Use of Healthcare Related Tracking Technologies

On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a bulletin to highlight the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. OCR administers and enforces the HIPAA Rules, including by investigating breach reports and complaints about regulated entitiesโ€™ noncompliance with the HIPAA Rules. A regulated entityโ€™s failure to comply with the HIPAA Rules may result in a civil money penalty.

The bulletin states, “Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules.”

According to the bulletin, “a tracking technology is a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app. After information is collected through tracking technologies from websites or mobile apps, it is then analyzed by owners of the website or mobile app (โ€œwebsite ownerโ€ or โ€œmobile app ownerโ€), or third parties, to create insights about usersโ€™ online activities.” These insights could be used in beneficial ways to help improve care or the patient experience. However, this tracking information could also be misused to promote misinformation, identity theft, stalking, and harassment.

If your organization is utilizing these technologies, it is important to fully read the entire bulletin.

Since this blog article was posted in December of 2022, a federal court vacated parts of the HHS Office for Civil Rights (OCR) bulletin that classified an IP address combined with visits to unauthenticated public health pages as Protected Health Information. While this struck down the strict guidance, healthcare entities must still navigate strict federal privacy and consumer laws.

Current Legal & Regulatory Reality

  • The Court Ruling: In American Hospital Association v. Becerra, a Texas federal judge ruled that HHS overstepped its authority under HIPAA by treating general website visitor metadata (like IP addresses linked to public unauthenticated webpages) as individually identifiable health information.
  • What Remains in Effect: Healthcare providers are still strictly prohibited from using tracking tools (like pixels or session replay) on authenticated pages (e.g., patient portals) without robust safeguards and Business Associate Agreements (BAAs).

This post was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.