Tracking pixels on a med spa website are the third-party scripts, Meta Pixel and Google tags among them, that report what a visitor did back to an advertising platform. Whether HIPAA governs them depends on which pages carry them and on whether the practice is a covered entity, and a 2024 court ruling narrowed the first question considerably.
Almost every guide on this topic still treats a December 2022 federal bulletin as settled law. A court took a large part of it out in June 2024. What follows is the current state, as of September 2026, and the setup that survives either reading.
What the 2022 bulletin claimed, and what a court took out
In December 2022 the HHS Office for Civil Rights published guidance saying that a visitor's IP address, combined with a visit to an unauthenticated page about specific health conditions or providers, could be protected health information. On June 20, 2024, a federal court declared that portion unlawful and vacated it. The guidance page itself now records the order.
The vacated language is quoted on the OCR guidance page as covering "circumstances where an online technology connects (1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers." That combination is what the court removed.
OCR withdrew its appeal in August 2024, according to the firms tracking the docket, so the vacatur is the state of play rather than an interim result. The practical effect for a med spa is narrow but real: a public Botox page carrying a Meta Pixel is no longer a HIPAA violation on the theory the bulletin advanced.
What survived: logged-in pages and the vendor agreement
Everything about user-authenticated pages survived the ruling untouched. OCR's guidance says tracking technologies inside authenticated pages may reach a patient's diagnosis and treatment information, prescription information and billing information, and that a regulated entity must configure those pages so the tracking only uses and discloses protected health information in line with the Privacy Rule.
For a med spa that means the patient portal, the logged-in account area and any confirmation page sitting behind a login. Those pages take no third-party tags. Not a filtered tag, not a tag with parameters stripped: none, because the page's own content is the disclosure.
The second survivor is the business associate question. OCR's guidance treats a tracking vendor that receives protected health information as a business associate whether or not the agreement exists. Whether a given ad platform will sign one is a question to put to that platform in writing before the tag goes on the page.
Whether a cash-pay med spa is a covered entity at all
A med spa is a HIPAA covered entity only if it transmits health information electronically in connection with a covered transaction, chiefly electronic claims and eligibility checks. That is the test in 45 CFR 160.103. HHS states that an entity meeting neither the covered entity nor the business associate definition does not have to comply with the HIPAA Rules.
A purely cash-pay aesthetics practice that never submits an electronic claim can fall outside that definition. A practice that bills insurance for anything, or that has a physician side of the house that does, generally falls inside it. Many med spas are genuinely uncertain which they are, and the answer is a question for a healthcare attorney rather than for a marketing agency.
The uncertainty is not an excuse to skip the work. Falling outside HIPAA removes one regulator and leaves the Federal Trade Commission, the ad platforms' own contracts and state law in place.
The FTC rule that binds whether or not HIPAA does
The FTC reaches health businesses that HIPAA does not, and it has used that reach on exactly this fact pattern. In February 2023 it brought its first enforcement action under the Health Breach Notification Rule against GoodRx, over disclosures of individually identifiable health information to Facebook, Google, Criteo, Branch and Twilio. GoodRx agreed to a $1.5 million civil penalty.
Samuel Levine, Director of the FTC's Bureau of Consumer Protection, said in the announcement: "Digital health companies and mobile apps should not cash in on consumers' extremely sensitive and personally identifiable health information." The case turned in large part on the gap between what the privacy policy promised and what the tags actually sent.
Two developments since then matter to a med spa. On July 20, 2023 the FTC and OCR sent a joint letter to roughly 130 hospital systems and telehealth providers about tracking technologies including Google Analytics and the Meta Pixel. And the FTC's amended Health Breach Notification Rule, effective July 29, 2024, clarified that health apps and similar technologies are covered. As of September 2026.
Whether a particular med spa website is a vendor of personal health records is a question for counsel. Section 5 of the FTC Act is the simpler exposure: a privacy policy that says patient information is never shared, on a site whose tags share it, is the deception the GoodRx and BetterHelp matters were built on.
What Meta and Google forbid on their own, separately from the law
Both major ad platforms ban this data in their own terms, which is enforceable against the account whatever a regulator does. Google's Health in personalized advertising policy, as of September 2026, treats invasive medical procedures as a sensitive interest category and names cosmetic surgery, surgical procedures and injections specifically. Advertiser-curated audiences for health-related content are not allowed in personalized advertising.
Read that against how med spa remarketing is usually built. A custom audience of everyone who visited the injectables page, or a lookalike seeded from it, is the pattern the policy describes, and enforcement lands on the ad account rather than on a lawyer's desk.
Meta's Business Tools Terms prohibit sending data that includes or is based on health information, and require that event and custom-audience names not reflect or imply it, so an event named "botox_consult_booked" is a policy problem in its own right. Meta also describes a filtering mechanism designed to keep potentially sensitive health data out of its ads ranking and optimization systems, so the data may be discarded after it is sent and the practice keeps the liability without the targeting.
The compliant setup, page by page
The setup that satisfies all three layers is decided page by page rather than site-wide, because the risk lives in what a page reveals about the person reading it. A homepage visit reveals nothing. A visit to a page about a specific treatment reveals what someone is considering, and a logged-in page reveals what they have actually had done.
| Page | What a third-party tag can see | What governs it | The setup |
|---|---|---|---|
| Homepage, about, contact | A visit and a referrer, no condition implied | Never inside the vacated combination | An ordinary client-side tag is defensible |
| Treatment pages | The procedure the visitor is researching | Google names injections and cosmetic surgery as sensitive | Measure, but keep these pages out of remarketing audiences |
| Booking and enquiry forms | Name, email, phone, the treatment chosen, sometimes intake answers | HIPAA authorization if the practice is a covered entity; FTC Act either way | Fire a conversion event with no parameters, never field values |
| Thank-you pages | The treatment, if the treatment is in the URL | Same exposure as the treatment page | One generic confirmation URL for every treatment |
| Portal and any page behind a login | Diagnosis, treatment, prescription and billing information | OCR guidance, untouched by the 2024 vacatur | No third-party tags at all |
One correction is worth making because the industry gets it backwards. Sending events server-side, through a conversions API rather than a browser tag, changes who transmits the data and gives the practice a filtering point. It does not change what may lawfully be transmitted. A server-side event carrying a treatment name is the same disclosure with better plumbing.
What this looks like when it runs
Buyers ask agencies one version of this question: how do you handle HIPAA compliance across digital forms, CRM automations and ad landing pages? The answer that means something is plumbing rather than a badge. Forms land in a system the practice owns, and conversion events carry that a booking happened, never who booked or what for.
Mirastart builds that layer as software rather than as a plugin setting. Booking systems that calculate real availability and send confirmations, follow-up automation that chases what people forget, and reporting that ties an inquiry back to its page all run in production for Charlotte businesses today, and each is a place a treatment name could leak if nobody designed it not to.
On the compliance question the honest form is narrow: controls that keep patient information out of ad platforms, and a business associate agreement where an engagement genuinely touches protected health information. The practice remains the covered entity throughout.
Sources
- HHS Office for Civil Rights: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates - The December 2022 bulletin, revised March 2024, and the notice of the June 20, 2024 order of the U.S. District Court for the Northern District of Texas declaring unlawful and vacating the guidance as to "circumstances where an online technology connects (1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers." The surviving guidance covers user-authenticated pages and treats a tracking vendor receiving PHI as a business associate.
- 45 CFR § 160.103 - Definitions (HIPAA covered entity) - A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a covered transaction. Cornell LII mirror of the eCFR; official text at ecfr.gov. The section does not decide whether a given practice runs such transactions.
- HHS: Covered Entities and Business Associates - HHS states that an entity meeting neither the covered entity nor the business associate definition does not have to comply with the HIPAA Rules, and points to CMS's decision tool for the determination.
- FTC: Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising - February 2023. First enforcement action under the Health Breach Notification Rule; disclosures of individually identifiable health information to Facebook, Google, Criteo, Branch and Twilio; a $1.5 million civil penalty. Quotation from Samuel Levine, Director of the FTC's Bureau of Consumer Protection.
- FTC business blog: FTC-HHS joint letter gets to the heart of the risks tracking technologies pose to personal health information - The July 20, 2023 joint letter from the FTC and OCR to approximately 130 hospital systems and telehealth providers about third-party tracking technologies including Google Analytics and the Meta Pixel.
- FTC: Finalizes Changes to the Health Breach Notification Rule - April 2024 final amendments, effective July 29, 2024, clarifying that health apps and similar technologies are covered and revising the definition of a breach of security. The rule reaches entities not covered by HIPAA; whether a given website is a vendor of personal health records is a separate analysis.
- Google Ads policy: Health in personalized advertising - Health is a sensitive interest category including invasive medical procedures, which the policy says includes cosmetic surgery, surgical procedures and injections. Advertiser-curated audiences for health-related content may not be used in personalized advertising; predefined Google audiences are configured without sensitive user signals and remain available.
- Meta Business Tools Terms - Prohibits sharing data that includes or is based on health information or other sensitive categories, and requires that event, conversion and custom-audience names not reflect, imply or be based on those categories.
- Meta Business Help Center: About Sensitive Health Information - Meta's signals-filtering mechanism is designed to prevent Business Tools data it categorizes as potentially sensitive health-related data from being ingested into its ads ranking and optimization systems.
- 45 CFR § 164.508 - Uses and disclosures for which an authorization is required (HIPAA Privacy Rule) - A covered entity must obtain a valid authorization before using protected health information for marketing. Cornell LII mirror of the eCFR; official text at ecfr.gov.
- Quarles & Brady: HHS OCR Withdraws Tracking Technologies Appeal in AHA v. Becerra - Law-firm analysis, not a primary document, cited for one fact the OCR guidance page does not state: that HHS withdrew its appeal of the June 20, 2024 order in August 2024, which is why the vacatur stands.