Privacy and compliance
Patient data never enters the system we build
We build so that patient health information never enters the marketing system. Most of what a practice buys from a studio never needs to touch it, the parts that could are engineered so they do not, and every piece is written down so your privacy officer can read it in one sitting.
Below is what we engineer, what we will not claim, and what stays yours to decide.
The measurement, field by field
What it holds
- Which channel produced an inquiry
- Whether the inquiry became an appointment
- The page a request was sent from
- The date and time it arrived
What it never holds
- A name sitting next to a condition
- A patient's name, which has no column to sit in
- The contents of a message
- Anything from a portal or a chart
- No HIPAA certification exists for agencies or software
- We cannot make a practice compliant
- We are not attorneys
- This page is not legal advice
- Your counsel has the last word
- No HIPAA certification exists for agencies or software
- We cannot make a practice compliant
- We are not attorneys
- This page is not legal advice
- Your counsel has the last word
The limits, stated first
Three claims we will never make
HIPAA certified
There is no HIPAA certification for an agency or for software. The federal health department operates no certification, accreditation, or approval program and does not recognize private ones. Any vendor selling that badge is selling its own opinion, so we do not sell one.
We make you compliant
Compliance is an attribute of your whole operation: your policies, your training, your risk analysis, your agreements, your conduct. A vendor can supply components built not to put you at risk. No vendor can supply compliance.
This is legal advice
We are not attorneys and nothing here is legal advice. Where a rule is involved we name it and route the decision back to your counsel or privacy officer, with everything they need to read it themselves.
Saying all three plainly is the point. A physician who has been sold the opposite before can check every one of them in a few minutes.
Tracking, in plain English
Your marketing pages can be measured. Your portal is a different building.
In December 2022 the federal health privacy regulator told practices that ordinary analytics or advertising code on a public page could itself be a disclosure of patient information, because the tracking company receives a visitor address alongside the page that was read. Hospital systems stripped the code off their sites that year.
On June 20, 2024 a federal court in American Hospital Association v. Becerra set that specific position aside as beyond the agency authority, and the government dropped its appeal that August. The rest of the guidance was left standing. So the frightening version is gone and the careful version is not, which is why anyone still selling either extreme is out of date.
- Dec 1, 2022The regulator publishes its online tracking guidance
- Mar 18, 2024A revised version softens the language
- Jun 20, 2024A federal court vacates the part covering public pages
- Aug 29, 2024The government withdraws its appeal
- Aug 2026No replacement guidance, and no rulemaking on tracking
Measurable
Public marketing pages
Homepage, services, directions, hours, about, careers
Which channel sent the visit
Which page was read
Whether the visit produced an appointment request
Campaign level performance
Advertising audiences built from people who read about a condition
Treated as patient bearing
Appointment requests and new patient forms
The public form that captures a name and a way to reach someone
That a request arrived
Which page and which source it came from
Advertising or analytics code on the page
Submission contents inside a notification email
Free text symptom boxes, which we do not build
No marketing code, ever
Patient portal and logged in scheduling
Anywhere the practice already knows who the person is
Advertising tags
Analytics tags
Session replay or heatmap scripts
Nothing about the portal changed in 2024, because nobody argued about it. On those surfaces the practice knows exactly who the person is and that they are a patient, so a tracking vendor receiving anything is receiving patient information. The public form sits in the middle: unauthenticated, but it captures a name and a reason to be contacted, which is identity plus purpose with nothing left to infer.
A cookie banner is not permission to share health information. The regulator says so directly, which is why bolting a consent tool onto a medical site does not answer the question. We do not treat acceptance as consent.
As of August 2026 the health privacy regulator has published no settlement citing website pixels or online scheduling. The cases that moved money were private lawsuits and the consumer protection regulator. That is a reason to design carefully, not a reason to be frightened, and it is the opposite of how this is usually sold.
How attribution is built
Attribution needs a source and an outcome, never a person
| Source | Outcome |
|---|---|
| Google Business Profile | Appointment booked |
| Search, non branded | Booking link opened |
| Practice site, services page | Form, new patient |
| Paid search, brand | Form, not booked |
No patient name, no reason for visit, no message contents.
