve.
Free HIPAA website scanners at a glance
Curve Compliance publishes this guide and lists its own scanner first. Every other row comes from that scanner's own page, opened on October 10, 2026. Where a page did not say whether it needs an email, we ran a test scan of example.com. Scanners whose page we could not open are not listed.
| Scanner | What it checks | Pages | Email needed? | Results | Source |
|---|---|---|---|---|---|
| Curve Compliance | 75 known tracking scripts in 11 categories, each with a risk level | The public URL you enter | No for the overall risk level; a work email unlocks the full list | On screen, in seconds | Curve Compliance |
| HIPAASCAN (Hipalytics) | Scripts, trackers and pixels, including GA4, Tag Manager, ad pixels, forms, widgets and session replay | The URL you enter | Yes, a business email to view the report (test scan) | Report in under 30 seconds | Hipalytics |
| Sounder | Over 50 tracking technologies, including ad pixels, GA4, YouTube and Maps embeds, cookies and form plugins | Your website; larger sites take longer | Yes, with name and organization | Emailed in 10 to 20 minutes; one site per hour | Sounder |
| Freshpaint Web Tracker Report | Scripts, pixels and tags firing, the risk of each, and vendors that won't sign BAAs | Page by page, where each tracker fires | Yes, with your website on a request form | A custom report you request | Freshpaint |
| Blacklight (The Markup) | Ad trackers, third-party cookies, fingerprinting, session recording, keystroke capture, Facebook, TikTok and Google | Homepage plus one randomly selected deeper page | No, URL only | On screen in 30 seconds to one minute | The Markup |
| Captain Compliance cookie scanner | Cookies, pixels, trackers and consent banner behavior | The page you enter | Yes, a free account | In your account, with report export | Captain Compliance |
| PixelFly tracking checker | GA4, Meta Pixel, TikTok Pixel and 15+ other tracking scripts | The page you enter | No account needed | On screen, with a tracking health score | PixelFly |
| Conversios tracking checker | GA4, Meta Pixel, Google Ads, Microsoft Ads, TikTok Pixel, events and consent mode | Your store's URL | Yes, an email to get the report (test scan) | A typical scan in under 2 minutes | Conversios |
| ByteTools privacy scanner | Analytics, tag managers, ad pixels, session replay, fingerprinting and widgets | The HTML or HAR file you paste or upload | No | In your browser; nothing is uploaded | ByteTools |
Curve Compliance, HIPAASCAN, Sounder and Freshpaint are built for healthcare. The other five are general tracker checkers, which still show the ad and analytics scripts a HIPAA review starts with.
What each free scanner checks
- Curve Compliance. The scanner page says it "loads the page, matches its HTML against 75 known tracking scripts in 11 categories, and lists each one it finds with a risk level." The overall rating is critical, high, medium or low; tag managers, consent tools and performance monitoring are listed but don't raise the rating on their own. AI assistants can request
/scan/{domain}.mdfor the same scan of a site's homepage as a markdown report. - HIPAASCAN by Hipalytics. HIPAASCAN says it "inspects every script, tracker, and pixel for HIPAA risk" and promises a report in under 30 seconds. On our test scan, the results screen asked us to "Enter your business email to view your HIPAA compliance report."
- Sounder. Sounder says "Our scanner uses a headless browser that visits your website the same way a real visitor would," and checks "over 50 tracking technologies in all." "Results are typically emailed within 10 to 20 minutes," one website per hour, and the scanner is designed for US healthcare websites.
- Freshpaint. Freshpaint offers a free Web Tracker Report. Its request page says "Freshpaint scans your website to identify all third-party scripts, pixels, and tags currently firing," and the report maps each tracker page by page and shows "which vendors won't sign BAAs." Its Web Tracker Monitoring product adds ongoing monitoring with weekly scans and alerts.
- Blacklight, from The Markup. Blacklight, a real-time website privacy inspector, asks only for a URL. Its methodology says it "visits its homepage as well as an additional randomly selected page deeper inside the same website." While a scan runs, the Blacklight page says it "normally takes between 30 seconds and one minute to finish all tests."
- Captain Compliance. The Captain Compliance cookie scanner "Verifies Reject works" on the consent banner, checks Global Privacy Control and dark patterns, and "Tests for over 100 jurisdictions." To run it, "Create an account and start your first free scan today."
- PixelFly. PixelFly works by "looking for tracking script patterns in your HTML," and "You can scan unlimited websites without creating an account."
- Conversios. Conversios is written for online stores. It checks whether key events fire and audits cookie setup and consent mode, and "A typical scan takes less than 2 minutes." On our test scan, the full report sat behind an email field.
- ByteTools. ByteTools reads HTML or a HAR file you paste or upload, and runs in your browser: "No HTML content is uploaded, stored, or transmitted."
What a scan can and cannot tell you
A scan answers the first question in a website privacy review: which vendors' scripts load on your pages. That matters most where patients act. The HHS bulletin on online tracking technologies says tracking on a regulated entity's webpage "that permits individuals to schedule appointments or use a symptom-checker tool without entering credentials may have access to PHI in certain circumstances." Scanning your booking, contact and condition pages shows which vendors could receive that data.
Scanners that take a URL load your pages the way an anonymous visitor does, so a few things sit outside what they show:
- Pages behind a login. Patient portals need credentials, so a public scan does not reach them. HHS says tracking technologies on these user-authenticated pages "generally have access to PHI." Test them with a test account.
- Server-side calls. Data your server, scheduler or CRM sends straight to a vendor never passes through the page. ByteTools lists "Server-side tracking or data broker activity" among the things its scanner cannot see.
- What a form sends. A scan shows that a form plugin or pixel is on the page. To see what a submission sends, submit test data and watch the requests.
- Scripts that wait for consent. Some scripts load only after a visitor clicks Accept, so results can differ by consent choice. The Captain Compliance scanner tests both.
- Contracts. A scan cannot tell you whether you have a BAA with a vendor it finds. The BAA Directory quotes common vendors' own terms.
A scan result is not a legal finding either. HHS says tracking technologies on "many unauthenticated webpages" do not have access to PHI, and its bulletin notes that on June 20, 2024, a federal court in American Hospital Association v. Becerra vacated part of the guidance about unauthenticated public pages. Whether a script on a given page is a HIPAA problem depends on the page, the data the script collects and your agreements, so talk to your counsel about your own obligations.
The pixels scans find most on healthcare sites
Curve's scanner page says "The Meta Pixel, the Google Ads tag and the TikTok Pixel are the scripts healthcare sites most often carry." None of the three platforms signs a BAA for ad tracking, according to their entries in the BAA Directory:
- Meta Pixel. Meta's Business Tools Terms say you will not share data with Meta that includes or is based on health information. See is the Meta Pixel HIPAA compliant.
- Google Ads tag and Google Analytics. Google says it does not intend its Google Ads call features to create HIPAA obligations, and that it does not offer BAAs for Google Analytics.
- TikTok Pixel. TikTok says it does not allow advertisers to share health information.
Curve's scanner rates session recording and call tracking scripts, along with ad pixels, as the highest risk. Booking widgets are another common gap; see Booking Widgets: A PHI Leak Audit.
How to get the most from a free scan
- Scan the pages patients use. Run your homepage, condition and treatment pages, booking page, contact form and thank-you page. The Curve Compliance scanner takes any public URL, so you can scan each one.
- Run a second scanner. Each tool uses its own script list, so a second scan is a quick cross-check.
- List every vendor. Write down each script and the company behind it, then check which ones sign a BAA in the BAA Directory.
- Test what a scan cannot reach. Sign in to the portal with a test account and submit forms with test data.
- Rescan after changes. A new plugin, redesign or campaign tag can add scripts. Scan again and keep the reports.
For a fuller method, read the healthcare pixel audit guide.
