Track Zocdoc bookings as ad conversions, HIPAA-compliant
When a visitor clicks your ad and then leaves your site to book on Zocdoc, the click ID and UTMs stay behind, so the booking can't be credited to the ad on its own. Curve Compliance carries that attribution across with a bridge token and credits the booking to the original ad click when Zocdoc's webhook arrives. It then sends the conversion server-side to Meta, Google, TikTok, Microsoft and LinkedIn, and a booking made days after the click still matches.
See how Curve Compliance tracks Zocdoc bookings on your own funnel.
How it works
Step 1
One script replaces your ad pixels
Curve's team installs the Curve Compliance script on your site in place of your browser ad pixels, so conversions reach your ad platforms from Curve's servers.
Step 2
The click to Zocdoc carries a bridge token
When a visitor clicks a plain link to Zocdoc, Curve keeps their ad attribution: click IDs, UTM parameters, the session and the page the click came from. It adds a short reference to that attribution, called a bridge token, to the booking link and records a booking_intent event. The token carries no form content and is not a patient identifier.
Step 3
Zocdoc returns the token with the booking
Zocdoc keeps the token with the appointment and includes it in the webhook it sends when the booking is made. Where a custom field is needed to carry the token into that webhook, Curve's team sets it up.
Step 4
Curve credits the booking to the ad click
The webhook is set up in Curve under Incoming Webhooks to match on the bridge token, and Curve's team configures it with you. When it arrives, Curve credits the booking to the original visit, even when the patient books days after the click.
Step 5
The conversion goes out server-side
Curve forwards the booking as a conversion to Meta, Google, TikTok, Microsoft and LinkedIn. Campaign Reporting then puts your ad spend next to the tracked bookings for each campaign.
What reaches Meta and Google
Meta and Google receive the Zocdoc booking as a conversion sent from Curve's servers and credited to the ad click that started it. TikTok, Microsoft and LinkedIn receive it the same way.
- Each ad platform receives only a fixed list of fields.
- Contact identifiers are off by default, and SHA-256 hashed when you turn them on.
- The event can use a neutral name such as "Lead" in place of a treatment or condition.
- The bridge token in the Zocdoc link carries no form content and is not a patient identifier.
- Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, and flags them so they can be fixed at the source.
- Event Logs show what Curve sent to each platform and what each platform accepted.
Read more about Meta Conversions API and Google Ads with Curve Compliance.
Does Zocdoc sign a BAA?
No quotable statement. Zocdoc's own privacy pages did not give us a statement about a BAA that we could retrieve and quote, so ask Zocdoc directly.
The pages we checked were Zocdoc's Privacy Policy and its intake and HIPAA authorization page. Zocdoc bookings happen on Zocdoc's own marketplace and booking pages, so the data about who booked sits with Zocdoc and with you.
Until Zocdoc signs a BAA with you, keep Protected Health Information out of Zocdoc, and keep ad pixels off any Zocdoc page that shows a condition, a service or an appointment. The booking can still count as a conversion when it reaches your ad platforms without health information.
Curve Compliance signs its own BAA with you on every plan.
We checked Zocdoc's own pages on September 29, 2026. The quotes and source links are on the Zocdoc entry in the BAA Directory.
Zocdoc booking tracking FAQ
Can I send Zocdoc bookings to Meta Conversions API?
Yes. Curve Compliance credits each Zocdoc booking to the ad click behind it when Zocdoc's webhook arrives, then sends it from Curve's servers to Meta Conversions API. Meta receives only a fixed list of fields, contact identifiers are off by default and SHA-256 hashed when enabled, and the event can use a neutral name such as "Lead". The same booking can also go to Google, TikTok, Microsoft and LinkedIn.
Does attribution survive if the patient books days later?
Yes. Zocdoc keeps the bridge token with the appointment and sends it back in its webhook, so Curve Compliance matches the booking to the original visit, with its click IDs, UTM parameters and the page the click came from, even when the patient books days after the ad click.
Does Zocdoc sign a BAA?
We could not find a quotable statement. Zocdoc's own privacy pages did not give us a statement about a BAA, so ask Zocdoc directly and keep Protected Health Information out of Zocdoc until a BAA is in place. Curve Compliance signs its own BAA with you on every plan.
What if the Zocdoc booking page is embedded or opens in a pop-up?
Curve's team sets that up. Plain links to Zocdoc are handled automatically, and embedded booking widgets, pop-ups and buttons that open the scheduler with JavaScript get a small custom setup from Curve's team. Either way, the booking is credited to the ad click that started it.
How long does setup take?
About a week; it varies case by case. Curve's team does the setup: it replaces your browser ad pixels with one script, configures the Zocdoc webhook under Incoming Webhooks, sets up any custom field the token needs and turns on forwarding to your ad platforms. Curve signs a BAA on every plan.
Track Zocdoc Bookings as Conversions
Curve's team sets up the Zocdoc handoff, the webhook and server-side delivery to your ad platforms, with a BAA on every plan.
- BAA on every plan
- Set up by Curve's team
- Server-side delivery