The two facts
Every question a practice actually asks about marketing has two facts in the answer: where an inquiry came from, and whether it turned into an appointment. Neither one requires knowing who the patient is or what is wrong with them, so neither one is collected.
Calls
We read your own Google Business Profile, Google Ads and Meta accounts and gather what those platforms publish about your practice into one place. Nothing is uploaded to them, no patient list is ever sent to an ad platform, and no audience is built from anyone who read a page about a condition.
Forms and web addresses
Form submissions are matched to the page and the source they arrived from, never to the message body. Notification emails say a request came in, they do not carry it around. And web addresses are designed so that nothing private ends up in them, because page paths and query strings are what quietly carry identity into logs that were never built to hold it.
Vendor agreements
A signed agreement is not a configuration
The part most agencies never check is which products will actually sign. Several of the tools reached for by default will not, and one of them says so in writing.
The rule
If a company handles information about your patients on your behalf, it is a business associate and it signs a business associate agreement before anything moves.
The status
The status is a fact about where data flows, not about paperwork: a vendor that meets the definition is one whether or not a contract exists.
What the contract adds
The contract is what gives you remedies, reporting duties, and a way out.
- Google AnalyticsDoes not signNo agreement offered, stated in writing
- Google AdsDoes not signNot covered by any published Google agreement
- Meta pixel and Conversions APIDoes not signNone offered, and its terms forbid sending health information
- Google Workspace, including FormsSignsCovered, accepted by a Workspace administrator
- PulseTrack, our own platformSignsNo agreement needed: no column in it can hold patient data
- Session replay and heatmap toolsDoes not signNot used on a practice site, by our own rule
Checked August 11, 2026, and checked again at the start of every engagement. A marketing page that says HIPAA compliant is not an agreement.
Why we audit anyway
A signed agreement is not a configuration. A practice can hold one and still have an integration quietly forwarding data to an advertising platform, which is why we audit what your tools actually send rather than what the contract says.
Why most of it never applies here
Most of what we build should never need one. That is a design choice, not an accident: every agreement we do not need is an exposure nobody has to manage.
Reviews and patient stories
A public reply can disclose that someone is a patient
Confirming that a person received care is a disclosure about the provision of care. No diagnosis is required for that, and the patient posting first does not change it, because the rules bind the practice rather than the person writing the review. Even the sentence beginning we are sorry your visit has already confirmed that a visit happened.
So the safe reply is the one that would read identically whether or not the poster was ever a patient. We draft a response to every review, positive or not, and none of them confirm a relationship or discuss care. That constraint is ours to hold even when a practice wants to correct the record in public.
Illustrative reply template
Thank you for the feedback. Privacy rules prevent us from discussing anyone's care, or confirming whether someone is a patient, in a public forum. If you would like to discuss a concern, please call our office manager and we will do everything we can to help.
- Confirms nothing about who the person is
- Moves the conversation to a phone call
- Reads the same to everyone else who sees it
The invitation
Every patient in the eligible group gets the same invitation, on the same trigger, with the same message. Sending only to the ones who seemed pleased is called gating: the consumer protection regulator publishes that exact funnel as an example of conduct that may be unfair or deceptive, and the review platforms prohibit it separately. We do not buy, trade, gate, or write reviews, and nobody on our team posts one for you.
The patient story
A published patient story or photograph needs the patient's signed authorization on a specific form, not a general photo release, because the two instruments do different work and only one of them is revocable. Before and after images are patient records; cropping the face does not change that, since a scar or a distinctive feature is often the very thing the photo exists to show. We will not run one without the authorization, and we take it down the day a patient changes their mind.
Accessibility
Accessibility is a build gate here, not a review note
You get the audit, dated. If anyone ever asks what was done and when, that file is the answer.
- 18routes tested
Every route on this site, not a sample.
- 2color themes
Light and dark, both measured.
- 0violations found
axe-core, recorded August 11, 2026.
Built to WCAG 2.2 AA. Claimed at 2.1 AA, because 2.1 is the level the federal rules actually name and conforming to 2.2 conforms to 2.1.
Since 2024, Section 1557 of the Affordable Care Act reaches a physician's practice with no size threshold, because Medicare Part B counts as federal financial assistance. The technical standard is not written in that section: 45 C.F.R. 92.204(b) routes to the health department Section 504 rule at 45 C.F.R. 84.84, which adopts WCAG 2.1 Level A and AA.
The compliance dates moved in May 2026, to May 11, 2027 for recipients with fifteen or more employees and May 10, 2028 below that, and both extensions are being challenged in court right now. So we do not sell a deadline. We build to the standard, which is the correct answer whichever way the dates land, and your counsel is the one to read the dates.
Automated testing catches part of the picture, so we tell you what was tested, when, and what was found rather than calling a site fully accessible. We do not install accessibility overlay widgets: they cover the markup instead of fixing it, and an overlay cannot label a control that has no label. The scheduler you embed is tested too, because you are answerable for what sits on your page.
Where the line sits
What we build, and what stays yours
What we engineer
- Attribution that needs no name, condition, or record
- A written tag inventory and data flow record, per practice
- Forms that ask how to reach someone, not what is wrong
- No advertising or analytics code on portals or logged in scheduling
- Accessibility tested route by route before launch
- Review responses that never confirm a patient relationship
What your practice owns
- Your compliance program, policies, and staff training
- Your risk analysis and your privacy officer
- Your business associate agreements and who signs them
- Your counsel's reading of any rule named on this page
- Anything you choose to run on your own phone system
- Your notice of privacy practices and how patients are told
Ask these before you sign
Five questions worth asking any marketing vendor
- Will you hand me a written list of every script on my site and what each one sends?
- Which of my tools will sign a business associate agreement, and on which plan tier?
- Do request addresses and query strings enter your logs, and are those logs covered?
- What do you deliberately not collect, and can I see that list?
- What did you test for accessibility, when, and what did you find?
Questions doctors ask
The answers are mostly no
Six questions worth asking any studio that wants to run your marketing, answered the way we would answer them on a call.
The short version
The other one is a question about which pages, not a yes or no. Every answer below says so in full.
Are you HIPAA certified?
NoNo, and neither is anyone else. There is no HIPAA certification for agencies or for software: the federal health department runs no such program and does not recognize private ones, so a certification badge is a vendor's own opinion about itself. What we can do is build the parts we control so they do not carry patient information, and document them so you can verify it.
Can you make my practice HIPAA compliant?
NoNo. Compliance is an attribute of your whole operation: policies, training, risk analysis, agreements, and conduct. We supply components built not to put you at risk, plus a written record of what each one collects and where it goes. Your privacy officer and your counsel do the rest, and we give them what they need to do it.
Is Google Analytics safe on a medical website?
Not a yes or noGoogle states in writing that it does not offer a business associate agreement for Analytics, and separately tells covered entities not to place its tags on authenticated pages. That makes it a question about which pages rather than a yes or no. We keep advertising and analytics code off portals, logged in scheduling, and any page that captures a name.
Does any of this touch our phone system?
NoWe do not touch your phone system in any way. What we measure arrives through your website and your booking link. The honest consequence is that a patient who simply picks up the phone is not attributed to a channel, and we would rather leave that gap visible in your report than close it with anything that sits in the middle of your practice.
Do you ask only satisfied patients for reviews?
NoNo. Every patient in the eligible group gets the same invitation, on the same trigger, with the same message. Asking only the pleased ones is gating, which the consumer protection regulator publishes as an example of potentially unfair or deceptive conduct, and which the review platforms prohibit. We do not buy, trade, gate, or write reviews.
Is anything on this page legal advice?
NoNo. We are not attorneys. This page describes how we build and what we will not claim. Where a rule is named, it is named so your counsel or privacy officer can read it themselves, and we hand over the tag inventory, the data flow record, and the dated accessibility audit so there is something real to check.
Next step
Bring your privacy officer to the first call
Thirty minutes in plain language. We will walk through what we would build, what it collects, and what your counsel should look at before anything ships.