What to do when a scan finds an ad pixel
Deleting the pixel also stops the conversions your campaigns optimize on. Curve Compliance keeps them flowing: it replaces browser ad pixels with one script and sends conversions server-side, from Curve's servers to Meta Conversions API, Google Ads, TikTok, Microsoft Advertising and LinkedIn.
- A fixed list of fields. Each platform receives only a fixed list of fields. Contact identifiers are off by default and SHA-256 hashed when turned on, and events can use neutral names.
- PHI-like patterns flagged. Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, before data reaches an ad platform, and flags them so they can be stopped at the source.
- A record of what went out. Event Logs show what Curve sent to each platform and what the platform accepted.
- Bookings still credited. Curve keeps the ad click when a patient books in IntakeQ, Calendly, Jane App, ZocDoc and other schedulers, even days later.
- Done for you, under a BAA. Curve signs a BAA on every plan, and Curve's team does the setup. Most customers are live in about a week.
Curve's BAA covers the data that passes through Curve; your scheduler, CRM and other vendors each need their own. Read more on Curve conversion tracking and how clinics move from browser pixels to server-side tracking.
Sources, checked October 10, 2026: Curve Compliance scanner; HIPAASCAN; Sounder; Freshpaint; Freshpaint report form; Blacklight; Blacklight methodology; Captain Compliance; PixelFly; Conversios; ByteTools; HHS, online tracking technologies; AHA v. Becerra opinion; and the Curve Compliance BAA Directory.
Frequently Asked Questions
Is there a free HIPAA website scanner?
Yes. The Curve Compliance scanner is free and shows a page's overall risk level in seconds. HIPAASCAN, Sounder and Freshpaint's Web Tracker Report are also free and built for healthcare, and Blacklight, PixelFly and ByteTools are free general tracker checkers.
What does a HIPAA website scan check?
It lists the third-party scripts that load on your pages, such as ad pixels, analytics, session recording, chat and call tracking. Healthcare scanners such as Curve Compliance, HIPAASCAN and Freshpaint rate the risk of each one, and some scanners also flag embedded maps, videos, form plugins and consent banner behavior.
Can a website scanner see my patient portal?
Not a public scan, because portal pages need a login. HHS says tracking technologies on user-authenticated pages "generally have access to PHI," so test the portal signed in with a test account and ask the portal vendor which scripts it loads.
Does a clean scan mean my website is HIPAA compliant?
No. A scan shows which scripts load on public pages at that moment, not logged-in pages, server-side data flows, what forms send, or whether you have a BAA with each vendor. Curve Compliance helps with ad tracking: it replaces browser ad pixels with server-side conversion tracking under a BAA on every plan.
Which tracking pixels show up most on healthcare websites?
Curve's scanner page names the Meta Pixel, the Google Ads tag and the TikTok Pixel as the scripts healthcare sites most often carry. None of the three platforms signs a BAA for ad tracking, according to the BAA Directory.
Do free HIPAA scanners need my email?
Some do. Sounder, HIPAASCAN, Freshpaint and Conversios ask for an email before the report, and Captain Compliance needs a free account. Curve Compliance shows the overall risk level without one and unlocks the full list with a work email. Blacklight, PixelFly and ByteTools ask only for a URL or the page HTML.
How often should a clinic rescan its website?
After every change that could add a script, such as a new plugin, redesign, booking tool or campaign tag, and on a fixed schedule. Save each report so you can show what changed.
What should I do if a scan finds the Meta Pixel?
List the pages it runs on, then plan its replacement. Curve Compliance replaces browser ad pixels with one script and sends conversions server-side to Meta Conversions API and other ad platforms, under a BAA on every plan. Book a call and Curve's team will review what your website sends with you.
Talk to Curve Compliance
Book a call. Run the free scan, then let Curve's team review what your website sends to Meta, Google and TikTok with you and set up server-side conversion tracking under a BAA on every plan. Book a call with Curve.
Related articles
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Curve's team sets up HIPAA-compliant ad tracking for you, and most customers are live in about a week.
Book a free tracking audit