MCP for Healthcare Marketing: What It Is and Why It Matters
MCP lets AI assistants read live ad, analytics and CRM data. What that changes for healthcare marketers, where PHI slips through, and what a safe MCP answer looks like.
MCP (the Model Context Protocol) is an open standard that lets AI assistants such as Claude and ChatGPT call tools that read, and sometimes change, live data in other systems, so a healthcare marketing team can question its ad, analytics and CRM data in plain English. The catch: whatever a tool returns reaches the AI vendor, patient details included. Curve, the HIPAA-compliant tracking platform with a signed BAA on every plan, built its MCP server for that gap: it answers campaign and funnel questions with rounded weekly totals, withholds small groups and returns no contact details, because the AI vendor you connect sits outside any BAA Curve signs.
What MCP is, in plain words
Anthropic released MCP as an open standard on November 25, 2024, describing it as a way for developers to build "secure, two-way connections between their data sources and AI-powered tools." In practice it is a common plug: a data source publishes one MCP server, and any AI app that speaks MCP can use it.
Three parts do the work:
- The host. The AI app you type into, such as Claude, ChatGPT or Cursor; the spec calls each connection inside it a client.
- The server. A small program that exposes tools. The official Google Ads server exposes exactly three:
list_accessible_customers,search(which runs GAQL queries) andget_resource_metadata. - The model. It reads the tool descriptions, decides which tool to call and with what arguments, then reads the result as part of the conversation.
With a classic API integration, a developer writes the query once and everyone knows what it pulls. With MCP, the model writes the query at the moment you ask, and the result becomes text inside its context. Our piece on MCP vs ad platform APIs covers what that shift does to PHI risk.
Local and remote servers
A server runs locally, launched by the AI app over stdio, or remotely at a URL over Streamable HTTP. Google's Ads and Analytics servers are self-hosted, on your machine or your own cloud; Meta's and HubSpot's are vendor-hosted.
Either way, security is left to the server's builder. The spec says MCP "cannot enforce these security principles at the protocol level," makes authorization optional, and calls tool annotations such as readOnlyHint hints, untrusted unless the server is trusted.
Why the big ad platforms shipped MCP servers
The common line is that every ad platform launched an MCP server in 2026. Close, but not quite. Google's came earliest of the four, in October 2025, and Amazon, Meta and TikTok followed between February and May 2026:
- Google Ads (October 2025). Open source. Google's docs call it "strictly read-only. It cannot modify bids, pause campaigns, or create new assets." It reads anything GAQL reaches, including search terms and conversions.
- Amazon Ads (open beta, February 2, 2026). Reporting, plus creating, updating and deleting campaigns, managing account settings and reading billing data.
- Meta (open beta, announced April 29, 2026). Write tools create campaigns, ad sets and ads in a paused state, and the AI client asks for confirmation before
ads_activate_entitysets anything live and starts spend. Advertisers can limit an agent to read-only, approval-required or full access. - TikTok (announced May 2026). Roughly 400 tools in "Full Disclosure" mode or about 40 in "Progressive Disclosure," including budget, bid and targeting changes.
- The tools around them. Google's GA4 server (labelled experimental, read-only), HubSpot's remote server (generally available since April 2026, reads and writes CRM records) and GoHighLevel's server (contacts, calendars, conversations, payments).
Two reasons show in the launch material. Reach: Claude, ChatGPT and Cursor all connect to MCP servers, so one server reaches all three. Spend: Meta says its connectors need "no developer credentials, API setup, or coding," TikTok says nearly the same, and both ship write tools. Google's read-only server is the exception, not the direction.
The uncomfortable part: none of the ad platforms' MCP documentation we reviewed says anything specific about health data. Google's repository says only that the server "will expose your data to the Agent or LLM that you connect to it."
What changes for a healthcare marketing team
The upside is speed. A question that used to mean an export and a pivot table becomes a sentence: "Which campaigns spent over $1,000 last month with no booked consultations?" The assistant writes the GAQL, calls search, and answers in seconds.
Five things change with it:
- Questions get cheap. People who never opened the dashboard start asking them.
- Nobody reviews the query. A model writes it at runtime, and a vague question can pull far more rows than needed.
- Data leaves the platform. Every result goes to the AI vendor and can persist in chat history, shared projects and logs.
- Chat becomes a control panel. On Meta, TikTok and Amazon, the session that reads performance can also create or change campaigns.
