Buyer's guide · Reference edition · Updated monthly

HIPAA-compliant website analytics: the 2026 buyer's guide

Google Analytics will not sign a Business Associate Agreement. That one fact is why you're reading this page. Every figure below is checked against a primary source and dated.

Last updated September 16, 2026About 25 minutes
0
OCR enforcement actions over website tracking, ever
$123M
Approved class settlements since 2022
15/30
Healthcare homepages still running GA4
2/13
Tools that sign a BAA without a tier gate

This guide covers what HIPAA actually requires of an analytics vendor, the three ways healthcare organizations solve it, and a straight comparison of 13 tools: which sign a BAA, on which plan, at what price, and what you give up with each. We built one of the 13, and we've said so everywhere it's relevant. The comparison is the same one we'd want if we were buying.

Section 1

What HIPAA actually requires of an analytics tool

HIPAA does not ban analytics. It bans handing protected health information to a company that has not signed a contract agreeing to protect it. That contract is a Business Associate Agreement. Under the Privacy Rule, a vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed BAA before that data flows. No BAA, no lawful flow. It is a binary.

Figure 1.1 · What is a BAA, and what only looks like oneThe only question to ask
A privacy policy is not a BAA

GDPR language, a data processing addendum, even a SOC 2 report. None of them makes a vendor a business associate. A DPA and a BAA are different documents governing different laws.

A setting is not a BAA either

IP anonymization, cookieless tracking, consent banners and retention limits are good hygiene. None of them changes whether the vendor has signed. If the vendor won't sign, configuration doesn't fix it.

"Will you sign a BAA on the plan I am buying?"

The one question with a yes or no answer. Several vendors sign, but only on their most expensive plan. "BAA: yes" without a tier isn't telling you what you need to know. We've named the tier in ours.

"Are you HIPAA compliant?" is the wrong question. Every vendor finds a way to say yes to that one.
Section 2

What counts as PHI on a website

This is where most of the genuine confusion lives, and where the law moved recently. In December 2022, HHS OCR published a bulletin on tracking technologies, revised in March 2024, saying that an IP address combined with a visit to a page about a health condition could itself be protected information, even on a public, unauthenticated page. The hospital industry challenged it, and the plaintiffs' complaint gave that pairing a name the court later adopted: the "Proscribed Combination."

Figure 2.1 · American Hospital Association v. Becerra: what was vacated, what still standsN.D. Tex., June 20, 2024
Vacated

An IP address plus a visit to a public, unauthenticated page about a health condition or provider is, by itself, protected information.

The court held OCR exceeded its statutory authority, because the rule would require a provider to discern a visitor's subjective intent. HHS appealed, then withdrew the appeal on August 29, 2024. The vacatur stands, unappealed.

Still in force
  • Authenticated pages: patient portals, logged-in scheduling, mobile apps
  • The underlying business associate and PHI obligations. Any vendor receiving PHI still needs a BAA or patient authorization
  • The rest of the bulletin, still on HHS.gov with a partial-vacatur disclaimer. No replacement guidance has issued
  • Every state wiretap, medical confidentiality and consumer protection statute. The ruling touched none of them
The opinion does not say whether the vacatur is nationwide or limited to the plaintiffs. Most commentators read it as universal; the court did not address it. Ask your own counsel. Ruling summary.

Headlines said a court struck down the HIPAA tracking rules. Three things are wrong with that sentence. It was guidance, not a rule. Only part of it was vacated. And HHS was never where the money came from: almost all of it rests on state wiretap statutes, medical confidentiality laws, common-law privacy claims and the FTC's deception theory. State law kept moving the other way. Washington's My Health My Data Act carries a private right of action. Nevada has its own consumer health data law, and Connecticut added consumer health data protections to its privacy act. California's Invasion of Privacy Act, a wiretapping law from 1967, is the engine behind several of the largest healthcare settlements of the past two years.

