Compliance

HIPAA and GDPR compliant healthcare marketing

How we bring clinics more patients without putting patient data, or your practice, at risk.

Get Your Free Growth Audit

Our approach in short

We market healthcare practices without exposing patient data.

  • Ad platforms never receive patient health information.
  • Tracking runs server-side and sends only the minimum event data needed to measure bookings.
  • We sign a BAA (US) or DPA (EU and UK) where the law requires one.
  • Every ad is written to meet healthcare advertising rules.

HIPAA (United States)

  • No PHI in ad platforms. We do not send diagnoses, conditions, treatments, appointment reasons or other protected health information to Meta, Google or any ad platform.
  • Server-side tracking. Instead of browser pixels on sensitive pages, we use server-side Conversions API setups that send only non-health events (for example "lead" or "booking") with the minimum required data.
  • Business Associate Agreements. Where we create, receive, store or send PHI for a practice, we sign a BAA, and we only use vendors who will sign one too.
  • Minimum necessary. Your CRM holds contact details and enquiry stage, not medical history.

Background: in 2022 the HHS Office for Civil Rights warned that tracking tools can disclose PHI. In June 2024 a Texas federal court (American Hospital Association v. Becerra) vacated part of that guidance for public pages.

Tracking on patient portals and pages that reveal health information still carries HIPAA risk. Read our guide: HIPAA and tracking pixels.

GDPR and UK GDPR (Europe)

  • Lawful basis and consent. Marketing and analytics cookies only with consent where the law requires it.
  • Data Processing Agreements under Article 28 with every client and vendor that processes personal data.
  • Special category data. Health data is treated as special category data: we keep it out of marketing systems wherever possible.
  • Data minimisation and retention limits agreed with each practice.

Healthcare advertising rules

  • Ads written for Meta's and Google's healthcare and medicines policies.
  • Local rules respected, such as the UK CAP Code and Germany's Heilmittelwerbegesetz.
  • No promised medical outcomes and no misleading before-and-after claims.
  • We do not promote services that conflict with our values. See our values.

How this website handles your data

  • A consent banner controls Google Analytics, the Meta Pixel and the Meta Conversions API. In Europe nothing loads until you agree.
  • Umami, our main analytics tool, is cookieless and does not collect personal data.
  • Fonts are self-hosted, so loading the site does not send your data to a font provider.
  • Details are in our privacy policy and cookie policy.

What "HIPAA-aligned" means on our site

There is no official HIPAA certification for agencies. "HIPAA-aligned" and "GDPR-compliant" mean our systems follow the practices above and we sign the agreements the law requires.

Each practice stays responsible for its own compliance program. We recommend a review by your own legal adviser.

This page describes our practices. It is general information, not legal advice.

See where your practice is losing patients

Our free 30-minute growth audit reviews your ads, tracking, landing pages, follow-up and compliance, and shows you what to fix first. No obligation.

Get Your Free Growth Audit