- Each platform grades its own work. Ask for cost per conversion across Meta and Google, and the assistant divides each platform's spend by that platform's self-reported conversions. Those counts were never built to agree.
That last one is a measurement problem before it is a privacy one. Curve sends conversions to each platform from its own server-side count, and Curve Analyst, inside the dashboard, sets what it sent beside what each platform credited. An assistant reading two ad platforms directly has no such referee. Curve MCP builds one in.
The PHI question MCP raises
Where patient data actually sits
The risk is rarely in campaign totals. It sits where rows get small or personal:
- CRM tools. GoHighLevel documents tools such as
calendars_get-appointment-notesandconversations_get-messages, which return what staff and patients wrote. In a clinic, that is PHI. More in our GoHighLevel verdict. - Customer lists. Meta's server can create and update custom audiences. A clinic's patient list is generally PHI, Meta signs no BAA for its ad products, and its Business Tools Terms forbid sending data that "includes or is based on... health information." Meta's MCP docs do not say whether the audience tools carry that restriction. See the customer list upload audit.
- Analytics. Page paths name conditions and services, and Google says it "does not offer Business Associate Agreements" for Google Analytics. The GA4 server inherits that gap, as our GA4 analysis explains.
- Small counts. Three conversions from one service-line campaign in a small town can point at a person. That is a de-identification problem, not a field problem, and small-group rules exist to reduce it.
Every hop needs its own answer
An MCP conversation has at least three parties: the system behind the server, the AI app and the model vendor. Each one that receives PHI on a clinic's behalf needs its own BAA; no agreement stretches to the next hop.
- Anthropic. In the Claude apps, a BAA is available only on Enterprise plans with HIPAA readiness on; Team, Pro and Max cannot enable it. Data sent to third parties through MCP connectors is not covered, and the Claude API's MCP connector is not HIPAA-eligible (see our Claude verdict).
- OpenAI. OpenAI offers a ChatGPT BAA only on its HIPAA-eligible offerings, such as sales-managed Enterprise with Regulated Workspace and ChatGPT for Healthcare; ChatGPT Business has none, and custom MCP connectors are "not verified by OpenAI."
- Ad platforms. Meta and Google do not sign BAAs for their advertising products.
- HubSpot. It offers a BAA through its Sensitive Data terms on Enterprise plans, but only for services it has explicitly authorised for PHI, and it has not said its MCP server is one. With Sensitive Data on, the MCP server blocks activity and conversation data; the docs do not list contact records as blocked.
The practical rule: if your team connects an MCP server from Claude Pro or ChatGPT Business, there is no BAA with the model vendor, so nothing that reaches the model may be PHI.
Read-only is not the same as safe
Google's Ads and GA4 servers cannot change a thing, yet they return whatever the connected account can see. Read-only protects the budget and the settings. It says nothing about what data reaches the model.
Tool results are an attack surface
Ad and CRM data contains text strangers wrote: search terms, UTM values anyone can put in a link, messages a lead typed into a chat widget. Instructions hidden in that text are what OWASP calls indirect prompt injection. In May 2025, Invariant Labs showed a malicious public GitHub issue steering an agent into leaking private repository data through the GitHub MCP server.
Keep attacker-written text and write tools apart. The MCP spec says there "SHOULD always be a human in the loop with the ability to deny tool invocations."
How Curve MCP answers without handing over patients
Curve MCP starts from the opposite end. Instead of exposing a platform's full API and hoping the model asks narrow questions, it releases a small, fixed set of numbers shaped to be safe before any question arrives, all drawn from data Curve already holds: its own tracking plus the spend each platform reports. The Curve MCP overview covers what it returns and why.
What it returns
- Organization-level KPIs: visitors, sessions, goal completions, funnel steps, and per-campaign spend, clicks, impressions, conversions and cost per conversion.
- Completed weeks only, as window totals plus a week-by-week series, over a fixed look-back: last week, or the last 4, 13 or 52 weeks.
- Reconciled server-side campaigns: spend, clicks and impressions as each ad platform reports them, next to the conversions Curve's server-side tracking recorded on a last-touch basis, with cost per conversion by completed week. One link opens the full sent, accepted and matched view inside Curve.
How it keeps answers aggregate
- People are counted across the whole reporting window, not visit by visit, and any group below a minimum size is withheld entirely.
