Website tracking privacy risks can remain hidden across a health provider’s digital estate until a patient, regulator, or plaintiff discovers them. A pixel installed for one advertising campaign, a script introduced through a plugin, or an analytics tool added by an outside agency can continue operating long after anyone remembers approving it, creating a website tracking privacy risk.
Privacy and compliance teams may not know every tool that is operating, what information it collects, or where that information is sent. For a health system managing multiple hospitals, locations, subdomains, service-line websites, and campaign pages, one forgotten or incorrectly configured script can affect hundreds or thousands of webpages. Request a complimentary web scan* to understand what’s running on your website, and whether it matches what you promised.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Health system websites are constantly being updated A large healthcare organization may operate a main corporate website alongside hospital websites, provider directories, service-line pages, campaign landing pages, patient portal login pages, recruitment sites, blogs, mobile applications, and websites inherited through acquisitions.
Different marketing teams, agencies, developers, and technology vendors may all be able to introduce new code. The result is a constantly changing web environment in which compliance, privacy, and information security teams may not have a complete picture of every third-party technology operating across the organization. Website tracking is widespread in healthcare Research suggests that third-party data transfers are present on the overwhelming majority of hospital websites.
A 2024 study of a nationally representative sample of 100 nonfederal acute care hospitals found that 96% of their websites transferred user information to at least one third party. The websites communicated with a median of nine third-party domains, and 86% had at least one third-party cookie. Only 71 of the 100 hospital websites had a publicly accessible website privacy policy.
Among those 71 policies, just 40 specifically identified third-party companies or services receiving user information. The findings highlight an important distinction. Having a privacy policy does not necessarily mean that the organization knows everything its website is doing or that the policy accurately describes current activity.
A privacy policy may have been correct when it was written but subsequently become outdated as new technologies, vendors, campaigns, and websites were introduced. Why larger healthcare organizations face greater challenges Health systems and multi-location healthcare groups can have hundreds of people involved in their digital operations. Marketing may select an analytics platform, an agency may deploy advertising pixels, a service line may introduce a new scheduling application, and a recently acquired practice may continue using its existing website technology.
Each decision may appear reasonable in isolation. Collectively, however, they can create a complex and poorly documented network of data connections. Common problems include: No central inventory of websites, subdomains, microsites, and landing pages Different privacy and consent practices across affiliated organizations Inconsistent use of tag management systems Technologies added without privacy, security, or legal review Inherited tracking code following mergers and acquisitions Expired campaigns with active tags Privacy policies that do not reflect actual website behavior Vendors introducing additional subprocesses or technologies Unclear responsibility for approving and monitoring website tools A review of the main health system homepage will not necessarily reveal what is happening on a specialty clinic website, an appointment page, a recruitment portal, or a location-specific landing page.
When does website tracking become a HIPAA issue? The HIPAA Rules apply when information collected through tracking technologies or disclosed to tracking technology vendors includes PHI. Pages that deserve particularly careful examination include: Authenticated patient portals Patient portal login and registration pages Online appointment scheduling pages Symptom checkers Provider search tools Pages that collect an email address or other identifying information Forms through which an individual describes a condition or reason for seeking care Pages containing treatment, prescription, billing, or medical record information The Department of Health and Human Services’ Office for Civil Rights states that a privacy policy, website notice, or terms of use document does not, by itself, make a disclosure of PHI permissible.
OCR also states that an ordinary cookie consent banner is not a HIPAA-compliant authorization . If a tracking vendor creates, receives, maintains, or transmits PHI on behalf of a regulated entity for a covered function, the vendor may be a business associate. The organization must determine whether the disclosure is permitted and whether an appropriate Business Associate Agreement is required.
Simply asking a vendor to remove or de-identify information after receiving it does not necessarily resolve the problem. If PHI has already been disclosed to the vendor, the disclosure itself must have a lawful basis. The solution for website tracking privacy risks Automated website privacy monitoring tools can help close the visibility gap.
Tools can scan public-facing pages for third-party scripts and cookies, identify external technologies operating across websites and subdomains, and flag activity that may require further investigation.
Originally published at hipaajournal.com


