Skip to main content
Guide

The HHS Tracking Bulletin, Annotated After AHA v. Becerra

What the HHS online tracking bulletin still says after AHA v. Becerra, the one part the court vacated, and what it means for clinic ad tracking.

7 min read

The HHS online tracking bulletin still governs most healthcare ad tracking. In June 2024, a federal court in American Hospital Association v. Becerra vacated one piece of it: the position that connecting a visitor's IP address with a visit to a public, unauthenticated page about a health condition or provider is enough, on its own, to trigger HIPAA. The rest stands, including the rules on patient portals, booking and intake forms, symptom checkers, apps, BAAs and cookie banners. Curve Compliance helps clinics and telehealth brands track ad conversions inside those rules, with server-side conversion tracking in place of pixels and a BAA on every plan.

Book a call. Curve Compliance sets up HIPAA-compliant, server-side conversion tracking for Meta, Google, TikTok, Microsoft and other ad platforms. Curve's team does the setup in about a week, and a BAA comes with every plan. Book a call with Curve.

Below, each passage from the bulletin is quoted from the HHS page and followed by what it means now. This guide is general information, not legal advice.

The timeline in four dates

  • December 2022. The HHS Office for Civil Rights (OCR) publishes "Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates."
  • March 18, 2024. OCR revises the bulletin. The revision says it does not have the force of law and reframes the public-page example around the visitor's reason for visiting.
  • June 20, 2024. Judge Mark Pittman of the Northern District of Texas declares the disputed part unlawful and vacates it, while denying a permanent injunction (opinion and order).
  • August 19 to September 4, 2024. HHS files a notice of appeal to the Fifth Circuit, and the appeal is then dismissed under Federal Rule of Appellate Procedure 42(b) (court docket).

As of September 2026, the bulletin opens with a notice describing the order and says "HHS is evaluating its next steps in light of that order."

What the court vacated, in its own words

The court called the disputed rule the "Proscribed Combination": circumstances where an online technology connects "(1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers." HIPAA only covers information that both relates to a person's health or care and identifies them. The court held that a visitor's reason for reading a public page is unknowable to the site, noting that "HIPAA doesn't mandate clairvoyance." Footnote 8 limits the reach of the ruling: the vacatur "is not intended to, and should not be construed as, limiting the legal operability of other guidance in the germane HHS document."

The bulletin, passage by passage

"Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors."

Still applies. This is the core rule, and the bulletin adds that disclosing PHI to tracking vendors "for marketing purposes, without individuals' HIPAA-compliant authorizations" is impermissible. Ad pixels are the obvious case.

A tracking technology is "a script or code on a website or mobile app used to gather information about users or their actions," including "cookies, web beacons or tracking pixels, session replay scripts, and fingerprinting scripts."

Still applies. The definition reaches well beyond ad pixels. Session replay and fingerprinting are named in the text.

"Tracking technologies on a regulated entity's user-authenticated webpages generally have access to PHI."

Still applies. Patient portals and telehealth platforms behind a login were never part of the case. The bulletin's own example is an appointment made through a clinic website: the tracking vendor "is a business associate, and a BAA is required."

Someone reading a hospital's oncology services page "to seek a second opinion on treatment options for their brain tumor": transmitting their "IP address, geographic location, or other identifying information showing their visit to that webpage is a disclosure of PHI."

Vacated. This is the example the ruling removed. An IP address plus a visit to a public service page is no longer treated as PHI on that basis alone.

"Tracking technologies on a regulated entity's unauthenticated webpage that permits individuals to schedule appointments or use a symptom-checker tool without entering credentials may have access to PHI in certain circumstances."

Still applies. The bulletin's example is a tracker collecting an email address or the "reason for seeking health care typed or selected" by the visitor. That is information the person entered, not an inference from a page view, and it is where most clinic ad conversions happen: bookings, intake forms and consult requests. Our booking widget PHI leak audit shows where those leaks usually sit.

If someone "enters credential information on that login webpage or enters registration information (e.g., name, email address) on that registration page, such information meets the definition of IIHI."

Still applies. Login and sign-up pages are public, but what people type into them is covered. The same goes for mobile apps a regulated entity offers, where the bulletin says the information collected "generally is PHI."

"Website banners that ask users to accept or reject a website's use of tracking technologies, such as cookies, do not constitute a valid HIPAA authorization."

Still applies. So does the line before it: a privacy policy that mentions tracking does not permit PHI disclosures either. More in cookie consent banners vs HIPAA authorization.

"It is insufficient for a tracking technology vendor to agree to remove PHI from the information it receives or de-identify the PHI before the vendor saves the information."

Still applies. A vendor's promise to filter PHI after receiving it does not replace a BAA.

If a tracking vendor will not sign a BAA, "the regulated entity can choose to establish a BAA with another vendor, for example a Customer Data Platform vendor," that de-identifies tracking information and discloses only de-identified information to vendors that will not sign one.

Still applies. This describes a vendor with a BAA sitting between your website and ad platforms that do not sign one. Curve Compliance works in that position. It signs a BAA on every plan and replaces browser pixels with server-side conversion tracking. It uses neutral event names, hashes identifiers with SHA-256 to each platform's requirements, and flags outgoing data that looks like PHI.

"OCR is prioritizing compliance with the HIPAA Security Rule in investigations into the use of online tracking technologies."

Still applies. The bulletin expects tracking to appear in your risk analysis and risk management. For an impermissible disclosure with no permission and no BAA, it presumes a breach unless you can show a low probability of compromise. See what triggers an OCR marketing investigation.

What the ruling does not change

The ruling is one district court's vacatur of one guidance position. HIPAA and its rules did not change. The bulletin itself notes that the FTC Act and the FTC's Health Breach Notification Rule can apply where HIPAA does not, and state consumer health privacy laws use their own definitions of health data.

What to do with the tracking on your site

  1. Sort your pages into three groups: behind a login, pages where visitors type or select health information (booking, intake, symptom tools, registration), and purely informational pages.
  2. Take ad pixels off the first two groups and send conversions server-side instead.
  3. Give conversions neutral names, such as "Appointment Booked," with no condition, service or drug in the name or parameters.
  4. Keep a BAA with every vendor that receives PHI, and do not rely on banners or privacy policy language as permission.
  5. Record your tracking in your Security Rule risk analysis.

Curve Compliance handles steps two and three for Meta, Google, TikTok, Microsoft, Reddit, Amazon, ChatGPT Ads and other platforms, and signs a BAA on every plan. Its team sets up tracking in about a week, attribution is kept through booking tools, and consent management is built in.

Book a call. See what your pixels send today, and how the same conversions look sent server-side under a BAA. Book a call with Curve.

Frequently Asked Questions

Did AHA v. Becerra strike down the HHS tracking bulletin?

No. The court vacated one position in it: that an IP address combined with a visit to a public page about health conditions or providers is enough, on its own, to trigger HIPAA. Its footnote 8 says the vacatur does not limit the rest of the guidance.

Is an IP address on a public healthcare page PHI now?

Not on that basis alone, under the ruling. But once a visitor types or selects health information, books an appointment or logs in, the bulletin's other examples apply, and identifiers sent alongside that information can be PHI.

Does the ruling cover patient portals or telehealth platforms?

No. Pages behind a login were not part of the case. The bulletin still says tracking on authenticated pages generally has access to PHI.

Did HHS appeal the ruling?

HHS filed a notice of appeal on August 19, 2024, and the Fifth Circuit appeal was dismissed on September 4, 2024 under Federal Rule of Appellate Procedure 42(b). The bulletin page says HHS is evaluating its next steps.

Is a cookie banner enough to run Meta or Google pixels on a clinic site?

No. The bulletin says accept or reject banners do not constitute a valid HIPAA authorization, and that section was not affected by the ruling.

Can a vendor with a BAA sit between my site and the ad platforms?

Yes. The bulletin describes that arrangement. Curve Compliance signs a BAA on every plan and sends conversions server-side in place of pixels, with neutral event names and SHA-256 hashing.

Next step

Check your own site

See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.

Or book a tracking audit

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit