This guide covers what HIPAA actually requires of an analytics vendor, the three ways healthcare organizations solve it, and a straight comparison of 13 tools: which sign a BAA, on which plan, at what price, and what you give up with each. We built one of the 13, and we've said so everywhere it's relevant. The comparison is the same one we'd want if we were buying.
What HIPAA actually requires of an analytics tool
HIPAA does not ban analytics. It bans handing protected health information to a company that has not signed a contract agreeing to protect it. That contract is a Business Associate Agreement. Under the Privacy Rule, a vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed BAA before that data flows. No BAA, no lawful flow. It is a binary.
GDPR language, a data processing addendum, even a SOC 2 report. None of them makes a vendor a business associate. A DPA and a BAA are different documents governing different laws.
IP anonymization, cookieless tracking, consent banners and retention limits are good hygiene. None of them changes whether the vendor has signed. If the vendor won't sign, configuration doesn't fix it.
The one question with a yes or no answer. Several vendors sign, but only on their most expensive plan. "BAA: yes" without a tier isn't telling you what you need to know. We've named the tier in ours.
What counts as PHI on a website
This is where most of the genuine confusion lives, and where the law moved recently. In December 2022, HHS OCR published a bulletin on tracking technologies, revised in March 2024, saying that an IP address combined with a visit to a page about a health condition could itself be protected information, even on a public, unauthenticated page. The hospital industry challenged it, and the plaintiffs' complaint gave that pairing a name the court later adopted: the "Proscribed Combination."
An IP address plus a visit to a public, unauthenticated page about a health condition or provider is, by itself, protected information.
The court held OCR exceeded its statutory authority, because the rule would require a provider to discern a visitor's subjective intent. HHS appealed, then withdrew the appeal on August 29, 2024. The vacatur stands, unappealed.
- Authenticated pages: patient portals, logged-in scheduling, mobile apps
- The underlying business associate and PHI obligations. Any vendor receiving PHI still needs a BAA or patient authorization
- The rest of the bulletin, still on HHS.gov with a partial-vacatur disclaimer. No replacement guidance has issued
- Every state wiretap, medical confidentiality and consumer protection statute. The ruling touched none of them
Headlines said a court struck down the HIPAA tracking rules. Three things are wrong with that sentence. It was guidance, not a rule. Only part of it was vacated. And HHS was never where the money came from: almost all of it rests on state wiretap statutes, medical confidentiality laws, common-law privacy claims and the FTC's deception theory. State law kept moving the other way. Washington's My Health My Data Act carries a private right of action. Nevada has its own consumer health data law, and Connecticut added consumer health data protections to its privacy act. California's Invasion of Privacy Act, a wiretapping law from 1967, is the engine behind several of the largest healthcare settlements of the past two years.
The enforcement record, stated precisely
Vocabulary matters here, and a lot of marketing content gets it wrong in ways a general counsel will catch. A class settlement is not a fine. Refunds are not a penalty. A pending complaint is an allegation. Start with the fact nobody puts in these articles: HHS OCR has never announced an enforcement action premised on website tracking technologies. The FTC has been the active federal enforcer, and the money has come from private class actions.
| Who | When | Outcome | What it was |
|---|---|---|---|
| HHS OCR | Ever | No enforcement action premised on website trackingNot a resolution agreement, not a civil money penalty. Checked against OCR's published enforcement list, September 2026. | None |
| HHS OCR and FTC | Jul 2023 | Joint warning letters to about 130 hospital systems and telehealth providersNamed the Meta Pixel and Google Analytics. A warning letter resolves nothing. | No penalty |
| GoodRx | Feb 2023 | $1.5MFTC Act and Health Breach Notification Rule, for sharing health data with Facebook, Google and Criteo. | Civil penalty |
| BetterHelp | 2023 | $7.8MSharing data with Facebook, Snapchat, Criteo and Pinterest. The FTC was explicit this is not a civil penalty. | Consumer refunds |
| Cerebral | Apr 2024 | Nearly $5.1M refunds, plus $10M penalty suspended to $2MTracking tools shared nearly 3.2M consumers' data with LinkedIn, Snapchat and TikTok. | Refunds and penalty |
| Monument | Apr 2024 | $2.5M penalty, fully suspendedFalse HIPAA compliance claims while running Meta and Google pixels. | Paid nothing |
| Hims & Hers | Jul 29, 2026 | Complaint filed by the FTC, Utah and California via Los Angeles County CounselFTC Act, ROSCA, state consumer protection law. Sharing with Meta and Snap alleged. No HIPAA count. Nothing adjudicated, nothing ordered, nothing admitted. | Pending |
| Defendant | Amount | Court | Trackers named | Status |
|---|---|---|---|---|
| Kaiser Permanente | $46M to $47.5M | N.D. Cal. | Google, Microsoft Bing, X | Approved Jul 2026 |
| Sutter Health | $21.5M | California state court | Google Analytics, Meta Pixel on portal login | Approved Mar 2026 |
| Aspen Dental | About $18.5M, two funds | Sangamon County, Illinois | Meta Pixel, Google tools on booking | Approved Oct 2025 |
| Mass General Brigham, Dana-Farber | $18.4M | Suffolk Superior Court, Massachusetts | Cookies and pixels | Approved 2022 |
| Allina Health | $12.5M | D. Minn. | Meta, Google; about 2.5M class members | Hearing Sep 24, 2026 |
| Advocate Aurora Health | $12.225M | E.D. Wis. | Meta Pixel, Google Analytics | Approved Jul 2024 |
| Penn Medicine | Up to $9.25M | Philadelphia Court of Common Pleas | Pixels on the myPennMedicine portal; Pennsylvania wiretap act | Hearing Nov 12, 2026 |
| Novant Health | $6.66M | M.D.N.C. | Meta Pixel on MyChart portal | Approved Jun 2024 |
| LifeStance Health | $3.03M, two subclasses | D. Ariz. | Meta Pixel, Google Analytics and others | Hearing Oct 16, 2026 |
| Atrium Health | Up to $1.8M | Mecklenburg County Superior Court, North Carolina | Pixels on the MyAtriumHealth portal | Hearing Sep 30, 2026 |
| Concord Hospital | $800,000 | Hillsborough Superior Court, New Hampshire | Google Analytics and Geonetric, both named as tracking technologies | Hearing Nov 3, 2026 |
| Totals | About $123M approved · about $27M proposed and awaiting a judge | |||
Two-year ban on the Meta Pixel and other tracking tools, plus a standing web governance committee.
The committee, not marketing, now decides what analytics code runs.
Discontinue all third-party tracking pixels other than pixels compliant with HIPAA, for five years from the settlement's Effective Date.
Scoped to third-party pixels, not all analytics. The clock starts after final approval and any appeals.
For two years, no analytics or advertising technologies on pennmedicine.org unless the web governance committee determines the use is consistent with applicable law.
A legal-consistency gate, not general approval. Covers pennmedicine.org, not the portal.
What is actually running on healthcare websites right now
In September 2026 we ran an informal audit of the homepages of 30 healthcare organizations, a mix of health systems, multi-location groups and behavioral health networks. We're not publishing the site list, but the shape of the results is worth reporting, because it wasn't what the headlines predict.
Note the shape of this. Three years of litigation removed the tag that was in the headlines, and left the one that carries most of the traffic data: half the sample was still sending page-level behavior to a company that states plainly it will not sign a BAA.
The three ways to solve this
There are only three real architectures. Everything on the market is a variation of one of them.
One vendor, one contract, one place the data lives.
The BAA covers the filter, not the destination.
No vendor to sign, so the compliance work is all yours.
Option 1: Replace the tool
Swap Google Analytics for an analytics platform that signs a BAA and holds the data under that agreement. One vendor, one contract, one place the data lives.
Good for: organizations that want the compliance question closed rather than managed, and teams without engineering capacity to babysit a data pipeline.
Trade-off: you leave the Google ecosystem for site analytics. Campaign tracking still works through UTM parameters, but native GA-to-Google-Ads audience sharing is not part of the deal, by design, because that sharing is the thing creating the exposure.
Option 2: Keep the tool, govern the data
Leave Google Analytics and the ad pixels in place and put a compliance layer in front of them that strips or masks identifiers before data reaches the destination. Freshpaint is the best-known example. Geonetric's Privacy Filter takes a similar shape from the agency side.
Good for: organizations with heavy investment in Google and Meta advertising infrastructure that they are unwilling to unwind, and enterprise budgets.
Trade-off: you are paying to keep tools that will never sign a BAA, and the filter is now a single point of failure carrying your compliance posture. Concord Hospital's proposed settlement names Google Analytics and Geonetric, a healthcare web agency's technology, side by side as tracking tools on the hospital's site. That is an allegation, not a finding, and it says nothing about whether a filter failed. It does show how a vendor's own tooling lands in the complaint next to the analytics tag.
To be fair to the category: Freshpaint does sign a BAA, and says so plainly. The question is what that signature covers. Ask any filter vendor: your BAA covers your service. What covers the destination? The honest answer is nothing, because Google will not sign one. That may still be the right trade for an organization with tens of millions in Google and Meta spend. It is a different decision from the one a regional health system with a five-person marketing team is making.
Option 3: Self-host
Run an open-source analytics platform on infrastructure you control. Matomo is the common choice, and its own documentation says that with self-hosting, compliance is the operator's job, because Matomo never touches the data.
Good for: organizations with a real infrastructure team, an appetite for owning encryption, access control, audit logging, patching and backups, and a security review process that can sign off on all of it.
Trade-off: you have not removed the compliance work, you have hired it. Matomo also states that its hosted Cloud service is not HIPAA compliant, so the self-hosted route is the only Matomo-branded path, and the operational burden is real and permanent.
The comparison
Everything below was checked against each vendor's own public pages in September 2026. Where a vendor doesn't publish something, we say so rather than guessing. Prices change; verify before you sign.
| Tool | Signs a BAA? On which plan | Published price | Hosting | Heatmaps / session recording | Tag manager | Built for |
|---|---|---|---|---|---|---|
| Google Analytics 4 | NoNoneGoogle states it does not offer BAAs for the service. | Free | No | Google Tag Manager, not on Google's BAA-covered list | General web | |
| Ghost MetricsThat's us | YesEvery plan, including StarterStandard BAA ready to sign on every plan. Minor redlines on Premium, custom terms on Enterprise. | $299 / $399 / $499 per month, Enterprise custom | US-hosted, each customer's data logically isolated | Premium and up | Yes | Healthcare marketing sites |
| Piwik PRO | Higher tierEnterprise onlyIts HIPAA page and help center say the BAA comes with the free trial and the Enterprise plan. Its pricing page marks the entry Enterprise tier, Data Fundamentals, as not including HIPAA support. | Business from €36/mo; Enterprise from €366/mo billed annually | US hosting on Enterprise only. Business is EU-operated hosting in Sweden | Yes | Yes | General, with a healthcare practice |
| Freshpaint | YesTier not publishedSays plainly on its own site that it signs a BAA. Which tiers include it is not published. | Not published. Comply, Perform and Scale tiers, all "Talk to Sales" | Not published | On higher tiers | n/a, governs data in transit | Healthcare marketing and ad activation |
| Matomo (self-hosted) | NoNone offeredIts HIPAA FAQ says you will not need to sign a BAA with Matomo because it does not host your data. | Community free; Team €275/mo; Business €1,450/mo; Enterprise €3,400/mo, billed annually | Yours | Yes, paid plugin | Yes | Teams with infrastructure |
| Matomo Cloud | NoNoneThe same FAQ states that Matomo Cloud is not HIPAA compliant. | From €29/mo excl. tax | Matomo, Frankfurt, Germany | Yes | Yes | General web |
| Microsoft Clarity | NoNone publishedIts terms say not to use it with content that may contain health care information. | Free | Microsoft | Yes, this is its core function | No | General web |
| Hotjar (now Contentsquare) | NoNone publishedNo BAA or HIPAA statement on Hotjar or Contentsquare pages. Hotjar is closed to new signups; new accounts go through Contentsquare. | Contentsquare free tier plus paid | Contentsquare | Yes | No | General web |
| Plausible | NoNonePlausible states plainly that it is not HIPAA compliant and does not offer a BAA. | $9 / $14 / $19 per month at 10k pageviews, scaling with volume | EU only | No | No | Privacy-conscious general web |
| Fathom | NoNoneNo HIPAA or BAA offering found on usefathom.com in September 2026, and its terms bar tracking personal data. Not the AI notetaker of the same name. | $15 / $25 / $45 per month at 100k / 200k / 500k pageviews | AWS for non-EU traffic; EU traffic kept on EU infrastructure. No region published | No | No | Privacy-conscious general web |
| Mixpanel | Higher tierEnterprise onlyIts HIPAA page offers the BAA to Enterprise plan customers. | Free tier, then custom | Mixpanel | Session replay | No | Product teams |
| Amplitude | Higher tierOn request via salesAmplitude says it can enter a BAA. Which plans qualify is not published. | Free tier, then custom | Amplitude | Session replay | No | Product teams |
| PostHog | Higher tierBoost ($250/mo) and aboveIts HIPAA docs: BAAs only for Boost, Scale or Enterprise, not the free or pay-as-you-go plan. AI features are carved out of the BAA and have to be switched off. | Free tier, usage-based, then Boost $250/mo, Scale $750/mo | US Cloud in Virginia, EU Cloud in Frankfurt | Yes | No | Product and engineering teams |
Every tool whose only price is free publishes no BAA. On a healthcare site, free tools are the ones most likely to appear in a complaint.
Piwik PRO, Mixpanel and PostHog all sign, and every one gates it behind a higher tier. Amplitude signs too, but doesn't publish which plans qualify. Piwik PRO's documentation puts the BAA on the free trial and the Enterprise plan, US hosting is Enterprise too, and its pricing page marks the entry Enterprise tier as not including HIPAA support, so the €36 Business tier isn't the product you'd be buying. If you're a three-location dental group, "yes" is frequently not a yes at your budget.
A roundup that lists Piwik PRO at €36 and calls it BAA-backed has combined two facts that don't go together. It's how a marketing director ends up in a budget meeting defending a number that was never real.
Searching for Fathom and HIPAA surfaces at least three unrelated companies, including an AI meeting notetaker that does publish a BAA page. The web analytics product is usefathom.com, and it has no HIPAA offering. If a listicle tells you Fathom signs a BAA, check which Fathom.
Mixpanel, Amplitude and PostHog will sign, and they are strong products built to answer questions about feature adoption inside an application. A hospital marketing team wants service-line traffic, campaign attribution, appointment funnels and a board report. You can force it, but you'll be building what the other category ships.
Listicles put Matomo in the HIPAA-compliant column without qualification. Matomo's own FAQ is clearer: it does not sign a BAA because it does not host your data, and Matomo Cloud is not HIPAA compliant. Self-hosted Matomo can be operated compliantly. That is a statement about you, not about Matomo.
Which raises the question this guide has been circling: if self-hosting is a legitimate path, why buy anything? Because self-hosting moves the work rather than removing it. Someone owns the servers, the encryption, the access controls, the audit logs, the patching, the backups and the security review, permanently. Organizations with an infrastructure team and a security function can carry that. A five-person marketing team at a regional health system cannot, and shouldn't pretend otherwise to save a subscription. That gap is the entire reason managed, BAA-backed platforms exist, ours included.
How to prove marketing works without tracking individuals
The objection that stops most of these projects isn't legal. It's a CFO asking why the marketing budget should survive if nobody can say which campaigns produce patients. It's a fair question, and the honest answer is that the individual-level attribution most teams think they have is mostly an illusion anyway. Cross-device journeys break it. Cookie lifetimes break it. Consent gates break it. A patient who sees a billboard, searches your brand three weeks later on a phone, and books from a laptop is credited to direct traffic on every platform you own.
- 01Aggregate funnels
Service-line page to appointment request to confirmed booking, as counts and rates by week. The number leadership actually asks about, and it does not require knowing who anyone is.
- 02Campaign attribution through UTM parameters
UTMs travel in the URL. No third-party cookie, identity graph or ad-platform pixel needed. You lose the remarketing audience. You keep the ability to say which campaign drove bookings.
- 03Holdout and geography tests
Run the campaign in four markets and not in three comparable ones, then compare booking volume. A better measure of incremental lift than last-click attribution ever was.
- 04Call tracking with the recording turned off
Phone is still how a large share of appointments get booked. Unique numbers per campaign give you attribution without capturing anything about the caller.
- 05Your own booking system
The conversion that matters already lives in a system you control and already have a BAA for. The ad platform's number is a worse number reported by a party with an interest in the answer.
How to evaluate a vendor in one meeting
Ten questions. Any vendor worth buying answers all ten without a follow-up call.
- Will you sign a BAA on the specific plan we are buying? Get the tier in writing.
- Can we see the BAA before we commit? Watch for vendors who will only show it after a signature elsewhere.
- Where is the data physically stored, and how is our data separated from other customers' data?
- Do you hold a BAA with your own hosting provider? A vendor with no upstream BAA has a gap it cannot close.
- Is any customer data used for advertising, model training, benchmarking or resale? Get a no in writing.
- What identifiers are stripped, at what point, and can you show us the before and after?
- Do you have a SOC 2 Type II report, and will you share it under NDA? SOC 2 is not HIPAA, but its absence tells you about operational maturity.
- What is your breach notification process and timeline?
- If we leave, what happens to our historical data, and in what format do we get it?
- Who installs it, and what does the install actually look like on our site?
A migration checklist
If you're switching, this is the sequence that avoids a gap in the data and an argument with legal. Start with the inventory: open DevTools on your homepage, an appointment page, a condition page and your portal login, reload, and look in the Network tab for googletagmanager, google-analytics, gtag, doubleclick, connect.facebook.net, tiktok, snapchat, linkedin, bing, clarity.ms, hotjar and criteo. Anatomy of a PHI Leak walks through it screen by screen.
- Inventory every tag currently firing on your homepage, an appointment or contact page, a condition page, and your portal login if it is public.
- Pull the sentence from your own privacy policy that promises confidentiality. Put it next to the network log.
- Export your historical analytics. Whatever you are leaving, get the data out first.
- Write down the five reports you actually use. Most teams use fewer than they think.
- Identify who controls the tag manager. If it is an agency, bring them in now, not after.
- Sign the BAA before real traffic flows. Do not run a trial on live patient traffic without one.
- Install the new snippet alongside the old one for a two-week overlap. Expect a discrepancy: tools count sessions differently.
- Rebuild goals and funnels first, reports second. Conversions are what people ask about.
- Confirm UTM parameters still resolve correctly on your live campaigns.
- Remove the old tags. Actually remove them. A dormant tag is still firing.
- Re-run the DevTools audit on the same four pages and confirm the list is what you expect.
- Document the decision, the date, the BAA, and who approved it. Your governance committee will ask.
- Put a quarterly reminder on someone's calendar to re-audit the tag manager. Every incident in the record started with a tag nobody remembered adding.
Frequently asked questions
Is Google Analytics HIPAA compliant?
No. Google states that it makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with the service. Google also says customers subject to HIPAA must not use Google Analytics in any way that implicates Google's access to or collection of PHI. Because Google will not sign a BAA, no configuration on your side makes it compliant for covered pages.
Does IP anonymization make Google Analytics compliant?
No. IP anonymization reduces one identifier. It does not create a BAA, and the vendor's willingness to sign is the requirement. It is a useful setting on a tool that is already permitted, not a way to permit a tool that is not.
Does server-side tagging solve this?
Not by itself. Server-side Google Tag Manager gives you control over what leaves your infrastructure, which is genuinely useful. But a BAA with the company hosting your server-side container binds that company, not the destination. If the data still lands at Google Analytics, you still have a destination that will not sign. Ask the relay vendor directly whether their BAA covers the destination. It does not.
Do cookie consent banners cover us?
No. Consent under GDPR or CCPA is a different mechanism from HIPAA authorization, and a banner does not create a business associate relationship. HIPAA authorization is specific, written and much narrower than a cookie banner click.
What about the June 2024 court ruling? Didn't that clear things up?
It cleared up one thing. A federal court vacated the portion of the HHS bulletin treating an IP address plus an unauthenticated page visit as protected information. The rest of the bulletin stands, including guidance on authenticated pages and the BAA requirement. More importantly, the large healthcare tracking settlements were brought under state wiretap statutes, medical confidentiality laws and consumer protection law, none of which that ruling touched. This is not legal advice. Talk to your counsel, and ask them specifically about state law exposure.
Two health systems, one month: pixel lawsuits after the AHA ruling
Has HHS ever fined anyone over website tracking?
No, and the vocabulary in the question is worth correcting too. HHS OCR does not issue fines; it enters resolution agreements, which include a settlement amount and a corrective action plan, or it imposes civil money penalties. As of September 2026 it has done neither in a matter premised on website tracking technologies. The nearest thing is a joint OCR and FTC warning letter sent to about 130 organizations in July 2023, which carries no penalty. The financial exposure in this area has come almost entirely from private class actions under state wiretap and privacy law.
Is Matomo HIPAA compliant?
Matomo does not sign a BAA, and states that its hosted Cloud service is not HIPAA compliant. Its position is that self-hosted Matomo does not require a BAA because Matomo never receives your data. That is a coherent position and it is also a transfer of responsibility: self-hosted Matomo can be operated compliantly, but the compliance is yours to build and maintain, not something the software gives you. Any listicle that puts Matomo in a HIPAA-compliant column without that qualifier is telling you something Matomo itself does not claim.
Which analytics tools will sign a BAA on an entry-level plan?
Very few. Most vendors that sign gate it behind an enterprise or higher-tier plan: Piwik PRO on Enterprise, PostHog from its $250 a month Boost package, Mixpanel on Enterprise, and Amplitude only after a conversation with sales. This is the single most common gap between what a comparison chart says and what you can actually buy, and it is why the tier column exists in ours.
We have no budget. What is the minimum responsible thing to do?
Audit what is firing on your appointment and portal pages, remove anything from a vendor that will not sign a BAA, and accept that you will lose some data until you can fund a replacement. Flying blind is bad. Flying blind is still better than an unfunded settlement.
Where to go from here
If you want to see what's currently firing on your own site, the inventory step above costs nothing and takes about ten minutes. Anatomy of a PHI Leak shows you exactly what to look for. If you want to see the product this guide's authors build, pricing is public, the BAA is on every plan, and a demo is one booking away.
This guide is general information about HIPAA and website analytics, not legal advice. Settlement figures and vendor terms were checked against primary sources on September 16, 2026 and are updated monthly. Ghost Metrics is one of the vendors compared.