Med Spa Tracking Pixels and HIPAA: What Still Binds After the 2024 Ruling

Perry Lam · FounderPublished

Tracking pixels on a med spa website are the third-party scripts, Meta Pixel and Google tags among them, that report what a visitor did back to an advertising platform. Whether HIPAA governs them depends on which pages carry them and on whether the practice is a covered entity, and a 2024 court ruling narrowed the first question considerably.

Almost every guide on this topic still treats a December 2022 federal bulletin as settled law. A court took a large part of it out in June 2024. What follows is the current state, as of September 2026, and the setup that survives either reading.

What the 2022 bulletin claimed, and what a court took out

In December 2022 the HHS Office for Civil Rights published guidance saying that a visitor's IP address, combined with a visit to an unauthenticated page about specific health conditions or providers, could be protected health information. On June 20, 2024, a federal court declared that portion unlawful and vacated it. The guidance page itself now records the order.

The vacated language is quoted on the OCR guidance page as covering "circumstances where an online technology connects (1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers." That combination is what the court removed.

OCR withdrew its appeal in August 2024, according to the firms tracking the docket, so the vacatur is the state of play rather than an interim result. The practical effect for a med spa is narrow but real: a public Botox page carrying a Meta Pixel is no longer a HIPAA violation on the theory the bulletin advanced.

What survived: logged-in pages and the vendor agreement

Everything about user-authenticated pages survived the ruling untouched. OCR's guidance says tracking technologies inside authenticated pages may reach a patient's diagnosis and treatment information, prescription information and billing information, and that a regulated entity must configure those pages so the tracking only uses and discloses protected health information in line with the Privacy Rule.

For a med spa that means the patient portal, the logged-in account area and any confirmation page sitting behind a login. Those pages take no third-party tags. Not a filtered tag, not a tag with parameters stripped: none, because the page's own content is the disclosure.

The second survivor is the business associate question. OCR's guidance treats a tracking vendor that receives protected health information as a business associate whether or not the agreement exists. Whether a given ad platform will sign one is a question to put to that platform in writing before the tag goes on the page.

Whether a cash-pay med spa is a covered entity at all

A med spa is a HIPAA covered entity only if it transmits health information electronically in connection with a covered transaction, chiefly electronic claims and eligibility checks. That is the test in 45 CFR 160.103. HHS states that an entity meeting neither the covered entity nor the business associate definition does not have to comply with the HIPAA Rules.

A purely cash-pay aesthetics practice that never submits an electronic claim can fall outside that definition. A practice that bills insurance for anything, or that has a physician side of the house that does, generally falls inside it. Many med spas are genuinely uncertain which they are, and the answer is a question for a healthcare attorney rather than for a marketing agency.

The uncertainty is not an excuse to skip the work. Falling outside HIPAA removes one regulator and leaves the Federal Trade Commission, the ad platforms' own contracts and state law in place.

The FTC rule that binds whether or not HIPAA does

The FTC reaches health businesses that HIPAA does not, and it has used that reach on exactly this fact pattern. In February 2023 it brought its first enforcement action under the Health Breach Notification Rule against GoodRx, over disclosures of individually identifiable health information to Facebook, Google, Criteo, Branch and Twilio. GoodRx agreed to a $1.5 million civil penalty.

Samuel Levine, Director of the FTC's Bureau of Consumer Protection, said in the announcement: "Digital health companies and mobile apps should not cash in on consumers' extremely sensitive and personally identifiable health information." The case turned in large part on the gap between what the privacy policy promised and what the tags actually sent.

Two developments since then matter to a med spa. On July 20, 2023 the FTC and OCR sent a joint letter to roughly 130 hospital systems and telehealth providers about tracking technologies including Google Analytics and the Meta Pixel. And the FTC's amended Health Breach Notification Rule, effective July 29, 2024, clarified that health apps and similar technologies are covered. As of September 2026.

Whether a particular med spa website is a vendor of personal health records is a question for counsel. Section 5 of the FTC Act is the simpler exposure: a privacy policy that says patient information is never shared, on a site whose tags share it, is the deception the GoodRx and BetterHelp matters were built on.

What Meta and Google forbid on their own, separately from the law

Both major ad platforms ban this data in their own terms, which is enforceable against the account whatever a regulator does. Google's Health in personalized advertising policy, as of September 2026, treats invasive medical procedures as a sensitive interest category and names cosmetic surgery, surgical procedures and injections specifically. Advertiser-curated audiences for health-related content are not allowed in personalized advertising.

Read that against how med spa remarketing is usually built. A custom audience of everyone who visited the injectables page, or a lookalike seeded from it, is the pattern the policy describes, and enforcement lands on the ad account rather than on a lawyer's desk.

Meta's Business Tools Terms prohibit sending data that includes or is based on health information, and require that event and custom-audience names not reflect or imply it, so an event named "botox_consult_booked" is a policy problem in its own right. Meta also describes a filtering mechanism designed to keep potentially sensitive health data out of its ads ranking and optimization systems, so the data may be discarded after it is sent and the practice keeps the liability without the targeting.

The compliant setup, page by page

The setup that satisfies all three layers is decided page by page rather than site-wide, because the risk lives in what a page reveals about the person reading it. A homepage visit reveals nothing. A visit to a page about a specific treatment reveals what someone is considering, and a logged-in page reveals what they have actually had done.

Where a third-party tag can sit on a med spa site, as of September 2026
PageWhat a third-party tag can seeWhat governs itThe setup
Homepage, about, contactA visit and a referrer, no condition impliedNever inside the vacated combinationAn ordinary client-side tag is defensible
Treatment pagesThe procedure the visitor is researchingGoogle names injections and cosmetic surgery as sensitiveMeasure, but keep these pages out of remarketing audiences
Booking and enquiry formsName, email, phone, the treatment chosen, sometimes intake answersHIPAA authorization if the practice is a covered entity; FTC Act either wayFire a conversion event with no parameters, never field values
Thank-you pagesThe treatment, if the treatment is in the URLSame exposure as the treatment pageOne generic confirmation URL for every treatment
Portal and any page behind a loginDiagnosis, treatment, prescription and billing informationOCR guidance, untouched by the 2024 vacaturNo third-party tags at all

One correction is worth making because the industry gets it backwards. Sending events server-side, through a conversions API rather than a browser tag, changes who transmits the data and gives the practice a filtering point. It does not change what may lawfully be transmitted. A server-side event carrying a treatment name is the same disclosure with better plumbing.

What this looks like when it runs

Buyers ask agencies one version of this question: how do you handle HIPAA compliance across digital forms, CRM automations and ad landing pages? The answer that means something is plumbing rather than a badge. Forms land in a system the practice owns, and conversion events carry that a booking happened, never who booked or what for.

Mirastart builds that layer as software rather than as a plugin setting. Booking systems that calculate real availability and send confirmations, follow-up automation that chases what people forget, and reporting that ties an inquiry back to its page all run in production for Charlotte businesses today, and each is a place a treatment name could leak if nobody designed it not to.

On the compliance question the honest form is narrow: controls that keep patient information out of ad platforms, and a business associate agreement where an engagement genuinely touches protected health information. The practice remains the covered entity throughout.

Sources

  1. HHS Office for Civil Rights: Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates - The December 2022 bulletin, revised March 2024, and the notice of the June 20, 2024 order of the U.S. District Court for the Northern District of Texas declaring unlawful and vacating the guidance as to "circumstances where an online technology connects (1) an individual's IP address with (2) a visit to a[n] [unauthenticated public webpage] addressing specific health conditions or healthcare providers." The surviving guidance covers user-authenticated pages and treats a tracking vendor receiving PHI as a business associate.
  2. 45 CFR § 160.103 - Definitions (HIPAA covered entity) - A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits any health information in electronic form in connection with a covered transaction. Cornell LII mirror of the eCFR; official text at ecfr.gov. The section does not decide whether a given practice runs such transactions.
  3. HHS: Covered Entities and Business Associates - HHS states that an entity meeting neither the covered entity nor the business associate definition does not have to comply with the HIPAA Rules, and points to CMS's decision tool for the determination.
  4. FTC: Enforcement Action to Bar GoodRx from Sharing Consumers' Sensitive Health Info for Advertising - February 2023. First enforcement action under the Health Breach Notification Rule; disclosures of individually identifiable health information to Facebook, Google, Criteo, Branch and Twilio; a $1.5 million civil penalty. Quotation from Samuel Levine, Director of the FTC's Bureau of Consumer Protection.
  5. FTC business blog: FTC-HHS joint letter gets to the heart of the risks tracking technologies pose to personal health information - The July 20, 2023 joint letter from the FTC and OCR to approximately 130 hospital systems and telehealth providers about third-party tracking technologies including Google Analytics and the Meta Pixel.
  6. FTC: Finalizes Changes to the Health Breach Notification Rule - April 2024 final amendments, effective July 29, 2024, clarifying that health apps and similar technologies are covered and revising the definition of a breach of security. The rule reaches entities not covered by HIPAA; whether a given website is a vendor of personal health records is a separate analysis.
  7. Google Ads policy: Health in personalized advertising - Health is a sensitive interest category including invasive medical procedures, which the policy says includes cosmetic surgery, surgical procedures and injections. Advertiser-curated audiences for health-related content may not be used in personalized advertising; predefined Google audiences are configured without sensitive user signals and remain available.
  8. Meta Business Tools Terms - Prohibits sharing data that includes or is based on health information or other sensitive categories, and requires that event, conversion and custom-audience names not reflect, imply or be based on those categories.
  9. Meta Business Help Center: About Sensitive Health Information - Meta's signals-filtering mechanism is designed to prevent Business Tools data it categorizes as potentially sensitive health-related data from being ingested into its ads ranking and optimization systems.
  10. 45 CFR § 164.508 - Uses and disclosures for which an authorization is required (HIPAA Privacy Rule) - A covered entity must obtain a valid authorization before using protected health information for marketing. Cornell LII mirror of the eCFR; official text at ecfr.gov.
  11. Quarles & Brady: HHS OCR Withdraws Tracking Technologies Appeal in AHA v. Becerra - Law-firm analysis, not a primary document, cited for one fact the OCR guidance page does not state: that HHS withdrew its appeal of the June 20, 2024 order in August 2024, which is why the vacatur stands.
Questions

Med spa tracking pixels hipaa, answered.

Can a med spa put the Meta Pixel on its website?

On general pages, yes. On pages behind a login, no. In between, it depends on what the page reveals and on Meta's own terms rather than on HIPAA alone. A federal court vacated the part of OCR's December 2022 guidance that treated an IP address plus a visit to a public page about a specific condition or provider as protected health information, so a pixel on a public treatment page is not a HIPAA violation on that theory. Meta's Business Tools Terms separately prohibit sending data that includes or is based on health information, and require that event and audience names not imply it. As of September 2026, and educational only, not legal advice.

Is my med spa a HIPAA covered entity?

It depends on whether the practice transmits health information electronically in connection with a covered transaction, which in practice usually means electronic insurance claims or eligibility checks. That is the test in 45 CFR 160.103, and HHS states that an entity meeting neither the covered entity nor the business associate definition does not have to comply with the HIPAA Rules. A purely cash-pay aesthetics practice can fall outside it; a practice with any insurance-billing side generally does not. Your healthcare attorney owns this question, and the answer changes which of the rules on this page apply to you.

Does sending conversions server-side make tracking HIPAA compliant?

No. A conversions API changes who transmits the data and gives you a place to filter it, which is a genuine control and worth having. It does not change what may lawfully be transmitted or what the platform's terms allow. A server-side event carrying a patient identifier or a treatment name is the same disclosure as a browser tag carrying it. Use server-side to strip parameters deliberately, and judge the setup by what leaves the building rather than by which pipe it left through.

Keep reading
Guide

Med Spa Facebook Ads: What Meta's Rules Actually Allow in 2026

Most med spa ad accounts get restricted by four Meta standards, not one. The policy map as of September 2026, read from Meta's own pages, and the campaign shapes that clear review and still book consults.

Read
Guide

Before-and-After Photos: What Med Spas Can and Cannot Post

The most persuasive asset a med spa owns is also the one most likely to create a problem. Three separate systems govern a results photo, and a signed release only answers one of them.

Read
Guide

Med Spa Treatment Pages: What Goes on One, in What Order

Every med spa SEO guide says one page per treatment. Almost none say what goes on the page. Here is the section order, the sub-question each section answers, and the line Google draws between a treatment page and a page spun per query.

Read
Charlotte

The Best Med Spa Marketing Options for Charlotte Spas (2026)

The strange truth about this niche: almost nobody ranking for 'med spa marketing Charlotte' is actually in Charlotte, and almost nobody touches the systems where the money leaks. Here's the honest map - disclosed, because we're one of them.

Read
Charlotte, NC

AI automation for Charlotte businesses that can't answer every call

AI automation from a Charlotte team: customer intake, follow-up, phone answering, and scheduling systems with safeguards - built by people you can meet.

In Charlotte

Web design and development in Charlotte, NC

Fast, accessible business sites, eCommerce experiences, landing pages, redesigns and booking journeys, built to load quickly and point at one obvious next step.

The practice

AI automation for Charlotte businesses

Reliable systems that handle repetitive communication, qualification, scheduling, support and data work, each one shipping with a tested human escalation path.

The practice