73% of Healthcare Sites Run Ad Trackers That Ignore Opt-Outs
73% of 59 major U.S. hospital and clinic websites were running advertising or marketing trackers even when visitors sent an active Global Privacy Control opt-out signal, according to an independent audit conducted by Verified Data for Piwik PRO. Sixty-nine percent used marketing or advertising cookies, and the narrow gap between the two figures indicates some trackers operate without cookies — meaning cookie-blocking alone does not close the exposure. Scans detected 75 unique tracking tools across the sites, including Google Marketing Platform on 33 domains and Google Analytics on 20. Cumulative healthcare pixel enforcement actions and settlements have exceeded $100 million since 2023.
Marketing leaders at multi-site groups are carrying legal exposure they usually cannot see from inside the ad platform. The practical fix is infrastructure, not policy — enforce opt-out at the tag layer, pull ad pixels off condition and appointment pages, and make BAA availability a hard requirement in vendor selection.
This article appears to be vendor-created or sponsored content. While we appreciate the value of the underlying information, our inclusion of it does not constitute an endorsement of the company itself.
While we aim to share useful and relevant resources, we do not guarantee the accuracy of content on this site or any external links. Views and opinions expressed in referenced content do not necessarily reflect those of Healthcare Growth Strategies.
Do healthcare websites still run ad trackers after a visitor opts out?
In most cases tested, yes. An audit of 59 major U.S. hospital and clinic sites found 73% still had advertising or marketing trackers firing while an active Global Privacy Control signal was present. GPC is a legally recognized opt-out in California and 11 other states, which makes ignoring it at the tag layer difficult to characterize as an accidental misconfiguration.
Can Google Analytics be made HIPAA-compliant?
No. Google does not sign business associate agreements and explicitly prohibits HIPAA-covered entities from using its services for any purpose involving PHI. Data also flows through Google’s infrastructure under Google’s terms. Adobe Analytics offers BAA arrangements, but only for certain enterprise configurations — the standard implementation does not provide a compliant path.
What counts as PHI on a healthcare marketing website?
More than most marketing teams assume. IP addresses combined with visits to condition-specific pages, URL paths that reveal a service line or physician profile, form-field data captured before submission, behavior inside patient portals, and click IDs such as GCLID or FBCLID that tie health-related actions back to an advertising profile can all qualify.