Figure 2.2 · How to treat each page typePractical rule for a marketing team
Treat as sensitive
Appointment requestsCondition and service-line pagesProvider searchSymptom checkersAnything behind a login
Treat as ordinary
HomepageCareersPress and newsroom
And get the BAA anyway, because the cost of being wrong is not symmetrical.
Section 3

The enforcement record, stated precisely

Vocabulary matters here, and a lot of marketing content gets it wrong in ways a general counsel will catch. A class settlement is not a fine. Refunds are not a penalty. A pending complaint is an allegation. Start with the fact nobody puts in these articles: HHS OCR has never announced an enforcement action premised on website tracking technologies. The FTC has been the active federal enforcer, and the money has come from private class actions.

Figure 3.1 · The federal recordAs of Sept 16, 2026
WhoWhenOutcomeWhat it was
HHS OCREverNo enforcement action premised on website trackingNot a resolution agreement, not a civil money penalty. Checked against OCR's published enforcement list, September 2026.None
HHS OCR and FTCJul 2023Joint warning letters to about 130 hospital systems and telehealth providersNamed the Meta Pixel and Google Analytics. A warning letter resolves nothing.No penalty
GoodRxFeb 2023$1.5MFTC Act and Health Breach Notification Rule, for sharing health data with Facebook, Google and Criteo.Civil penalty
BetterHelp2023$7.8MSharing data with Facebook, Snapchat, Criteo and Pinterest. The FTC was explicit this is not a civil penalty.Consumer refunds
CerebralApr 2024Nearly $5.1M refunds, plus $10M penalty suspended to $2MTracking tools shared nearly 3.2M consumers' data with LinkedIn, Snapchat and TikTok.Refunds and penalty
MonumentApr 2024$2.5M penalty, fully suspendedFalse HIPAA compliance claims while running Meta and Google pixels.Paid nothing
Hims & HersJul 29, 2026Complaint filed by the FTC, Utah and California via Los Angeles County CounselFTC Act, ROSCA, state consumer protection law. Sharing with Meta and Snap alleged. No HIPAA count. Nothing adjudicated, nothing ordered, nothing admitted.Pending
GoodRx paid a civil penalty, a penalty imposed under a statute. BetterHelp paid consumer refunds, which the FTC was explicit is not a civil penalty. Monument's penalty was suspended in full, so it paid nothing. Hims & Hers is a complaint, and if you see it cited as an outcome, the person citing it has not read the docket.
Figure 3.2 · Healthcare tracking class settlementsAs of Sept 16, 2026
DefendantAmountCourtTrackers namedStatus
Kaiser Permanente$46M to $47.5MN.D. Cal.Google, Microsoft Bing, XApproved Jul 2026
Sutter Health$21.5MCalifornia state courtGoogle Analytics, Meta Pixel on portal loginApproved Mar 2026
Aspen DentalAbout $18.5M, two fundsSangamon County, IllinoisMeta Pixel, Google tools on bookingApproved Oct 2025
Mass General Brigham, Dana-Farber$18.4MSuffolk Superior Court, MassachusettsCookies and pixelsApproved 2022
Allina Health$12.5MD. Minn.Meta, Google; about 2.5M class membersHearing Sep 24, 2026
Advocate Aurora Health$12.225ME.D. Wis.Meta Pixel, Google AnalyticsApproved Jul 2024
Penn MedicineUp to $9.25MPhiladelphia Court of Common PleasPixels on the myPennMedicine portal; Pennsylvania wiretap actHearing Nov 12, 2026
Novant Health$6.66MM.D.N.C.Meta Pixel on MyChart portalApproved Jun 2024
LifeStance Health$3.03M, two subclassesD. Ariz.Meta Pixel, Google Analytics and othersHearing Oct 16, 2026
Atrium HealthUp to $1.8MMecklenburg County Superior Court, North CarolinaPixels on the MyAtriumHealth portalHearing Sep 30, 2026
Concord Hospital$800,000Hillsborough Superior Court, New HampshireGoogle Analytics and Geonetric, both named as tracking technologiesHearing Nov 3, 2026
TotalsAbout $123M approved · about $27M proposed and awaiting a judge
Amounts are settlement funds, not fines. Every defendant denies wrongdoing; none is a finding of liability. Proposed means a judge has not yet approved it, so the word is "proposed," not "paid." Three of the 5 pending cases are in state court under wiretap and privacy statutes. An $800,000 settlement won't make a headline, and it will still ruin a marketing department's year.
Figure 3.3 · The terms that outlast the moneyRead the documents, not the summaries
$875,000 · final approval Oct 2025Eisenhower Health

Two-year ban on the Meta Pixel and other tracking tools, plus a standing web governance committee.

The committee, not marketing, now decides what analytics code runs.

$3.03M · proposedLifeStance Health

Discontinue all third-party tracking pixels other than pixels compliant with HIPAA, for five years from the settlement's Effective Date.

Scoped to third-party pixels, not all analytics. The clock starts after final approval and any appeals.

Up to $9.25M · proposedPenn Medicine

For two years, no analytics or advertising technologies on pennmedicine.org unless the web governance committee determines the use is consistent with applicable law.

A legal-consistency gate, not general approval. Covers pennmedicine.org, not the portal.

Every one of these gets summarized somewhere as a blanket ban on analytics, and that is not what the documents say. What they share: all three move the decision from the marketing team to a committee. Your vendor question becomes "can I put a signed BAA in front of the committee."
Section 4

What is actually running on healthcare websites right now

In September 2026 we ran an informal audit of the homepages of 30 healthcare organizations, a mix of health systems, multi-location groups and behavioral health networks. We're not publishing the site list, but the shape of the results is worth reporting, because it wasn't what the headlines predict.

Figure 4.1 · What 30 healthcare homepages runInformal audit, Sept 2026
Google Analytics 4
15usually with Google Ads or DoubleClick tags
No analytics detected
6everything switched off
Freshpaint
4
Session recorders
3Clarity, Hotjar, Mouseflow, one each
Piwik PRO
2
Matomo
2
Tag manager, nothing fired
2most likely consent-gated
Meta Pixel
0not on a single homepage
Categories overlap, since one site can run several tools. Session recording is the highest-risk category on the page, because it captures form interactions. Six sites with nothing detected usually means someone got scared and switched everything off, and nobody can now say which campaigns produce appointments.

Note the shape of this. Three years of litigation removed the tag that was in the headlines, and left the one that carries most of the traffic data: half the sample was still sending page-level behavior to a company that states plainly it will not sign a BAA.

Section 5

The three ways to solve this

There are only three real architectures. Everything on the market is a variation of one of them.

Figure 5.1 · Three architectures, and what the BAA covers in eachFollow the contract
There is a fourth thing people do, which is not an architecture: turn everything off. It is the only option that guarantees you cannot answer a board question about which campaigns produce patients.

Option 1: Replace the tool

Swap Google Analytics for an analytics platform that signs a BAA and holds the data under that agreement. One vendor, one contract, one place the data lives.

Good for: organizations that want the compliance question closed rather than managed, and teams without engineering capacity to babysit a data pipeline.

Trade-off: you leave the Google ecosystem for site analytics. Campaign tracking still works through UTM parameters, but native GA-to-Google-Ads audience sharing is not part of the deal, by design, because that sharing is the thing creating the exposure.

Option 2: Keep the tool, govern the data

Leave Google Analytics and the ad pixels in place and put a compliance layer in front of them that strips or masks identifiers before data reaches the destination. Freshpaint is the best-known example. Geonetric's Privacy Filter takes a similar shape from the agency side.

Good for: organizations with heavy investment in Google and Meta advertising infrastructure that they are unwilling to unwind, and enterprise budgets.

Trade-off: you are paying to keep tools that will never sign a BAA, and the filter is now a single point of failure carrying your compliance posture. Concord Hospital's proposed settlement names Google Analytics and Geonetric, a healthcare web agency's technology, side by side as tracking tools on the hospital's site. That is an allegation, not a finding, and it says nothing about whether a filter failed. It does show how a vendor's own tooling lands in the complaint next to the analytics tag.

To be fair to the category: Freshpaint does sign a BAA, and says so plainly. The question is what that signature covers. Ask any filter vendor: your BAA covers your service. What covers the destination? The honest answer is nothing, because Google will not sign one. That may still be the right trade for an organization with tens of millions in Google and Meta spend. It is a different decision from the one a regional health system with a five-person marketing team is making.

Option 3: Self-host

Run an open-source analytics platform on infrastructure you control. Matomo is the common choice, and its own documentation says that with self-hosting, compliance is the operator's job, because Matomo never touches the data.

Good for: organizations with a real infrastructure team, an appetite for owning encryption, access control, audit logging, patching and backups, and a security review process that can sign off on all of it.

Trade-off: you have not removed the compliance work, you have hired it. Matomo also states that its hosted Cloud service is not HIPAA compliant, so the self-hosted route is the only Matomo-branded path, and the operational burden is real and permanent.

Section 6

The comparison

Everything below was checked against each vendor's own public pages in September 2026. Where a vendor doesn't publish something, we say so rather than guessing. Prices change; verify before you sign.

Figure 6.1 · 13 analytics tools: who signs a BAA, on which plan, at what priceChecked Sept 16, 2026
ToolSigns a BAA? On which planPublished priceHostingHeatmaps / session recordingTag managerBuilt for
Google Analytics 4NoNoneGoogle states it does not offer BAAs for the service.FreeGoogleNoGoogle Tag Manager, not on Google's BAA-covered listGeneral web
Ghost MetricsThat's usYesEvery plan, including StarterStandard BAA ready to sign on every plan. Minor redlines on Premium, custom terms on Enterprise.$299 / $399 / $499 per month, Enterprise customUS-hosted, each customer's data logically isolatedPremium and upYesHealthcare marketing sites
Piwik PROHigher tierEnterprise onlyIts HIPAA page and help center say the BAA comes with the free trial and the Enterprise plan. Its pricing page marks the entry Enterprise tier, Data Fundamentals, as not including HIPAA support.Business from €36/mo; Enterprise from €366/mo billed annuallyUS hosting on Enterprise only. Business is EU-operated hosting in SwedenYesYesGeneral, with a healthcare practice
FreshpaintYesTier not publishedSays plainly on its own site that it signs a BAA. Which tiers include it is not published.Not published. Comply, Perform and Scale tiers, all "Talk to Sales"Not publishedOn higher tiersn/a, governs data in transitHealthcare marketing and ad activation
Matomo (self-hosted)NoNone offeredIts HIPAA FAQ says you will not need to sign a BAA with Matomo because it does not host your data.Community free; Team €275/mo; Business €1,450/mo; Enterprise €3,400/mo, billed annuallyYoursYes, paid pluginYesTeams with infrastructure
Matomo CloudNoNoneThe same FAQ states that Matomo Cloud is not HIPAA compliant.From €29/mo excl. taxMatomo, Frankfurt, GermanyYesYesGeneral web
Microsoft ClarityNoNone publishedIts terms say not to use it with content that may contain health care information.FreeMicrosoftYes, this is its core functionNoGeneral web
Hotjar (now Contentsquare)NoNone publishedNo BAA or HIPAA statement on Hotjar or Contentsquare pages. Hotjar is closed to new signups; new accounts go through Contentsquare.Contentsquare free tier plus paidContentsquareYesNoGeneral web
PlausibleNoNonePlausible states plainly that it is not HIPAA compliant and does not offer a BAA.$9 / $14 / $19 per month at 10k pageviews, scaling with volumeEU onlyNoNoPrivacy-conscious general web
FathomNoNoneNo HIPAA or BAA offering found on usefathom.com in September 2026, and its terms bar tracking personal data. Not the AI notetaker of the same name.$15 / $25 / $45 per month at 100k / 200k / 500k pageviewsAWS for non-EU traffic; EU traffic kept on EU infrastructure. No region publishedNoNoPrivacy-conscious general web
MixpanelHigher tierEnterprise onlyIts HIPAA page offers the BAA to Enterprise plan customers.Free tier, then customMixpanelSession replayNoProduct teams
AmplitudeHigher tierOn request via salesAmplitude says it can enter a BAA. Which plans qualify is not published.Free tier, then customAmplitudeSession replayNoProduct teams
PostHogHigher tierBoost ($250/mo) and aboveIts HIPAA docs: BAAs only for Boost, Scale or Enterprise, not the free or pay-as-you-go plan. AI features are carved out of the BAA and have to be switched off.Free tier, usage-based, then Boost $250/mo, Scale $750/moUS Cloud in Virginia, EU Cloud in FrankfurtYesNoProduct and engineering teams
Yes means the vendor signs a BAA on the plan named. Higher tier means it signs, but not on its entry plan. Download the BAA comparison as an image for your team.
Free is the expensive option.

