Google Tag Gateway on Healthcare Sites: What It Changes
Google tag gateway serves Google tags from your own domain, but measurement events are still forwarded to Google. What that means for HIPAA tracking.
Google tag gateway for advertisers changes where your Google tag loads from, not who receives the data. Google's help centre says the gateway "loads the tag from your domain and sends measurement events to your domain, where they are forwarded to Google." On a clinic or telehealth site, that means the gateway does not make a Google tag on a booking or intake page HIPAA-safe. Curve Compliance takes a different route: server-side conversion tracking in place of the browser tag, set up by Curve's team with a BAA on every plan.
Book a call. Curve Compliance sets up HIPAA-compliant, server-side conversion tracking for Google, Meta, TikTok, Microsoft and other ad platforms. Curve's team does the setup in about a week, and a BAA comes with every plan. Book a call with Curve.
What Google tag gateway is
Google announced the gateway on May 2, 2025 and began rolling it out the following week. It lets you deploy a Google tag "using your own first-party infrastructure, hosted on your website's domain," through a content delivery network such as Cloudflare or Akamai, a load balancer or a web server. You switch it on from the Google tag's Admin settings with no change to the tag code on your pages. It requires an existing Google tag.
Google gives three reasons to use it. It reports an 11% uplift in signals for advertisers who configured it. Loading from your own domain makes measurement more durable. And Google said gateway tags would get confidential computing by default, and its Cloudflare setup page describes a Trusted Execution Environment. In Google's words, the data is processed "before it's encrypted and sent to Google for measurement and analytics."
What stays the same for HIPAA
Three things do not change.
- The script still runs in the visitor's browser. It is the same Google tag, loaded from a different address, and it still sees the page it runs on.
- Google still receives the events. The gateway forwards measurement events to Google, so anything in them still reaches Google.
- Google's position on PHI is unchanged. Its Google Analytics help article on HIPAA says HIPAA-regulated entities "must refrain from exposing to Google any data that may be considered Protected Health Information," and that Google "does not offer Business Associate Agreements in connection with this service." It adds that authenticated pages "are likely to be HIPAA-covered" and should not carry Analytics tags.
The HHS tracking bulletin is about what is disclosed to the tracking vendor, not which domain the script loads from. Its warning about trackers on booking and symptom-checker pages still applies.
The consent setting to check
Google's setup instructions include a warning: "Enabling this feature affects Google tag firing behavior. If your current tag behavior is impacted by user consent actions, adopt Consent Mode and review your consent settings to ensure your preferences are respected." A consent tool that recognizes Google tags by their Google address may treat a tag served from your own domain differently. After switching the gateway on, test that declined visitors are still honored. Our guide to Google Consent Mode v2 for healthcare covers the settings.
Gateway plus server-side tagging
Google describes pairing the gateway with server-side Google Tag Manager, where you "can cleanse, enrich, and control exactly what data is forwarded to Google." That gives you a place to filter. The filtering rules are yours to design and keep current as pages, forms and campaigns change, and whatever passes the filter still goes to Google.
Before you switch it on
- List every page the Google tag runs on. Take it off pages behind a login and pages tied to providing care, such as booking and intake, in line with Google's own HIPAA guidance for Analytics.
- Check what the tag collects from forms on the pages that remain.
- Read your conversion action names and parameters for conditions, services or drug names, and rename them neutrally.
- After enabling the gateway, test that visitors who decline tracking are still honored.
- Record the change in your HIPAA risk analysis, as the HHS bulletin expects for tracking technologies.
What a healthcare site should send Google
Keep conversions to what Google needs to match and optimize: the click ID, the time of the conversion, a neutral conversion action name, an optional value, and a hashed email or phone formatted to Google's specification where there is no click ID. Our guides on what clinics should send through Google Ads Data Manager and server-side Enhanced Conversions go field by field.
How Curve Compliance fits
Curve sends Google Ads conversions server-side in place of the browser tag, with neutral event names, SHA-256 hashing to Google's requirements and PHI-like pattern detection on outgoing data. Attribution is kept through booking tools, and consent management applies visitors' choices to every send. The same setup covers Meta, TikTok, Microsoft, Reddit, Amazon, ChatGPT Ads and others. Curve's team sets it up in about a week, with a BAA on every plan.
Book a call. See what your Google tag sends today, and what the same conversions look like sent server-side. Book a call with Curve.
Frequently Asked Questions
Does Google tag gateway make Google Ads tracking HIPAA compliant?
No. It changes where the tag loads from and routes events through your domain, but Google's own documentation says those events are forwarded to Google. What the tag collects on health pages still reaches Google.
Does Google sign a BAA for Google Analytics?
Google's Analytics help centre says Google does not offer Business Associate Agreements in connection with Google Analytics and that HIPAA-regulated entities must not expose PHI to it.
Is Google tag gateway the same as server-side tagging?
No. The gateway can run through a CDN on its own. Google describes pairing it with server-side Google Tag Manager, which is a separate server container that you configure and maintain.
Will my consent banner still work after enabling the gateway?
Google says enabling the gateway affects tag firing behavior and tells advertisers whose tags depend on consent to adopt Consent Mode and review their settings. Test declined visitors after switching it on.
Can I use the gateway on some pages of a healthcare site?
Google's HIPAA guidance for Analytics says regulated entities may only use Google Analytics on pages that are not HIPAA-covered, and should work with legal counsel to identify those pages. The gateway does not change that assessment.
What does Curve Compliance send Google instead?
Server-side conversions with neutral event names and identifiers hashed with SHA-256 to Google's requirements, with attribution kept through booking tools and a BAA on every plan.
Related articles
- GuideIs Google Ads Conversion Tracking HIPAA Compliant? Client-Side Risks and Server-Side Solutions
- GuideAggregated Event Measurement: Healthcare Setup
- GuideServer-to-Server Pixels Are Still Pixels: Google S2S and TikTok S2S in the FTC Complaint
- GuideGTM Server-Side Container for Healthcare: HIPAA-Compliant Tag Manager Setup
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit