What You Can Send
What a GLP-1 Clinic Can Send Ad Platforms
Start with what leaves your site. The HHS bulletin on online tracking says that when a tracking vendor receives protected health information for a covered function, regulated entities must “enter into a business associate agreement (BAA) with these tracking technology vendors to ensure that PHI is protected in accordance with the HIPAA Rules.” Its own example is a clinic booking: the website “might automatically transmit information regarding the appointment and the individual's IP address to a tracking technology vendor.” HHS also says tracking on a page that “permits individuals to schedule appointments or use a symptom-checker tool without entering credentials may have access to PHI in certain circumstances.”
On June 20, 2024, in American Hospital Association v. Becerra, a federal court in Texas vacated one part of that bulletin, the part that treated an IP address plus a visit to a public page about a health condition or provider as enough to trigger HIPAA. The notice at the top of the HHS page says HHS “is evaluating its next steps in light of that order.” Whether a given page on your site involves PHI is a question for your counsel.
Meta draws its own line. Its page About prohibited information lists health information it does not want sent through Meta Business Tools, including “Prescription medications, and over-the-counter (OTC) and supplements for specific medical conditions” and “Body specifications, bodily activities, and biological cycles.” It says the names you choose for events, conversions and Custom Audiences “must not reflect, imply, or be based on any prohibited information.” Meta can also place a pixel into a core setup, which “restricts the transmission of certain data, such as custom parameters and anything in a URL following the domain”. A BMI answer, a drug name in a page URL or an event called semaglutide_consult can all fall under those headings. See what core setup means for a health and wellness business.
Curve Compliance helps on the data side. The free website scan lists the pixels and trackers on your quiz, booking and checkout pages. Curve then replaces browser ad pixels with one script, sends each platform only a fixed list of fields under neutral event names, keeps contact identifiers off by default and SHA-256 hashes them when you turn them on, and detects PHI-like patterns such as condition names, form answers and emails in URLs before data reaches an ad platform, flagging them so they can be stopped at the source.