- Counts and spend are rounded, and cost per conversion is calculated from the rounded figures. Where one number could be subtracted from another to expose a small group, the smaller one is withheld.
- A goal, funnel or campaign name appears only if the organization approved it. Otherwise it reads "(label hidden)."
- Inputs are fixed choices, never free text, and no string a website visitor can set (UTMs, page paths, referrers) is ever returned. That also closes the most obvious prompt-injection channel.
- A final guard checks every response for anything shaped like an email, phone number, ID, date or name. If it finds one, or cannot run, the answer is blocked, not cleaned.
How access is controlled
- Works with any client that can connect to an MCP server: Claude (desktop, web and Claude Code), ChatGPT, Cursor and other MCP-capable agents.
- Read-only, with no write actions of any kind.
- Off by default for every user, and only the clinic's primary user can switch it on for the organization.
- Scoped access tokens that expire. Issuing one needs a confirmation code, and admins are notified.
- The service runs under its own database role, which cannot read contact details, form answers or journeys; it checks that at every start.
- Every call is logged. If the log entry cannot be written, no data is returned.
Person-level questions, such as who booked from the spring campaign, get a link instead of data. The link needs a dashboard login, works once, expires quickly and carries nothing itself; Curve Analyst answers the question inside the dashboard.
The limits are deliberate. There is no revenue or ROAS, no breakdown by channel, device, region or page, no custom date range, and figures can trail the dashboard by up to a week. The AI vendor you connect is your choice, not a subprocessor under our BAA, which is why the server releases only numbers designed not to describe anyone.
Frequently asked questions
Is MCP itself HIPAA compliant?
No. HIPAA regulates covered entities and their business associates, not protocols, and the MCP spec leaves authorization optional and security to each server's builder. The real question is a specific server, AI app and model vendor, taken together.
Is ad platform performance data PHI?
Campaign-level spend, clicks and impressions usually are not PHI on their own, because they do not identify an individual. Risk rises when rows get small, go person-level (contacts, appointment notes, customer lists) or tie a person to a health service. HHS guidance sets no single numeric threshold for acceptable identification risk, which is why suppression rules matter.
Does a BAA with Anthropic or OpenAI cover MCP connectors?
Not by default. Anthropic puts data sent to third parties through MCP connectors outside its BAA, and OpenAI calls custom MCP connectors "not verified by OpenAI." Treat every connector as outside the agreement unless the vendor confirms otherwise in writing.
Is a local MCP server safer than a hosted one?
Not automatically. A local server keeps its credentials on your machine, but it also runs with your machine's privileges, and the MCP security guidance lists local server compromise as its own attack. Judge a server by what it can return and who publishes it, not where it runs.
Can an AI assistant spend ad budget through an MCP server?
Not through Google's official server, which is read-only. Through Meta's, yes: new entities need a confirmed activation, but ads_update_entity can change the budget of an ad set that is already spending, with no pause step. TikTok's and Amazon's servers can also create and change campaigns. Where a platform offers a read-only setting, as Meta does per asset, use it for reporting agents.
Should a clinic just block MCP?
A blanket ban rarely stops the questions; it moves them into copy and paste. An export pasted into a chat has no scopes, no audit log and no small-group rules, which is why pasting a patient funnel into ChatGPT is the worse option. A better policy names approved servers, the data allowed to reach a model, and who may enable write access.
Does Curve MCP make an AI assistant HIPAA compliant?
No, and no MCP server can. It controls what leaves the platform: rounded weekly aggregates with small groups withheld, no contact details, no visitor-set text, and a guard that blocks rather than scrubs. Compliance for the AI app and the model vendor is still your decision.
Where to start
- Inventory what is connected. List every MCP server in every AI app your team and agencies use, with the account each one signs in as.
- Sort each server by what it reads and what it can change. Switch write access off, or to approval-required, wherever the platform allows it.
- Hold each one to a written standard. Our HIPAA-safe MCP checklist lists the questions: BAA coverage per hop, output shaping, token scopes, audit logs.
- Give the team a safe default for campaign questions. Book a demo of Curve MCP to see week-level campaign and funnel answers in an AI assistant, with person-level questions routed back into the dashboard.
Reviewed September 2026. Vendor details reflect official vendor pages as of September 24, 2026. MCP servers change quickly; confirm current terms before connecting one.
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit