Resources

 

 

 

2025 Backstage Pass Website

Webinars

Like our conference, these digital marketing webinars and case studies were created to educate leaders in the healthcare industry on emerging Internet technologies and to provide an environment in which healthcare marketers, Web leaders, IT professionals and strategists can learn from the other attendees and presenters.

 

webinars-hero

 

Stay connected by tuning into the latest broadcasts, where strategic leaders share their perspectives on emerging trends and pressing challenges in the healthcare industry. Together, we’ll delve into groundbreaking innovations and pivotal policy updates shaping the future of healthcare.

Catch the audio-only episodes on Touch Point Media, available on your favorite podcast streaming platforms.

 

promo-greymatters

The Latest Hospital Digital Marketing Articles

 GreyMatters is your hospital digital marketing guide, with articles on hospital digital marketing best practices, trends, updates and more.

Why Should Marketers Care About Compliance in Healthcare Analytics?

This article was written by Liz Griffin, Global SVP, Sales, at Piano Analytics. Liz leads the global commercial team for Piano Analytics across North America and Europe, building out Piano's go-to-market motion across healthcare, retail banking and finance, e-commerce, and more. 

photo of Liz Griffin

Healthcare marketers run a similar playbook as other industries: pixels for retargeting, Google Analytics for traffic, Meta for audience building. In healthcare, that standard practice is often a HIPAA violation and liable to an Office for Civil Rights (OCR) fine. 

From 2023 to 2025, U.S. healthcare providers paid over $100 million in penalties tied to tracking pixel violations alone. A page visit about cardiac rehab, a scheduling form filled out by a potential patient, or an IP address that links a name to a diagnosis – all of it can qualify as Protected Health Information (PHI). When that data flows to Meta or Google without a Business Associate Agreement (BAA) – a contract that legally binds your vendor to protect patient data – you've immediately violated HIPAA. 

A 2022 study of the top 100 U.S. hospitals found that one-third used tools like Google Analytics and Meta Pixel that transferred visitor data – including PHI – to third parties. Advocate Aurora Health paid $12.25 million after exposing data from 3 million patients via Meta Pixel. Mass General Brigham settled for $18.4 million. GoodRx paid $25 million for exposing prescription data. 

But compliance is more than just avoiding a fine. It's what lets a patient safely book an appointment without wondering who can find out about – and misuse – their diagnosis. Every unauthorized pixel puts that trust at risk, and increasingly, so does unchecked AI.  

If you use AI to personalize content, understand users deeply, or build lookalike audiences, it needs the same oversight as your tracking pixels. Otherwise, it absorbs PHI just like a pixel does, but in a way that's harder to catch and harder to explain to an auditor. 

Enforcement is accelerating – and marketing is the target 

OCR collected $9.9 million in fines in 2024, a 37% jump from the year before. According to IBM’s 2025 Cost of a Data Breach Report, the average healthcare breach costs $7.42 million – before legal fees and the years of regulatory monitoring that typically follow.  

Non-compliance with regulations adds an average of $173,692 to that figure – and when a breach hits, 86% of organizations experience operational disruption: campaigns pause, teams get pulled into legal response, and patient acquisition stops. And the regulatory pressure keeps building – Oklahoma just became the 20th state to pass comprehensive data privacy legislation, a sign that states aren't waiting for federal action. 

Where most organizations go wrong

The organizations paying the biggest settlements all made the same mistakes: they didn't check how their tools handled patient data before deploying them, didn't have contracts (BAAs) with vendors that protected their data, and weren't asking patients for consent.  

A patient books an appointment, the pixel activates to send data about that action to Meta or Google. When this lands on their servers with no data privacy agreement in place – that's the sequence regulators are targeting. 

What to do next 

Choose platforms that show you exactly which tools are collecting data on your site and what they're capturing on every page patients interact with.

Some vendors will tell you they're HIPAA-compliant but won't put it in writing for your specific setup – always verify before you sign.