Federal & Sector Law

HIPAA / HITECH

Federal health privacy rules. Tracking pixels on patient portals and authenticated pages can transmit PHI; OCR enforces, settlements exceed $100M.

HIPAA / HITECH requirements

HIPAA's Privacy and Security Rules govern how covered entities and their business associates handle protected health information. The tracking-technology question arrived in December 2022, when HHS's Office for Civil Rights issued a bulletin stating that pixels and analytics tags on patient portals and some public pages could transmit PHI to vendors without a business associate agreement. A federal court vacated the part of that guidance covering unauthenticated pages in June 2024, but tracking on authenticated portals, scheduling flows, and any page where the visitor's identity and health condition can be inferred together remains squarely within the rule. Civil penalties are tiered, with an annual cap above $2.1 million for each violation category. Hospitals and health systems have paid well over $100 million in related private settlements since 2023.

See what your sites and apps actually send

Get a free site analysis: every tracker, mapped to the laws that apply to it.