This article was written by Liz Griffin, Global SVP, Sales, at Piano Analytics. Liz leads the global commercial team for Piano Analytics across North America and Europe, building out Piano's go-to-market motion across healthcare, retail banking and finance, e-commerce, and more.

Healthcare marketers run a similar playbook as other industries: pixels for retargeting, Google Analytics for traffic, Meta for audience building. In healthcare, that standard practice is often a HIPAA violation and liable to an Office for Civil Rights (OCR) fine.
From 2023 to 2025, U.S. healthcare providers paid over $100 million in penalties tied to tracking pixel violations alone. A page visit about cardiac rehab, a scheduling form filled out by a potential patient, or an IP address that links a name to a diagnosis – all of it can qualify as Protected Health Information (PHI). When that data flows to Meta or Google without a Business Associate Agreement (BAA) – a contract that legally binds your vendor to protect patient data – you've immediately violated HIPAA.
A 2022 study of the top 100 U.S. hospitals found that one-third used tools like Google Analytics and Meta Pixel that transferred visitor data – including PHI – to third parties. Advocate Aurora Health paid $12.25 million after exposing data from 3 million patients via Meta Pixel. Mass General Brigham settled for $18.4 million. GoodRx paid $25 million for exposing prescription data.
But compliance is more than just avoiding a fine. It's what lets a patient safely book an appointment without wondering who can find out about – and misuse – their diagnosis. Every unauthorized pixel puts that trust at risk, and increasingly, so does unchecked AI.
If you use AI to personalize content, understand users deeply, or build lookalike audiences, it needs the same oversight as your tracking pixels. Otherwise, it absorbs PHI just like a pixel does, but in a way that's harder to catch and harder to explain to an auditor.
Enforcement is accelerating – and marketing is the target
OCR collected $9.9 million in fines in 2024, a 37% jump from the year before. According to IBM’s 2025 Cost of a Data Breach Report, the average healthcare breach costs $7.42 million – before legal fees and the years of regulatory monitoring that typically follow.
Non-compliance with regulations adds an average of $173,692 to that figure – and when a breach hits, 86% of organizations experience operational disruption: campaigns pause, teams get pulled into legal response, and patient acquisition stops. And the regulatory pressure keeps building – Oklahoma just became the 20th state to pass comprehensive data privacy legislation, a sign that states aren't waiting for federal action.
Where most organizations go wrong
The organizations paying the biggest settlements all made the same mistakes: they didn't check how their tools handled patient data before deploying them, didn't have contracts (BAAs) with vendors that protected their data, and weren't asking patients for consent.
A patient books an appointment, the pixel activates to send data about that action to Meta or Google. When this lands on their servers with no data privacy agreement in place – that's the sequence regulators are targeting.
What to do next
Choose platforms that show you exactly which tools are collecting data on your site and what they're capturing on every page patients interact with.
Some vendors will tell you they're HIPAA-compliant but won't put it in writing for your specific setup –
always verify before you sign.