Every tool whose only price is free publishes no BAA. On a healthcare site, free tools are the ones most likely to appear in a complaint.

"Signs a BAA" is doing a lot of work.

Piwik PRO, Mixpanel and PostHog all sign, and every one gates it behind a higher tier. Amplitude signs too, but doesn't publish which plans qualify. Piwik PRO's documentation puts the BAA on the free trial and the Enterprise plan, US hosting is Enterprise too, and its pricing page marks the entry Enterprise tier as not including HIPAA support, so the €36 Business tier isn't the product you'd be buying. If you're a three-location dental group, "yes" is frequently not a yes at your budget.

Check the price you'd actually pay.

A roundup that lists Piwik PRO at €36 and calls it BAA-backed has combined two facts that don't go together. It's how a marketing director ends up in a budget meeting defending a number that was never real.

Watch for name collisions on Fathom.

Searching for Fathom and HIPAA surfaces at least three unrelated companies, including an AI meeting notetaker that does publish a BAA page. The web analytics product is usefathom.com, and it has no HIPAA offering. If a listicle tells you Fathom signs a BAA, check which Fathom.

Product analytics is a category mismatch.

Mixpanel, Amplitude and PostHog will sign, and they are strong products built to answer questions about feature adoption inside an application. A hospital marketing team wants service-line traffic, campaign attribution, appointment funnels and a board report. You can force it, but you'll be building what the other category ships.

Matomo's position is often misreported.

Listicles put Matomo in the HIPAA-compliant column without qualification. Matomo's own FAQ is clearer: it does not sign a BAA because it does not host your data, and Matomo Cloud is not HIPAA compliant. Self-hosted Matomo can be operated compliantly. That is a statement about you, not about Matomo.

Which raises the question this guide has been circling: if self-hosting is a legitimate path, why buy anything? Because self-hosting moves the work rather than removing it. Someone owns the servers, the encryption, the access controls, the audit logs, the patching, the backups and the security review, permanently. Organizations with an infrastructure team and a security function can carry that. A five-person marketing team at a regional health system cannot, and shouldn't pretend otherwise to save a subscription. That gap is the entire reason managed, BAA-backed platforms exist, ours included.

Section 7

How to prove marketing works without tracking individuals

The objection that stops most of these projects isn't legal. It's a CFO asking why the marketing budget should survive if nobody can say which campaigns produce patients. It's a fair question, and the honest answer is that the individual-level attribution most teams think they have is mostly an illusion anyway. Cross-device journeys break it. Cookie lifetimes break it. Consent gates break it. A patient who sees a billboard, searches your brand three weeks later on a phone, and books from a laptop is credited to direct traffic on every platform you own.

Figure 7.1 · What survives the switchFive measurements that need no identity
  1. 01
    Aggregate funnels

    Service-line page to appointment request to confirmed booking, as counts and rates by week. The number leadership actually asks about, and it does not require knowing who anyone is.

  2. 02
    Campaign attribution through UTM parameters

    UTMs travel in the URL. No third-party cookie, identity graph or ad-platform pixel needed. You lose the remarketing audience. You keep the ability to say which campaign drove bookings.

  3. 03
    Holdout and geography tests

    Run the campaign in four markets and not in three comparable ones, then compare booking volume. A better measure of incremental lift than last-click attribution ever was.

  4. 04
    Call tracking with the recording turned off

    Phone is still how a large share of appointments get booked. Unique numbers per campaign give you attribution without capturing anything about the caller.

  5. 05
    Your own booking system

    The conversion that matters already lives in a system you control and already have a BAA for. The ad platform's number is a worse number reported by a party with an interest in the answer.

Your reported conversion numbers will drop when you make this switch, sometimes by a lot. That's not lost performance. It's the end of double-counting across platforms that each claimed the same booking. Brief leadership before the first report lands. More in How to prove your marketing is working when you can't track individuals.
Section 8

How to evaluate a vendor in one meeting

Ten questions. Any vendor worth buying answers all ten without a follow-up call.

Figure 8.1 · Ten questions for one meeting
  1. Will you sign a BAA on the specific plan we are buying? Get the tier in writing.
  2. Can we see the BAA before we commit? Watch for vendors who will only show it after a signature elsewhere.
  3. Where is the data physically stored, and how is our data separated from other customers' data?
  4. Do you hold a BAA with your own hosting provider? A vendor with no upstream BAA has a gap it cannot close.
  5. Is any customer data used for advertising, model training, benchmarking or resale? Get a no in writing.
  6. What identifiers are stripped, at what point, and can you show us the before and after?
  7. Do you have a SOC 2 Type II report, and will you share it under NDA? SOC 2 is not HIPAA, but its absence tells you about operational maturity.
  8. What is your breach notification process and timeline?
  9. If we leave, what happens to our historical data, and in what format do we get it?
  10. Who installs it, and what does the install actually look like on our site?
Two questions to ask about the tools you are replacing: what would we hand our privacy officer if they asked for the BAA covering Google, and when did anyone last audit what is in our tag manager and who can add to it?
Section 9

A migration checklist

If you're switching, this is the sequence that avoids a gap in the data and an argument with legal. Start with the inventory: open DevTools on your homepage, an appointment page, a condition page and your portal login, reload, and look in the Network tab for googletagmanager, google-analytics, gtag, doubleclick, connect.facebook.net, tiktok, snapchat, linkedin, bing, clarity.ms, hotjar and criteo. Anatomy of a PHI Leak walks through it screen by screen.

Figure 9.1 · What a tracker inventory looks likeIllustration
Figure 9.2 · Before, during, afterSequence
Before you switch
  • Inventory every tag currently firing on your homepage, an appointment or contact page, a condition page, and your portal login if it is public.
  • Pull the sentence from your own privacy policy that promises confidentiality. Put it next to the network log.
  • Export your historical analytics. Whatever you are leaving, get the data out first.
  • Write down the five reports you actually use. Most teams use fewer than they think.
  • Identify who controls the tag manager. If it is an agency, bring them in now, not after.
During
  • Sign the BAA before real traffic flows. Do not run a trial on live patient traffic without one.
  • Install the new snippet alongside the old one for a two-week overlap. Expect a discrepancy: tools count sessions differently.
  • Rebuild goals and funnels first, reports second. Conversions are what people ask about.
  • Confirm UTM parameters still resolve correctly on your live campaigns.
After
  • Remove the old tags. Actually remove them. A dormant tag is still firing.
  • Re-run the DevTools audit on the same four pages and confirm the list is what you expect.
  • Document the decision, the date, the BAA, and who approved it. Your governance committee will ask.
  • Put a quarterly reminder on someone's calendar to re-audit the tag manager. Every incident in the record started with a tag nobody remembered adding.
Pull the sentence from your privacy policy that promises confidentiality and put it next to the network log. That pairing is the whole compliance conversation in one screenshot.
Section 10

Frequently asked questions

Is Google Analytics HIPAA compliant?

No. Google states that it makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with the service. Google also says customers subject to HIPAA must not use Google Analytics in any way that implicates Google's access to or collection of PHI. Because Google will not sign a BAA, no configuration on your side makes it compliant for covered pages.

Why Google Analytics was never built for healthcare

Does IP anonymization make Google Analytics compliant?

No. IP anonymization reduces one identifier. It does not create a BAA, and the vendor's willingness to sign is the requirement. It is a useful setting on a tool that is already permitted, not a way to permit a tool that is not.

Does server-side tagging solve this?

Not by itself. Server-side Google Tag Manager gives you control over what leaves your infrastructure, which is genuinely useful. But a BAA with the company hosting your server-side container binds that company, not the destination. If the data still lands at Google Analytics, you still have a destination that will not sign. Ask the relay vendor directly whether their BAA covers the destination. It does not.

Server-side tagging won't save you

Do cookie consent banners cover us?

No. Consent under GDPR or CCPA is a different mechanism from HIPAA authorization, and a banner does not create a business associate relationship. HIPAA authorization is specific, written and much narrower than a cookie banner click.

What about the June 2024 court ruling? Didn't that clear things up?

It cleared up one thing. A federal court vacated the portion of the HHS bulletin treating an IP address plus an unauthenticated page visit as protected information. The rest of the bulletin stands, including guidance on authenticated pages and the BAA requirement. More importantly, the large healthcare tracking settlements were brought under state wiretap statutes, medical confidentiality laws and consumer protection law, none of which that ruling touched. This is not legal advice. Talk to your counsel, and ask them specifically about state law exposure.

Two health systems, one month: pixel lawsuits after the AHA ruling

Has HHS ever fined anyone over website tracking?

No, and the vocabulary in the question is worth correcting too. HHS OCR does not issue fines; it enters resolution agreements, which include a settlement amount and a corrective action plan, or it imposes civil money penalties. As of September 2026 it has done neither in a matter premised on website tracking technologies. The nearest thing is a joint OCR and FTC warning letter sent to about 130 organizations in July 2023, which carries no penalty. The financial exposure in this area has come almost entirely from private class actions under state wiretap and privacy law.

Is Matomo HIPAA compliant?

Matomo does not sign a BAA, and states that its hosted Cloud service is not HIPAA compliant. Its position is that self-hosted Matomo does not require a BAA because Matomo never receives your data. That is a coherent position and it is also a transfer of responsibility: self-hosted Matomo can be operated compliantly, but the compliance is yours to build and maintain, not something the software gives you. Any listicle that puts Matomo in a HIPAA-compliant column without that qualifier is telling you something Matomo itself does not claim.

Which analytics tools will sign a BAA on an entry-level plan?

Very few. Most vendors that sign gate it behind an enterprise or higher-tier plan: Piwik PRO on Enterprise, PostHog from its $250 a month Boost package, Mixpanel on Enterprise, and Amplitude only after a conversation with sales. This is the single most common gap between what a comparison chart says and what you can actually buy, and it is why the tier column exists in ours.

We have no budget. What is the minimum responsible thing to do?

Audit what is firing on your appointment and portal pages, remove anything from a vendor that will not sign a BAA, and accept that you will lose some data until you can fund a replacement. Flying blind is bad. Flying blind is still better than an unfunded settlement.

Section 11

Where to go from here

If you want to see what's currently firing on your own site, the inventory step above costs nothing and takes about ten minutes. Anatomy of a PHI Leak shows you exactly what to look for. If you want to see the product this guide's authors build, pricing is public, the BAA is on every plan, and a demo is one booking away.

This guide is general information about HIPAA and website analytics, not legal advice. Settlement figures and vendor terms were checked against primary sources on September 16, 2026 and are updated monthly. Ghost Metrics is one of the vendors compared.

Get the BAA before the next report lands.

Ghost Metrics signs a Business Associate Agreement on every plan, including Starter. Book a demo and we'll walk through what's firing on your site today and what a switch looks like.